Latest Microsoft CVEs

Every organization faces unique cybersecurity challenges, but successful outcomes require more than technology alone. Our case studies highlight how Gilliam Security works alongside executives, security leaders, and stakeholders to build practical security programs, strengthen governance, manage risk, and achieve critical compliance objectives in complex business environments.

From guiding organizations through leadership transitions and regulatory audits to establishing governance functions for global enterprises and preparing government contractors for CMMC requirements, these engagements demonstrate our commitment to delivering measurable results, sustainable security practices, and long-term business value.

Provided below are the Microsoft CVEs from the last 30 days:

CVE-2026-68801 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 21, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-64903 Microsoft Office Remote Code Execution Vulnerability
Published on: August 21, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-64899 Microsoft Office Information Disclosure Vulnerability
Published on: August 21, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability
Published on: August 21, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability
Published on: August 21, 2026
Corrected **Exploited** to **No**. This vulnerability was not exploited in the wild. This is an informational change only.
Read Details

CVE-2026-54981 Visual Studio Code Python Extension Security Feature Bypass Vulnerability
Published on: August 21, 2026
Affected software updated with new package information.
Read Details

CVE-2026-58547 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability
Published on: August 21, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-49183 Windows Clipboard Server Elevation of Privilege Vulnerability
Published on: August 21, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-55134 Microsoft Word Remote Code Execution Vulnerability
Published on: August 21, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-50466 Microsoft Brokering File System Elevation of Privilege Vulnerability
Published on: August 21, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-32202 Windows Shell Spoofing Vulnerability
Published on: August 21, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-62834 Azure Data Factory Elevation of Privilege Vulnerability
Published on: August 20, 2026
<p>Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.</p>
Read Details

CVE-2026-65801 Microsoft Exchange Online Elevation of Privilege Vulnerability
Published on: August 20, 2026
<p>Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.</p>
Read Details

CVE-2026-68789 Azure SQL Database Elevation of Privilege Vulnerability
Published on: August 20, 2026
<p>Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.</p>
Read Details

CVE-2026-69519 Azure Stack HCI Information Disclosure Vulnerability
Published on: August 20, 2026
<p>Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.</p>
Read Details

CVE-2026-69851 Microsoft Entra ID Elevation of Privilege Vulnerability
Published on: August 20, 2026
<p>Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.</p>
Read Details

CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability
Published on: August 20, 2026
<p>Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.</p>
Read Details

CVE-2026-62703 Windows DWM Core Library Information Disclosure Vulnerability
Published on: August 20, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability
Published on: August 20, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-62754 Windows Kerberos Elevation of Privilege Vulnerability
Published on: August 20, 2026
Updated links to security updates. This is an informational change only.
Read Details

CVE-2026-62755 Windows DHCP Client Elevation of Privilege Vulnerability
Published on: August 20, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-65786 Desktop Window Manager Elevation of Privilege Vulnerability
Published on: August 20, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-55015 Microsoft Remote Help Denial of Service Vulnerability
Published on: August 20, 2026
<p>Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.</p>
Read Details

CVE-2026-55013 Windows Remote Help Defense Spoofing Vulnerability
Published on: August 20, 2026
<p>Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.</p>
Read Details

CVE-2026-61363 Remote Desktop Client Remote Code Execution Vulnerability
Published on: August 20, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-62728 Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published on: August 20, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-66802 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability
Published on: August 20, 2026
Corrected the Executive Summary to clarify that the vulnerability affects Windows Device Health Attestation (DHA), not Microsoft Azure Attestation. This is an informational change only.
Read Details

CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability
Published on: August 20, 2026
Updated links to security updates. This is an informational change only.
Read Details

CVE-2026-70105 Microsoft Word Information Disclosure Vulnerability
Published on: August 20, 2026
Information published. This CVE was addressed by updates that were released in August 2026, but the CVE was inadvertently omitted from the August 2026 Security Updates. This is an informational change only. Customers who have already installed the August 2026 updates do not need to take any further action.
Read Details

CVE-2026-65770 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
Published on: August 20, 2026
<p>Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.</p>
Read Details

CVE-2026-63509 Microsoft Fabric Elevation of Privilege Vulnerability
Published on: August 20, 2026
<p>Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.</p>
Read Details

CVE-2026-65816 Azure Arc Elevation of Privilege Vulnerability
Published on: August 20, 2026
<p>Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.</p>
Read Details

CVE-2026-66309 Azure SQL Database Elevation of Privilege Vulnerability
Published on: August 20, 2026
<p>Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.</p>
Read Details

CVE-2026-66800 Azure Data Factory Information Disclosure Vulnerability
Published on: August 20, 2026
<p>Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.</p>
Read Details

CVE-2026-68782 Azure SQL Database Elevation of Privilege Vulnerability
Published on: August 20, 2026
<p>Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.</p>
Read Details

CVE-2026-69419 Azure Data Manager for Energy Remote Code Execution Vulnerability
Published on: August 20, 2026
<p>Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.</p>
Read Details

CVE-2026-69502 Azure SQL Database Elevation of Privilege Vulnerability
Published on: August 20, 2026
<p>Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.</p>
Read Details

CVE-2026-69400 Azure Logic Apps Elevation of Privilege Vulnerability
Published on: August 20, 2026
<p>Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.</p>
Read Details

CVE-2026-69555 Azure Arc Elevation of Privilege Vulnerability
Published on: August 20, 2026
<p>Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.</p>
Read Details

CVE-2026-69558 Microsoft Partner Center Information Disclosure Vulnerability
Published on: August 20, 2026
<p>Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.</p>
Read Details

CVE-2026-69543 Azure Virtual Machines Elevation of Privilege Vulnerability
Published on: August 20, 2026
<p>Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.</p>
Read Details

CVE-2026-69855 Microsoft Copilot in Azure Information Disclosure Vulnerability
Published on: August 20, 2026
<p>Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.</p>
Read Details

CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
Published on: August 20, 2026
Added clarifying information to the mitigation. This is an informational change only.
Read Details

CVE-2026-54118 Microsoft SQL Server Remote Code Execution Vulnerability
Published on: August 20, 2026
The CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only.
Read Details

CVE-2026-54117 Microsoft SQL Server Remote Code Execution Vulnerability
Published on: August 20, 2026
The CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only.
Read Details

CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability
Published on: August 20, 2026
Updated links to security updates. This is an informational change only.
Read Details

CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability
Published on: August 20, 2026
Corrected the Executive Summary to clarify that the vulnerability affects Windows Device Health Attestation (DHA), not Microsoft Azure Attestation. This is an informational change only.
Read Details

CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability
Published on: August 19, 2026
Acknowledgement Updated
Read Details

CVE-2026-62705 Microsoft Brokering File System Elevation of Privilege Vulnerability
Published on: August 19, 2026
Corrected the CVE title from **Windows Bind Filter Driver Elevation of Privilege Vulnerability** to **Microsoft Brokering File System Elevation of Privilege Vulnerability** and updated the acknowledgement. These are informational changes only.
Read Details

CVE-2026-69414 Microsoft Defender Elevation of Privilege Vulnerability
Published on: August 19, 2026
CWE added. Informational change only.
Read Details

CVE-2026-65811 Power BI Remote Code Execution Vulnerability
Published on: August 19, 2026
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
Read Details

CVE-2026-65675 CoPilot Chat Security Feature Bypass Vulnerability
Published on: August 19, 2026
CWE added. Informational change only.
Read Details

CVE-2020-1173 Microsoft Power BI Report Server Spoofing Vulnerability
Published on: August 19, 2026
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
Read Details

CVE-2021-26859 Microsoft Power BI Information Disclosure Vulnerability
Published on: August 19, 2026
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
Read Details

CVE-2021-41372 Power BI Report Server Spoofing Vulnerability
Published on: August 19, 2026
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
Read Details

CVE-2023-21806 Power BI Report Server Spoofing Vulnerability
Published on: August 19, 2026
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
Read Details

CVE-2024-43612 Power BI Report Server Spoofing Vulnerability
Published on: August 19, 2026
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
Read Details

CVE-2024-43481 Power BI Report Server Spoofing Vulnerability
Published on: August 19, 2026
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
Read Details

CVE-2026-50383 Windows Print Spooler Information Disclosure Vulnerability
Published on: August 19, 2026
Acknowledgement Updated
Read Details

CVE-2026-49798 Windows Kernel Elevation of Privilege Vulnerability
Published on: August 19, 2026
Acknowledgement Updated
Read Details

CVE-2026-58647 Microsoft PowerBI Report Server Spoofing Vulnerability
Published on: August 19, 2026
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
Read Details

CVE-2026-42912 Windows Telephony Service Elevation of Privilege Vulnerability
Published on: August 19, 2026
Acknowledgement Updated
Read Details

CVE-2026-24301 Microsoft Copilot Information Disclosure Vulnerability
Published on: August 18, 2026
<p>Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.</p>
Read Details

CVE-2026-65791 Windows iSCSI Target Service Remote Code Execution Vulnerability
Published on: August 18, 2026
Acknowledgement Updated
Read Details

CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
Published on: August 18, 2026
Acknowledgement Updated
Read Details

CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability
Published on: August 18, 2026
Acknowledgement Updated
Read Details

CVE-2026-47632 Azure Connected Machine Agent Elevation of Privilege Vulnerability
Published on: August 18, 2026
Corrected the affected product from **Azure Monitor Agent Metrics Extension** to **Azure Connected Machine Agent** and updated the Security Updates table. This is an informational change only.
Read Details

CVE-2026-50419 Windows Kernel Information Disclosure Vulnerability
Published on: August 18, 2026
Acknowledgement Updated
Read Details

CVE-2026-56642 Microsoft Fabric Data Warehouse Remote Code Execution Vulnerability
Published on: August 18, 2026
Updated the Security Updates table by removing an affected software entry. No user action is required. This is an informational change only.
Read Details

CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability
Published on: August 17, 2026
Acknowledgement Updated
Read Details

CVE-2026-56188 Windows Server Network driver Remote Code Execution Vulnerability
Published on: August 17, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-62722 Microsoft Brokering File System Elevation of Privilege Vulnerability
Published on: August 17, 2026
Corrected the CVE description and title. This is an informational change only.
Read Details

CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability
Published on: August 17, 2026
Acknowledgement Updated
Read Details

CVE-2026-63519 Microsoft Office Graphics Component Remote Code Execution Vulnerability
Published on: August 17, 2026
Acknowledgement Updated
Read Details

CVE-2026-63513 Microsoft Office Graphics Component Remote Code Execution Vulnerability
Published on: August 17, 2026
Acknowledgement Updated
Read Details

CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability
Published on: August 17, 2026
Acknowledgement Updated
Read Details

CVE-2026-58612 PowerShell Information Disclosure Vulnerability
Published on: August 17, 2026
Acknowledgement Updated
Read Details

CVE-2026-62886 .NET Elevation of Privilege Vulnerability
Published on: August 17, 2026
Acknowledgement Updated
Read Details

CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability
Published on: August 17, 2026
Acknowledgement Updated
Read Details

CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability
Published on: August 16, 2026
Corrected build number for the security update. This in an informational change only.
Read Details

CVE-2026-65769 Microsoft Teams iOS Information Disclosure Vulnerability
Published on: August 16, 2026
Corrected build number for the security update. This in an informational change only.
Read Details

CVE-2026-57104 Azure Storage Explorer Elevation of Privilege Vulnerability
Published on: August 16, 2026
Corrected build number for the security update. This in an informational change only.
Read Details

CVE-2026-65767 Microsoft Teams for Android Spoofing Vulnerability
Published on: August 16, 2026
Corrected build number for the security update. This in an informational change only.
Read Details

CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability
Published on: August 16, 2026
Corrected the listed software in the Security Updates table. Microsoft recommends installing the security update as soon as possible.
Read Details

CVE-2026-72970 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Published on: August 14, 2026
<p>Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.</p>
Read Details

CVE-2026-61347 Windows Event Logging Service Information Disclosure Vulnerability
Published on: August 14, 2026
Acknowledgement Updated
Read Details

CVE-2026-62746 Win32k Information Disclosure Vulnerability
Published on: August 14, 2026
Acknowledgement Updated
Read Details

CVE-2026-62755 Windows DHCP Client Elevation of Privilege Vulnerability
Published on: August 14, 2026
Acknowledgement Updated
Read Details

CVE-2026-62777 Windows License Manager Elevation of Privilege Vulnerability
Published on: August 14, 2026
Acknowledgement Updated
Read Details

CVE-2026-65671 Remote Access API Elevation of Privilege Vulnerability
Published on: August 14, 2026
Acknowledgement Updated
Read Details

CVE-2026-68821 Windows Package Manager Elevation of Privilege Vulnerability
Published on: August 14, 2026
Acknowledgement Updated
Read Details

CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
Published on: August 14, 2026
Acknowledgement Updated
Read Details

Chromium: CVE-2026-19560 Use after free in Blink
Published on: August 14, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

Chromium: CVE-2026-19559 Use after free in HTML
Published on: August 14, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

Chromium: CVE-2026-19558 Use after free in Extensions
Published on: August 14, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

Chromium: CVE-2026-19557 Use after free in TabStrip
Published on: August 14, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

Chromium: CVE-2026-19556 Use after free in V8
Published on: August 14, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-59126 Windows Event Logging Service Elevation of Privilege Vulnerability
Published on: August 14, 2026
Acknowledgement Updated
Read Details

CVE-2026-58612 PowerShell Information Disclosure Vulnerability
Published on: August 14, 2026
The security updates for Powershell have been updated.
Read Details

CVE-2026-59119 PowerShell Elevation of Privilege Vulnerability
Published on: August 14, 2026
The security updates for Powershell have been updated.
Read Details

CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability
Published on: August 14, 2026
The security updates for Powershell have been updated.
Read Details

CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability
Published on: August 14, 2026
The security updates for Powershell have been updated.
Read Details

CVE-2026-50523 Microsoft PowerShell Remote Code Execution Vulnerability
Published on: August 14, 2026
The security updates for Powershell have been updated.
Read Details

CVE-2026-69414 Microsoft Defender Elevation of Privilege Vulnerability
Published on: August 14, 2026
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.
Read Details

CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability
Published on: August 14, 2026
Acknowledgement Updated
Read Details

CVE-2026-49162 Microsoft Brokering File System Elevation of Privilege Vulnerability
Published on: August 14, 2026
Acknowledgement Updated
Read Details

CVE-2026-50313 Windows NTFS Remote Code Execution Vulnerability
Published on: August 14, 2026
Acknowledgement Updated
Read Details

CVE-2026-32153 Windows Speech Runtime Elevation of Privilege Vulnerability
Published on: August 14, 2026
Acknowledgement Updated
Read Details

CVE-2026-48566 Windows DWM Core Library Information Disclosure Vulnerability
Published on: August 14, 2026
This CVE has been discovered to be an Elevation of Privilege and not an Information Disclosure. The CVE's Impact has been updated.
Read Details

CVE-2026-49162 Microsoft Brokering File System Elevation of Privilege Vulnerability
Published on: August 13, 2026
Added acknowledgements. This is an informational change only.
Read Details

CVE-2026-49798 Windows Kernel Elevation of Privilege Vulnerability
Published on: August 13, 2026
Acknowledgement Updated
Read Details

CVE-2026-50342 Windows MIDI Service Module Elevation of Privileges Vulnerability
Published on: August 13, 2026
Acknowledgement Updated
Read Details

CVE-2026-50298 Windows Spaceport.sys Elevation of Privilege Vulnerability
Published on: August 13, 2026
Acknowledgement Updated
Read Details

CVE-2026-50309 Windows NTFS Remote Code Execution Vulnerability
Published on: August 13, 2026
Acknowledgement Updated
Read Details

CVE-2026-50387 Windows GDI Elevation of Privilege Vulnerability
Published on: August 13, 2026
Acknowledgement Updated
Read Details

CVE-2026-50383 Windows Print Spooler Information Disclosure Vulnerability
Published on: August 13, 2026
Acknowledgement Updated
Read Details

CVE-2026-50461 Windows NTFS Remote Code Execution Vulnerability
Published on: August 13, 2026
Acknowledgement Updated
Read Details

CVE-2026-45592 Windows Internet (wininet.dll) Elevation of Privilege Vulnerability
Published on: August 13, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-45593 Windows SDK Elevation of Privilege Vulnerability
Published on: August 13, 2026
Acknowledgement Updated
Read Details

CVE-2026-45597 Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability
Published on: August 13, 2026
Acknowledgement Updated
Read Details

CVE-2026-45638 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published on: August 13, 2026
Acknowledgement Updated
Read Details

CVE-2026-45637 Microsoft DWM Core Library Elevation of Privilege Vulnerability
Published on: August 13, 2026
Acknowledgement Updated
Read Details

CVE-2026-44814 Windows DWM Core Library Information Disclosure Vulnerability
Published on: August 13, 2026
Acknowledgement Updated
Read Details

CVE-2026-61346 Windows Graphics Kernel Elevation of Privilege Vulnerability
Published on: August 13, 2026
Acknowledgement Updated
Read Details

CVE-2026-62695 Windows Storage Elevation of Privilege Vulnerability
Published on: August 13, 2026
Acknowledgement Updated
Read Details

CVE-2026-61359 Windows Storage Elevation of Privilege Vulnerability
Published on: August 13, 2026
Acknowledgement Updated
Read Details

CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
Published on: August 13, 2026
Acknowledgement Updated
Read Details

CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability
Published on: August 13, 2026
Added acknowledgements. This is an informational change only.
Read Details

CVE-2026-62688 Windows MIDI Service Module Elevation of Privileges Vulnerability
Published on: August 13, 2026
Acknowledgement Updated
Read Details

CVE-2026-62897 .NET Framework Remote Code Execution Vulnerability
Published on: August 13, 2026
Removed Linux and macOS products from the Affected Software table. This is an informational change only.
Read Details

CVE-2026-62902 .NET Information Disclosure Vulnerability
Published on: August 13, 2026
Removed Linux and macOS products from the Affected Software table. This is an informational change only.
Read Details

CVE-2026-70354 .NET Core Remote Code Execution Vulnerability
Published on: August 13, 2026
Removed Linux and macOS products from the Affected Software table. This is an informational change only.
Read Details

CVE-2026-62871 .NET Elevation of Privilege Vulnerability
Published on: August 13, 2026
Removed Linux and macOS products from the Affected Software table. This is an informational change only.
Read Details

CVE-2026-62886 .NET Elevation of Privilege Vulnerability
Published on: August 13, 2026
Removed Linux and macOS products from the Affected Software table. This is an informational change only.
Read Details

CVE-2026-62898 Microsoft QUIC Information Disclosure Vulnerability
Published on: August 13, 2026
Removed Linux and macOS products from the Affected Software table. This is an informational change only.
Read Details

CVE-2026-64906 Microsoft Access Remote Code Execution Vulnerability
Published on: August 13, 2026
Acknowledgement Updated
Read Details

CVE-2026-65796 Windows iSCSI Target Service Remote Code Execution Vulnerability
Published on: August 13, 2026
Updated the CVE title, changed the security impact from Denial of Service to Remote Code Execution, changed the severity from Important to Critical, updated the CVSS score from 5.9 to 8.1, and corrected the severity and impact entries in the Security Updates table. These are informational changes only. Customers who have successfully installed the update do not need to take any further action.
Read Details

CVE-2026-62696 Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability
Published on: August 12, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability
Published on: August 12, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability
Published on: August 12, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-68815 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 12, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-70348 Windows Management Services Denial of Service Vulnerability
Published on: August 12, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-42976 Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability
Published on: August 12, 2026
Updated product information in the Software Update table. This is an informational change only.
Read Details

CVE-2026-50687 Windows Win32k Elevation of Privilege Vulnerability
Published on: August 12, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-58538 Windows Bluetooth Service Elevation of Privilege Vulnerability
Published on: August 12, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-50655 Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Published on: August 12, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-58643 Windows Admin Center Spoofing Vulnerability
Published on: August 12, 2026
Corrected Build Number in the Security Updates table. This is an informational change only.
Read Details

CVE-2026-50476 Windows Network Connections Service Elevation of Privilege Vulnerability
Published on: August 12, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2022-41127 Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
Published on: August 12, 2026
Updated the build numbers. This is an informational update only.
Read Details

CVE-2026-45637 Microsoft DWM Core Library Elevation of Privilege Vulnerability
Published on: August 12, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-50472 Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-56174 Windows Narrator Braille Elevation of Privilege Vulnerability
Published on: August 11, 2026
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-58650 Visual Studio Code Security Feature Bypass Vulnerability
Published on: August 11, 2026
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Read Details

CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability
Published on: August 11, 2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-57105 Microsoft Office SharePoint Spoofing Vulnerability
Published on: August 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Read Details

CVE-2026-62829 Microsoft SharePoint Server Spoofing Vulnerability
Published on: August 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Read Details

CVE-2026-62827 Microsoft SharePoint Server Elevation of Privilege Vulnerability
Published on: August 11, 2026
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Read Details

CVE-2026-62837 Microsoft SharePoint Server Information Disclosure Vulnerability
Published on: August 11, 2026
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
Read Details

CVE-2026-63514 Microsoft SharePoint Server Remote Code Execution Vulnerability
Published on: August 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-63512 Microsoft SharePoint Server Tampering Vulnerability
Published on: August 11, 2026
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
Read Details

CVE-2026-63516 Microsoft SharePoint Server Spoofing Vulnerability
Published on: August 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Read Details

CVE-2026-63520 Microsoft SharePoint Server Remote Code Execution Vulnerability
Published on: August 11, 2026
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-40375 Microsoft Dynamics Business Central Information Disclosure Vulnerability
Published on: August 11, 2026
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
Read Details

CVE-2026-54113 Remote Procedure Call Denial of Service Vulnerability
Published on: August 11, 2026
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.
Read Details

CVE-2026-54984 Windows Imaging Component Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-49179 Windows Active Directory Domain Services Remote Code Execution Vulnerability
Published on: August 11, 2026
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-58612 PowerShell Information Disclosure Vulnerability
Published on: August 11, 2026
Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.
Read Details

CVE-2026-59113 Visual Studio Code Remote Code Execution Vulnerability
Published on: August 11, 2026
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-47299 Azure Monitor Agent Elevation of Privilege Vulnerability
Published on: August 11, 2026
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.
Read Details

CVE-2026-47285 Visual Studio Code Information Disclosure Vulnerability
Published on: August 11, 2026
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Read Details

CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability
Published on: August 11, 2026
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-59127 Windows Installer Elevation of Privilege Vulnerability
Published on: August 11, 2026
Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-59128 Windows Encrypting File System (EFS) Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-59133 Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability
Published on: August 11, 2026
Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.
Read Details

CVE-2026-59130 AMD Zen Information Disclosure Vulnerability
Published on: August 11, 2026
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-59132 Windows TCP/IP Denial of Service Vulnerability
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-59135 Microsoft Windows Search Component Information Disclosure Vulnerability
Published on: August 11, 2026
Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-59134 Remote Desktop Client Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-59136 Microsoft COM for Windows Information Disclosure Vulnerability
Published on: August 11, 2026
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-59137 Windows Event Logging Service Information Disclosure Vulnerability
Published on: August 11, 2026
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-59138 Microsoft Remote Registry Service Denial of Service Vulnerability
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-61345 Microsoft Remote Registry Service Denial of Service Vulnerability
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-61346 Windows Graphics Kernel Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61353 Windows Telephony Service Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61347 Windows Event Logging Service Information Disclosure Vulnerability
Published on: August 11, 2026
Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-61361 Windows DHCP Client Remote Code Execution Vulnerability
Published on: August 11, 2026
Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.
Read Details

CVE-2026-61348 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61350 Windows NTFS Information Disclosure Vulnerability
Published on: August 11, 2026
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
Read Details

CVE-2026-61356 Windows Remote Desktop Services Elevation of Privilege Vulnerability
Published on: August 11, 2026
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61367 Windows Remote Desktop Services Elevation of Privilege Vulnerability
Published on: August 11, 2026
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61923 Windows Display Enhancement Service Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61366 Windows Network Connection Broker Elevation of Privilege Vulnerability
Published on: August 11, 2026
Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61368 Windows Hyper-V Information Disclosure Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-61924 Windows Remote Desktop Client Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Read Details

CVE-2026-61925 Windows Installer Elevation of Privilege Vulnerability
Published on: August 11, 2026
Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61927 Windows Bind Filter Driver Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61928 Windows Hello Tampering Vulnerability
Published on: August 11, 2026
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
Read Details

CVE-2026-61930 Windows Kernel Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61937 Windows HTTP.sys Elevation of Privilege Vulnerability
Published on: August 11, 2026
Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62692 Windows Remote Desktop Services Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61932 Windows DWM Core Library Elevation of Privilege Vulnerability
Published on: August 11, 2026
Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61933 Windows DWM Core Library Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-61934 Windows Bind Filter Driver Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61936 Windows Defender Firewall Service Security Feature Bypass Vulnerability
Published on: August 11, 2026
Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.
Read Details

CVE-2026-61939 Winlogon Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Winlogon allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62695 Windows Storage Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62688 Windows MIDI Service Module Elevation of Privileges Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62690 Windows Push Notifications Elevation of Privilege Vulnerability
Published on: August 11, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62693 Windows MIDI Service Module Elevation of Privileges Vulnerability
Published on: August 11, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62696 Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability
Published on: August 11, 2026
Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62702 Windows Graphics Kernel Denial of Service Vulnerability
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-62699 Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.
Read Details

CVE-2026-62703 Windows DWM Core Library Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-62705 Windows Bind Filter Driver Elevation of Privilege Vulnerability
Published on: August 11, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62707 Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62713 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62712 Windows Win32k Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62718 Windows DHCP Server Information Disclosure Vulnerability
Published on: August 11, 2026
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
Read Details

CVE-2026-62715 Windows DHCP Server Information Disclosure Vulnerability
Published on: August 11, 2026
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
Read Details

CVE-2026-62716 Windows DHCP Server Information Disclosure Vulnerability
Published on: August 11, 2026
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
Read Details

CVE-2026-62719 Windows Message Queuing Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62722 Windows Bind Filter Driver Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62723 Windows Telephony Service Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62724 Windows Telephony Service Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62748 Windows Telephony Service Elevation of Privilege Vulnerability
Published on: August 11, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62729 Windows Telephony Service Elevation of Privilege Vulnerability
Published on: August 11, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62746 Win32k Information Disclosure Vulnerability
Published on: August 11, 2026
Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-62740 Windows Imaging Component Information Disclosure Vulnerability
Published on: August 11, 2026
Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-62753 Windows HTTP.sys Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62735 Windows HTTP.sys Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62737 Windows Kernel Elevation of Privilege Vulnerability
Published on: August 11, 2026
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62739 Windows HTTP.sys Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62742 Windows DHCP Server Information Disclosure Vulnerability
Published on: August 11, 2026
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
Read Details

CVE-2026-62745 Windows DHCP Server Information Disclosure Vulnerability
Published on: August 11, 2026
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
Read Details

CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62750 Windows HTTP Protocol Stack Tampering Vulnerability
Published on: August 11, 2026
Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.
Read Details

CVE-2026-62754 Windows Kerberos Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62783 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62755 Windows DHCP Client Elevation of Privilege Vulnerability
Published on: August 11, 2026
Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62758 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62766 Windows Kerberos Elevation of Privilege Vulnerability
Published on: August 11, 2026
Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62773 Windows Kerberos Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62772 Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62774 Windows Graphics Kernel Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62785 Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-62777 Windows License Manager Elevation of Privilege Vulnerability
Published on: August 11, 2026
Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62779 Windows Schannel Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62792 Windows TCP/IP Remote Code Execution Vulnerability
Published on: August 11, 2026
Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-62784 Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-62787 Windows DNS Server Remote Code Execution Vulnerability
Published on: August 11, 2026
Use after free in Windows DNS allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-62798 Win32k Information Disclosure Vulnerability
Published on: August 11, 2026
Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-62795 Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability
Published on: August 11, 2026
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-62796 Windows NTFS Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-62797 Windows NTFS Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62812 Windows DHCP Server Elevation of Privilege Vulnerability
Published on: August 11, 2026
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62815 Microsoft QUIC Remote Code Execution Vulnerability
Published on: August 11, 2026
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-62816 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.
Read Details

CVE-2026-62817 Windows DNS Server Remote Code Execution Vulnerability
Published on: August 11, 2026
Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.
Read Details

CVE-2026-62818 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
Published on: August 11, 2026
Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-62819 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published on: August 11, 2026
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
Read Details

CVE-2026-62820 Windows DNS Server Remote Code Execution Vulnerability
Published on: August 11, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-62876 Windows Win32k Elevation of Privilege Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62877 Windows Win32k Elevation of Privilege Vulnerability
Published on: August 11, 2026
Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62878 Windows DNS Server Remote Code Execution Vulnerability
Published on: August 11, 2026
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-62889 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published on: August 11, 2026
Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-62890 Windows GDI+ Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.
Read Details

CVE-2026-62892 Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62893 Windows Deployment Services TFTP Server Remote Code Execution Vulnerability
Published on: August 11, 2026
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-62894 Windows DWM Core Library Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62897 .NET Framework Remote Code Execution Vulnerability
Published on: August 11, 2026
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-62899 .NET Security Feature Bypass Vulnerability
Published on: August 11, 2026
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
Read Details

CVE-2026-62900 .NET Information Disclosure Vulnerability
Published on: August 11, 2026
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
Read Details

CVE-2026-62901 .NET Denial of Service Vulnerability
Published on: August 11, 2026
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
Read Details

CVE-2026-62902 .NET Information Disclosure Vulnerability
Published on: August 11, 2026
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
Read Details

CVE-2026-62908 Windows Backup Engine Elevation of Privilege Vulnerability
Published on: August 11, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62909 .NET Elevation of Privilege Vulnerability
Published on: August 11, 2026
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62910 Microsoft Exchange Server Elevation of Privilege Vulnerability
Published on: August 11, 2026
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Read Details

CVE-2026-62912 Microsoft Exchange Server Denial of Service Vulnerability
Published on: August 11, 2026
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
Read Details

CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-62914 Microsoft Exchange Server Spoofing Vulnerability
Published on: August 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
Read Details

CVE-2026-62915 Microsoft Exchange Server Security Feature Bypass Vulnerability
Published on: August 11, 2026
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
Read Details

CVE-2026-54123 Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability
Published on: August 11, 2026
Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-63513 Microsoft Office Graphics Component Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-63515 Microsoft Office Remote Code Execution Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-63517 Microsoft Office Graphics Component Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-63521 Microsoft Office Word Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-63519 Microsoft Office Graphics Component Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-64922 Microsoft SharePoint Server Spoofing Vulnerability
Published on: August 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Read Details

CVE-2026-65657 Microsoft Office Remote Code Execution Vulnerability
Published on: August 11, 2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-65656 Microsoft Office Remote Code Execution Vulnerability
Published on: August 11, 2026
Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-65658 Microsoft SharePoint Server Remote Code Execution Vulnerability
Published on: August 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-65661 Microsoft Office Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-65663 Microsoft SharePoint Server Remote Code Execution Vulnerability
Published on: August 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-65660 Microsoft SharePoint Server Spoofing Vulnerability
Published on: August 11, 2026
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Read Details

CVE-2026-65664 Microsoft Office Graphics Component Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-65665 Microsoft SharePoint Server Remote Code Execution Vulnerability
Published on: August 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-65662 Windows GDI Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-65671 Remote Access API Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65672 Remote Access API Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65675 CoPilot Chat Security Feature Bypass Vulnerability
Published on: August 11, 2026
No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.
Read Details

CVE-2026-65678 Windows Win32k Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65785 Windows DHCP Client Denial of Service Vulnerability
Published on: August 11, 2026
Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.
Read Details

CVE-2026-65784 Windows NTFS Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-65786 Desktop Window Manager Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65789 Windows DNS Server Remote Code Execution Vulnerability
Published on: August 11, 2026
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-65787 Desktop Window Manager Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65788 Desktop Window Manager Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65807 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 11, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-65811 Power BI Remote Code Execution Vulnerability
Published on: August 11, 2026
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-65813 Microsoft Exchange Server Elevation of Privilege Vulnerability
Published on: August 11, 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Read Details

CVE-2026-65814 Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65815 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Published on: August 11, 2026
Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-66799 Windows Key Guard Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-68792 Microsoft Office Elevation of Privilege Vulnerability
Published on: August 11, 2026
Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-68793 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-68794 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-68795 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 11, 2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-68796 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-68800 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-68802 Microsoft Excel Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-68807 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-68806 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 11, 2026
Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-68808 Microsoft Excel Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-68809 Powerpoint Information Disclosure Vulnerability
Published on: August 11, 2026
Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-68810 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 11, 2026
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-68811 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 11, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-68813 Microsoft Excel Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-68815 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-68816 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 11, 2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-68819 Windows Network File System Denial of Service Vulnerability
Published on: August 11, 2026
Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.
Read Details

CVE-2026-68820 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-68821 Windows Package Manager Elevation of Privilege Vulnerability
Published on: August 11, 2026
Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-69320 Visual Studio Code Remote Code Execution Vulnerability
Published on: August 11, 2026
Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-69278 Visual Studio Code Security Feature Bypass Vulnerability
Published on: August 11, 2026
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Read Details

CVE-2026-69306 Visual Studio Code Security Feature Bypass Vulnerability
Published on: August 11, 2026
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Read Details

CVE-2026-70307 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65769 Microsoft Teams iOS Information Disclosure Vulnerability
Published on: August 11, 2026
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.
Read Details

CVE-2026-66301 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Published on: August 11, 2026
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network.
Read Details

CVE-2026-70312 Powerpoint Information Disclosure Vulnerability
Published on: August 11, 2026
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-70311 Microsoft Office Word Remote Code Execution Vulnerability
Published on: August 11, 2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-70313 Microsoft PowerPoint Remote Code Execution Vulnerability
Published on: August 11, 2026
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-70310 Microsoft Word Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-70316 Powerpoint Information Disclosure Vulnerability
Published on: August 11, 2026
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-70315 Microsoft Office Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-70321 Microsoft SharePoint Remote Code Execution Vulnerability
Published on: August 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-70318 Microsoft Excel Information Disclosure Vulnerability
Published on: August 11, 2026
Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-70314 Microsoft Office Information Disclosure Vulnerability
Published on: August 11, 2026
Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-70317 Microsoft Office Information Disclosure Vulnerability
Published on: August 11, 2026
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-70325 Powerpoint Information Disclosure Vulnerability
Published on: August 11, 2026
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-70319 Microsoft Office Word Information Disclosure Vulnerability
Published on: August 11, 2026
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-70320 Powerpoint Information Disclosure Vulnerability
Published on: August 11, 2026
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-70323 Microsoft Office Information Disclosure Vulnerability
Published on: August 11, 2026
Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-70322 Powerpoint Information Disclosure Vulnerability
Published on: August 11, 2026
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-70324 Microsoft SharePoint Elevation of Privilege Vulnerability
Published on: August 11, 2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Read Details

CVE-2026-70327 Microsoft Excel Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
Read Details

CVE-2026-70328 Microsoft Excel Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
Read Details

CVE-2026-70329 Microsoft Outlook Remote Code Execution Vulnerability
Published on: August 11, 2026
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-70304 Windows DNS Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-70330 Windows DNS Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability
Published on: August 11, 2026
Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
Read Details

CVE-2026-70336 Visual Studio Code Remote Code Execution Vulnerability
Published on: August 11, 2026
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-57104 Azure Storage Explorer Elevation of Privilege Vulnerability
Published on: August 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.
Read Details

CVE-2026-70340 Azure CycleCloud Elevation of Privilege Vulnerability
Published on: August 11, 2026
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
Read Details

CVE-2026-65806 Azure CycleCloud Information Disclosure Vulnerability
Published on: August 11, 2026
Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.
Read Details

CVE-2026-61352 Remote Desktop Client Remote Code Execution Vulnerability
Published on: August 11, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-65783 Windows Autopilot Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
Published on: August 11, 2026
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-70344 Windows Installer Elevation of Privilege Vulnerability
Published on: August 11, 2026
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-70345 Windows Installer Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-70346 Windows Installer Elevation of Privilege Vulnerability
Published on: August 11, 2026
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-70347 Windows Installer Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-70348 Windows Management Services Denial of Service Vulnerability
Published on: August 11, 2026
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
Read Details

CVE-2026-70355 Microsoft SharePoint Server Elevation of Privilege Vulnerability
Published on: August 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Read Details

CVE-2026-72971 Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability
Published on: August 11, 2026
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
Read Details

CVE-2026-19137 Use after free in WebGL
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-70339 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Published on: August 11, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-19140 Use after free in GPU
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19138 Heap buffer overflow in CrashReporting
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19139 Race in CredentialProvider
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19145 Use after free in Translate
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19142 Use after free in Views
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19144 Use after free in HTML
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19146 Uninitialized Use in GPU
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19147 Use after free in Aura
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19149 Use after free in Aura
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19148 Out of bounds write in GPU
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19151 Use after free in V8
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19153 Insufficient validation of untrusted input in Workers
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19152 Inappropriate implementation in Navigation
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19155 Use after free in Payments
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19158 Use after free in Views
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19157 Out of bounds write in ANGLE
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19156 Heap buffer overflow in Base
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19150 Inappropriate implementation in V8
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19161 Uninitialized Use in Skia
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19162 Out of bounds write in V8
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19160 Uninitialized Use in Skia
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19163 Use after free in Media
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19159 Use after free in Views
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19164 Insufficient validation of untrusted input in Codecs
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19165 Use after free in Extensions
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19167 Integer overflow in GPU
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19166 Use after free in Web Authentication
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19170 Use after free in WebGL
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19169 Insufficient validation of untrusted input in Contextual Tasks
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19173 Out of bounds write in Skia
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19172 Use after free in Views
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19168 Inappropriate implementation in V8
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19174 Integer overflow in V8
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19176 Use after free in Skia
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19171 Use after free in Media
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19175 Use after free in Payments
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-19177 Insufficient validation of untrusted input in UI
Published on: August 11, 2026
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Read Details

CVE-2026-42976 Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability
Published on: August 11, 2026
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-54981 Visual Studio Code Python Extension Security Feature Bypass Vulnerability
Published on: August 11, 2026
Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.
Read Details

CVE-2026-58641 .NET Elevation of Privilege Vulnerability
Published on: August 11, 2026
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
Read Details

CVE-2026-58651 Microsoft Word Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-59119 PowerShell Elevation of Privilege Vulnerability
Published on: August 11, 2026
Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-59122 Windows Telephony Service Elevation of Privilege Vulnerability
Published on: August 11, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-59125 Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability
Published on: August 11, 2026
Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-59126 Windows Event Logging Service Elevation of Privilege Vulnerability
Published on: August 11, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-59131 AMD Zen Information Disclosure Vulnerability
Published on: August 11, 2026
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-61349 Windows Work Folder Service Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61363 Remote Desktop Client Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-61359 Windows Storage Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61355 Windows Sensor Data Service Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61364 Windows Remote Desktop Services Elevation of Privilege Vulnerability
Published on: August 11, 2026
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61365 Windows Remote Desktop Services Elevation of Privilege Vulnerability
Published on: August 11, 2026
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61357 Application Information Services Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61358 Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability
Published on: August 11, 2026
Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61360 Windows GDI Information Disclosure Vulnerability
Published on: August 11, 2026
Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-61920 Windows DNS Server Remote Code Execution Vulnerability
Published on: August 11, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-61926 Windows USB Driver Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61918 Windows Remote Desktop Client Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Read Details

CVE-2026-61921 Windows Remote Desktop Client Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Read Details

CVE-2026-61929 Windows Kernel Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-61938 Windows Installer Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62698 Microsoft Digest Authentication Elevation of Privilege Vulnerability
Published on: August 11, 2026
Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62700 Windows NTFS Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62701 Windows Telephony Service Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62708 Windows Kernel Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.
Read Details

CVE-2026-62709 Windows GDI+ Information Disclosure Vulnerability
Published on: August 11, 2026
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-62710 Windows Device Association Service Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62711 Windows Win32k Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62720 Windows DHCP Server Information Disclosure Vulnerability
Published on: August 11, 2026
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
Read Details

CVE-2026-62714 Windows DHCP Server Information Disclosure Vulnerability
Published on: August 11, 2026
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
Read Details

CVE-2026-62717 Windows Message Queuing Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62721 Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability
Published on: August 11, 2026
Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62725 Windows Telephony Service Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62726 Windows Telephony Service Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62728 Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published on: August 11, 2026
Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62733 Windows Win32k Elevation of Privilege Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62743 Win32k Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-62730 Windows Wired AutoConfig Service Information Disclosure Vulnerability
Published on: August 11, 2026
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-62732 Windows Telephony Service Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62734 Windows Telephony Service Elevation of Privilege Vulnerability
Published on: August 11, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62736 Windows DHCP Client Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62757 Windows Schannel Security Feature Bypass Vulnerability
Published on: August 11, 2026
Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.
Read Details

CVE-2026-62741 Windows HTTP.sys Elevation of Privilege Vulnerability
Published on: August 11, 2026
Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62749 Windows Kernel Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62751 Windows Projected File System Elevation of Privilege Vulnerability
Published on: August 11, 2026
Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62752 Windows Kerberos Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62769 Windows DNS Elevation of Privilege Vulnerability
Published on: August 11, 2026
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62771 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62761 Windows DHCP Server Elevation of Privilege Vulnerability
Published on: August 11, 2026
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62768 Windows Installer Elevation of Privilege Vulnerability
Published on: August 11, 2026
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62770 Windows Shell Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62775 Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability
Published on: August 11, 2026
Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-62799 Windows SMB Client Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62776 Windows DHCP Server Elevation of Privilege Vulnerability
Published on: August 11, 2026
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62778 Windows DNS Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.
Read Details

CVE-2026-62780 Windows Kernel Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62782 Windows SMB Client Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
Read Details

CVE-2026-62781 RPC Runtime Library Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-62800 Windows SMBv3 Server Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-62786 Win32k Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-62788 Windows Kernel Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62790 Windows SMBv3 Server Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-62793 Windows NTFS Information Disclosure Vulnerability
Published on: August 11, 2026
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-62803 Windows DHCP Server Elevation of Privilege Vulnerability
Published on: August 11, 2026
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62807 Windows DHCP Server Elevation of Privilege Vulnerability
Published on: August 11, 2026
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62811 Windows HTTP.sys Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62814 Windows DHCP Server Information Disclosure Vulnerability
Published on: August 11, 2026
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
Read Details

CVE-2026-62823 Windows DHCP Server Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
Read Details

CVE-2026-62824 Remote Desktop Client Remote Code Execution Vulnerability
Published on: August 11, 2026
Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-62822 Windows GDI+ Remote Code Execution Vulnerability
Published on: August 11, 2026
Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-62832 Windows User Profile Service Elevation of Privilege Vulnerability
Published on: August 11, 2026
Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62871 .NET Elevation of Privilege Vulnerability
Published on: August 11, 2026
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-62872 .NET Framework Elevation of Privilege Vulnerability
Published on: August 11, 2026
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
Read Details

CVE-2026-62880 Windows NTFS Elevation of Privilege Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62881 Windows DNS Elevation of Privilege Vulnerability
Published on: August 11, 2026
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62883 Windows DNS Elevation of Privilege Vulnerability
Published on: August 11, 2026
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62885 Windows Win32k Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62886 .NET Elevation of Privilege Vulnerability
Published on: August 11, 2026
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
Read Details

CVE-2026-62887 Windows NTFS Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-62888 Windows DWM Core Library Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-62911 Microsoft Exchange Server Elevation of Privilege Vulnerability
Published on: August 11, 2026
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Read Details

CVE-2026-62842 Microsoft Office Graphics Component Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-63524 Microsoft Office Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-63525 Microsoft Office Word Remote Code Execution Vulnerability
Published on: August 11, 2026
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-63526 Microsoft Office Graphics Component Remote Code Execution Vulnerability
Published on: August 11, 2026
Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-63528 Microsoft Office Word Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-63527 Microsoft Office Word Remote Code Execution Vulnerability
Published on: August 11, 2026
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-63529 Microsoft Office Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-63530 Microsoft Office Word Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-63531 Microsoft Office Word Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-63532 Microsoft Office Remote Code Execution Vulnerability
Published on: August 11, 2026
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-63533 Microsoft Office Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-64897 Microsoft SharePoint Server Spoofing Vulnerability
Published on: August 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Read Details

CVE-2026-64898 Microsoft Office Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-64900 Microsoft SharePoint Server Spoofing Vulnerability
Published on: August 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Read Details

CVE-2026-64902 Microsoft SharePoint Server Spoofing Vulnerability
Published on: August 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Read Details

CVE-2026-64899 Microsoft Office Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-64903 Microsoft Office Remote Code Execution Vulnerability
Published on: August 11, 2026
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-64901 Microsoft SharePoint Server Remote Code Execution Vulnerability
Published on: August 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-64904 Microsoft Office Remote Code Execution Vulnerability
Published on: August 11, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-64905 Microsoft Office Word Remote Code Execution Vulnerability
Published on: August 11, 2026
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-64907 Microsoft Office Word Remote Code Execution Vulnerability
Published on: August 11, 2026
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-64906 Microsoft Access Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-64909 Microsoft Office Remote Code Execution Vulnerability
Published on: August 11, 2026
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-64910 Microsoft Office Remote Code Execution Vulnerability
Published on: August 11, 2026
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-64912 Microsoft Access Remote Code Execution Vulnerability
Published on: August 11, 2026
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-64911 Microsoft Office Remote Code Execution Vulnerability
Published on: August 11, 2026
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-64908 Microsoft Access Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-64914 Microsoft Access Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-64915 Microsoft Office Word Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-64916 Microsoft SharePoint Server Spoofing Vulnerability
Published on: August 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Read Details

CVE-2026-64920 Microsoft Access Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-64917 Microsoft Office Word Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-64919 Microsoft Access Remote Code Execution Vulnerability
Published on: August 11, 2026
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-64921 Microsoft SharePoint Server Elevation of Privilege Vulnerability
Published on: August 11, 2026
Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Read Details

CVE-2026-62882 Microsoft Outlook Spoofing Vulnerability
Published on: August 11, 2026
Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
Read Details

CVE-2026-65673 Microsoft Entra Connect Elevation of Privilege Vulnerability
Published on: August 11, 2026
CVET-EOP
Read Details

CVE-2026-65681 Windows iSCSI Target Service Denial of Service Vulnerability
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-65680 Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability
Published on: August 11, 2026
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65679 Windows iSCSI Target Service Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-65773 Windows Kernel Elevation of Privilege Vulnerability
Published on: August 11, 2026
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65774 Windows Installer Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65775 Windows Win32k Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65776 Windows Win32k Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65777 Active Directory Security Feature Bypass Vulnerability
Published on: August 11, 2026
Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.
Read Details

CVE-2026-65779 Windows Autopilot Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65780 Windows Autopilot Elevation of Privilege Vulnerability
Published on: August 11, 2026
Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65778 Windows Autopilot Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65782 Windows Autopilot Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65781 Windows Autopilot Elevation of Privilege Vulnerability
Published on: August 11, 2026
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65790 Windows Message Queuing Elevation of Privilege Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65791 Windows iSCSI Target Service Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-65795 Windows DNS Elevation of Privilege Vulnerability
Published on: August 11, 2026
No cwe for this issue in Windows DNS allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65794 Windows SMB Client Information Disclosure Vulnerability
Published on: August 11, 2026
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
Read Details

CVE-2026-65797 Windows DNS Elevation of Privilege Vulnerability
Published on: August 11, 2026
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65799 Windows DNS Elevation of Privilege Vulnerability
Published on: August 11, 2026
Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65798 Windows DNS Elevation of Privilege Vulnerability
Published on: August 11, 2026
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-65796 Windows iSCSI Target Service Denial of Service Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.
Read Details

CVE-2026-65810 .NET Framework Elevation of Privilege Vulnerability
Published on: August 11, 2026
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
Read Details

CVE-2026-66802 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability
Published on: August 11, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-66805 Microsoft SharePoint Server Remote Code Execution Vulnerability
Published on: August 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-66806 Microsoft Office Word Information Disclosure Vulnerability
Published on: August 11, 2026
Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability
Published on: August 11, 2026
Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-66808 Microsoft SharePoint Server Remote Code Execution Vulnerability
Published on: August 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-66810 Microsoft Office Word Information Disclosure Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-66809 Microsoft Office Graphics Component Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-68797 Microsoft Excel Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-68798 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-68799 Microsoft Excel Information Disclosure Vulnerability
Published on: August 11, 2026
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Read Details

CVE-2026-68801 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-68803 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 11, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-68804 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 11, 2026
Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-68805 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-68812 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-68814 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-68817 Microsoft Excel Remote Code Execution Vulnerability
Published on: August 11, 2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-56179 Windows Network Address Translation (NAT) Spoofing Vulnerability
Published on: August 11, 2026
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
Read Details

CVE-2026-70130 Microsoft Office Remote Code Execution Vulnerability
Published on: August 11, 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-70306 Microsoft Office SharePoint Spoofing Vulnerability
Published on: August 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Read Details

CVE-2026-70326 Microsoft SharePoint Server Elevation of Privilege Vulnerability
Published on: August 11, 2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Read Details

CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability
Published on: August 11, 2026
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
Read Details

CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability
Published on: August 11, 2026
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-70354 .NET Core Remote Code Execution Vulnerability
Published on: August 11, 2026
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
Read Details

CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability
Published on: August 11, 2026
Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-62738 Windows Management Instrumentation Information Disclosure Vulnerability
Published on: August 11, 2026
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
Read Details

CVE-2026-62898 Microsoft QUIC Information Disclosure Vulnerability
Published on: August 11, 2026
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
Read Details

CVE-2026-65767 Microsoft Teams for Android and iOS Spoofing Vulnerability
Published on: August 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
Read Details

CVE-2026-58639 Microsoft SharePoint Server Spoofing Vulnerability
Published on: August 11, 2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Read Details

CVE-2026-62839 Microsoft SharePoint Server Spoofing Vulnerability
Published on: August 11, 2026
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Read Details

CVE-2026-62917 Microsoft SharePoint Server Spoofing Vulnerability
Published on: August 11, 2026
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Read Details

CVE-2026-59118 Copilot Cowork Elevation of Privilege Vulnerability
Published on: August 11, 2026
Corrected CVE title. This is an informational change only.
Read Details

CVE-2026-6727 MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability
Published on: August 11, 2026
[CVE-2026-6727](https://www.cve.org/CVERecord?id=CVE-2026-6727) is an Information Disclosure vulnerability in the TPM 2.0 reference implementation involving an RSA OAEP timing side channel. MITRE assigned this CVE on behalf of the Trusted Computing Group. This document incorporates updates to Microsoft Windows that address this vulnerability. Please see [CVE-2026-6727](https://www.cve.org/CVERecord?id=CVE-2026-6727) for more information.
Read Details

CVE-2026-6726 MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot Reuse
Published on: August 11, 2026
[CVE-2026-6726](https://www.cve.org/CVERecord?id=CVE-2026-6726) is a Spoofing vulnerability in the TPM 2.0 reference implementation involving improper object-slot reuse. MITRE assigned this CVE on behalf of the Trusted Computing Group. This document incorporates updates to Microsoft Windows that address this vulnerability. Please see [CVE-2026-6726](https://www.cve.org/CVERecord?id=CVE-2026-6726) for more information.
Read Details

CVE-2025-2308 HDF5 Scale-Offset Filter H5Z__scaleoffset_decompress_one_byte heap-based overflow
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-2309 HDF5 Type Conversion Logic H5T__bit_copy heap-based overflow
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-64581 xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68258 drm/amdkfd: Check bounds on CRIU restore queue type and mqd size
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68203 media: vivid: fix cleanup bugs in vivid_init()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-64653 GitHub CLI: Unescaped variable components in request URLs could allow path traversal
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68186 binfmt_misc: set have_execfd only once the interpreter is opened
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68114 drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68183 firmware: stratix10-svc: fix memory leaks and list corruption bugs
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68190 staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-64652 GitHub CLI: Partial token disclosure in `gh auth status` output
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68273 drm/amdgpu: Fix context pstate override handling
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68097 ksmbd: validate ACE size against SID sub-authorities
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68412 wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-71497 jsoup: Cleaner may expose markup with custom raw-text elements
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-61477 Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68235 drm/amd/display: dce100: skip non-DP stream encoders for DP MST
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68407 wifi: nl80211: free RNR data on MBSSID mismatch
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-71556 go-git: Worktree operations may follow symlinks
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68323 tipc: serialize udp bearer replicast list updates
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-71557 go-git: Malicious reference names may modify files outside the reference storage
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68363 wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-65819 gopacket: Multiple layer decoders panic on crafted packets (out-of-bounds/underflow) enabling unauthenticated remote DoS via DecodingLayerParser
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68388 smb/client: handle overlapping allocated ranges in fallocate
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68288 net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68256 drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68242 drm/i915/gt: Fix NULL deref on sched_engine alloc failure
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68252 drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68374 usb: core: sysfs: add lock to bos_descriptors_read()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68353 wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68187 exec: fix unsigned loop counter wrap in transfer_args_to_stack()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68411 wifi: mac80211_hwsim: clamp virtio RX length before skb_put
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68152 amt: fix use-after-free in AMT delayed works
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68189 Bluetooth: hci_sync: Protect UUID list traversal
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68351 wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68136 net: gro: fix double aggregation of flush-marked skbs
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68083 ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68352 wifi: ath6kl: fix OOB read from firmware IE lengths in connect event
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68254 drm/i915/vrr: require valid min/max vfreq for VRR
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68238 drm/amdgpu: Release VFCT ACPI table reference
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68241 drm/i915/mst: limit DP MST ESI service loop
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68362 wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68315 sctp: validate stream count in sctp_process_strreset_inreq()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-15534 Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68272 drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68197 wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68148 fscrypt: Add missing superblock check in find_or_insert_direct_key()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-66486 Improper Output Encoding in GNU cpio
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68249 drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68155 libceph: Reject monmaps advertising zero monitors
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68397 net/iucv: take a reference on the socket found in afiucv_hs_rcv()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-66484 Path Traversal in GNU cpio
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68312 cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-72522 libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68130 ksmbd: defer destroy_previous_session() until after NTLM authentication
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68350 wifi: carl9170: fix OOB read from off-by-two in TX status handler
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68337 bpf: Reject redirect helpers without a bpf_net_context
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68395 ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68297 tipc: fix u16 MTU truncation in media and bearer MTU validation
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68141 net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68371 usb: musb: omap2430: Do not put borrowed of_node in probe
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68110 drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68206 media: v4l2-ctrls: validate HEVC active reference counts
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68195 wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68143 net: slip: serialize receive against buffer reallocation
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68111 drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68355 wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68125 mac802154: llsec: reject frames shorter than the authentication tag
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68176 tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68234 drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68366 usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68145 iomap: fix out-of-bounds bitmap_set() with zero-length range
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68278 drm/dp/mst: fix buffer overflows in sideband chunk accumulation
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68405 wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68255 drm/virtio: bound EDID block reads to the response buffer
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68100 ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68277 drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68115 drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68414 wifi: cfg80211: cancel sched scan results work on unregister
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68158 libceph: Fix multiplication overflow in decode_new_up_state_weight()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68318 pds_core: fix use-after-free on workqueue during remove
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68222 media: msi2500: Return queued buffers on start_streaming() failure
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68413 wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68182 comedi: comedi_parport: deal with premature interrupt
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68280 drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68428 KVM: x86/mmu: Fix use-after-free on vendor module reload
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68331 dpaa2-eth: put MAC endpoint device on disconnect
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68231 media: airspy: Return queued buffers on start_streaming() failure
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68131 rbd: Reset positive result codes to zero in object map update path
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68118 tcp: challenge ACK for non-exact RST in SYN-RECEIVED
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68129 gve: fix Rx queue stall on alloc failure
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68112 drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68175 tracing: Fix resource leak on mmiotrace trace_pipe close
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68156 libceph: refresh auth->authorizer_buf{,_len} after authorizer update
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68328 nfp: Check resource mutex allocation
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68217 media: pwc: Drain fill_buf on start_streaming() failure
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68123 openvswitch: fix GSO userspace truncation underflow
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68218 media: pci: dm1105: Free allocated workqueue
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68250 drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68422 btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68404 wifi: cfg80211: use wiphy work for socket owner autodisconnect
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68284 bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68408 wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68165 mm/damon/core: validate ranges in damon_set_regions()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68369 usb: gadget: printer: fix infinite loop in printer_read()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68137 net/x25: fix use-after-free in x25_kill_by_neigh()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68406 wifi: cfg80211: validate PMSR FTM preamble range
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68364 drm/amd/display: Fix ISM dc_lock deadlock during suspend
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68317 pds_core: fix auxiliary device add/del races
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68202 ALSA: seq: close a re-opened queue timer in the destructor
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68154 libceph: reject zero bucket types in crush_decode
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68417 RDMA/siw: publish QP after initialization
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68223 media: meson: vdec: Fix memory leak in error path of vdec_open
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68303 drm/vc4: hvs/v3d: Fix null dereference in unbind
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68199 wifi: ath6kl: fix OOB access from firmware ADDBA window size
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68320 sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68109 drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68336 bonding: fix devconf_all NULL dereference when IPv6 is disabled
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68300 sctp: auth: verify auth requirement when auth_chunk is NULL
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68192 wifi: brcmfmac: make release_scratchbuffers idempotent
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68116 vxlan: mdb: Fix source list corruption on a failed replace
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68257 drm/amdkfd: fix 32-bit overflow in CWSR total size calculation
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68419 RDMA/irdma: Prevent rereg_mr for non-mem regions
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68099 ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68426 xfrm: fix stale skb->prev after async crypto steals a GSO segment
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68157 libceph: guard missing CRUSH type name lookup
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68425 IB/mad: Drop unmatched RMPP responses before reassembly
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68354 firewire: net: Fix fragmented datagram reassembly
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68180 intel_th: fix MSC output device reference leak
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68392 Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68409 wifi: mac80211: defer link RX stats percpu free to RCU
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68279 drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68357 watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68113 drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68309 wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68368 usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68402 wifi: cfg80211: bound element ID read when checking non-inheritance
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68310 wifi: mt76: mt7915: guard HE capability lookups
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68367 usb: gadget: f_tcm: synchronize delayed set_alt with teardown
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68386 bpf, sockmap: Reject unhashed UDP sockets on sockmap update
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68140 net/iucv: fix use-after-free of a severed iucv_path
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68219 media: nxp: imx8-isi: Fix potential out-of-bounds issues
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68329 iommu/amd: Wait for completion instead of returning early in iommu_completion_wait()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68396 scsi: core: wake eh reliably when using scsi_schedule_eh
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68248 drm/i915: Return NULL on error in active_instance
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68246 drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68376 sctp: fix auth_hmacs array size in struct sctp_cookie
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68269 drm/i915/gem: Add missing nospec on parallel submit slot
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68349 wifi: carl9170: fix buffer overflow in rx_stream failover path
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68301 net: hsr: fix memory leak on slave unregistration by removing synced VLANs
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68135 net: hip04: fix RX buffer leak on build_skb failure
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68326 wifi: mwifiex: bound uAP association event IEs to the event buffer
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68117 tipc: clear sock->sk on the failed-insert path in tipc_sk_create()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68106 drm/amdgpu: fix division by zero with invalid uvd dimensions
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68294 net: qrtr: restrict socket creation to the initial network namespace
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68293 net/mlx5: Fix MCIA register buffer overflow on 32 dword reads
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68149 fs: preserve ACL_DONT_CACHE state in forget_cached_acl()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68151 binfmt_elf_fdpic: only honour the first PT_INTERP
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68335 rds: drop incoming messages that cross network namespace boundaries
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68410 wifi: libertas: fix memory leak in helper_firmware_cb()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68212 media: saa7134: Fix a possible memory leak in saa7134_video_init1
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68418 RDMA/irdma: Prevent user-triggered null deref on QP create
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68361 hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68090 debugobjects: Plug race against a concurrent OOM disable
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68126 mac802154: hold an interface reference across the scan worker
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68416 mtd: fix double free and WARN_ON in add_mtd_device() error paths
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68247 drm/i915/bios: range check LFP Data Block panel_type2
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68245 drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68377 net/sched: act_tunnel_key: Defer dst_release to RCU callback
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68103 drm/amdgpu: reject mapping a reserved doorbell to a new queue
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68147 fscrypt: Avoid dynamic allocation in fscrypt_get_devices()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68381 ksmbd: pin conn during async oplock break notification
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68343 smb: client: validate DFS referral PathConsumed
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68184 cdrom: fix stack out-of-bounds read in CDROMVOLCTRL
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68124 mctp: serial: handle zero-length frames to prevent rx buffer overflow
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68146 ftrace: Add global mutex to serialize trace_parser access
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68401 firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68322 rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68373 wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68214 media: rtl2832: fix use-after-free in rtl2832_remove()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68327 wan: wanxl: Only reset hardware after BAR mapping
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68188 Bluetooth: RFCOMM: Fix session UAF in set_termios
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68360 hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68271 drm/nouveau: fix reversed error cleanup order in ucopy functions
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68162 sctp: avoid auth_enable sysctl UAF during netns teardown
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68229 media: cedrus: skip invalid H.264 reference list entries
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68359 hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68313 tipc: fix infinite loop in __tipc_nl_compat_dumpit
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68324 iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68121 pppoe: reload header pointer after dev_hard_header()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68132 super: fix emergency thaw deadlock on frozen block devices
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68209 media: sun4i-csi: Return queued buffers on start_streaming() failure
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-20348 ClamAV XAR File Format Processing Memory Corruption Vulnerability
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68102 drm/amdgpu: fix aperture mapping leak
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68325 iommu/amd: Bound the early ACPI HID map
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68085 Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68196 wifi: wilc1000: validate assoc response length before subtracting header
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68370 usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68233 drm/vc4: Shut down BO cache timer before teardown
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-64654 GitHub CLI: Terminal escape sequence injection in multiple `gh` commands
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68304 wifi: brcmfmac: fix 802.1X-SHA256 call trace warning
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68243 drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-20339 ClamAV PESpin File Format Processing Integer Overflow Vulnerability
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-20338 ClamAV ZIP File Format Processing Memory Corruption Vulnerability
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-20347 ClamAV Mach-O File Format Processing Memory Corruption Vulnerability
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-20337 ClamAV ZIP File Format Processing Memory Corruption Vulnerability
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-20346 ClamAV PDF File Format Processing Memory Corruption Vulnerability
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-64563 rhashtable: clear stale iter->p on table restart
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-64655 GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68098 ksmbd: bound DACL dedup walk to copied ACEs
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68104 drm/amdgpu: invoke pm_genpd_remove() before freeing genpd
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68210 media: stm32: dcmi: unregister notifier on probe failure
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68399 bpf: Fix UAF in sock clone early bailouts
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68127 ila: reload IPv6 header after pskb_may_pull in checksum adjust
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68244 drm/i915/gem: Do not leak siblings[] on proto context error
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68171 arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68289 tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68181 mei: bus: access mei_device under device_lock on cleanup
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68348 ASoC: tas2781: bound firmware description string parsing
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68308 wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68365 USB: serial: io_edgeport: cap received transmit credits
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68391 Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68302 amt: re-read skb header pointers after every pull
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68286 drop_monitor: perform u64_stats updates under IRQ-disabled section
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68333 dpaa2-switch: put MAC endpoint device on disconnect
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68427 gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-66485 Uncontrolled Memory Allocation in GNU cpio
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68161 sctp: close UDP tunnel sockets during netns teardown
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68306 wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68338 net/packet: avoid fanout hook re-registration after unregister
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68185 LoongArch: Move jump_label_init() before parse_early_param()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68096 audit: fix recursive locking deadlock in audit_dupe_exe()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68287 drop_monitor: fix size calculations for 64-bit attributes
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68403 wifi: brcmfmac: initialize SDIO data work before cleanup
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68220 media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68389 Bluetooth: hci_qca: Clear memdump state on invalid dump size
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68166 userfaultfd: prevent registration of special VMAs
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68198 wifi: ath6kl: fix use-after-free in aggr_reset_state()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68398 ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68194 wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68215 media: radio-si476x: Unregister v4l2_device on probe failure
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68091 HID: wacom: stop hardware after post-start probe failures
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68159 libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68138 net/sched: serialize qdisc_rtab_list against concurrent get/put
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68299 vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68205 media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68259 drm/amdkfd: Check bounds in allocate_event_notification_slot
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68207 media: ti: vpe: unwind v4l2 device registration on probe error
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68088 usb: gadget: function: rndis: add length check to response query
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68108 drm/amdgpu/vce: fix integer overflow in image size
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68226 media: cx23885: add ioremap return check and cleanup
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68142 geneve: require CAP_NET_ADMIN in the device netns for changelink
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68086 mm/khugepaged: write all dirty file folios when collapsing
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68160 ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68144 phonet: pep: fix use-after-free in pep_get_sb()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68164 mm/damon/core: disallow overlapping input ranges for damon_set_regions()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68107 drm/amdgpu/vcn4: avoid rereading IB param length
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68204 media: vivid: check for vb2_is_busy() when toggling caps
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68236 drm/amd/display: set new_stream to NULL after release
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68340 hwmon: occ: validate poll response sensor blocks
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68253 drm/i915/hdcp: check streams[] bounds before overflow
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68339 Bluetooth: btusb: validate Realtek vendor event length
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68169 mptcp: pm: userspace: fix use-after-free in get_local_id
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68093 KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68153 libceph: remove debugfs files before client teardown
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68084 staging: vme_user: fix location monitor leak in tsi148 bridge
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-20345 ClamAV GPT File Format Processing Memory Corruption Vulnerability
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-72568 Redis - Heap Out-of-Bounds Read in Cluster Bus PING Message Handler
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68105 drm/amdgpu: Fix kernel panic during driver load failure
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68216 media: pwc: Return queued buffers on start_streaming() failure
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-68251 drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()
Published on: August 11, 2026
Information published.
Read Details

CVE-2024-42079 gfs2: Fix NULL pointer dereference in gfs2_log_flush
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-64523 net/handshake: Take a long-lived file reference at submit
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-64525 xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-64513 KVM: x86: Unconditionally recompute CR8 intercept on PPR update
Published on: August 11, 2026
Information published.
Read Details

CVE-2024-14040 net: nexthop: Increase weight to u16
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-55995 Double-free in the iSNS attribute decoder in open-iscsi
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-43871 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-64377 cpufreq: qcom-cpufreq-hw: Fix possible double free
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-64388 smb/client: fix chown/chgrp with SMB3 POSIX Extensions
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-64539 Bluetooth: eir: Fix stack OOB write when prepending the Flags AD
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-54332 GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-55969 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-6879 Quadratic Behavior in xml.etree.ElementPath Index Predicates
Published on: August 11, 2026
Information published.
Read Details

CVE-2024-57895 ksmbd: set ATTR_CTIME flags when setting mtime
Published on: August 11, 2026
Information published.
Read Details

CVE-2024-57898 wifi: cfg80211: clear link ID from bitmap during link delete after clean up
Published on: August 11, 2026
Information published.
Read Details

CVE-2024-57893 ALSA: seq: oss: Fix races at processing SysEx messages
Published on: August 11, 2026
Information published.
Read Details

CVE-2024-57888 workqueue: Do not warn when cancelling WQ_MEM_RECLAIM work from !WQ_MEM_RECLAIM worker
Published on: August 11, 2026
Information published.
Read Details

CVE-2024-57795 RDMA/rxe: Remove the direct link to net_device
Published on: August 11, 2026
Information published.
Read Details

CVE-2024-52005 The sideband payload is passed unfiltered to the terminal in git
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-21682 eth: bnxt: always recalculate features after XDP clearing, fix null-deref
Published on: August 11, 2026
Information published.
Read Details

CVE-2024-57857 RDMA/siw: Remove direct link to net_device
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-21629 net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packets
Published on: August 11, 2026
Information published.
Read Details

CVE-2024-57899 wifi: mac80211: fix mbss changed flags corruption on 32 bit systems
Published on: August 11, 2026
Information published.
Read Details

CVE-2026-3087 shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-37853 drm/amdkfd: debugfs hang_hws skip GPU with MES
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-37884 bpf: Fix deadlock between rcu_tasks_trace and event_mutex.
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-37961 ipvs: fix uninit-value for saddr in do_output_route4
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-37920 xsk: Fix race condition in AF_XDP generic RX path
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-37877 iommu: Clear iommu-dma ops on cleanup
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-37931 btrfs: adjust subpage bit start based on sectorsize
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-37856 btrfs: harden block_group::bg_list against list_del() races
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-37842 spi: fsl-qspi: use devm function instead of driver remove
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-37945 net: phy: allow MDIO bus PM ops to start/stop state machine for phylink-controlled PHY
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-37849 KVM: arm64: Tear down vGIC on failed vCPU creation
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-37852 drm/amdgpu: handle amdgpu_cgs_create_device() errors in amd_powerplay_create()
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-37878 perf/core: Fix WARN_ON(!ctx) in __free_event() for partial init
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-37879 9p/net: fix improper handling of bogus negative read/write replies
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-37903 drm/amd/display: Fix slab-use-after-free in hdcp
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-37938 tracing: Verify event formats that have "%*p.."
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-37957 KVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-37980 block: fix resource leak in blk_register_queue() error path
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-37861 scsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue
Published on: August 11, 2026
Information published.
Read Details

CVE-2025-37959 bpf: Scrub packet on bpf_redirect_peer
Published on: August 11, 2026
Information published.
Read Details

CVE-2024-21380 Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability
Published on: August 10, 2026
Updated the build numbers. This is an informational update only.
Read Details

CVE-2026-50309 Windows NTFS Remote Code Execution Vulnerability
Published on: August 10, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-50357 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Published on: August 10, 2026
Acknowledgement Updated
Read Details

CVE-2026-40417 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Published on: August 10, 2026
Updated the build numbers. This is an informational update only.
Read Details

CVE-2025-29821 Microsoft Dynamics Business Central Information Disclosure Vulnerability
Published on: August 10, 2026
Updated the build numbers. This is an informational update only.
Read Details

CVE-2021-34474 Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
Published on: August 10, 2026
Updated the build numbers. This is an informational update only.
Read Details

CVE-2021-40440 Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
Published on: August 10, 2026
Updated the build numbers. This is an informational update only.
Read Details

CVE-2024-38225 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Published on: August 10, 2026
Updated the build numbers. This is an informational update only.
Read Details

CVE-2021-36946 Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
Published on: August 10, 2026
Updated the build numbers. This is an informational update only.
Read Details

CVE-2026-54876 Client-Side Memory Leak in OCSP Response Checking
Published on: August 10, 2026
Information published.
Read Details

CVE-2026-64146 erofs: fix metabuf leak in inode xattr initialization
Published on: August 10, 2026
Information published.
Read Details

CVE-2026-26197 Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c
Published on: August 10, 2026
Information published.
Read Details

CVE-2026-64192 bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
Published on: August 10, 2026
Information published.
Read Details

CVE-2026-64189 netfilter: ipset: fix race between dump and ip_set_list resize
Published on: August 10, 2026
Information published.
Read Details

CVE-2026-56145 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Published on: August 10, 2026
Information published.
Read Details

CVE-2026-63999 ethtool: rss: fix indir_table and hkey leak on get_rxfh failure
Published on: August 10, 2026
Information published.
Read Details

CVE-2026-63978 net/handshake: Drain pending requests at net namespace exit
Published on: August 10, 2026
Information published.
Read Details

CVE-2026-63974 Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close
Published on: August 10, 2026
Information published.
Read Details

CVE-2026-64082 riscv: Fix register corruption from uninitialized cregs on error
Published on: August 10, 2026
Information published.
Read Details

CVE-2026-38753 A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
Published on: August 10, 2026
Information published.
Read Details

CVE-2026-38752 A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
Published on: August 10, 2026
Information published.
Read Details

CVE-2026-26199 Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero
Published on: August 10, 2026
Information published.
Read Details

CVE-2026-64187 xfs: fail recovery on a committed log item with no regions
Published on: August 10, 2026
Information published.
Read Details

CVE-2026-64205 i2c: i801: fix hardware state machine corruption in error path
Published on: August 10, 2026
Information published.
Read Details

CVE-2026-64190 net: team: fix NULL pointer dereference in team_xmit during mode change
Published on: August 10, 2026
Information published.
Read Details

CVE-2026-64206 Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock
Published on: August 10, 2026
Information published.
Read Details

CVE-2026-39879 SQL injection in syslog-ng SQL destionation driver
Published on: August 10, 2026
Information published.
Read Details

CVE-2026-64572 ipv4: fib: free fib_alias with kfree_rcu() on insert error path
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64569 mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64567 btrfs: reject free space cache with more entries than pages
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64577 gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64561 KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64564 sctp: don't free the ASCONF's own transport in DEL-IP processing
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64562 KVM: nVMX: Hide shadow VMCS right after VMCLEAR
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-18839 Popt-devel: popt-static: size_t underflow in singleoptionhelp
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64590 dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64583 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64584 usb: gadget: f_midi: cancel pending IN work before freeing the midi object
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64571 wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64576 nexthop: initialize extack in nh_res_bucket_migrate()
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64676 Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memory
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-47243 Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs
Published on: August 09, 2026
Information published.
Read Details

CVE-2025-49506 Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-34191 Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-34501 Apache Portable Runtime Utility: Heap buffer overflow in APR redis client
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-34502 Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-68081 KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-68082 libceph: fix two unsafe bare decodes in decode_lockers()
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-54876 Client-Side Memory Leak in OCSP Response Checking
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-71225 Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-71226 Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-71227 Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-44605 Rpm: heap buffer overflow in ndb slot table parsing
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64574 wifi: mac80211: tear down new links on vif update error path
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64573 Bluetooth: qca: fix NVM tag length underflow in TLV parser
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64565 Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64604 KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64578 ksmbd: validate compound request size before reading StructureSize2
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64579 xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64580 xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-50540 Kata Containers: Config Path Annotation Arbitrary File Loading
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-63140 Reachable Assertion in Elasticsearch Leading to Denial of Service
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-63136 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-53910 Heap-based Buffer Overflow in GNU diffutils
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-63308 Helm Files.Lines Denial of Service via Empty Chart Files
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-15588 Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-26080 HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-26081 HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-15788 WCOW cache mount source selector resolves NTFS junctions outside of cache root
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64560 posix-cpu-timers: Prevent UAF caused by non-leader exec() race
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-63263 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-62994 CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin
Published on: August 09, 2026
Information published.
Read Details

CVE-2026-64542 ipv6: ndisc: fix NULL deref in accept_untracked_na()
Published on: August 09, 2026
Information published.
Read Details

CVE-2025-62725 Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations
Published on: August 08, 2026
Information published.
Read Details

CVE-2026-68480 x86/bugs: Make Safe-RET robust against interrupt injection
Published on: August 08, 2026
Information published.
Read Details

CVE-2026-32597 PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)
Published on: August 08, 2026
Information published.
Read Details

CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys
Published on: August 08, 2026
Information published.
Read Details

CVE-2026-44509 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate.
Published on: August 08, 2026
Information published.
Read Details

CVE-2026-44508 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate.
Published on: August 08, 2026
Information published.
Read Details

CVE-2026-55995 Double-free in the iSNS attribute decoder in open-iscsi
Published on: August 08, 2026
Information published.
Read Details

CVE-2026-44943 remote limited file-write as root via discovery in open-iscsi
Published on: August 08, 2026
Information published.
Read Details

CVE-2026-44510 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate.
Published on: August 08, 2026
Information published.
Read Details

CVE-2026-44944 iscsiuio control-socket authentication bypass in open-iscsi
Published on: August 08, 2026
Information published.
Read Details

CVE-2026-6879 Quadratic Behavior in xml.etree.ElementPath Index Predicates
Published on: August 08, 2026
Information published.
Read Details

CVE-2026-48524 PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
Published on: August 08, 2026
Information published.
Read Details

CVE-2019-9924 rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.
Published on: August 07, 2026
Information published.
Read Details

CVE-2019-9192 In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion
Published on: August 07, 2026
Information published.
Read Details

CVE-2019-6706 Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.
Published on: August 07, 2026
Information published.
Read Details

CVE-2018-5407 Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
Published on: August 07, 2026
Information published.
Read Details

CVE-2018-1128 It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.
Published on: August 07, 2026
Information published.
Read Details

CVE-2018-6829 cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation.
Published on: August 07, 2026
Information published.
Read Details

CVE-2016-2568 pkexec, when used with --user nonpriv, allows local users to escape to the parent session
Published on: August 07, 2026
Information published.
Read Details

CVE-2010-4052 Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD.
Published on: August 07, 2026
Information published.
Read Details

CVE-2007-3205 The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed. NOTE: it is not clear whether this is a design limitation of the function or a bug in PHP, although it is likely to be regarded as a bug in Hardened-PHP and Suhosin.
Published on: August 07, 2026
Information published.
Read Details

CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability
Published on: August 07, 2026
Acknowledgement Updated
Read Details

CVE-2026-50659 .NET Spoofing Vulnerability
Published on: August 07, 2026
Acknowledgement Updated
Read Details

CVE-2026-47303 ASP.NET Core Elevation of Privilege Vulnerability
Published on: August 07, 2026
Acknowledgement Updated
Read Details

CVE-2026-62836 Azure SQL Managed Instance Elevation of Privilege Vulnerability
Published on: August 06, 2026
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
Read Details

CVE-2026-62896 Microsoft Teams Elevation of Privilege Vulnerability
Published on: August 06, 2026
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
Read Details

CVE-2026-65668 Microsoft Purview eDiscovery Elevation of Privilege Vulnerability
Published on: August 06, 2026
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.
Read Details

CVE-2026-59118 Microsoft Power Apps Elevation of Privilege Vulnerability
Published on: August 06, 2026
Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.
Read Details

CVE-2026-50516 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
Published on: August 06, 2026
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
Read Details

CVE-2026-50481 Azure Active Directory Elevation of Privilege Vulnerability
Published on: August 06, 2026
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
Read Details

CVE-2026-62918 Microsoft Teams Spoofing Vulnerability
Published on: August 06, 2026
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
Read Details

CVE-2026-59115 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
Published on: August 06, 2026
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
Read Details

CVE-2026-49163 Application Insights Profiler Elevation of Privilege Vulnerability
Published on: August 06, 2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.
Read Details

CVE-2026-68823 Azure Confidential Ledger Remote Code Execution Vulnerability
Published on: August 06, 2026
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-70332 Microsoft Office SharePoint Spoofing Vulnerability
Published on: August 06, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Read Details

CVE-2026-56161 Azure Logic Apps Information Disclosure Vulnerability
Published on: August 06, 2026
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
Read Details

CVE-2026-62830 Azure SRE Agent Elevation of Privilege Vulnerability
Published on: August 06, 2026
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
Read Details

CVE-2026-65667 Microsoft Teams Elevation of Privilege Vulnerability
Published on: August 06, 2026
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Read Details

CVE-2026-56162 Azure SQL Database Elevation of Privilege Vulnerability
Published on: August 06, 2026
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
Read Details

CVE-2026-50515 Azure Service Bus Remote Code Execution Vulnerability
Published on: August 06, 2026
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-62869 Azure Entra ID Spoofing Vulnerability
Published on: August 06, 2026
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.
Read Details

CVE-2026-63522 Azure SQL Database Elevation of Privilege Vulnerability
Published on: August 06, 2026
Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.
Read Details

CVE-2026-63508 Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability
Published on: August 06, 2026
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
Read Details

CVE-2026-62873 Microsoft 365 Admin Center Elevation of Privilege Vulnerability
Published on: August 06, 2026
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
Read Details

CVE-2026-55050 Microsoft Word Information Disclosure Vulnerability
Published on: August 06, 2026
Acknowledgement Updated
Read Details

CVE-2026-50416 Win32k Information Disclosure Vulnerability
Published on: August 03, 2026
Acknowledgement Updated
Read Details

CVE-2026-50341 Windows NTFS Information Disclosure Vulnerability
Published on: August 03, 2026
Acknowledgement Updated
Read Details

CVE-2026-50493 DirectX Graphics Kernel Elevation of Privilege Vulnerability
Published on: August 03, 2026
Acknowledgement Updated
Read Details

CVE-2026-54128 Windows DHCP Client Remote Code Execution Vulnerability
Published on: July 30, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-55129 Microsoft Office Remote Code Execution Vulnerability
Published on: July 30, 2026
Acknowledgement Updated
Read Details

CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution Vulnerability
Published on: July 30, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability
Published on: July 30, 2026
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability
Published on: July 30, 2026
Informational Change. CVE ID stays the same.
Read Details

CVE-2026-24304 Azure Cosmos DB Remote Code Execution Vulnerability
Published on: July 30, 2026
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-50422 Windows NTFS Elevation of Privilege Vulnerability
Published on: July 28, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-47301 Configuration Manager Elevation of Privilege Vulnerability
Published on: July 28, 2026
Corrected Build Number in the Security Updates table. This is an informational change only.
Read Details

CVE-2026-59117 Windows Terminal Remote Code Execution Vulnerability
Published on: July 28, 2026
Change the name of the affected software from **Microsoft Power Apps** to **Microsoft Power Apps Desktop Client**. This is an informational change only.
Read Details

Chromium: CVE-2026-13032 Use after free in WebGL
Published on: July 28, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Read Details

Chromium: CVE-2026-13028 Use after free in WebGL
Published on: July 28, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Read Details

Chromium: CVE-2026-13030 Uninitialized Use in GPU
Published on: July 28, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Read Details

Chromium: CVE-2026-13037 Use after free in WebView
Published on: July 28, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Read Details

CVE-2026-50333 Windows Spaceport.sys Elevation of Privilege Vulnerability
Published on: July 27, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-50697 Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published on: July 27, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-50343 Microsoft Install Service Elevation of Privilege Vulnerability
Published on: July 27, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-56159 DHCP Server Service Remote Code Execution Vulnerability
Published on: July 27, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()
Published on: July 27, 2026
Information published.
Read Details

CVE-2024-14040 net: nexthop: Increase weight to u16
Published on: July 27, 2026
Information published.
Read Details

CVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
Published on: July 27, 2026
Information published.
Read Details

CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting
Published on: July 27, 2026
Information published.
Read Details

CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()
Published on: July 27, 2026
Information published.
Read Details

Chromium: CVE-2026-16804 Use after free in Input
Published on: July 25, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Read Details

Chromium: CVE-2026-16805 Use after free in Blink
Published on: July 25, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Read Details

Chromium: CVE-2026-16806 Use after free in WebMCP
Published on: July 25, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Read Details

Chromium: CVE-2026-16807 Out of bounds write in Codecs
Published on: July 25, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Read Details

CVE-2026-62835 Azure Portal Information Disclosure Vulnerability
Published on: July 24, 2026
Corrected the CVE description and title. This is an informational change only.
Read Details

CVE-2026-48561 Microsoft Edge Copilot Remote Code Execution Vulnerability
Published on: July 24, 2026
Corrected the CVE description and title. This is an informational change only.
Read Details

CVE-2026-59676 Local File Deletion Attack Vector in rm_rf() in seunshare
Published on: July 24, 2026
Information published.
Read Details

CVE-2026-59677 Process Kill Attack Vector in killall() in seunshare
Published on: July 24, 2026
Information published.
Read Details

CVE-2026-64600 xfs: resample the data fork mapping after cycling ILOCK
Published on: July 24, 2026
Information published.
Read Details

CVE-2026-56167 Azure AI Search Elevation of Privilege Vulnerability
Published on: July 23, 2026
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
Read Details

CVE-2026-56163 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
Published on: July 23, 2026
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
Read Details

CVE-2026-56165 Microsoft Account Remote Code Execution Vulnerability
Published on: July 23, 2026
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
Read Details

CVE-2026-54120 Microsoft Surface Remote Code Execution Vulnerability
Published on: July 23, 2026
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-56160 Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability
Published on: July 23, 2026
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
Read Details

CVE-2026-35425 Azure API Management (APIM) Remote Code Execution Vulnerability
Published on: July 23, 2026
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-49159 Microsoft Graph Information Disclosure Vulnerability
Published on: July 23, 2026
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
Read Details

CVE-2026-50517 Microsoft M365 Copilot Remote Code Execution Vulnerability
Published on: July 23, 2026
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
Read Details

CVE-2026-56191 Microsoft Exchange Online Tampering Vulnerability
Published on: July 23, 2026
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
Read Details

CVE-2026-57106 Data Quality Elevation of Privilege Vulnerability
Published on: July 23, 2026
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
Read Details

CVE-2026-62825 Azure Key Vault Elevation of Privilege Vulnerability
Published on: July 23, 2026
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
Read Details

CVE-2026-58630 Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
Published on: July 23, 2026
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
Read Details

CVE-2026-58275 Azure DNS Elevation of Privilege Vulnerability
Published on: July 23, 2026
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
Read Details

CVE-2026-62835 Online Services Information Disclosure Vulnerability
Published on: July 23, 2026
Improper authorization in Online Services allows an unauthorized attacker to disclose information over a network.
Read Details

CVE-2026-47729 Squid: Memory disclosure in FTP gateway
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-56145 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-63140 Reachable Assertion in Elasticsearch Leading to Denial of Service
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-63136 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-53910 Heap-based Buffer Overflow in GNU diffutils
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-55973 'dns-error-reporting: yes' leads to stack buffer overflow
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-44687 Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-50248 BOGUS configured primary hostname accepted for XFR in auth/rpz zones
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-55708 Privacy/configuration issue when adding local data in views through 'unbound-control'
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-44621 Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-55717 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-40691 Packet of death for DNSCrypt over TCP
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-32665 Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-46582 A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-42955 Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-50046 Possible heap use-after-free in an error path when a DoT forwarded query is jostled out
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-55990 Packet of death for a DNSCrypt misconfigured Unbound
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-55991 Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-50251 Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-50252 Possible cache poisoning attack by mapping source port population per thread
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-50243 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-63308 Helm Files.Lines Denial of Service via Empty Chart Files
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-15588 Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-26080 HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-26081 HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-15788 WCOW cache mount source selector resolves NTFS junctions outside of cache root
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-44509 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate.
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-44508 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate.
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-50012 Squid: Memory corruption in cache_digest reply handling
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-54171 Excon: redact additional sensitive/risky headers when following redirects
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-38753 A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-38752 A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-63263 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-62994 CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-50045 'max-global-quota' reset by DNSSEC validation restarts
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-44690 Cross-zone wildcard cache poisoning via RRSIG.labels manipulation
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-52863 Memory corruption could lead to crash and denial of service
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-56416 Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-56444 Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-54478 DNS Cookie bypass when combined with proxy-protocol use
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-14586 Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-41637 Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-44510 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate.
Published on: July 23, 2026
Information published.
Read Details

CVE-2026-15028 Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-57219 RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-59884 pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-59886 pyasn1: Uncontrolled resource consumption when converting decoded REAL values
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-42533 NGINX Map directive and Regex matching vulnerability
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-56434 NGINX ngx_http_ssi_module vulnerability
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-26197 Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-64192 bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-64189 netfilter: ipset: fix race between dump and ip_set_list resize
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-64188 net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-57220 RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-57217 RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-57213 RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-57216 RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-57211 RabbitMQ: UNC SSRF affecting the management UI on Windows
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-57215 RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-59885 pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-26199 Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-64187 xfs: fail recovery on a committed log item with no regions
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-64205 i2c: i801: fix hardware state machine corruption in error path
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-64190 net: team: fix NULL pointer dereference in team_xmit during mode change
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-64206 Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-64191 i2c: stub: Reject I2C block transfers with invalid length
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-39879 SQL injection in syslog-ng SQL destionation driver
Published on: July 22, 2026
Information published.
Read Details

CVE-2026-50407 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Published on: July 22, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-50377 Windows Kernel Elevation of Privilege Vulnerability
Published on: July 22, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-50466 Microsoft Brokering File System Elevation of Privilege Vulnerability
Published on: July 22, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-50441 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Published on: July 22, 2026
Updated an acknowledgement. This is an informational change only.
Read Details

CVE-2026-50458 Microsoft Brokering File System Elevation of Privilege Vulnerability
Published on: July 22, 2026
Updated an acknowledgement. This is an informational change only.
Read Details