Every CVE whose affected-product data names Microsoft Windows App, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (21)
CVE-2026-59124 — CVSS 9.8 (critical): Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a…
CVE-2026-42985 — CVSS 8.8 (high): Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2025-26645 — CVSS 8.8 (high): Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-47289 — CVSS 8.8 (high): Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2025-29966 — CVSS 8.8 (high): Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
CVE-2026-59133 — CVSS 8.8 (high): Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate…
CVE-2025-48817 — CVSS 8.8 (high): Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2025-58718 — CVSS 8.8 (high): Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2025-27487 — CVSS 8.0 (high): Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network.
CVE-2020-0919 — CVSS 7.8 (high): An elevation of privilege vulnerability exists in Remote Desktop App for Mac in the way it allows an attacker to load unsigned binaries…
CVE-2026-42908 — CVSS 7.5 (high): Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-42909 — CVSS 7.5 (high): Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized…
CVE-2026-42992 — CVSS 7.5 (high): Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-44799 — CVSS 7.5 (high): Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-44801 — CVSS 7.5 (high): Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-45639 — CVSS 7.5 (high): Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2025-32715 — CVSS 6.5 (medium): Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-69550 — CVSS 6.5 (medium): Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-23656 — CVSS 5.9 (medium): Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-21517 — CVSS 4.7 (medium): Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges…