,

Vulnerability Watch No39

📡 Windows DHCP Client Heap Overflow Enables Privilege Escalation
Patch affected Windows endpoints and servers promptly; privilege-escalation vulnerabilities can turn a limited local compromise into broader system control.
CVE-2026-62736 is a heap-based buffer overflow in the Windows DHCP Client. An authorized local attacker can exploit the flaw to elevate privileges. It is rated HIGH with CVSS 7.8.
🔗 Read more 🔗
Source: NVD

🧠 Browserslist Cache Exhaustion Can Crash Processes
Teams running services where users can influence Browserslist queries should upgrade to 4.28.7 promptly, especially for long-lived or internet-facing processes where memory exhaustion could cause a practical denial of service.
CVE-2026-73089 affects Browserslist prior to 4.28.7 and allows attacker-influenced query values to fill unbounded caches, causing linear memory growth and eventually an out-of-memory process crash. The flaw can bypass the caller-controlled BROWSERSLIST_DISABLE_CACHE mitigation. It is rated HIGH with CVSS 7.5 and is fixed in version 4.28.7.
🔗 Read more 🔗
Source: NVD

🧩 Browserslist Stats Parsing Opens Door to Crashes and Prototype Changes
Upgrade Browserslist to 4.28.7 promptly anywhere browserslist-stats.json, opts.stats, or CLI –stats input can come from untrusted or partially trusted sources.
CVE-2026-73088 affects Browserslist prior to 4.28.7, where normalizeStats() processes untrusted statistics data using an unguarded for…in loop and unsafe plain-object property access. Crafted inherited Object.prototype keys can trigger an uncaught TypeError or alter the prototype of the normalized object. It is rated HIGH with CVSS 7.5 and is fixed in version 4.28.7.
🔗 Read more 🔗
Source: NVD

🔑 Nanoid Integer Bug Can Make Security Tokens Predictable
Applications using nanoid for authentication, session, CSRF, API-key, or other security-sensitive identifiers should patch urgently to 3.3.12 or 5.1.11 as appropriate, particularly if callers can influence the requested ID size.
CVE-2026-73086 affects nanoid before versions 3.3.12 and 5.1.11. A user-influenced size value can overflow during signed 32-bit coercion and corrupt the process-wide CSPRNG poolOffset, causing later session tokens, CSRF tokens, API keys, and identifiers to become the deterministic string ‘uuuuuuuuuuuuuuuuuuuuu’ until restart. It is rated HIGH with CVSS 7.4 and is fixed in versions 3.3.12 and 5.1.11.
🔗 Read more 🔗
Source: NVD

🪟 Windows CLFS Race Condition Enables Local Privilege Escalation
Windows administrators should prioritize the relevant security update on endpoints and servers where local users or compromised low-privilege accounts could attempt privilege escalation.
CVE-2026-62728 is a time-of-check time-of-use race condition in the Windows Common Log File System Driver. An authorized local attacker can exploit the flaw to elevate privileges. It is rated HIGH with CVSS 7.
🔗 Read more 🔗
Source: NVD

☎️ Windows Telephony Race Condition Allows Privilege Escalation
Patch affected Windows systems promptly, particularly shared endpoints, terminal servers, and machines where lower-privilege users may obtain local execution.
CVE-2026-62729 is an improper synchronization race condition in the Windows Telephony Service. An authorized local attacker can exploit concurrent access to a shared resource to elevate privileges. It is rated HIGH with CVSS 7.
🔗 Read more 🔗
Source: NVD

📞 Windows Telephony Heap Overflow Enables Local Privilege Escalation
Treat this as a high-priority Windows patch for systems where attackers could gain local code execution or access through a compromised user account.
CVE-2026-62732 is a heap-based buffer overflow in the Windows Telephony Service. An authorized local attacker can exploit the vulnerability to elevate privileges. It is rated HIGH with CVSS 7.8.
🔗 Read more 🔗
Source: NVD

🖥️ Windows Win32K Out-of-Bounds Read Enables Privilege Escalation
Endpoint and Windows fleet administrators should patch promptly because local privilege-escalation flaws are valuable for attackers who already have an initial foothold.
CVE-2026-62733 is an out-of-bounds read vulnerability in Windows Win32K. An authorized local attacker can exploit the issue to elevate privileges. It is rated HIGH with CVSS 7.8.
🔗 Read more 🔗
Source: NVD

☎️ Another Windows Telephony Race Condition Raises Local Privileges
Apply the relevant Windows security update promptly, especially on systems where untrusted or compromised users can execute code locally.
CVE-2026-62734 is an improper synchronization race condition in the Windows Telephony Service involving concurrent use of a shared resource. An authorized local attacker can exploit the flaw to elevate privileges. It is rated HIGH with CVSS 7.
🔗 Read more 🔗
Source: NVD

🌐 Windows HTTP.sys Heap Overflow Enables Local Privilege Escalation
Windows server and endpoint administrators should patch promptly, with extra attention to systems using HTTP.sys-backed services and machines where attackers could obtain local access.
CVE-2026-62735 is a heap-based buffer overflow in Windows HTTP.sys. An authorized local attacker can exploit the memory-corruption flaw to elevate privileges. It is rated HIGH with CVSS 7.8.
🔗 Read more 🔗
Source: NVD

⚙️ Windows Kernel Pointer Dereference Enables Privilege Escalation
Prioritize patching across Windows fleets, since kernel-level privilege escalation can be especially useful to attackers seeking to turn an existing low-privilege foothold into full system control.
CVE-2026-62737 is an untrusted pointer dereference vulnerability in the Windows Kernel. An authorized local attacker can exploit the issue to elevate privileges. It is rated HIGH with CVSS 7.8.
🔗 Read more 🔗
Source: NVD

🌐 Second Windows HTTP.sys Heap Overflow Raises Local Privileges
Apply the relevant Windows update promptly, particularly on servers and endpoints where an attacker who gains local execution could use this flaw to escalate privileges.
CVE-2026-62739 is a heap-based buffer overflow in Windows HTTP.sys. An authorized local attacker can exploit the vulnerability to elevate privileges. It is rated HIGH with CVSS 7.8.
🔗 Read more 🔗
Source: NVD