The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.
For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
Legal Disclaimer:
Here is where you can read the NVD legal disclaimer.
-
CVE-2026-58631 - Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
Published: July 14, 2026; 1:17:13 PM -0400 -
CVE-2026-58635 - Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
Published: July 14, 2026; 1:17:13 PM -0400 -
CVE-2026-58636 - Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.
Published: July 14, 2026; 1:17:13 PM -0400 -
CVE-2026-58640 - Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Published: July 14, 2026; 1:17:14 PM -0400V3.1: 7.8 HIGH
-
CVE-2026-58647 - Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.
Published: July 14, 2026; 1:17:14 PM -0400V3.1: 5.4 MEDIUM
-
CVE-2026-49177 - Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.
Published: July 14, 2026; 2:17:23 PM -0400 -
CVE-2026-58545 - Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.
Published: July 14, 2026; 2:18:42 PM -0400 -
CVE-2026-58626 - Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
Published: July 14, 2026; 2:18:44 PM -0400 -
CVE-2026-58627 - Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: July 14, 2026; 2:18:44 PM -0400V3.1: 7.5 HIGH
-
CVE-2026-58628 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.
Published: July 14, 2026; 2:18:44 PM -0400 -
CVE-2026-58629 - Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
Published: July 14, 2026; 2:18:45 PM -0400 -
CVE-2026-58632 - Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Published: July 14, 2026; 2:18:45 PM -0400 -
CVE-2026-58637 - Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
Published: July 14, 2026; 2:18:45 PM -0400V3.1: 7.0 HIGH
-
CVE-2026-58638 - Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
Published: July 14, 2026; 2:18:46 PM -0400V3.1: 5.5 MEDIUM
-
CVE-2026-50321 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.
Published: July 14, 2026; 2:17:30 PM -0400V3.1: 7.0 HIGH
-
CVE-2026-50322 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
Published: July 14, 2026; 2:17:31 PM -0400 -
CVE-2026-58538 - Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
Published: July 14, 2026; 2:18:41 PM -0400 -
CVE-2026-58539 - Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Published: July 14, 2026; 2:18:41 PM -0400V3.1: 7.5 HIGH
-
CVE-2026-58540 - Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
Published: July 14, 2026; 2:18:41 PM -0400 -
CVE-2026-58541 - Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.
Published: July 14, 2026; 2:18:41 PM -0400