Desktop Window Manager Information Disclosure
CVE-2026-20805Actively exploited zero-day allowing attackers to read memory addresses from remote ALPC port. Added to CISA KEV catalog.
Windows LSASS Remote Code Execution
CVE-2026-20854Critical RCE vulnerability in Local Security Authority Subsystem Service allowing remote attackers to execute arbitrary code.
Microsoft Office Remote Code Execution
CVE-2026-20952Critical remote code execution vulnerability in Microsoft Office suite.
Windows Graphics Component EoP
CVE-2026-20822Critical elevation of privilege vulnerability in Windows Graphics Component.
Microsoft Excel Remote Code Execution
CVE-2026-20957Critical RCE in Excel allowing code execution through malicious spreadsheet files.
VBS Enclave Elevation of Privilege
CVE-2026-20876Critical elevation of privilege in Windows Virtualization-Based Security enclave.
Chrome ANGLE Out-of-Bounds Memory Access
CVE-2025-14174Out-of-bounds memory access in ANGLE graphics library actively exploited in the wild. Buffer overflow in Metal renderer could lead to code execution.
Windows Secure Boot Certificate Expiration
CVE-2026-21265Secure Boot certificates from 2011 nearing expiration. Systems not updated have increased risk of Secure Boot bypass attacks.
Agere Modem Driver Privilege Escalation
CVE-2023-31096Vulnerable third-party modem drivers exploited to gain admin privileges. Microsoft has removed agrsm64.sys and agrsm.sys in January 2026 update.