CVE-2026-67368
Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a netw
CVSS
8.8
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 8 sept 2026 · Última mod.: 8 sept 2026 · CWE-59
Sin historial EPSS suficiente todavía.
Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-786226.0 MED—
———The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents.4hCVE-2026-839997.0 ALT—
———Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.7hCVE-2026-819637.8 ALT—
———Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.6hCVE-2026-705638.1 ALT—
———Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.7hCVE-2026-697714.7 MED—
———Improper link resolution before file access ('link following') in Windows Container Manager Service allows an authorized attacker to bypass a security feature locally.6hCVE-2026-694254.7 MED—
———Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to perform tampering locally.6h