CVE-2026-50314 Microsoft
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated July 14, 2026
CVE-2026-50327 Microsoft
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Windows 11 Version 24H2 for ARM64-based Systems · Windows 11 Version 24H2 for x64-based Systems · +6 more
Updated July 14, 2026
CVE-2026-50370 Microsoft
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +13 more
Updated July 14, 2026
CVE-2026-50380 Microsoft
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
CVSS 9.6
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +25 more
Updated July 14, 2026
CVE-2026-50382 Microsoft
Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +17 more
Updated July 14, 2026
CVE-2026-50392 Microsoft
Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 11 Version 24H2 for ARM64-based Systems · Windows 11 Version 24H2 for x64-based Systems · +6 more
Updated July 14, 2026
CVE-2026-50444 Microsoft
Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +13 more
Updated July 14, 2026
CVE-2026-50467 Microsoft
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated July 14, 2026
CVE-2026-50474 Microsoft
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +25 more
Updated July 14, 2026
CVE-2026-50518 Microsoft
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVSS 9.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +13 more
Updated July 14, 2026
CVE-2026-50680 Microsoft
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
CVSS 8.2
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +17 more
Updated July 14, 2026
CVE-2026-50694 Microsoft
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
CVSS 8.1
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +25 more
Updated July 14, 2026
CVE-2026-54121 Microsoft
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +13 more
Updated July 14, 2026
CVE-2026-54127 Microsoft
Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.
CVSS 7.4
Update availability Security update available Affected: Windows 11 Version 24H2 for ARM64-based Systems · Windows 11 Version 24H2 for x64-based Systems · +7 more
Updated July 14, 2026
CVE-2026-54982 Microsoft
Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +25 more
Updated July 14, 2026
CVE-2026-54992 Microsoft
Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.
CVSS 8.4
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +25 more
Updated July 14, 2026
CVE-2026-54995 Microsoft
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
CVSS 8.1
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +25 more
Updated July 14, 2026
CVE-2026-54999 Microsoft
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +25 more
Updated July 14, 2026
CVE-2026-55008 Microsoft
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVSS 9.6
Update availability Security update available Affected: Microsoft Exchange Server 2016 Cumulative Update 23 · Microsoft Exchange Server 2019 Cumulative Update 14 · +2 more
Updated July 14, 2026
CVE-2026-55010 Microsoft
Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
CVSS 9.8
Update availability Patch status unknown Affected: Minecraft Bedrock Dedicated Server
Updated July 14, 2026
CVE-2026-55011 Microsoft
Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Patch status unknown Affected: Microsoft Malware Protection Engine
Updated July 14, 2026
CVE-2026-55012 Microsoft
Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Patch status unknown Affected: Microsoft Malware Protection Engine
Updated July 14, 2026
CVE-2026-55018 Microsoft
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated July 14, 2026
CVE-2026-55022 Microsoft
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated July 14, 2026