CWE-416— Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.— MITRE CWE catalog
7,407 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-416page 141 of 149
- CVE-2026-50359HIGHCVSS 7.8EG 7.02026-07-14
Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-50369HIGHCVSS 8.8EG 8.82026-07-14
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
- CVE-2026-50371HIGHCVSS 7.0EG 7.02026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.
- CVE-2026-50374MEDIUMCVSS 6.8EG 6.32026-07-14
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack.
- CVE-2026-50379HIGHCVSS 7.5EG 7.52026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.
- CVE-2026-50384HIGHCVSS 7.0EG 7.02026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-50385HIGHCVSS 8.8EG 8.82026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
- CVE-2026-50392HIGHCVSS 7.0EG 7.02026-07-14
Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
- CVE-2026-50393HIGHCVSS 7.8EG 7.02026-07-14
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
- CVE-2026-50396HIGHCVSS 7.8EG 7.02026-07-14
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
- CVE-2026-50397HIGHCVSS 7.0EG 7.02026-07-14
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-50398HIGHCVSS 8.8EG 8.82026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.
- CVE-2026-50403HIGHCVSS 7.0EG 7.02026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
- CVE-2026-50404HIGHCVSS 7.0EG 7.02026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.
- CVE-2026-50406HIGHCVSS 7.8EG 7.02026-07-14
Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
- CVE-2026-50410HIGHCVSS 7.0EG 7.02026-07-14
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
- CVE-2026-50413HIGHCVSS 7.8EG 8.82026-07-14
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
- CVE-2026-50414HIGHCVSS 8.8EG 7.52026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.
- CVE-2026-50425HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.
- CVE-2026-50427HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.
- CVE-2026-50432MEDIUMCVSS 6.5EG 5.32026-07-14
Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.
- CVE-2026-50433HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
- CVE-2026-50436HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-50439CRITICALCVSS 9.8EG 8.12026-07-14
Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.
- CVE-2026-50440HIGHCVSS 7.0EG 7.82026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-50449HIGHCVSS 7.0EG 7.02026-07-14
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
- CVE-2026-50452HIGHCVSS 7.0EG 7.02026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-50457HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
- CVE-2026-50458HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
- CVE-2026-50459HIGHCVSS 7.0EG 7.02026-07-14
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-50460HIGHCVSS 8.1EG 8.12026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-50466HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally.
- CVE-2026-50467HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-50474HIGHCVSS 8.8EG 8.82026-07-14
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-50476HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.
- CVE-2026-50478HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-50486HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
- CVE-2026-50487HIGHCVSS 8.1EG 8.12026-07-14
Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-50490HIGHCVSS 7.0EG 7.02026-07-14
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
- CVE-2026-50493HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-50500HIGHCVSS 7.5EG 7.52026-07-14
Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.
- CVE-2026-50505HIGHCVSS 7.5EG 7.52026-07-14
Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.
- CVE-2026-50521HIGHCVSS 8.3EG 8.32026-07-01
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
- CVE-2026-50666HIGHCVSS 8.8EG 8.82026-07-14
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.
- CVE-2026-50669HIGHCVSS 7.0EG 7.02026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-50672HIGHCVSS 7.0EG 7.02026-07-14
Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.
- CVE-2026-50674HIGHCVSS 7.0EG 7.02026-07-14
Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-50676HIGHCVSS 7.8EG 7.82026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.
- CVE-2026-50677HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
- CVE-2026-50687HIGHCVSS 8.8EG 8.82026-07-14
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Map vulnerabilities like CWE-416 to your infrastructure
EchelonGraph correlates every CVE — across CWE-416 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →