2026 · High

High-severity vulnerabilities disclosed in 2026

High-rated CVEs published in 2026, with SEC.co remediation and prioritization guidance.

4140 published vulnerabilities · page 20 of 42

  • CVE-2026-12958HIGH 7.8

    Language Servers for AWS contain a flaw in how they validate symbolic links (symlinks). When a local user opens a workspace containing a maliciously crafted symlink, an attacker can trick the application into writing arbitrary files to locations outside the intended workspace boundary. This bypasses the trust controls that should prevent such access. An attacker would need local access to the machine and user interaction to open the malicious workspace, but successful exploitation could result in unauthorized file creation or modification on the system.

  • CVE-2026-13037HIGH 7.8

    A use-after-free memory flaw was discovered in Google Chrome's WebView component on Android devices. An attacker could craft a malicious HTML page that, when opened by a user, exploits this flaw to run arbitrary code within Chrome's sandbox. The vulnerability affects Chrome versions before 149.0.7827.197 and requires local access plus user interaction (opening a webpage), but once triggered, grants the attacker the ability to execute code with the privileges of the Chrome process.

  • CVE-2026-13079HIGH 7.8

    A flaw in WatchGuard's Mobile VPN with SSL client for Windows lets someone with regular user access on an affected machine escalate their privileges to full system control. An attacker already on the machine—whether a disgruntled employee, someone who gained access through another vulnerability, or a local contractor—could exploit this to gain administrator-level permissions and take over the system. The issue affects all versions of the client up to and including 2026.2.

  • CVE-2026-13126HIGH 7.8

    A flaw in Foxit PDF Editor and Foxit PDF Reader allows an attacker to craft a malicious PDF file containing embedded JavaScript that deletes pages from the document. This deletion renders the PDF's internal structure invalid. When the application subsequently tries to write data to pop-up annotations within that corrupted file, it crashes. The vulnerability requires user interaction (opening the malicious PDF) but can lead to denial of service and potential information disclosure or modification depending on what data is in memory at the time of the crash.

  • CVE-2026-13127HIGH 7.8

    A vulnerability in PDF handling software allows attackers to crash an application by crafting a malicious PDF file that exploits how JavaScript modifies document structure. When a user opens the affected PDF, JavaScript code rewrites the internal page layout, invalidating the page objects that the application relies on. However, thumbnail previews continue to reference these now-invalid objects, causing the application to crash. This is a local attack requiring user interaction—an attacker must trick someone into opening a specially crafted PDF file.

  • CVE-2026-13128HIGH 7.8

    A vulnerability in Foxit PDF Editor and PDF Reader allows an attacker to craft a malicious PDF file containing embedded JavaScript that triggers a page deletion, causing the application to crash. The vulnerability requires user interaction (opening the PDF) but does not require special privileges. An attacker could use this to disrupt work or as part of a broader attack chain, though the primary impact is denial of service through application instability.

  • CVE-2026-13129HIGH 7.8

    A vulnerability in PDF processing applications allows attackers to crash the program by crafting a malicious PDF file with a corrupted field tree structure. When the application opens the file and JavaScript attempts to access form fields, it ends up holding a reference to an invalid object, eventually causing the application to read from an invalid memory location and crash. This is a local attack that requires user interaction—the victim must open the malicious PDF—but successful exploitation denies service and could mask further system compromise attempts.

  • CVE-2026-13778HIGH 7.8

    A use-after-free vulnerability exists in Google Chrome's WebUSB implementation on macOS. When a user connects a malicious USB peripheral while Chrome is running, an attacker can trigger memory corruption that leads to arbitrary code execution with the privileges of the logged-in user. The flaw affects Chrome versions prior to 150.0.7871.47 on Mac systems and requires the user to interact with the malicious device; it cannot be exploited remotely.

  • CVE-2026-13800HIGH 7.8

    Google Chrome on Windows has a flaw in its automatic updater that allows a local attacker to gain elevated system privileges by tricking a user into opening a malicious file. The vulnerability requires the attacker already has local system access and user interaction (such as opening a file), but once triggered, it can lead to complete system compromise. This is a high-severity issue affecting Chrome versions prior to 150.0.7871.47.

  • CVE-2026-13827HIGH 7.8

    A use-after-free flaw in Chrome's Updater component on macOS allows a local attacker with standard user permissions to escalate privileges by tricking a user into opening a malicious file. The vulnerability exists in Chrome versions prior to 150.0.7871.47. While exploitation requires local access and user interaction, successful exploitation grants full system-level capabilities on the affected machine.

  • CVE-2026-13844HIGH 7.8

    Google Chrome on Windows contains a use-after-free vulnerability in its updater component that allows a local attacker to escalate privileges to the OS level. An attacker would need to trick a user into opening a malicious file, after which the flaw in Chrome's update mechanism can be exploited to run code with system privileges. This affects Chrome versions prior to 150.0.7871.47.

  • CVE-2026-13863HIGH 7.8

    A vulnerability in Google Chrome's CustomTabs feature on Android allows a local attacker to gain elevated system privileges by tricking a user into opening a malicious file. The flaw stems from inadequate validation of user-supplied input, meaning Chrome doesn't properly check file contents before processing them through CustomTabs. An attacker with local device access could craft a specially-designed file that, when opened, breaks out of Chrome's normal security boundaries and executes with higher privileges.

  • CVE-2026-13927HIGH 7.8

    Google Chrome on Android contains a flaw in how it validates user-provided input within its user interface. A local attacker who can place a specially crafted file on an affected device and convince a user to interact with it could gain elevated privileges on the device. This is a local privilege escalation vulnerability that requires the attacker to already have some presence on the device and user interaction to succeed.

  • CVE-2026-14018HIGH 7.8

    A use-after-free flaw in Chrome's Updater component on Windows allows a local attacker to escalate to full system-level privileges by delivering a specially crafted file. The vulnerability requires user interaction (such as opening a file) but no special permissions to exploit. Once triggered, an attacker gains complete control over the compromised system. Google has assigned this a Medium severity rating in Chromium but the CVSS score reflects high severity due to the combination of complete system compromise and the realistic attack vector for Windows users.

  • CVE-2026-14060HIGH 7.8

    A flaw in Chrome's Chromoting component on Windows allows a local attacker to gain elevated privileges by opening a specially crafted file. The vulnerability stems from insufficient validation of untrusted input. To exploit this, an attacker must already have access to the target machine and user interaction is required—the victim must open the malicious file. Chrome versions prior to 150.0.7871.47 are affected.

  • CVE-2026-14094HIGH 7.8

    A use-after-free memory vulnerability exists in Google Chrome's installer on Windows systems. An attacker with local access can exploit this flaw by providing a malicious file to cause Chrome to access memory that has already been freed, leading to a crash or potentially arbitrary code execution with elevated system privileges. This is a local attack requiring user interaction (such as opening or installing a malicious file), not a remote exploitation vector.

  • CVE-2026-14124HIGH 7.8

    Google Chrome on Windows contains a flaw in how it handles credential provider operations that could allow a local attacker to escalate their privileges to system or administrator level by tricking a user into interacting with a specially crafted file. The vulnerability requires user interaction but no special privileges to exploit, making it a practical attack vector for malware or local attackers seeking elevated access.

  • CVE-2026-14191HIGH 7.8

    WinRAR and UnRAR contain a critical memory corruption vulnerability in how they handle RAR5 recovery volume sets (.rev files). When processing multiple recovery files together, the software fails to properly validate file boundaries, allowing an attacker to write malicious data to unintended memory locations. An attacker can exploit this by providing a crafted set of recovery files that, when a user attempts to repair or test an archive, corrupt the application's internal data structures. This can lead to information disclosure, data corruption, or potential code execution depending on what adjacent objects occupy the corrupted memory.

  • CVE-2026-14605HIGH 7.8

    RT-Thread versions up to 5.0.2 contain a stack-based buffer overflow vulnerability in the CAN (Controller Area Network) handler for Loongson LS1C devices. The flaw exists in the recvmsg function within the ls1c_can.h library component and can be exploited by a local attacker to corrupt memory on the stack, potentially leading to privilege escalation, data theft, or system compromise. An attacker must already have local system access to trigger the vulnerability, which significantly narrows the threat surface but remains serious in embedded or IoT deployment contexts where physical or administrative access may be easier to obtain.

  • CVE-2026-14606HIGH 7.8

    RT-Thread versions up to 5.0.2 contain a stack-based buffer overflow vulnerability in the SWM341 CAN (Controller Area Network) handler component. An attacker with local access and standard user privileges can trigger a buffer overflow through the CAN_Receive function, potentially allowing arbitrary code execution or system crash. The vulnerability is particularly concerning because exploit code has already been publicly released, making active exploitation more likely.

  • CVE-2026-20455HIGH 7.8

    CVE-2026-20455 is a local privilege escalation vulnerability in MediaTek's geniezone component affecting a wide range of SoC firmware versions. An attacker who already holds system-level privileges can exploit a missing bounds check in memory write operations to escalate their access further. The vulnerability requires no user interaction and impacts dozens of MediaTek chipset families used in Android devices and embedded systems.

  • CVE-2026-2049HIGH 7.8

    GIMP contains a heap buffer overflow vulnerability in its HDR file parser that can lead to remote code execution. When a user opens a malicious HDR file or is tricked into visiting a compromised page hosting one, an attacker can overflow a memory buffer and execute arbitrary code with the privileges of the user running GIMP. The vulnerability requires user interaction but poses significant risk to creative professionals and any organization using GIMP for image processing workflows.

  • CVE-2026-2050HIGH 7.8

    GIMP, the widely-used open-source image editor, contains a vulnerability in how it processes HDR (High Dynamic Range) image files. When a user opens a specially crafted malicious HDR file, an attacker can exploit improper input validation to overflow a memory buffer and execute arbitrary code on the affected system. This is a local attack that requires user interaction—an attacker cannot exploit it remotely without social engineering a user to open a malicious file.

  • CVE-2026-21029HIGH 7.8

    A flaw in Samsung's Galaxy Editing Service allows a local attacker with basic user privileges to gain elevated access and control on affected devices. The vulnerability stems from improper export of application components, meaning internal functions that should remain private are exposed to other apps. An attacker already with local access can exploit this to perform privileged operations without needing to trick a user or rely on any special conditions. This is fixed in the June 2026 Samsung Monthly Security Release (SMR).

  • CVE-2026-21030HIGH 7.8

    A flaw in MediaTek's Audio Hardware Abstraction Layer (HAL) component fails to properly restrict access to audio-related privileged functions. An attacker with local access to an affected device can bypass these controls and execute operations that should require higher permissions. This vulnerability affects Samsung Android devices and requires the attacker to already have some level of access to the device, but once exploited, grants significant control over the audio system and potentially other sensitive device functions.

  • CVE-2026-21031HIGH 7.8

    AppBlock, a Samsung Android security component, contains an authorization flaw that allows a local attacker to launch arbitrary activity on an affected device. The vulnerability requires user interaction to trigger—for example, the user must perform an action or accept a prompt that inadvertently enables the attack. While the flaw is local-only (not remotely exploitable), it grants the attacker significant control over the device once activated.

  • CVE-2026-21379HIGH 7.8

    CVE-2026-21379 is a memory corruption vulnerability affecting Qualcomm wireless and compute platforms. The flaw occurs when the system attempts to allocate memory with sizes exceeding safe limits, potentially allowing a local attacker with basic user privileges to compromise system confidentiality, integrity, and availability. While exploitation requires local access and standard user rights, the impact scope is significant—an attacker can read sensitive data, modify system state, or crash the device.

  • CVE-2026-22926HIGH 7.8

    Omnissa Workspace ONE Assist for macOS contains a local privilege escalation vulnerability that allows an authenticated user with standard privileges to gain elevated system access. An attacker already present on a macOS system could exploit this flaw to escalate their permissions without requiring user interaction, potentially compromising the entire system and its data.

  • CVE-2026-22927HIGH 7.8

    Omnissa Workspace ONE Tunnel for Windows contains a local privilege escalation vulnerability that allows a logged-in user to gain elevated system permissions. An attacker with standard user access can exploit this flaw without requiring user interaction or network access, making it a direct path to administrative control of affected Windows systems. This is particularly concerning in environments where Workspace ONE is deployed for secure remote access and device management.

  • CVE-2026-24064HIGH 7.8

    Waves Central for macOS has a serious local privilege escalation flaw in versions 13.0.9 through 16.5.5. An attacker with access to a user account on an affected Mac can inject malicious code into a trusted Waves process by manipulating how the system loads libraries, then escalate to root privileges. This vulnerability is fixed in version 16.6.2 and should be treated as urgent by any organization running Waves audio production software on macOS.

  • CVE-2026-24155HIGH 7.8

    NVIDIA's NeMo Framework contains a code injection vulnerability that allows an attacker with local access and limited user privileges to execute arbitrary code on affected systems. The vulnerability is rooted in unsafe handling of code execution paths, enabling attackers to escalate privileges, steal sensitive data, or modify system information. This is a significant risk for organizations running NeMo-based machine learning applications, particularly in research and production environments where model training or inference occurs.

  • CVE-2026-24221HIGH 7.8

    NVIDIA's NVTabular library contains a deserialization vulnerability that could allow an authenticated attacker to execute arbitrary code, modify data, or steal sensitive information. The vulnerability is rated HIGH severity and requires local system access and valid user credentials to exploit. While not currently listed as actively exploited, this flaw merits prompt attention given the potential for code execution on systems processing sensitive machine learning datasets.

  • CVE-2026-24228HIGH 7.8

    NVIDIA NeMo Framework for Linux has a vulnerability that allows an attacker with local access to execute arbitrary code by providing specially crafted data that the application deserializes without validation. This could give an attacker elevated privileges, the ability to modify data, or access to sensitive information. The vulnerability requires the attacker to already have local user-level access to the system.

  • CVE-2026-24237HIGH 7.8

    NVIDIA NVTabular is vulnerable to unsafe deserialization of untrusted data. An attacker with local access and basic user privileges could exploit this flaw to execute arbitrary code, modify data, or steal sensitive information from systems running the affected software.

  • CVE-2026-24240HIGH 7.8

    NVIDIA Megatron Bridge for Linux has a security flaw that allows attackers to execute arbitrary code on affected systems by tricking them into processing malicious data. An attacker without special permissions can exploit this vulnerability if a user interacts with a specially crafted file or input, potentially taking full control of the system, stealing sensitive data, or modifying files. The vulnerability affects the deserialization process—how the application reconstructs data from storage—and is rated as HIGH severity.

  • CVE-2026-24242HIGH 7.8

    NVIDIA's Megatron Bridge for Linux has a vulnerability that lets an attacker trick the server into making unintended network requests on its behalf. This type of flaw, known as server-side request forgery (SSRF), could allow an attacker to access sensitive information that the server can reach but the attacker normally could not. The vulnerability requires local access and user interaction to exploit, making it a meaningful but not trivial threat to systems running vulnerable versions.

  • CVE-2026-24243HIGH 7.8

    NVIDIA's Megatron Bridge for Linux has a flaw that allows attackers to execute malicious code on affected systems by tricking them into processing untrusted data. The vulnerability requires local access and user interaction, but successful exploitation could give an attacker full control over the system, access to sensitive information, and the ability to modify or delete data. This is a significant risk for organizations running NVIDIA's deep learning infrastructure components.

  • CVE-2026-24244HIGH 7.8

    NVIDIA Megatron Bridge for Linux is vulnerable to unsafe deserialization, where an attacker can trick the software into processing malicious data. If successful, an attacker could run arbitrary code on the affected system, steal sensitive information, modify data, or gain elevated privileges. The vulnerability requires local access and user interaction (such as opening a malicious file), but poses significant risk to systems where Megatron Bridge processes untrusted input.

  • CVE-2026-24245HIGH 7.8

    NVIDIA's Megatron Bridge for Linux contains a deserialization vulnerability that could allow an attacker to execute arbitrary code on an affected system. The vulnerability requires local access and user interaction—an attacker cannot exploit it remotely. If successfully exploited, the impact is severe: an attacker could run commands with the privileges of the affected user, tamper with data, steal sensitive information, or escalate privileges further. This is a local attack surface, meaning the threat actor must already have a presence on the target machine or trick a user into opening a malicious file.

  • CVE-2026-24246HIGH 7.8

    NVIDIA's Megatron Bridge for Linux has a flaw that allows attackers to execute arbitrary code on affected systems. The vulnerability stems from improper handling of dynamically managed code resources, meaning an attacker could manipulate how the system loads and runs code. A user must interact with a malicious element to trigger the attack, but no special privileges are required. Successful exploitation could lead to complete system compromise, including unauthorized code execution, privilege escalation, unauthorized data access, and data modification.

  • CVE-2026-24247HIGH 7.8

    NVIDIA's Megatron Bridge for Linux has a serious flaw that allows attackers to trick the software into processing malicious data. When an attacker sends specially crafted input, the application deserializes it without proper validation, potentially giving the attacker the ability to run code on the affected system, steal sensitive information, modify data, or gain elevated privileges. The vulnerability requires user interaction (such as opening a file or clicking a link) but no authentication.

  • CVE-2026-24248HIGH 7.8

    NVIDIA's Megatron Bridge for Linux has a flaw that lets an attacker manipulate how code is generated on a system. If exploited, this could allow unauthorized code execution, privilege escalation, data modification, or theft of sensitive information. The vulnerability requires local access and user interaction to trigger, but the potential damage spans multiple security domains.

  • CVE-2026-24249HIGH 7.8

    NVIDIA's Megatron Bridge for Linux has a flaw that allows an attacker with local access to inject malicious data into the application, leading to arbitrary code execution. Because the vulnerable code doesn't properly validate serialized data before processing it, a local user can exploit this to run commands with the same privileges as the application, steal sensitive information, or modify data on the system.

  • CVE-2026-24250HIGH 7.8

    NVIDIA Megatron Bridge for Linux has a vulnerability that fails to properly validate user inputs, potentially allowing an attacker with local access to execute code, gain elevated privileges, tamper with data, or steal sensitive information. The vulnerability requires an authenticated user on the system to exploit, but once triggered, the impact is severe.

  • CVE-2026-24251HIGH 7.8

    NVIDIA's Megatron Bridge for Linux has a vulnerability that allows an attacker with local access to execute arbitrary code and gain elevated privileges on affected systems. The flaw stems from improper handling of dynamic code resources, which could let an authenticated user manipulate how the system manages executable code in memory. This is a serious issue for any organization running machine learning workloads that rely on Megatron optimization frameworks.

  • CVE-2026-25260HIGH 7.8

    A memory corruption vulnerability in Qualcomm firmware and associated devices allows a local, authenticated attacker to corrupt memory by modifying shared buffers concurrently without the system validating those changes. This is a time-of-check-time-of-use (TOCTOU) style flaw where kernel or firmware code assumes a buffer's contents remain unchanged, but a malicious user-mode process modifies it between the check and actual use. The vulnerability requires local access and valid credentials but can lead to complete system compromise.

  • CVE-2026-25271HIGH 7.8

    A memory corruption vulnerability exists in multiple Qualcomm chipsets and firmware components when handling asynchronous input parameters. The flaw stems from a classic time-of-check to time-of-use (TOCTOU) race condition where data is validated at one point but then modified before being used, allowing an attacker with local access to corrupt memory and potentially execute code with elevated privileges. This affects a broad range of Qualcomm wireless, audio, and modem components commonly found in enterprise and consumer devices.

  • CVE-2026-25551HIGH 7.8

    Seagull Software BarTender versions 2021 R1 through 12.0.1 contain a flaw that allows local users with standard privileges to gain system-level access. The vulnerability stems from how BarTender's system service handles incoming network requests—it trusts serialized data without proper validation, allowing an attacker to craft malicious requests that execute code with the highest Windows privileges. Because the vulnerable service only listens on the local machine, an attacker must already have a local user account to exploit it, but once inside, they can escalate to full system control.

  • CVE-2026-25865HIGH 7.8

    Punto Switcher, a keyboard input utility, has a local privilege escalation vulnerability in versions up to 4.5.0.583. The application calls a Windows system function (RunDll32.exe) without specifying its full file path. An attacker with local access can create a malicious file with that name and place it in a location that Windows searches before the legitimate system directory. When Punto Switcher runs, it will execute the attacker's file instead, allowing arbitrary code execution under the user's privileges.

  • CVE-2026-27788HIGH 7.8

    ServerView Agents for Windows versions up to 11.60.04 contain a privilege escalation vulnerability rooted in improper file or resource permissions. Any local user with valid credentials on the affected server can exploit this flaw to gain SYSTEM-level access, effectively taking complete control of the system. The vulnerability requires no user interaction and affects all Windows deployments running the vulnerable software versions.

  • CVE-2026-28577HIGH 7.8

    A vulnerability in Android's window management system allows a locally authenticated attacker to perform a tapjacking attack—placing hidden overlay windows on top of legitimate applications to intercept user input or actions. This attack doesn't require user interaction to trigger and can result in unauthorized privilege escalation. The attacker needs only local access to the device (such as through an installed app), making it a practical threat in real-world scenarios.

  • CVE-2026-28580HIGH 7.8

    CVE-2026-28580 is a local privilege escalation vulnerability affecting Google Android. An attacker with basic user-level access to a device can exploit an incorrect bounds check in multiple persistence-related functions to gain elevated privileges without requiring additional capabilities or interaction from the user. The issue stems from a synchronization problem that allows the attacker to manipulate persistent data in an unexpected way, ultimately escalating their permissions on the system.

  • CVE-2026-28615HIGH 7.8

    CVE-2026-28615 is a local privilege escalation vulnerability in Google Android's Telecomm component that allows an attacker with limited user-level access to bypass permission checks and initiate unauthorized phone calls. The vulnerability requires no user interaction and no special execution privileges beyond standard app permissions, making it straightforward to exploit once an attacker gains initial device access.

  • CVE-2026-32325HIGH 7.8

    ServerView Agents for Windows contains a privilege escalation flaw that allows an already-authenticated local user to gain SYSTEM-level access. This is not a remote attack—the attacker must have legitimate credentials and local login capability on the affected server. However, once inside, they can elevate to the highest privilege level, potentially taking full control of the system.

  • CVE-2026-32652HIGH 7.8

    Dell AIOps Collector versions before 1.18.3 ship with hardcoded or default credentials that a local attacker can exploit to gain broad filesystem access. The vulnerability only affects new installations; systems that have been patched or upgraded to 1.18.3 or later are protected, regardless of their original version. This is a local-only attack requiring console access—remote exploitation is not possible.

  • CVE-2026-33828HIGH 7.8

    A security flaw in Windows Attestation allows an authorized user on a Windows system to bypass security boundaries and gain elevated privileges without requiring interaction or elevated starting permissions. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server. An attacker who already has local access to a system can exploit this to run code with higher privileges, potentially compromising the entire system.

  • CVE-2026-34695HIGH 7.8

    Adobe InDesign versions 21.3, 20.5.3 and earlier contain a stack-based buffer overflow vulnerability that could allow an attacker to execute arbitrary code on a victim's computer. An attacker would need to trick a user into opening a malicious file—there is no remote exploitation vector. The vulnerability affects InDesign on both Windows and macOS systems.

  • CVE-2026-34696HIGH 7.8

    Adobe InDesign versions 21.3, 20.5.3 and earlier contain a Use After Free memory vulnerability that allows attackers to execute arbitrary code on a user's computer. The flaw requires a user to open a specially crafted malicious file—there is no remote attack vector. Once triggered, an attacker gains full control of the application and can read, modify, or delete user data, install malware, or pivot to other systems with the privileges of the logged-in user.

  • CVE-2026-34697HIGH 7.8

    Adobe InDesign Desktop has a stack-based buffer overflow flaw that allows attackers to run arbitrary code on your computer if you open a malicious file. The vulnerability affects InDesign version 21.3, 20.5.3, and earlier on both Windows and macOS. It requires user interaction—the attacker must trick you into opening a crafted document—but once triggered, the code runs with your user privileges. This is a serious issue because InDesign documents are commonly shared and trusted, making social engineering attacks plausible.

  • CVE-2026-34698HIGH 7.8

    Adobe InDesign Desktop contains a memory handling flaw that allows attackers to execute arbitrary code on a user's computer if the user opens a specially crafted file. The vulnerability affects InDesign versions 21.3, 20.5.3 and earlier on both Windows and macOS systems. While the flaw is serious, exploiting it requires social engineering or file delivery—an attacker cannot trigger it remotely over the network.

  • CVE-2026-34699HIGH 7.8

    Adobe InDesign Desktop contains a heap memory vulnerability that could allow an attacker to execute arbitrary code on a victim's computer. The flaw exists in versions 21.3, 20.5.3, and earlier on both Windows and macOS. An attacker would need to trick a user into opening a specially crafted file—such as an InDesign document—to trigger the vulnerability. If successful, the attacker gains the same permissions as the logged-in user, potentially enabling data theft, malware installation, or lateral movement within a network.

  • CVE-2026-34700HIGH 7.8

    Adobe InDesign versions 21.3, 20.5.3 and earlier contain a memory vulnerability that allows an attacker to execute arbitrary code on a victim's computer. The attack requires social engineering—a user must be tricked into opening a malicious file. Once opened, the flaw allows the attacker to run code with the same privileges as the InDesign user, potentially compromising the entire system. This is a serious but not trivial threat: it requires user interaction and affects only specific InDesign versions, but the payoff for an attacker is significant.

  • CVE-2026-34701HIGH 7.8

    Adobe InDesign Desktop has a memory safety flaw that allows attackers to execute arbitrary code on a victim's machine by crafting a malicious document. When an unsuspecting user opens the file in InDesign 21.3, 20.5.3, or earlier versions, the vulnerability is triggered, giving the attacker the same privileges as the user running InDesign. This is a serious risk for design teams and publishers who regularly work with untrusted or externally-sourced documents.

  • CVE-2026-34702HIGH 7.8

    Adobe InDesign versions 21.3, 20.5.3 and earlier contain a stack-based buffer overflow flaw that allows attackers to execute arbitrary code with the privileges of the user running InDesign. The vulnerability requires social engineering—an attacker must trick a user into opening a specially crafted file. Once opened, the malicious file triggers the overflow and grants the attacker code execution on the victim's machine. This affects both Windows and macOS deployments of InDesign.

  • CVE-2026-34706HIGH 7.8

    Adobe InCopy, a professional editorial software tool, contains a vulnerability that allows attackers to execute malicious code on a user's system when the user opens a specially crafted file. The flaw stems from improper memory handling (out-of-bounds write) that can be exploited to gain full control of the affected system under the privileges of the logged-in user. Affected versions include InCopy 21.3, 20.5.3, and earlier releases. The attack requires social engineering—convincing a user to open a malicious document—but once successful, the impact is severe.

  • CVE-2026-34707HIGH 7.8

    Adobe InCopy versions 21.3, 20.5.3 and earlier contain a memory safety flaw that allows attackers to execute arbitrary code on affected systems. The vulnerability is triggered when a user opens a specially crafted malicious file, making it a file-based attack vector that relies on social engineering or document distribution. The flaw exists in how InCopy handles memory allocation during file parsing, creating conditions where an attacker-controlled payload can overwrite adjacent heap memory and gain code execution privileges.

  • CVE-2026-34708HIGH 7.8

    Adobe InCopy versions 21.3, 20.5.3 and earlier contain a stack-based buffer overflow flaw that could allow an attacker to execute arbitrary code with the privileges of the user running the application. The vulnerability requires an attacker to trick a user into opening a specially crafted malicious file, making it a user-interaction-dependent threat. InCopy is Adobe's collaborative editing companion to InDesign, widely used in publishing and design workflows, so this affects organizations relying on these tools for content creation and layout work.

  • CVE-2026-34709HIGH 7.8

    Adobe Substance3D Sampler versions 6.0.0 and earlier contain a memory corruption flaw that could allow attackers to execute arbitrary code on a victim's computer. The vulnerability requires a user to open a specially crafted malicious file, making social engineering the primary attack vector. Once exploited, an attacker gains the same privileges as the logged-in user, potentially compromising sensitive design assets, credentials, or system access.

  • CVE-2026-34710HIGH 7.8

    Adobe Substance3D Sampler versions 6.0.0 and earlier contain a flaw that allows attackers to execute arbitrary code on a user's computer. The vulnerability is triggered when a user opens a specially crafted malicious file in the application. Once the file is opened, an attacker gains the ability to run code with the same privileges as the logged-in user, potentially compromising design assets, stealing credentials, or pivoting to other systems on the network.

  • CVE-2026-36213HIGH 7.8

    Microvirt MEmu Android Emulator version 9.2.7.0 contains a local privilege escalation vulnerability in its MemuService.exe component. An attacker with standard user-level access on a system running this emulator version can exploit an improper permission or privilege assignment flaw to gain elevated (administrator-level) privileges. This vulnerability requires local access and cannot be exploited remotely.

  • CVE-2026-36574HIGH 7.8

    CactusViewer v2.3.0 contains a DLL hijacking vulnerability that allows an attacker to execute arbitrary code and escalate privileges on a system where the application is installed. The flaw occurs because the application loads dynamic libraries in an unsafe manner, enabling an attacker to place a malicious DLL in a location the application searches before legitimate system libraries. When CactusViewer runs, it loads the attacker's malicious code instead of the legitimate library, granting the attacker the same privilege level as the user running the application.

  • CVE-2026-38950HIGH 7.8

    ESA AnomalyMatch versions before 1.3.1 contain a critical flaw that allows attackers with local system access to run malicious code by uploading specially crafted model checkpoint files. The vulnerability stems from the application's use of unsafe deserialization when loading PyTorch model files, which can execute arbitrary Python code during the loading process. An attacker who can place a malicious model file in the session directories—or trick a user into loading one—gains the ability to execute commands with the privileges of the AnomalyMatch process.

  • CVE-2026-38972HIGH 7.8

    Notepad3 versions up to 6.25.822.1 contain a DLL search-order hijacking flaw that allows a local attacker to inject malicious code. When a user opens the About dialog, the application attempts to load a library file (MSFTEDIT.DLL) by name alone, without specifying a full path. An attacker who can write files to the application's directory or to other locations Windows searches for DLLs can plant a malicious version and achieve arbitrary code execution under the user's privileges. This is a classic privilege-escalation and code-execution vector that requires local file-system access but no special user privileges to exploit.

  • CVE-2026-39822HIGH 7.8

    CVE-2026-39822 is a symlink-following vulnerability in Go's file handling on Unix systems. When opening a file through Go's os.Root abstraction, the system incorrectly follows symbolic links that point outside the intended root directory if the path ends with a forward slash. For example, attempting to open "symlink/" will follow the symlink even if it targets a location outside the root boundary. This allows a local attacker with user-level privileges to read, modify, or delete files they should not have access to.

  • CVE-2026-40290HIGH 7.8

    OP-TEE is a trusted execution environment that provides a secure processing space on Arm-based processors. A race condition in OP-TEE versions 3.16.0 through 4.10.x creates a use-after-free vulnerability in the shared memory management code. The vulnerability occurs when OP-TEE is configured to manage secure partitions (a specific operational mode). A local user could exploit this by timing concurrent operations on shared memory to cause the system to access memory that has already been freed, potentially compromising the confidentiality, integrity, or availability of the secure environment.

  • CVE-2026-40404HIGH 7.8

    A flaw in Windows' Universal Disk Format (UDF) file system driver allows a logged-in user to gain elevated privileges on their machine. An attacker with basic user access can exploit a memory corruption issue in the UDFS driver to execute code with system-level permissions, potentially taking full control of the affected computer. This is a local-only vulnerability—attackers cannot exploit it remotely—but it represents a significant post-compromise escalation path and a serious risk in multi-tenant or shared-access environments.

  • CVE-2026-40409HIGH 7.8

    A flaw in Windows' Universal Disk Format (UDF) file system driver allows a user with standard local access to gain elevated privileges on their machine. An attacker with a user account can craft specially formatted UDF media or manipulate UDF structures to trigger the vulnerability and execute code with system-level permissions. This is a local elevation-of-privilege issue—it requires prior access to the system but bypasses privilege boundaries to reach administrative capabilities.

  • CVE-2026-40619HIGH 7.8

    A high-severity vulnerability in Genetec Security Center main server installations can allow an attacker who already has local access to the server's operating system to steal the Server Admin credentials. The unusual aspect of this vulnerability is that it affects specific installation builds rather than entire product versions—meaning two installations of the same version number could have different risk levels depending on which build was deployed. There is currently no public evidence that this flaw is being actively exploited in the wild.

  • CVE-2026-40715HIGH 7.8

    Dell ThinOS 10 versions before 2602_10.0765 contain an access control flaw that allows a user with basic system access to gain elevated administrative privileges. An attacker already on the system as a regular user could leverage this vulnerability to take full control, making it a critical privilege escalation risk for any organization relying on ThinOS-based thin clients or endpoints.

  • CVE-2026-41092HIGH 7.8

    A flaw in Microsoft Kinect's access control allows someone who already has local user access to a Windows machine to elevate their privileges to a higher level of system access. This is a local-only attack that requires an attacker to have an existing account on the target system; it cannot be exploited remotely. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server platforms.

  • CVE-2026-41158HIGH 7.8

    A vulnerability exists where a regular (non-privileged) user can exploit a flaw in GPU memory handling to write data to physical memory pages that have been freed by the kernel. The issue stems from improper cleanup of GPU-allocated memory—when pages are freed, the GPU can still access and modify them before they're reassigned. This allows an attacker without administrative rights to corrupt kernel memory or escalate privileges by writing to areas they shouldn't control.

  • CVE-2026-41857HIGH 7.8

    A malicious or compromised BOSH Director can trick operators into executing arbitrary shell commands on their local workstations. When an operator runs standard BOSH CLI commands like bosh ssh, bosh scp, or bosh logs -f, a hostile Director can inject and run commands with the operator's privileges. This affects BOSH CLI versions before 7.10.5 and requires user interaction—the operator must run the vulnerable command—but succeeds with default settings.

  • CVE-2026-41859HIGH 7.8

    BOSH nats-sync, a component that synchronizes NATS authorization data with BOSH director state, fails to validate SSL/TLS certificates when communicating with the BOSH director. An attacker positioned on the network between nats-sync and the director can intercept traffic, steal administrative credentials (HTTP Basic auth headers or UAA client secrets), and modify the list of VMs that nats-sync writes to the NATS authorization file. This combination of credential theft and authorization tampering could grant attackers full administrative control of the BOSH deployment.

  • CVE-2026-42828HIGH 7.8

    A flaw in Windows' Projected File System Filter Driver can allow an authorized user to gain elevated privileges on a local machine. The vulnerability stems from the driver reading beyond intended buffer boundaries, which an attacker with standard user permissions can exploit to escalate to higher privilege levels. This is a local-only issue—an attacker must already have login access to the system.

  • CVE-2026-42829HIGH 7.8

    CVE-2026-42829 is a local privilege escalation vulnerability affecting Windows 11 across multiple update versions. An authenticated user with standard privileges can bypass Windows Administrator Protection—a security boundary designed to restrict administrative actions—through improper access control handling. Exploitation requires local system access and valid credentials, but does not require user interaction. The vulnerability grants an attacker full system-level permissions including read, modify, and delete capabilities.

  • CVE-2026-42837HIGH 7.8

    A flaw in Windows' Projected File System Filter Driver allows a local attacker with basic user permissions to read memory outside of intended boundaries and gain elevated system privileges. The vulnerability requires the attacker to already have local access to the machine—they cannot exploit it remotely over a network. This is a local privilege escalation risk affecting multiple versions of Windows 10, Windows 11, and Windows Server.

  • CVE-2026-42851HIGH 7.8

    Kitty is a popular GPU-accelerated terminal emulator that runs on multiple platforms. A critical design flaw in versions before 0.47.0 allows any untrusted content written to the terminal—such as text from a remote SSH session, a downloaded file, log output, or an email viewed in a pager—to execute arbitrary Python code within kitty's process space with the user's full privileges. This happens silently, with no warnings, permission dialogs, or user interaction required beyond the initial act of viewing the content. The vulnerability is especially dangerous because users often pipe untrusted data to their terminal without suspicion (e.g., viewing logs, reading downloaded files, or reviewing remote output).

  • CVE-2026-42902HIGH 7.8

    Microsoft PowerToys contains an authorization flaw that allows someone with local access and a valid account on a system to gain elevated privileges. An attacker who already has user-level credentials can exploit this design weakness to obtain higher-level permissions, potentially taking full control of the affected system. The vulnerability requires local access and legitimate user credentials to trigger, limiting exposure but creating a meaningful risk in shared or multi-tenant environments.

  • CVE-2026-42905HIGH 7.8

    A use-after-free vulnerability exists in Windows DWM (Desktop Window Manager) Core Library that allows an authorized user on a Windows system to execute code and take control of the machine. The flaw requires the attacker to already have a user account on the system; it cannot be exploited remotely. When successfully exploited, an attacker can gain the highest level of system access (SYSTEM privilege), enabling complete compromise of the device. This is a local privilege escalation vulnerability affecting multiple versions of Windows 10, Windows 11, and Windows Server.

  • CVE-2026-42910HIGH 7.8

    A memory safety flaw in Windows Hotpatch Monitoring Service allows a person with local access and standard user privileges to write data beyond the intended buffer boundaries, potentially gaining elevated system permissions. The vulnerability requires an attacker already logged into the machine, but does not require user interaction once access is obtained.

  • CVE-2026-42916HIGH 7.8

    A flaw in the Windows NT OS kernel allows a person who already has local access to a system to gain elevated privileges—essentially moving from a standard user account to administrator-level control. The vulnerability stems from an integer overflow issue, where a numerical calculation exceeds its intended boundary, potentially corrupting memory or program logic in a way that a local attacker can exploit. This affects a broad range of Windows 10 and Windows 11 versions, as well as Windows Server 2012 through 2025.

  • CVE-2026-42958HIGH 7.8

    CVE-2026-42958 is a use-after-free memory vulnerability in an application that processes files. When a specially crafted file is opened, the application can mishandle memory, leading to memory corruption. An attacker could exploit this to run malicious code with the same privileges as the user running the application. The vulnerability requires local access and user interaction (opening a file), but once triggered, the impact is severe.

  • CVE-2026-42977HIGH 7.8

    A race condition in Windows Push Notifications allows an authorized user on a Windows machine to exploit a timing gap and gain elevated system privileges. An attacker who already has basic user access can trigger this vulnerability locally without needing to interact with the system at a particular moment—the flaw is entirely automated once initiated. This affects multiple versions of Windows 10, Windows 11, and Windows Server.

  • CVE-2026-42978HIGH 7.8

    CVE-2026-42978 is a privilege escalation vulnerability in Windows Push Notifications that affects multiple versions of Windows 10, Windows 11, and Windows Server. An authenticated attacker with local access can exploit a race condition—a timing-based flaw where concurrent operations on a shared resource lack proper synchronization—to gain elevated system privileges. This is a local attack requiring an existing user account, but the consequences are severe: an attacker could gain administrative control of the affected system. The vulnerability is not currently being exploited in the wild according to public disclosures.

  • CVE-2026-42979HIGH 7.8

    A race condition in Windows Push Notifications allows an attacker who already has local access to a computer to gain higher-level privileges. The vulnerability exploits a timing gap in how the notification system handles shared resources, enabling privilege escalation. This is a local attack that requires an authorized user account to initiate, but could allow an attacker to break out of restricted accounts and gain administrative control.

  • CVE-2026-42980HIGH 7.8

    CVE-2026-42980 is a privilege escalation flaw in the Windows NT kernel that allows a user with local access to gain full administrative control of an affected system. The vulnerability stems from an integer underflow condition in memory management code. An attacker who has already logged into the machine can exploit this weakness to run code with the highest privileges, potentially compromising the entire system. This is a serious risk in environments where users share systems or where insider threats are a concern.

  • CVE-2026-42983HIGH 7.8

    A use-after-free flaw exists in Windows Desktop Window Manager (DWM) Core Library that allows an attacker with local system access to escape their privilege level and gain full system control. The vulnerability requires the attacker to already have a foothold on the machine, but once exploited, it grants administrator-level access. This is a classic privilege escalation attack that becomes dangerous when combined with other attack chains—for instance, an attacker who gains initial access through a phishing email or vulnerable web browser can weaponize this flaw to lock down the system permanently.

  • CVE-2026-42986HIGH 7.8

    A use-after-free flaw in Microsoft's Graphics Component allows an authorized local user to escalate their privileges to a higher level of system access. The vulnerability requires the attacker to already have login credentials and local system access, but once exploited can lead to full control of the affected machine. This is a memory safety issue where freed memory is accessed, potentially allowing arbitrary code execution at elevated privilege levels.

  • CVE-2026-42989HIGH 7.8

    CVE-2026-42989 is a local privilege escalation vulnerability in Windows Winlogon—the system component responsible for user authentication and session management. An attacker who already has basic user-level access to a Windows machine can exploit a flaw in how Winlogon resolves file links, allowing them to gain full administrative control. The vulnerability does not require user interaction and affects multiple versions of Windows 10, Windows 11, and Windows Server platforms.

  • CVE-2026-42991HIGH 7.8

    CVE-2026-42991 is a race condition in Windows Push Notifications that allows an authorized local user to escalate their privileges to a higher level of access. The vulnerability requires an attacker who already has login credentials and cannot be exploited remotely. It affects multiple versions of Windows 10, Windows 11, and Windows Server. While the barrier to exploitation is moderate due to timing constraints, the impact is severe—an attacker could gain system-level control.