CVE-2026-68830 Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability

Improper link resolution before file access (‘link following’) in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally. Continue reading CVE-2026-68830 Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability→

CVE-2026-68824 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally. Continue reading CVE-2026-68824 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability→