From Our Security Partners
CVE-2026-40374 Microsoft Power Automate Desktop Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.
CVE-2026-34333 Windows Win32k Elevation of Privilege Vulnerability
Use after free in Windows Win32K – GRFX allows an authorized attacker to elevate privileges locally.
CVE-2026-40405 Windows TCP/IP Denial of Service Vulnerability
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
CVE-2026-34342 Windows Print Spooler Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
CVE-2026-40410 Windows SMB Client Elevation of Privilege Vulnerability
Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally.
CVE-2026-34343 Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges locally.
CVE-2026-40419 Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-34344 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Access of resource using incompatible type (‘type confusion’) in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-41094 Microsoft Data Formulator Remote Code Execution Vulnerability
Improper control of generation of code (‘code injection’) in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network.
CVE-2026-34345 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.