PatchSiren

Microsoft CVE debriefs · Page 40

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50420

CVE-2026-50420 is a MEDIUM severity vulnerability in Windows HTTP.sys that allows an unauthorized attacker to disclose information locally through an out-of-bounds read. The CVE record was published on 2026-07-14T18:17:45.290Z and was last modified on 2026-07-16T14:16:52.867Z. The NVD entry is currently Awaiting Analysis. This vulnerability affects Windows systems and is classified as CWE-125. The CVSS sc [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50418

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:17:44.990Z and has not been modified since then. This Improper access control vulnerability in Windows System allows an unauthorized attacker to bypass a security feature locally, with a CVSS score of 5.1 and MEDIUM severity. Security teams should assess the vulnerability and apply patches or [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50417

A high-severity vulnerability, CVE-2026-50417, exists in Windows NTFS, allowing an authorized attacker to execute code locally. This heap-based buffer overflow vulnerability has a CVSS score of 7.8 and is considered HIGH severity. The vulnerability affects various versions of Windows 10, Windows 11, and Windows Server. System administrators and security teams should prioritize patching this vulnerability [truncated]

LOW Microsoft CVE published 2026-07-14

CVE-2026-50416

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:17:44.690Z and has not been modified since then. This vulnerability in Windows Win32K allows an authorized attacker to disclose sensitive information locally, with a CVSS score of 3.3 and classified as LOW severity. System administrators and security teams should be aware of this vulnerability [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50415

CVE-2026-50415 is a MEDIUM-severity vulnerability in Windows Media that allows an unauthorized attacker to disclose information over a network. The CVE record was published on 2026-07-14T18:17:44.540Z and was last modified on 2026-07-20T14:04:43.130Z. The vulnerability has a CVSS score of 5.3 and is classified as CWE-200. It affects multiple versions of Windows 10, Windows 11, and Windows Server. Users of [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50414

A high-severity vulnerability, CVE-2026-50414, exists in Windows Media due to a race condition. An authorized attacker can exploit this vulnerability to elevate privileges over a network. This vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. System administrators and users of Windows Media should be aware of this vulnerability and take necessary precautions to prevent exploitation [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50413

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:17:44.287Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability, a use-after-free issue in Windows Runtime, allows an authorized attacker to elevate privileges locally, posing a high severity risk with a CVSS score of 8.8. System administrators and secu [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50412

A HIGH severity vulnerability, CVE-2026-50412, has been identified in Windows NTFS. This vulnerability is a stack-based buffer overflow that can allow an authorized attacker to elevate privileges locally. The CVE record was published on 2026-07-14T18:17:44.110Z and was last modified on 2026-07-20T14:14:09.690Z. The vulnerability has a CVSS score of 7.8 and a CVSS severity of HIGH. The CVSS vector is CVSS: [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50411

A stack-based buffer overflow vulnerability exists in Active Directory Federation Services (AD FS). An unauthorized attacker could exploit this vulnerability to deny service over a network. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. This issue affects AD FS deployments, which may face potential service disruption if exploited. Limited information is available about the v [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50410

CVE-2026-50410 is a high-severity vulnerability in Windows Runtime that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and users are advised to apply it as soon as possible. The vulnerability is a use-after-free issue in Windows Runtime. System administrators and users of [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50407

A heap-based buffer overflow vulnerability exists in the Windows Resilient File System (ReFS). An authorized attacker could exploit this vulnerability to elevate privileges locally on Windows 10, Windows 11, and Windows Server systems. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. The vulnerability is caused by a heap-based buffer overflow in the Windows Resilient File System (ReFS).

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50406

CVE-2026-50406 is a high-severity vulnerability in Windows Backup Engine, caused by a use-after-free issue that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7 and a CVSS severity of HIGH. Microsoft has patched this vulnerability, and system administrators should apply the patch to prevent potential privilege escalation attacks. The vulnerability affect [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50405

CVE-2026-50405 is a HIGH severity vulnerability in Windows Filtering Platform (WFP) with a CVSS score of 7.8. The CVE record was published on 2026-07-14T18:17:43.033Z and was last modified on 2026-07-16T05:16:23.457Z. The NVD entry is currently Awaiting Analysis. The vulnerability has insufficient granularity of access control, allowing an authorized attacker to elevate privileges locally.

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50404

CVE-2026-50404 is a high-severity vulnerability in Windows Media that allows an authorized attacker to elevate privileges locally due to a race condition. The vulnerability affects Windows Media and has a CVSS score of 7, indicating a high severity. The CVE record was published on 2026-07-14T18:17:42.907Z and was last modified on 2026-07-20T17:12:56.700Z. System administrators and users of Windows Media s [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50403

CVE-2026-50403 is a high-severity vulnerability in Windows Runtime that allows an authorized attacker to elevate privileges locally due to a race condition. The vulnerability has a CVSS score of 7 and is classified as HIGH. Microsoft has released a patch for this vulnerability, and users are advised to apply it as soon as possible. The vulnerability affects Windows 11 and Windows Server 2025 systems, and [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50402

CVE-2026-50402 is a HIGH-severity vulnerability in Windows NTFS that allows local privilege escalation. The vulnerability is caused by incorrect conversion between numeric types. An authorized attacker can exploit this vulnerability to elevate privileges locally. This vulnerability affects Windows 10, Windows 11, and Windows Server systems. System administrators should be aware of this vulnerability and a [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50401

CVE-2026-50401 is an out-of-bounds read vulnerability in Windows Cloud Files Mini Filter Driver. An authorized attacker can exploit this vulnerability to disclose information locally. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. This type of vulnerability can allow attackers with local access to gain sensitive information, potentially leading to further exploitation. System administ [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50400

CVE-2026-50400 is a stack-based buffer overflow vulnerability in Windows App Installer. An authorized attacker can exploit this vulnerability to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. This vulnerability affects Windows App Installer and allows an attacker with local access and authorization to elevate privileges. The HIGH severity of the v [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50399

CVE-2026-50399 is an out-of-bounds read vulnerability in the Windows Kernel. An authorized attacker can exploit this vulnerability to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. This vulnerability affects multiple versions of Windows, including Windows 10, Windows 11, and Windows Server. System administrators and users of Windows 10, Windows 11 [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50398

CVE-2026-50398 is a high-severity vulnerability in Windows Media that allows an authorized attacker to elevate privileges over a network. The vulnerability is caused by a race condition in the Windows Media component. Microsoft has released a patch to address this vulnerability. The vulnerability has a CVSS score of 8.8 and is considered high-severity. System administrators and users of Windows Media shou [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50397

CVE-2026-50397 is a high-severity vulnerability in Windows Kernel, allowing an authorized attacker to elevate privileges locally. The vulnerability is caused by a use-after-free issue. Microsoft has released a patch to address this issue. The vulnerability affects Windows 10, Windows 11, and Windows Server systems. System administrators and users should apply the patch to prevent potential privilege escal [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50396

CVE-2026-50396 is a high-severity vulnerability in Windows Kernel-Mode Drivers. An authorized attacker can exploit this use-after-free vulnerability to elevate privileges locally. The vulnerability has a CVSS score of 7 and a CVSS severity of HIGH. Microsoft has released a patch for this vulnerability. System administrators and users of Windows 11 and Windows Server 2025 should be aware of this vulnerabil [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50394

CVE-2026-50394 is a MEDIUM severity vulnerability with a CVSS score of 5.5, affecting Windows Media. An authorized attacker can exploit this vulnerability to disclose information locally. The CVE record was published on 2026-07-14T18:17:41.560Z and has not been modified since. This vulnerability is caused by the exposure of sensitive information to an unauthorized actor in Windows Media. System administra [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50393

CVE-2026-50393 is a high-severity vulnerability in Windows Kernel-Mode Drivers. An authorized attacker can exploit this use-after-free vulnerability to elevate privileges locally. The vulnerability has a CVSS score of 7 and a CVSS severity of HIGH. Microsoft has released a patch for this vulnerability. System administrators and users of Windows 11 and Windows Server 2025 should be aware of this vulnerabil [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50391

CVE-2026-50391 is a HIGH severity vulnerability in Windows Group Policy that allows an authorized attacker to elevate privileges locally. The CVE record was published on 2026-07-14T18:17:41.093Z and was last modified on 2026-07-16T05:16:23.130Z. The NVD entry is currently Awaiting Analysis. This vulnerability is caused by improper privilege management in Windows Group Policy, which can lead to local privi [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50390

CVE-2026-50390 is a HIGH severity vulnerability in Windows Kernel caused by access of resource using incompatible type ('type confusion'). An authorized attacker can exploit this vulnerability to elevate privileges locally. This vulnerability affects Windows 10, Windows 11, and Windows Server products. Users should apply patches immediately to prevent local privilege escalation attacks. The vulnerability [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50389

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:17:40.753Z and has not been modified since then. This MEDIUM severity vulnerability, with a CVSS score of 5.5, allows an authorized attacker to disclose information locally through Windows File Explorer. Defenders should verify configurations and monitor for unauthorized access attempts. The v [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50388

CVE-2026-50388 is an out-of-bounds read vulnerability in Windows NTFS, allowing an unauthorized attacker to execute code locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. Microsoft has released a patch for this vulnerability. The vulnerability affects Windows operating systems and has been assigned a CVSS score of 7.8. System administrators and users should be aware of [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50387

A HIGH severity vulnerability exists in Windows GDI, which could allow an authorized attacker to elevate privileges locally. This CVE record was published on 2026-07-14T18:17:40.390Z and was last modified on 2026-07-16T05:16:22.867Z. The vulnerability is a stack-based buffer overflow in Windows GDI. Administrators and users of Windows systems should be aware of this vulnerability and take necessary precau [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50386

A heap-based buffer overflow vulnerability exists in Windows NTFS, allowing an unauthorized attacker to execute code locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. This type of vulnerability typically occurs when a program writes more data to a buffer than it is designed to hold, causing adjacent memory to be overwritten. In this case, the vulnerability is particula [truncated]