VulnSea

CWE-416

CVEs classified under CWE-416, newest first.

1092 CVEsRSS

CVE-2026-73022High· 7.0
2w ago

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.26%via NVD
CVE-2026-73010Critical· 9.8
2w ago

Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.

Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · windows_10_1809EPSS 0.97%via NVD
CVE-2026-73009Critical· 9.8
2w ago

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · windows_10_1607EPSS 0.97%via NVD
CVE-2026-73005High· 7.0
2w ago

Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.20%via NVD
CVE-2026-73003High· 7.0
2w ago

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.26%via NVD
CVE-2026-72987High· 8.1
2w ago

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.71%via NVD
CVE-2026-72983Critical· 9.8
2w ago

Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.

Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · windows_10_1607EPSS 0.97%via NVD
CVE-2026-72981High· 8.1
2w ago

Use after free in IP Helper allows an unauthorized attacker to execute code over a network.

Use after free in IP Helper allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.71%via NVD
CVE-2026-72979Critical· 9.8
2w ago

Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · windows_10_1607EPSS 0.97%via NVD
CVE-2026-72965High· 7.8
2w ago

Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally.

Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-72963High· 7.0
2w ago

Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally.

Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.26%via NVD
CVE-2026-72954High· 7.5
2w ago

Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.

Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.66%via NVD
CVE-2026-72943High· 7.5
2w ago

Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.

Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.66%via NVD
CVE-2026-72936High· 8.1
2w ago

Use after free in Windows SMB Client allows an unauthorized attacker to execute code over a network.

Use after free in Windows SMB Client allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_11_23h2EPSS 0.71%via NVD
CVE-2026-72930High· 7.0
2w ago

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally.

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.26%via NVD
CVE-2026-72928High· 7.5
2w ago

Use after free in Windows DNS allows an authorized attacker to execute code over a network.

Use after free in Windows DNS allows an authorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_server_2025EPSS 0.66%via NVD
CVE-2026-72926High· 7.0
2w ago

Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally.

Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.26%via NVD
CVE-2026-71342High· 7.0
2w ago

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.26%via NVD
CVE-2026-71340High· 7.0
2w ago

Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.

Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.26%via NVD
CVE-2026-71333High· 7.0
2w ago

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.26%via NVD
CVE-2026-71332High· 7.0
2w ago

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.26%via NVD
CVE-2026-70585High· 7.0
2w ago

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally.

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally.

▾ Twilightmicrosoft · windows_server_2012EPSS 0.26%via NVD
CVE-2026-70582Medium· 6.4
2w ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.22%via NVD
CVE-2026-70577High· 7.0
2w ago

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.26%via NVD
CVE-2026-70570High· 7.5
2w ago

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

▾ Twilightmicrosoft · windows_10_1607EPSS 0.69%via NVD
CVE-2026-70565High· 7.0
2w ago

Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker to elevate privileges locally.

Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.26%via NVD
CVE-2026-70342High· 8.1
2w ago

Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network.

Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.71%via NVD
CVE-2026-69989High· 8.1
2w ago

Use after free in DNS Server allows an unauthorized attacker to execute code over a network.

Use after free in DNS Server allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.71%via NVD
CVE-2026-69911High· 7.0
2w ago

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.26%via NVD
CVE-2026-69896High· 7.0
2w ago

Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_11_24h2EPSS 0.26%via NVD
CWE-416 vulnerabilities (CVEs) — page 7 · VulnSea