CVE-2026-62792 8.1
Aug 11, 2026

CVE-2026-62792: Stack-Based Buffer Overflow in the IPv6 Hop-by-Hop Options Parser

A remote, unauthenticated stack-based buffer overflow in the Windows TCP/IP driver (tcpip.sys) lets a crafted IPv6 Hop-by-Hop options header advance the packet cursor past the NET_BUFFER bounds, corrupting memory and enabling remote code...

Read full report →
CVE-2026-45657 9.8
Jun 9, 2026

CVE-2026-45657: Use-After-Free in the Windows IPv4/IPv6 Forward-Path Cache (IppCreateForwardPath)

A remotely reachable use-after-free in the Windows kernel TCP/IP driver tcpip.sys, where a forward-path cache entry becomes hash-table-visible before it is marked valid, letting a concurrent lookup observe and free a half-initialized ent...

Read full report →
CVE-2026-42904 9.6
Jun 9, 2026

CVE-2026-42904: Heap-Based Buffer Overflow in the Windows TCP/IP FSE Message Reassembly Path

A missing 0x400 bound in tcpip.sys!FseProcessIncomingMessages let an adjacent-network attacker overflow the fixed-size WSK message-reassembly buffer with attacker-controlled length prefixes and payload, yielding kernel heap corruption an...

Read full report →
CVE-2026-33827 8.1
Apr 14, 2026

CVE-2026-33827: Use-After-Free in the Windows IPv4 Source-Routing Path (Ipv4pReceiveRoutingHeader)

A race condition in tcpip.sys's IPv4 source-route forwarding path let an unauthenticated remote attacker trigger a use-after-free on an IPP_PATH object by dropping its last reference before the forwarding code finished using it, yielding...

Read full report →