PULSE
EN VIVO17señales / 24h
FEED
ransomqilin reclama a Wanted · NL · Not Foundransomsilentransomgroup reclama a R...er · Not Foundransomsilentransomgroup reclama a R... D... · Not Foundransomspacebears reclama a Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano · IT · Agriculture and Food Productionransomgenesis reclama a **E*** · US · Not Foundransomorova reclama a Ganzhou Xinye Craft Co., Ltd. · HK · Manufacturingransompanzer reclama a Xpress Tech · Technologyransomqilin reclama a G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L · IT · Transportationransomqilin reclama a Crown Group · PK · Otherransomdragonforce reclama a QPC Global · GB · Otherransominterlock reclama a AngMar Companies · Not Foundransompayload reclama a B&B Hydraulik · DE · Manufacturingransompayload reclama a Stücheli Architekten · CH · Professional Servicesransompayload reclama a Baya Technologies · Technologyransomqilin reclama a Wanted · NL · Not Foundransomsilentransomgroup reclama a R...er · Not Foundransomsilentransomgroup reclama a R... D... · Not Foundransomspacebears reclama a Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano · IT · Agriculture and Food Productionransomgenesis reclama a **E*** · US · Not Foundransomorova reclama a Ganzhou Xinye Craft Co., Ltd. · HK · Manufacturingransompanzer reclama a Xpress Tech · Technologyransomqilin reclama a G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L · IT · Transportationransomqilin reclama a Crown Group · PK · Otherransomdragonforce reclama a QPC Global · GB · Otherransominterlock reclama a AngMar Companies · Not Foundransompayload reclama a B&B Hydraulik · DE · Manufacturingransompayload reclama a Stücheli Architekten · CH · Professional Servicesransompayload reclama a Baya Technologies · Technology
← Todos los CVEs
CVE Watch30 jul 2026

CVE-2026-20840

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVSS

7.8

Alto

EPSS

4.4%

p90

KEV

Exploit Today

27

0-100

Publicado: 13 ene 2026 · Última mod.: 30 jul 2026 · CWE-122

EPSS · 30d
2.4%EPSS · 30 días4.4%
2026-07-142026-08-11
Descripción técnica

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2024-140436.3 MED
0A vulnerability was determined in Open5GS up to 2.7.1. This vulnerability affects the function mme_s6a_subscription_data_from_avp of the file src/mme/mme-fd-path.c of the component Diameter S6a Interface. Executing a manipulation of the argument msisdn_len can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.7.2 is able to resolve this issue. This patch is called 7ea82cb87bb65c3694d8d7c7a5efed1c4d3c9304. Upgrading the affected component is recommended.12h
CVE-2026-73242
0FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using it with RRC in IOV pointer offsets, allowing a malicious RDP peer to trigger out-of-bounds reads and in-place writes during CredSSP/NLA Kerberos decryption. This issue is fixed in version 3.30.0.16h
CVE-2026-713318.1 ALT
0Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.7h
CVE-2026-703477.8 ALT
0Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.14h
CVE-2026-703457.8 ALT
0Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.14h
CVE-2026-703306.7 MED
0Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.14h