CVE-2026-59137
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
CVSS
5.5
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 11, 2026 · Last modified: Aug 11, 2026 · CWE-908
Not enough EPSS history yet.
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-703175.5 MED—
———Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.15hCVE-2026-687995.5 MED—
———Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.12hCVE-2026-627405.5 MED—
———Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.11hCVE-2026-627095.5 MED—
———Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.11hCVE-2026-591365.5 MED—
———Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.11hCVE-2026-582475.3 MED—
——0SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensitive data from previously used memory, leading to a low on confidentiality, with no impact on integrity and availability of the application.18h