HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-68821 — Improper privilege management in Windows Package Manager allows an authorized at...

·Source: NIST NVD

Updated:

Executive Summary

Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.

Analysis

Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally. CVSS Score: 7.3. Published: 2026-08-11T17:19:06.540.

Indicators of Compromise (1)

CVE (1)
CVE-2026-68821
Source Attribution

Originally published by NIST NVD on Aug 11, 2026. Verified by: NIST.

Related Threats

MEDIUMVulnerability

Rep. Thompson brings bipartisan rural hospital cybersecurity act to House

NorthCentralPA reports: A group of legislators has introduced the bipartisan Rural Hospital Cybersecurity Enhancement Act to the House of Representatives with the intention to strengthen rural hospitals’ protection against cyber threats. The group includes U.S. Reps. Glenn “GT” Thompson (R-Pa.), Kim Schrier (D-Wash.), Erin Houchin (R-Ind.), Jill Tokuda (D-Hawaii), Jefferson Shreve (R-Ind.), and Je

DataBreaches.net
CRITICALVulnerability

NVD CRITICAL: CVE-2024-13784 — The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPre...

The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input from form submissions. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no

CVE-2024-13784
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-18316 — The Solace Extra plugin for WordPress is vulnerable to unauthorized modification...

The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_action-import-zip and wp_ajax_nopriv_action-import-zip and only verifies the 'ajax-nonce' nonce, which is emitted on every admin page via wp_localize_script

CVE-2026-18316
NIST NVD