CVE-2026-42828
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.
CVSS
7.8
High
EPSS
0.3%
p25
KEV
—
Exploit Today
8
0-100
Published: Jun 9, 2026 · Last modified: Jul 23, 2026 · CWE-126
0.3%EPSS · 30 days0.3%
2026-08-172026-09-14
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-906103.3 LOW1.9%
——1A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegraph/svg_attributes.c of the component MP4Box. Performing a manipulation results in buffer over-read. The attack is only possible with local access. The exploit has been made public and could be used. Upgrading to version abi-16.23 mitigates this issue. The patch is named afca1f1181668d85941d51ed1adf647807d5d975. Upgrading the affected component is recommended.19hCVE-2026-76653—22.4%
——7A missing
authentication vulnerability in the VPN configuration management has been
identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker
may be able to access and modify VPN configuration information without valid
credentials.
Successful
exploitation may allow a remote unauthenticated attacker to disclose and modify
VPN configuration information.4dCVE-2026-839515.5 MED33.5%
——10Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.7dCVE-2026-839495.5 MED33.5%
——10Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.7dCVE-2026-813995.5 MED31.9%
——10Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.6dCVE-2026-785164.3 MED41.4%
——12Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack.5d