CWE-416— Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.— MITRE CWE catalog
7,405 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-416page 140 of 149
- CVE-2026-47921HIGHCVSS 7.8EG 7.82026-06-09
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera…
- CVE-2026-47924MEDIUMCVSS 5.5EG 5.52026-06-09
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive informatio…
- CVE-2026-47955HIGHCVSS 7.8EG 7.82026-06-09
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera…
- CVE-2026-48090MEDIUMCVSS 5.9EG 5.92026-06-26
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, the HTTP OAuth2 filter (envoy.filters.http.oauth2) can leave an in-flight async token exchange attached to a downst…
- CVE-2026-48563HIGHCVSS 7.5EG 7.52026-06-09
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-48571HIGHCVSS 7.0EG 7.02026-07-14
Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.
- CVE-2026-48572HIGHCVSS 7.0EG 7.02026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.
- CVE-2026-48583HIGHCVSS 7.8EG 7.82026-06-09
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-48913HIGHCVSS 7.3EG 7.32026-06-08
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
- CVE-2026-49162HIGHCVSS 7.0EG 7.02026-07-14
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
- CVE-2026-49166HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.
- CVE-2026-49167MEDIUMCVSS 4.7EG 4.72026-07-14
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-49169HIGHCVSS 8.0EG 8.02026-07-14
Use after free in DNS Server allows an authorized attacker to execute code over a network.
- CVE-2026-49171HIGHCVSS 7.5EG 7.52026-07-14
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
- CVE-2026-49173HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-49183HIGHCVSS 7.0EG 7.02026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-49412HIGHCVSS 7.8EG 7.82026-06-27
The kernel handler for IPV6_MSFILTER dropped a serializing lock in order to copy the source-filter list from userspace, then reacquired the lock. During this window another thread could free the multicast filter structure, leaving the han…
- CVE-2026-49417HIGHCVSS 7.0EG 7.02026-06-27
Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remained valid. The freed memory could then be reused elsewhere while still accessible through the stale mapping. The /dev/dsp d…
- CVE-2026-49496MEDIUMCVSS 6.1EG 6.12026-06-10
Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator invalidation when PcodeCacher::allocateInstruction reallocates the issued vector. Attackers can trigger memory corrupti…
- CVE-2026-49784HIGHCVSS 7.0EG 7.02026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.
- CVE-2026-49795HIGHCVSS 8.8EG 8.82026-07-14
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-49798CRITICALCVSS 9.3EG 9.32026-07-14
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-49802HIGHCVSS 7.0EG 7.02026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-49806HIGHCVSS 7.0EG 7.02026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-49808HIGHCVSS 7.8EG 7.82026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-50219MEDIUMCVSS 5.9EG 4.92026-06-04
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
- CVE-2026-50257HIGHCVSS 7.8EG 7.82026-06-05
A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set …
- CVE-2026-50260HIGHCVSS 7.8EG 7.82026-06-05
A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client c…
- CVE-2026-50261HIGHCVSS 7.8EG 7.82026-06-05
A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changin…
- CVE-2026-50263MEDIUMCVSS 5.5EG 5.52026-06-05
A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.
- CVE-2026-50293HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.
- CVE-2026-50296HIGHCVSS 7.0EG 7.02026-07-14
Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-50305HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
- CVE-2026-50306HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
- CVE-2026-50307HIGHCVSS 7.0EG 7.02026-07-14
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
- CVE-2026-50312MEDIUMCVSS 4.7EG 4.72026-07-14
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2026-50314HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-50317HIGHCVSS 7.8EG 7.82026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to elevate privileges locally.
- CVE-2026-50321HIGHCVSS 7.0EG 7.82026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-50322HIGHCVSS 7.0EG 7.02026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
- CVE-2026-50323HIGHCVSS 7.0EG 7.02026-07-14
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
- CVE-2026-50326HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.
- CVE-2026-50329HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-50331HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.
- CVE-2026-50340HIGHCVSS 8.8EG 8.52026-07-14
Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network.
- CVE-2026-50345HIGHCVSS 7.0EG 7.02026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
- CVE-2026-50348HIGHCVSS 8.1EG 7.02026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-50353HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
- CVE-2026-50354HIGHCVSS 7.1EG 7.12026-07-14
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-50358HIGHCVSS 7.8EG 7.02026-07-14
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
Map vulnerabilities like CWE-416 to your infrastructure
EchelonGraph correlates every CVE — across CWE-416 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →