HIGHVulnerability
Verified
Global

CISA KEV: Microsoft Windows — Microsoft Windows Buffer Overflow Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.

Analysis

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization. Added to CISA Known Exploited Vulnerabilities catalog on 2026-05-20. Remediation due: 2026-06-03.

Indicators of Compromise (1)

CVE (1)
CVE-2008-4250
Source Attribution

Originally published by CISA KEV on May 20, 2026. Verified by: CISA.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-15896 — The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to...

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'file_upload_auth' setting defaults to empty, meaning no au

CVE-2026-15896
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-19660 — The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass ...

The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled

CVE-2026-19660
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-14378 — The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leadi...

The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by

CVE-2026-14378
NIST NVD