Search

Threats

Active vulnerabilities, exploits, and security alerts

2 Active
9 Tracked
Critical Active
Zero-Day

Desktop Window Manager Information Disclosure

CVE-2026-20805

Actively exploited zero-day allowing attackers to read memory addresses from remote ALPC port. Added to CISA KEV catalog.

Critical Patched
CVE

Windows LSASS Remote Code Execution

CVE-2026-20854

Critical RCE vulnerability in Local Security Authority Subsystem Service allowing remote attackers to execute arbitrary code.

Critical Patched
CVE

Microsoft Office Remote Code Execution

CVE-2026-20952

Critical remote code execution vulnerability in Microsoft Office suite.

Critical Patched
CVE

Windows Graphics Component EoP

CVE-2026-20822

Critical elevation of privilege vulnerability in Windows Graphics Component.

Critical Patched
CVE

Microsoft Excel Remote Code Execution

CVE-2026-20957

Critical RCE in Excel allowing code execution through malicious spreadsheet files.

Critical Patched
CVE

VBS Enclave Elevation of Privilege

CVE-2026-20876

Critical elevation of privilege in Windows Virtualization-Based Security enclave.

Critical Patched
Zero-Day

Chrome ANGLE Out-of-Bounds Memory Access

CVE-2025-14174

Out-of-bounds memory access in ANGLE graphics library actively exploited in the wild. Buffer overflow in Metal renderer could lead to code execution.

High Active
Critical Patch

Windows Secure Boot Certificate Expiration

CVE-2026-21265

Secure Boot certificates from 2011 nearing expiration. Systems not updated have increased risk of Secure Boot bypass attacks.

High Patched
CVE

Agere Modem Driver Privilege Escalation

CVE-2023-31096

Vulnerable third-party modem drivers exploited to gain admin privileges. Microsoft has removed agrsm64.sys and agrsm.sys in January 2026 update.