CVE-2026-50441
Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
CVSS
7.8
High
EPSS
0.3%
p26
KEV
—
Exploit Today
8
0-100
Published: Jul 14, 2026 · Last modified: Jul 22, 2026 · CWE-822
0.2%EPSS · 30 days0.3%
2026-08-182026-09-14
Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-908905.5 MED—
——0ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating system crash.2dCVE-2026-339646.4 MED0.8%
——0An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs when a malformed message is sent to the camera driver, causing limited information disclosure or denial of service.1dCVE-2026-839398.2 HIG22.2%
——7Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.5dCVE-2026-834987.8 HIG23.0%
——7Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.5dCVE-2026-800838.8 HIG13.5%
——4Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code locally.5dCVE-2026-784516.8 MED37.1%
——11Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.4d