Windows Vulnerabilities

10 advisories affecting Windows

10

Total CVEs

7

Critical

3

High

CVE-2026-30903

Mar 11, 2026

Critical (9.6)

External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access....

Read Advisory

CVE-2026-23669

Mar 10, 2026

High (8.8)

Use after free in Windows Print Spooler Components allows an authorized attacker to execute code over a network....

Read Advisory

CVE-2026-28391

Mar 5, 2026

Critical (9.8)

OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests, allowing attackers to bypass command approval restrictions. Remote attack...

Read Advisory

CVE-2026-25673

Mar 3, 2026

High (7.5)

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django calls `urllib.parse.urlsplit()`, which performs NFKC normalization on Windows th...

Read Advisory

CVE-2026-2999

Mar 2, 2026

Critical (9.8)

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary executable files from ...

Read Advisory

CVE-2026-3000

Mar 2, 2026

Critical (9.8)

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary DLL files from a remot...

Read Advisory

CVE-2025-30411

Feb 20, 2026

Critical (10.0)

Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (...

Read Advisory

CVE-2025-30412

Feb 20, 2026

Critical (10.0)

Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (...

Read Advisory

CVE-2025-30416

Feb 20, 2026

Critical (10.0)

Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Li...

Read Advisory

CVE-2026-2542

Feb 16, 2026

High (7.0)

A weakness has been identified in Total VPN 0.5.29.0 on Windows. Affected by this vulnerability is an unknown functionality of the file C:\Program Files\Total VPN\win-service.exe. Executing a manipula...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.