These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-42977 is a high-severity elevation of privilege vulnerability in Windows Push Notifications. An authorized attacker could exploit this vulnerability to elevate privileges locally. The vulnerability is caused by a concurrent execution using shared resource with improper synchronization, also known as a race condition.
CVE-2026-42974 is a HIGH severity vulnerability in Windows Performance Monitor that allows an unauthorized attacker to execute code over a network. The vulnerability is caused by an integer underflow (wrap or wraparound) and has a CVSS score of 8.1. The vulnerability affects various versions of Windows 11 and Windows Server.
CVE-2026-42973 is a medium-severity vulnerability in Windows Push Notifications that allows an authorized attacker to disclose information locally. The vulnerability has a CVSS score of 5.5 and is classified as CWE-200. It was published on 2026-06-09T17:17:13.013Z and last modified on 2026-06-10T19:54:11.160Z.
CVE-2026-42972 is a MEDIUM severity vulnerability with a CVSS score of 5.5. It allows an authorized attacker to disclose information locally in Windows Hyper-V. The vulnerability was published on 2026-06-09T17:17:12.810Z and modified on 2026-06-10T19:55:47.920Z.
CVE-2026-42971 is a medium-severity vulnerability in Windows Push Notifications that allows an authorized attacker to disclose information locally. The vulnerability has a CVSS score of 5.5 and is classified as CWE-200. It was published on 2026-06-09T17:17:12.650Z and last modified on 2026-06-11T19:52:35.303Z.
CVE-2026-42970 is a medium-severity vulnerability in Windows Push Notifications that allows an authorized attacker to disclose information locally. The vulnerability has a CVSS score of 5.5 and is classified as CWE-200. It was published on 2026-06-09T17:17:12.463Z and last modified on 2026-06-11T19:52:51.250Z.
CVE-2026-42969 is a medium-severity vulnerability in Windows Push Notifications that allows an authorized attacker to disclose information locally. The vulnerability has a CVSS score of 5.5 and is classified as CWE-908: Use of Uninitialized Resource. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server.
CVE-2026-42968 is a MEDIUM severity vulnerability with a CVSS score of 5.5. It was published on 2026-06-09 and modified on 2026-06-11. The vulnerability is an out-of-bounds read in the Windows Telephony Service, which allows an authorized attacker to disclose information locally. The Common Vulnerability Scoring System (CVSS) vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N. The weakness is classifi [truncated]
CVE-2026-42916 is a HIGH severity vulnerability in the Windows NT OS Kernel. An integer underflow (wrap or wraparound) allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-42916).
CVE-2026-42915 is a vulnerability in Windows TCP/IP that allows an authorized attacker to deny service over an adjacent network. The vulnerability has a CVSS score of 5.7 and a severity of MEDIUM. It was published on 2026-06-09T17:17:11.780Z and modified on 2026-06-11T19:52:04.170Z.
CVE-2026-42914 is a MEDIUM severity vulnerability in Windows Kerberos, which can cause a Denial of Service (DoS). The vulnerability has a CVSS score of 5.3 and was published on 2026-06-09T17:17:11.593Z. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server.
CVE-2026-42913 is a high-severity vulnerability in Microsoft Remote Desktop Client, allowing unauthorized attackers to execute code over a network via a heap-based buffer overflow. The vulnerability has a CVSS score of 7.5 and is considered HIGH. It was published on 2026-06-09 and last modified on 2026-06-17. Affected products include Remote Desktop Client and various Windows versions. Users should apply [truncated]
CVE-2026-42912 is a HIGH severity vulnerability in Windows Telephony Service. It is caused by a race condition, which is a type of concurrency issue that occurs when multiple processes or threads try to access a shared resource without proper synchronization. This vulnerability allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7 and a CVSS severity of HIGH.
CVE-2026-42911 is a HIGH severity vulnerability in Windows Ancillary Function Driver for WinSock. The vulnerability is caused by a use-after-free issue, which allows an authorized attacker to elevate privileges locally. The CVSS score for this vulnerability is 7.0, with a CVSS vector of CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.
CVE-2026-42910 is a HIGH severity vulnerability in Windows Hotpatch Monitoring Service that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-42910) 2026-06-09. The vulnerability affects multiple versions of Windows 11 and Windows Server 2025.
CVE-2026-42909 is a high-severity vulnerability in the Remote Desktop Client that allows an unauthorized attacker to execute code over a network. The vulnerability is caused by a heap-based buffer overflow and has a CVSS score of 7.5.
CVE-2026-42908 is a high-severity vulnerability in Windows RDP that allows unauthorized attackers to disclose information over a network. The vulnerability has a CVSS score of 7.5 and is classified as HIGH. It was published on 2026-06-09 and last modified on 2026-06-17. The vulnerability affects multiple versions of Windows, including Windows 10, Windows 11, and Windows Server. Microsoft has provided a ve [truncated]
CVE-2026-42907 is a MEDIUM severity vulnerability with a CVSS score of 6.5. It was published on 2026-06-09T17:17:10.450Z and modified on 2026-06-11T19:23:50.633Z. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server.
CVE-2026-42906 is a MEDIUM severity vulnerability (CVSS Score: 5.5) in Windows Shell that allows an authorized attacker to disclose information locally. The vulnerability was published on 2026-06-09T17:17:10.310Z and last modified on 2026-06-11T16:13:37.987Z.
CVE-2026-42905 is a use-after-free vulnerability in the Windows DWM Core Library. This vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. An authorized attacker can exploit this vulnerability locally to elevate privileges.
CVE-2026-42904 is a critical vulnerability in Windows TCP/IP that allows an unauthorized attacker to elevate privileges over an adjacent network. The vulnerability has a CVSS score of 9.6 and is classified as CRITICAL.
CVE-2026-42903 is a vulnerability in Windows Kerberos that allows an authorized attacker to deny service over a network. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. It was published on 2026-06-09T17:17:09.800Z and modified on 2026-06-11T16:17:05.920Z.
CVE-2026-42837 is a HIGH severity vulnerability in the Windows Projected File System Filter Driver. A buffer over-read issue exists that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8.
CVE-2026-42836 is a HIGH-severity vulnerability in Microsoft Windows, with a CVSS score of 7. The vulnerability is caused by a concurrent execution using shared resource with improper synchronization, also known as a race condition, in the Function Discovery Service (fdwsd.dll). This allows an authorized attacker to elevate privileges locally.
CVE-2026-42828 is a HIGH severity vulnerability in the Windows Projected File System Filter Driver. A buffer over-read issue exists that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8.
CVE-2026-41108 is a heap-based buffer overflow vulnerability in Microsoft Windows DNS that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7 and a severity of HIGH. It was published on 2026-06-09T17:17:06.920Z and modified on 2026-06-11T17:03:34.950Z.
CVE-2026-41092 is a HIGH severity vulnerability with a CVSS score of 7.8. It was published on 2026-06-09T17:17:06.597Z and modified on 2026-06-11T17:04:49.490Z. The vulnerability is related to improper access control in Microsoft Kinect, which allows an authorized attacker to elevate privileges locally. The Common Vulnerability Scoring System (CVSS) vector for this vulnerability is CVSS:3.1/AV:L/AC:L/PR:L [truncated]
CVE-2026-40409 is a HIGH severity Elevation of Privilege vulnerability in the Windows Universal Disk Format File System Driver (UDFS). The vulnerability has a CVSS score of 7.8 and was published on 2026-06-09T17:17:06.417Z. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server.
CVE-2026-40404 is a HIGH severity Elevation of Privilege vulnerability in the Windows Universal Disk Format File System Driver (UDFS). The vulnerability has a CVSS score of 7.8 and was published on 2026-06-09T17:17:06.240Z. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server.
CVE-2026-34335 is a HIGH severity vulnerability in Windows Ancillary Function Driver for WinSock. The vulnerability is caused by a use-after-free issue, which allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7 and was published on 2026-06-09T17:17:05.117Z.