CWE-416
8,553 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CVEs (8,553)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 2Windows 11 24h2 Windows 11 25h2Aug 13, 2026 Aug 11, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. |
1Microsoft 3Windows 11 24h2 Windows 11 25h2Windows 11 26h1Aug 13, 2026 Aug 11, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. |
1Microsoft 2Windows 11 24h2 Windows 11 25h2Aug 13, 2026 Aug 11, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. |
1Microsoft 4Windows 11 24h2 Windows 11 25h2Windows 11 26h1+1 moreAug 13, 2026 Aug 11, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreAug 16, 2026 Aug 11, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreAug 16, 2026 Aug 11, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
1Microsoft 5365 Apps Microsoft 365Office 2019+2 moreAug 14, 2026 Aug 11, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreAug 16, 2026 Aug 11, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally. |
1Microsoft 3.net Visual Studio 2022Visual Studio 2026Aug 14, 2026 Aug 11, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. |
1Microsoft 7Windows 10 1607 Windows 10 1809Windows Server 2012+4 moreSep 2, 2026 Aug 11, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. |
1Microsoft 10Windows 10 1809 Windows 10 21h2Windows 10 22h2+7 moreAug 16, 2026 Aug 11, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. |
1Microsoft 8Windows 10 21h2 Windows 10 22h2Windows 11 23h2+5 moreAug 13, 2026 Aug 11, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreAug 16, 2026 Aug 11, 2026 N/A· v4 8.1 HIGH· v3 N/A· v2 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine |
1Microsoft 7Windows 10 1607 Windows 10 1809Windows Server 2012+4 moreAug 16, 2026 Aug 11, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network. |
1Microsoft 6Windows 11 23h2 Windows 11 24h2Windows 11 25h2+3 moreAug 14, 2026 Aug 11, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreAug 16, 2026 Aug 11, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. |
1Microsoft 5Windows 11 23h2 Windows 11 24h2Windows 11 25h2+2 moreAug 13, 2026 Aug 11, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
1Microsoft 7Windows 10 1607 Windows 10 1809Windows Server 2012+4 moreSep 2, 2026 Aug 11, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Use after free in Windows DNS allows an authorized attacker to execute code over a network. |
1Microsoft 5Windows 11 23h2 Windows 11 24h2Windows 11 25h2+2 moreAug 13, 2026 Aug 11, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
1Microsoft 4Windows 11 24h2 Windows 11 25h2Windows 11 26h1+1 moreAug 13, 2026 Aug 11, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally. |