Latest Microsoft CVEs
Every organization faces unique cybersecurity challenges, but successful outcomes require more than technology alone. Our case studies highlight how Gilliam Security works alongside executives, security leaders, and stakeholders to build practical security programs, strengthen governance, manage risk, and achieve critical compliance objectives in complex business environments.From guiding organizations through leadership transitions and regulatory audits to establishing governance functions for global enterprises and preparing government contractors for CMMC requirements, these engagements demonstrate our commitment to delivering measurable results, sustainable security practices, and long-term business value.
Provided below are the Microsoft CVEs from the last 30 days:
CVE-2026-68801 Microsoft Excel Remote Code Execution Vulnerability Published on: August 21, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-64903 Microsoft Office Remote Code Execution Vulnerability Published on: August 21, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-64899 Microsoft Office Information Disclosure Vulnerability Published on: August 21, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability Published on: August 21, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability Published on: August 21, 2026 Corrected **Exploited** to **No**. This vulnerability was not exploited in the wild. This is an informational change only. Read Details
CVE-2026-54981 Visual Studio Code Python Extension Security Feature Bypass Vulnerability Published on: August 21, 2026 Affected software updated with new package information. Read Details
CVE-2026-58547 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability Published on: August 21, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-49183 Windows Clipboard Server Elevation of Privilege Vulnerability Published on: August 21, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-55134 Microsoft Word Remote Code Execution Vulnerability Published on: August 21, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-50466 Microsoft Brokering File System Elevation of Privilege Vulnerability Published on: August 21, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-32202 Windows Shell Spoofing Vulnerability Published on: August 21, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62834 Azure Data Factory Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-65801 Microsoft Exchange Online Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-68789 Azure SQL Database Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69519 Azure Stack HCI Information Disclosure Vulnerability Published on: August 20, 2026 <p>Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69851 Microsoft Entra ID Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability Published on: August 20, 2026 <p>Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-62703 Windows DWM Core Library Information Disclosure Vulnerability Published on: August 20, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability Published on: August 20, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62754 Windows Kerberos Elevation of Privilege Vulnerability Published on: August 20, 2026 Updated links to security updates. This is an informational change only. Read Details
CVE-2026-62755 Windows DHCP Client Elevation of Privilege Vulnerability Published on: August 20, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-65786 Desktop Window Manager Elevation of Privilege Vulnerability Published on: August 20, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-55015 Microsoft Remote Help Denial of Service Vulnerability Published on: August 20, 2026 <p>Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.</p> Read Details
CVE-2026-55013 Windows Remote Help Defense Spoofing Vulnerability Published on: August 20, 2026 <p>Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.</p> Read Details
CVE-2026-61363 Remote Desktop Client Remote Code Execution Vulnerability Published on: August 20, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62728 Windows Common Log File System Driver Elevation of Privilege Vulnerability Published on: August 20, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-66802 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability Published on: August 20, 2026 Corrected the Executive Summary to clarify that the vulnerability affects Windows Device Health Attestation (DHA), not Microsoft Azure Attestation. This is an informational change only. Read Details
CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability Published on: August 20, 2026 Updated links to security updates. This is an informational change only. Read Details
CVE-2026-70105 Microsoft Word Information Disclosure Vulnerability Published on: August 20, 2026 Information published. This CVE was addressed by updates that were released in August 2026, but the CVE was inadvertently omitted from the August 2026 Security Updates. This is an informational change only. Customers who have already installed the August 2026 updates do not need to take any further action. Read Details
CVE-2026-65770 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability Published on: August 20, 2026 <p>Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-63509 Microsoft Fabric Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-65816 Azure Arc Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-66309 Azure SQL Database Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-66800 Azure Data Factory Information Disclosure Vulnerability Published on: August 20, 2026 <p>Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-68782 Azure SQL Database Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69419 Azure Data Manager for Energy Remote Code Execution Vulnerability Published on: August 20, 2026 <p>Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69502 Azure SQL Database Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69400 Azure Logic Apps Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69555 Azure Arc Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69558 Microsoft Partner Center Information Disclosure Vulnerability Published on: August 20, 2026 <p>Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69543 Azure Virtual Machines Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69855 Microsoft Copilot in Azure Information Disclosure Vulnerability Published on: August 20, 2026 <p>Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability Published on: August 20, 2026 Added clarifying information to the mitigation. This is an informational change only. Read Details
CVE-2026-54118 Microsoft SQL Server Remote Code Execution Vulnerability Published on: August 20, 2026 The CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only. Read Details
CVE-2026-54117 Microsoft SQL Server Remote Code Execution Vulnerability Published on: August 20, 2026 The CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only. Read Details
CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability Published on: August 20, 2026 Updated links to security updates. This is an informational change only. Read Details
CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability Published on: August 20, 2026 Corrected the Executive Summary to clarify that the vulnerability affects Windows Device Health Attestation (DHA), not Microsoft Azure Attestation. This is an informational change only. Read Details
CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability Published on: August 19, 2026 Acknowledgement Updated Read Details
CVE-2026-62705 Microsoft Brokering File System Elevation of Privilege Vulnerability Published on: August 19, 2026 Corrected the CVE title from **Windows Bind Filter Driver Elevation of Privilege Vulnerability** to **Microsoft Brokering File System Elevation of Privilege Vulnerability** and updated the acknowledgement. These are informational changes only. Read Details
CVE-2026-69414 Microsoft Defender Elevation of Privilege Vulnerability Published on: August 19, 2026 CWE added. Informational change only. Read Details
CVE-2026-65811 Power BI Remote Code Execution Vulnerability Published on: August 19, 2026 Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. Read Details
CVE-2026-65675 CoPilot Chat Security Feature Bypass Vulnerability Published on: August 19, 2026 CWE added. Informational change only. Read Details
CVE-2020-1173 Microsoft Power BI Report Server Spoofing Vulnerability Published on: August 19, 2026 Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. Read Details
CVE-2021-26859 Microsoft Power BI Information Disclosure Vulnerability Published on: August 19, 2026 Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. Read Details
CVE-2021-41372 Power BI Report Server Spoofing Vulnerability Published on: August 19, 2026 Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. Read Details
CVE-2023-21806 Power BI Report Server Spoofing Vulnerability Published on: August 19, 2026 Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. Read Details
CVE-2024-43612 Power BI Report Server Spoofing Vulnerability Published on: August 19, 2026 Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. Read Details
CVE-2024-43481 Power BI Report Server Spoofing Vulnerability Published on: August 19, 2026 Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. Read Details
CVE-2026-50383 Windows Print Spooler Information Disclosure Vulnerability Published on: August 19, 2026 Acknowledgement Updated Read Details
CVE-2026-49798 Windows Kernel Elevation of Privilege Vulnerability Published on: August 19, 2026 Acknowledgement Updated Read Details
CVE-2026-58647 Microsoft PowerBI Report Server Spoofing Vulnerability Published on: August 19, 2026 Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. Read Details
CVE-2026-42912 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 19, 2026 Acknowledgement Updated Read Details
CVE-2026-24301 Microsoft Copilot Information Disclosure Vulnerability Published on: August 18, 2026 <p>Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-65791 Windows iSCSI Target Service Remote Code Execution Vulnerability Published on: August 18, 2026 Acknowledgement Updated Read Details
CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability Published on: August 18, 2026 Acknowledgement Updated Read Details
CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability Published on: August 18, 2026 Acknowledgement Updated Read Details
CVE-2026-47632 Azure Connected Machine Agent Elevation of Privilege Vulnerability Published on: August 18, 2026 Corrected the affected product from **Azure Monitor Agent Metrics Extension** to **Azure Connected Machine Agent** and updated the Security Updates table. This is an informational change only. Read Details
CVE-2026-50419 Windows Kernel Information Disclosure Vulnerability Published on: August 18, 2026 Acknowledgement Updated Read Details
CVE-2026-56642 Microsoft Fabric Data Warehouse Remote Code Execution Vulnerability Published on: August 18, 2026 Updated the Security Updates table by removing an affected software entry. No user action is required. This is an informational change only. Read Details
CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability Published on: August 17, 2026 Acknowledgement Updated Read Details
CVE-2026-56188 Windows Server Network driver Remote Code Execution Vulnerability Published on: August 17, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62722 Microsoft Brokering File System Elevation of Privilege Vulnerability Published on: August 17, 2026 Corrected the CVE description and title. This is an informational change only. Read Details
CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability Published on: August 17, 2026 Acknowledgement Updated Read Details
CVE-2026-63519 Microsoft Office Graphics Component Remote Code Execution Vulnerability Published on: August 17, 2026 Acknowledgement Updated Read Details
CVE-2026-63513 Microsoft Office Graphics Component Remote Code Execution Vulnerability Published on: August 17, 2026 Acknowledgement Updated Read Details
CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability Published on: August 17, 2026 Acknowledgement Updated Read Details
CVE-2026-58612 PowerShell Information Disclosure Vulnerability Published on: August 17, 2026 Acknowledgement Updated Read Details
CVE-2026-62886 .NET Elevation of Privilege Vulnerability Published on: August 17, 2026 Acknowledgement Updated Read Details
CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability Published on: August 17, 2026 Acknowledgement Updated Read Details
CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability Published on: August 16, 2026 Corrected build number for the security update. This in an informational change only. Read Details
CVE-2026-65769 Microsoft Teams iOS Information Disclosure Vulnerability Published on: August 16, 2026 Corrected build number for the security update. This in an informational change only. Read Details
CVE-2026-57104 Azure Storage Explorer Elevation of Privilege Vulnerability Published on: August 16, 2026 Corrected build number for the security update. This in an informational change only. Read Details
CVE-2026-65767 Microsoft Teams for Android Spoofing Vulnerability Published on: August 16, 2026 Corrected build number for the security update. This in an informational change only. Read Details
CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability Published on: August 16, 2026 Corrected the listed software in the Security Updates table. Microsoft recommends installing the security update as soon as possible. Read Details
CVE-2026-72970 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Published on: August 14, 2026 <p>Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-61347 Windows Event Logging Service Information Disclosure Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-62746 Win32k Information Disclosure Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-62755 Windows DHCP Client Elevation of Privilege Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-62777 Windows License Manager Elevation of Privilege Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-65671 Remote Access API Elevation of Privilege Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-68821 Windows Package Manager Elevation of Privilege Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
Chromium: CVE-2026-19560 Use after free in Blink Published on: August 14, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
Chromium: CVE-2026-19559 Use after free in HTML Published on: August 14, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
Chromium: CVE-2026-19558 Use after free in Extensions Published on: August 14, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
Chromium: CVE-2026-19557 Use after free in TabStrip Published on: August 14, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
Chromium: CVE-2026-19556 Use after free in V8 Published on: August 14, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-59126 Windows Event Logging Service Elevation of Privilege Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-58612 PowerShell Information Disclosure Vulnerability Published on: August 14, 2026 The security updates for Powershell have been updated. Read Details
CVE-2026-59119 PowerShell Elevation of Privilege Vulnerability Published on: August 14, 2026 The security updates for Powershell have been updated. Read Details
CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability Published on: August 14, 2026 The security updates for Powershell have been updated. Read Details
CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability Published on: August 14, 2026 The security updates for Powershell have been updated. Read Details
CVE-2026-50523 Microsoft PowerShell Remote Code Execution Vulnerability Published on: August 14, 2026 The security updates for Powershell have been updated. Read Details
CVE-2026-69414 Microsoft Defender Elevation of Privilege Vulnerability Published on: August 14, 2026 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available. Read Details
CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-49162 Microsoft Brokering File System Elevation of Privilege Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-50313 Windows NTFS Remote Code Execution Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-32153 Windows Speech Runtime Elevation of Privilege Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-48566 Windows DWM Core Library Information Disclosure Vulnerability Published on: August 14, 2026 This CVE has been discovered to be an Elevation of Privilege and not an Information Disclosure. The CVE's Impact has been updated. Read Details
CVE-2026-49162 Microsoft Brokering File System Elevation of Privilege Vulnerability Published on: August 13, 2026 Added acknowledgements. This is an informational change only. Read Details
CVE-2026-49798 Windows Kernel Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-50342 Windows MIDI Service Module Elevation of Privileges Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-50298 Windows Spaceport.sys Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-50309 Windows NTFS Remote Code Execution Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-50387 Windows GDI Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-50383 Windows Print Spooler Information Disclosure Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-50461 Windows NTFS Remote Code Execution Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-45592 Windows Internet (wininet.dll) Elevation of Privilege Vulnerability Published on: August 13, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-45593 Windows SDK Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-45597 Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-45638 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-45637 Microsoft DWM Core Library Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-44814 Windows DWM Core Library Information Disclosure Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-61346 Windows Graphics Kernel Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-62695 Windows Storage Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-61359 Windows Storage Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability Published on: August 13, 2026 Added acknowledgements. This is an informational change only. Read Details
CVE-2026-62688 Windows MIDI Service Module Elevation of Privileges Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-62897 .NET Framework Remote Code Execution Vulnerability Published on: August 13, 2026 Removed Linux and macOS products from the Affected Software table. This is an informational change only. Read Details
CVE-2026-62902 .NET Information Disclosure Vulnerability Published on: August 13, 2026 Removed Linux and macOS products from the Affected Software table. This is an informational change only. Read Details
CVE-2026-70354 .NET Core Remote Code Execution Vulnerability Published on: August 13, 2026 Removed Linux and macOS products from the Affected Software table. This is an informational change only. Read Details
CVE-2026-62871 .NET Elevation of Privilege Vulnerability Published on: August 13, 2026 Removed Linux and macOS products from the Affected Software table. This is an informational change only. Read Details
CVE-2026-62886 .NET Elevation of Privilege Vulnerability Published on: August 13, 2026 Removed Linux and macOS products from the Affected Software table. This is an informational change only. Read Details
CVE-2026-62898 Microsoft QUIC Information Disclosure Vulnerability Published on: August 13, 2026 Removed Linux and macOS products from the Affected Software table. This is an informational change only. Read Details
CVE-2026-64906 Microsoft Access Remote Code Execution Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-65796 Windows iSCSI Target Service Remote Code Execution Vulnerability Published on: August 13, 2026 Updated the CVE title, changed the security impact from Denial of Service to Remote Code Execution, changed the severity from Important to Critical, updated the CVSS score from 5.9 to 8.1, and corrected the severity and impact entries in the Security Updates table. These are informational changes only. Customers who have successfully installed the update do not need to take any further action. Read Details
CVE-2026-62696 Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability Published on: August 12, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability Published on: August 12, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability Published on: August 12, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-68815 Microsoft Excel Remote Code Execution Vulnerability Published on: August 12, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-70348 Windows Management Services Denial of Service Vulnerability Published on: August 12, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-42976 Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability Published on: August 12, 2026 Updated product information in the Software Update table. This is an informational change only. Read Details
CVE-2026-50687 Windows Win32k Elevation of Privilege Vulnerability Published on: August 12, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-58538 Windows Bluetooth Service Elevation of Privilege Vulnerability Published on: August 12, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-50655 Microsoft Windows Media Foundation Remote Code Execution Vulnerability Published on: August 12, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-58643 Windows Admin Center Spoofing Vulnerability Published on: August 12, 2026 Corrected Build Number in the Security Updates table. This is an informational change only. Read Details
CVE-2026-50476 Windows Network Connections Service Elevation of Privilege Vulnerability Published on: August 12, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2022-41127 Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability Published on: August 12, 2026 Updated the build numbers. This is an informational update only. Read Details
CVE-2026-45637 Microsoft DWM Core Library Elevation of Privilege Vulnerability Published on: August 12, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-50472 Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-56174 Windows Narrator Braille Elevation of Privilege Vulnerability Published on: August 11, 2026 Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-58650 Visual Studio Code Security Feature Bypass Vulnerability Published on: August 11, 2026 Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. Read Details
CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability Published on: August 11, 2026 Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-57105 Microsoft Office SharePoint Spoofing Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-62829 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-62827 Microsoft SharePoint Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-62837 Microsoft SharePoint Server Information Disclosure Vulnerability Published on: August 11, 2026 Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. Read Details
CVE-2026-63514 Microsoft SharePoint Server Remote Code Execution Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Read Details
CVE-2026-63512 Microsoft SharePoint Server Tampering Vulnerability Published on: August 11, 2026 Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network. Read Details
CVE-2026-63516 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-63520 Microsoft SharePoint Server Remote Code Execution Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-40375 Microsoft Dynamics Business Central Information Disclosure Vulnerability Published on: August 11, 2026 Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network. Read Details
CVE-2026-54113 Remote Procedure Call Denial of Service Vulnerability Published on: August 11, 2026 Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network. Read Details
CVE-2026-54984 Windows Imaging Component Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-49179 Windows Active Directory Domain Services Remote Code Execution Vulnerability Published on: August 11, 2026 Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-58612 PowerShell Information Disclosure Vulnerability Published on: August 11, 2026 Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-59113 Visual Studio Code Remote Code Execution Vulnerability Published on: August 11, 2026 Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-47299 Azure Monitor Agent Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-47285 Visual Studio Code Information Disclosure Vulnerability Published on: August 11, 2026 Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-59127 Windows Installer Elevation of Privilege Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-59128 Windows Encrypting File System (EFS) Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. Read Details
CVE-2026-59133 Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability Published on: August 11, 2026 Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-59130 AMD Zen Information Disclosure Vulnerability Published on: August 11, 2026 No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. Read Details
CVE-2026-59132 Windows TCP/IP Denial of Service Vulnerability Published on: August 11, 2026 Information published. Read Details
CVE-2026-59135 Microsoft Windows Search Component Information Disclosure Vulnerability Published on: August 11, 2026 Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. Read Details
CVE-2026-59134 Remote Desktop Client Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-59136 Microsoft COM for Windows Information Disclosure Vulnerability Published on: August 11, 2026 Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally. Read Details
CVE-2026-59137 Windows Event Logging Service Information Disclosure Vulnerability Published on: August 11, 2026 Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally. Read Details
CVE-2026-59138 Microsoft Remote Registry Service Denial of Service Vulnerability Published on: August 11, 2026 Information published. Read Details
CVE-2026-61345 Microsoft Remote Registry Service Denial of Service Vulnerability Published on: August 11, 2026 Information published. Read Details
CVE-2026-61346 Windows Graphics Kernel Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61353 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61347 Windows Event Logging Service Information Disclosure Vulnerability Published on: August 11, 2026 Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally. Read Details
CVE-2026-61361 Windows DHCP Client Remote Code Execution Vulnerability Published on: August 11, 2026 Use after free in Windows DHCP Client allows an authorized attacker to execute code locally. Read Details
CVE-2026-61348 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61350 Windows NTFS Information Disclosure Vulnerability Published on: August 11, 2026 Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. Read Details
CVE-2026-61356 Windows Remote Desktop Services Elevation of Privilege Vulnerability Published on: August 11, 2026 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61367 Windows Remote Desktop Services Elevation of Privilege Vulnerability Published on: August 11, 2026 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61923 Windows Display Enhancement Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61366 Windows Network Connection Broker Elevation of Privilege Vulnerability Published on: August 11, 2026 Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61368 Windows Hyper-V Information Disclosure Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally. Read Details
CVE-2026-61924 Windows Remote Desktop Client Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-61925 Windows Installer Elevation of Privilege Vulnerability Published on: August 11, 2026 Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61927 Windows Bind Filter Driver Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61928 Windows Hello Tampering Vulnerability Published on: August 11, 2026 Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. Read Details
CVE-2026-61930 Windows Kernel Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61937 Windows HTTP.sys Elevation of Privilege Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62692 Windows Remote Desktop Services Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61932 Windows DWM Core Library Elevation of Privilege Vulnerability Published on: August 11, 2026 Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61933 Windows DWM Core Library Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. Read Details
CVE-2026-61934 Windows Bind Filter Driver Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61936 Windows Defender Firewall Service Security Feature Bypass Vulnerability Published on: August 11, 2026 Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally. Read Details
CVE-2026-61939 Winlogon Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Winlogon allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62695 Windows Storage Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62688 Windows MIDI Service Module Elevation of Privileges Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62690 Windows Push Notifications Elevation of Privilege Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62693 Windows MIDI Service Module Elevation of Privileges Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62696 Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62702 Windows Graphics Kernel Denial of Service Vulnerability Published on: August 11, 2026 Information published. Read Details
CVE-2026-62699 Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack. Read Details
CVE-2026-62703 Windows DWM Core Library Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62705 Windows Bind Filter Driver Elevation of Privilege Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62707 Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62713 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62712 Windows Win32k Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62718 Windows DHCP Server Information Disclosure Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. Read Details
CVE-2026-62715 Windows DHCP Server Information Disclosure Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. Read Details
CVE-2026-62716 Windows DHCP Server Information Disclosure Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. Read Details
CVE-2026-62719 Windows Message Queuing Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62722 Windows Bind Filter Driver Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62723 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62724 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62748 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62729 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62746 Win32k Information Disclosure Vulnerability Published on: August 11, 2026 Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62740 Windows Imaging Component Information Disclosure Vulnerability Published on: August 11, 2026 Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62753 Windows HTTP.sys Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62735 Windows HTTP.sys Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62737 Windows Kernel Elevation of Privilege Vulnerability Published on: August 11, 2026 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62739 Windows HTTP.sys Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62742 Windows DHCP Server Information Disclosure Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. Read Details
CVE-2026-62745 Windows DHCP Server Information Disclosure Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. Read Details
CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62750 Windows HTTP Protocol Stack Tampering Vulnerability Published on: August 11, 2026 Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network. Read Details
CVE-2026-62754 Windows Kerberos Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62783 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62755 Windows DHCP Client Elevation of Privilege Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62758 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62766 Windows Kerberos Elevation of Privilege Vulnerability Published on: August 11, 2026 Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62773 Windows Kerberos Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62772 Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62774 Windows Graphics Kernel Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62785 Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62777 Windows License Manager Elevation of Privilege Vulnerability Published on: August 11, 2026 Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62779 Windows Schannel Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62792 Windows TCP/IP Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62784 Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network. Read Details
CVE-2026-62787 Windows DNS Server Remote Code Execution Vulnerability Published on: August 11, 2026 Use after free in Windows DNS allows an authorized attacker to execute code over a network. Read Details
CVE-2026-62798 Win32k Information Disclosure Vulnerability Published on: August 11, 2026 Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62795 Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability Published on: August 11, 2026 Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62796 Windows NTFS Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62797 Windows NTFS Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62812 Windows DHCP Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62815 Microsoft QUIC Remote Code Execution Vulnerability Published on: August 11, 2026 Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62816 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. Read Details
CVE-2026-62817 Windows DNS Server Remote Code Execution Vulnerability Published on: August 11, 2026 Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network. Read Details
CVE-2026-62818 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability Published on: August 11, 2026 Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network. Read Details
CVE-2026-62819 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Published on: August 11, 2026 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine Read Details
CVE-2026-62820 Windows DNS Server Remote Code Execution Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62876 Windows Win32k Elevation of Privilege Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62877 Windows Win32k Elevation of Privilege Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62878 Windows DNS Server Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62889 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Published on: August 11, 2026 Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62890 Windows GDI+ Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally. Read Details
CVE-2026-62892 Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62893 Windows Deployment Services TFTP Server Remote Code Execution Vulnerability Published on: August 11, 2026 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62894 Windows DWM Core Library Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62897 .NET Framework Remote Code Execution Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-62899 .NET Security Feature Bypass Vulnerability Published on: August 11, 2026 Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. Read Details
CVE-2026-62900 .NET Information Disclosure Vulnerability Published on: August 11, 2026 Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-62901 .NET Denial of Service Vulnerability Published on: August 11, 2026 Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. Read Details
CVE-2026-62902 .NET Information Disclosure Vulnerability Published on: August 11, 2026 Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-62908 Windows Backup Engine Elevation of Privilege Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62909 .NET Elevation of Privilege Vulnerability Published on: August 11, 2026 Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62910 Microsoft Exchange Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-62912 Microsoft Exchange Server Denial of Service Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network. Read Details
CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. Read Details
CVE-2026-62914 Microsoft Exchange Server Spoofing Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-62915 Microsoft Exchange Server Security Feature Bypass Vulnerability Published on: August 11, 2026 Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. Read Details
CVE-2026-54123 Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability Published on: August 11, 2026 Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally. Read Details
CVE-2026-63513 Microsoft Office Graphics Component Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-63515 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-63517 Microsoft Office Graphics Component Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-63521 Microsoft Office Word Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-63519 Microsoft Office Graphics Component Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64922 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-65657 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-65656 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-65658 Microsoft SharePoint Server Remote Code Execution Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Read Details
CVE-2026-65661 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-65663 Microsoft SharePoint Server Remote Code Execution Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Read Details
CVE-2026-65660 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-65664 Microsoft Office Graphics Component Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-65665 Microsoft SharePoint Server Remote Code Execution Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Read Details
CVE-2026-65662 Windows GDI Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally. Read Details
CVE-2026-65671 Remote Access API Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65672 Remote Access API Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65675 CoPilot Chat Security Feature Bypass Vulnerability Published on: August 11, 2026 No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network. Read Details
CVE-2026-65678 Windows Win32k Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65785 Windows DHCP Client Denial of Service Vulnerability Published on: August 11, 2026 Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network. Read Details
CVE-2026-65784 Windows NTFS Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. Read Details
CVE-2026-65786 Desktop Window Manager Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65789 Windows DNS Server Remote Code Execution Vulnerability Published on: August 11, 2026 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-65787 Desktop Window Manager Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65788 Desktop Window Manager Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65807 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-65811 Power BI Remote Code Execution Vulnerability Published on: August 11, 2026 Improper input validation in Power BI allows an authorized attacker to execute code over a network. Read Details
CVE-2026-65813 Microsoft Exchange Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-65814 Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65815 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. Read Details
CVE-2026-66799 Windows Key Guard Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-68792 Microsoft Office Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-68793 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68794 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68795 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68796 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68800 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68802 Microsoft Excel Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-68807 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68806 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68808 Microsoft Excel Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-68809 Powerpoint Information Disclosure Vulnerability Published on: August 11, 2026 Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-68810 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68811 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68813 Microsoft Excel Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-68815 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68816 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68819 Windows Network File System Denial of Service Vulnerability Published on: August 11, 2026 Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network. Read Details
CVE-2026-68820 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-68821 Windows Package Manager Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69320 Visual Studio Code Remote Code Execution Vulnerability Published on: August 11, 2026 Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-69278 Visual Studio Code Security Feature Bypass Vulnerability Published on: August 11, 2026 Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. Read Details
CVE-2026-69306 Visual Studio Code Security Feature Bypass Vulnerability Published on: August 11, 2026 Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. Read Details
CVE-2026-70307 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65769 Microsoft Teams iOS Information Disclosure Vulnerability Published on: August 11, 2026 Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-66301 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability Published on: August 11, 2026 Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network. Read Details
CVE-2026-70312 Powerpoint Information Disclosure Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70311 Microsoft Office Word Remote Code Execution Vulnerability Published on: August 11, 2026 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-70313 Microsoft PowerPoint Remote Code Execution Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70310 Microsoft Word Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70316 Powerpoint Information Disclosure Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70315 Microsoft Office Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70321 Microsoft SharePoint Remote Code Execution Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Read Details
CVE-2026-70318 Microsoft Excel Information Disclosure Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70314 Microsoft Office Information Disclosure Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70317 Microsoft Office Information Disclosure Vulnerability Published on: August 11, 2026 Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70325 Powerpoint Information Disclosure Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70319 Microsoft Office Word Information Disclosure Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70320 Powerpoint Information Disclosure Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70323 Microsoft Office Information Disclosure Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70322 Powerpoint Information Disclosure Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70324 Microsoft SharePoint Elevation of Privilege Vulnerability Published on: August 11, 2026 Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-70327 Microsoft Excel Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-70328 Microsoft Excel Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-70329 Microsoft Outlook Remote Code Execution Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-70304 Windows DNS Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-70330 Windows DNS Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally. Read Details
CVE-2026-70336 Visual Studio Code Remote Code Execution Vulnerability Published on: August 11, 2026 Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-57104 Azure Storage Explorer Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network. Read Details
CVE-2026-70340 Azure CycleCloud Elevation of Privilege Vulnerability Published on: August 11, 2026 Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-65806 Azure CycleCloud Information Disclosure Vulnerability Published on: August 11, 2026 Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network. Read Details
CVE-2026-61352 Remote Desktop Client Remote Code Execution Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-65783 Windows Autopilot Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-70344 Windows Installer Elevation of Privilege Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-70345 Windows Installer Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-70346 Windows Installer Elevation of Privilege Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-70347 Windows Installer Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-70348 Windows Management Services Denial of Service Vulnerability Published on: August 11, 2026 Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally. Read Details
CVE-2026-70355 Microsoft SharePoint Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-72971 Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability Published on: August 11, 2026 Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally. Read Details
CVE-2026-19137 Use after free in WebGL Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-70339 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Published on: August 11, 2026 Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-19140 Use after free in GPU Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19138 Heap buffer overflow in CrashReporting Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19139 Race in CredentialProvider Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19145 Use after free in Translate Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19142 Use after free in Views Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19144 Use after free in HTML Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19146 Uninitialized Use in GPU Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19147 Use after free in Aura Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19149 Use after free in Aura Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19148 Out of bounds write in GPU Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19151 Use after free in V8 Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19153 Insufficient validation of untrusted input in Workers Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19152 Inappropriate implementation in Navigation Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19155 Use after free in Payments Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19158 Use after free in Views Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19157 Out of bounds write in ANGLE Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19156 Heap buffer overflow in Base Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19150 Inappropriate implementation in V8 Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19161 Uninitialized Use in Skia Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19162 Out of bounds write in V8 Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19160 Uninitialized Use in Skia Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19163 Use after free in Media Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19159 Use after free in Views Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19164 Insufficient validation of untrusted input in Codecs Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19165 Use after free in Extensions Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19167 Integer overflow in GPU Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19166 Use after free in Web Authentication Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19170 Use after free in WebGL Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19169 Insufficient validation of untrusted input in Contextual Tasks Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19173 Out of bounds write in Skia Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19172 Use after free in Views Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19168 Inappropriate implementation in V8 Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19174 Integer overflow in V8 Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19176 Use after free in Skia Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19171 Use after free in Media Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19175 Use after free in Payments Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19177 Insufficient validation of untrusted input in UI Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-42976 Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability Published on: August 11, 2026 Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-54981 Visual Studio Code Python Extension Security Feature Bypass Vulnerability Published on: August 11, 2026 Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally. Read Details
CVE-2026-58641 .NET Elevation of Privilege Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. Read Details
CVE-2026-58651 Microsoft Word Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-59119 PowerShell Elevation of Privilege Vulnerability Published on: August 11, 2026 Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-59122 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-59125 Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability Published on: August 11, 2026 Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-59126 Windows Event Logging Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-59131 AMD Zen Information Disclosure Vulnerability Published on: August 11, 2026 No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. Read Details
CVE-2026-61349 Windows Work Folder Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61363 Remote Desktop Client Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-61359 Windows Storage Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61355 Windows Sensor Data Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61364 Windows Remote Desktop Services Elevation of Privilege Vulnerability Published on: August 11, 2026 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61365 Windows Remote Desktop Services Elevation of Privilege Vulnerability Published on: August 11, 2026 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61357 Application Information Services Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Application Information Services allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61358 Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61360 Windows GDI Information Disclosure Vulnerability Published on: August 11, 2026 Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. Read Details
CVE-2026-61920 Windows DNS Server Remote Code Execution Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network. Read Details
CVE-2026-61926 Windows USB Driver Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61918 Windows Remote Desktop Client Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-61921 Windows Remote Desktop Client Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-61929 Windows Kernel Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61938 Windows Installer Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62698 Microsoft Digest Authentication Elevation of Privilege Vulnerability Published on: August 11, 2026 Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62700 Windows NTFS Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62701 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62708 Windows Kernel Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. Read Details
CVE-2026-62709 Windows GDI+ Information Disclosure Vulnerability Published on: August 11, 2026 Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62710 Windows Device Association Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62711 Windows Win32k Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62720 Windows DHCP Server Information Disclosure Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. Read Details
CVE-2026-62714 Windows DHCP Server Information Disclosure Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. Read Details
CVE-2026-62717 Windows Message Queuing Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62721 Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability Published on: August 11, 2026 Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62725 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62726 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62728 Windows Common Log File System Driver Elevation of Privilege Vulnerability Published on: August 11, 2026 Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62733 Windows Win32k Elevation of Privilege Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62743 Win32k Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62730 Windows Wired AutoConfig Service Information Disclosure Vulnerability Published on: August 11, 2026 Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62732 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62734 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62736 Windows DHCP Client Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62757 Windows Schannel Security Feature Bypass Vulnerability Published on: August 11, 2026 Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network. Read Details
CVE-2026-62741 Windows HTTP.sys Elevation of Privilege Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62749 Windows Kernel Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62751 Windows Projected File System Elevation of Privilege Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62752 Windows Kerberos Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62769 Windows DNS Elevation of Privilege Vulnerability Published on: August 11, 2026 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62771 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62761 Windows DHCP Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62768 Windows Installer Elevation of Privilege Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62770 Windows Shell Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62775 Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability Published on: August 11, 2026 Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62799 Windows SMB Client Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62776 Windows DHCP Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62778 Windows DNS Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network. Read Details
CVE-2026-62780 Windows Kernel Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62782 Windows SMB Client Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-62781 RPC Runtime Library Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62800 Windows SMBv3 Server Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. Read Details
CVE-2026-62786 Win32k Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62788 Windows Kernel Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62790 Windows SMBv3 Server Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. Read Details
CVE-2026-62793 Windows NTFS Information Disclosure Vulnerability Published on: August 11, 2026 Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62803 Windows DHCP Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62807 Windows DHCP Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62811 Windows HTTP.sys Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62814 Windows DHCP Server Information Disclosure Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. Read Details
CVE-2026-62823 Windows DHCP Server Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. Read Details
CVE-2026-62824 Remote Desktop Client Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62822 Windows GDI+ Remote Code Execution Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62832 Windows User Profile Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62871 .NET Elevation of Privilege Vulnerability Published on: August 11, 2026 Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-62872 .NET Framework Elevation of Privilege Vulnerability Published on: August 11, 2026 Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-62880 Windows NTFS Elevation of Privilege Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62881 Windows DNS Elevation of Privilege Vulnerability Published on: August 11, 2026 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62883 Windows DNS Elevation of Privilege Vulnerability Published on: August 11, 2026 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62885 Windows Win32k Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62886 .NET Elevation of Privilege Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. Read Details
CVE-2026-62887 Windows NTFS Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62888 Windows DWM Core Library Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62911 Microsoft Exchange Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-62842 Microsoft Office Graphics Component Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-63524 Microsoft Office Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-63525 Microsoft Office Word Remote Code Execution Vulnerability Published on: August 11, 2026 Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-63526 Microsoft Office Graphics Component Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-63528 Microsoft Office Word Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-63527 Microsoft Office Word Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-63529 Microsoft Office Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-63530 Microsoft Office Word Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-63531 Microsoft Office Word Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-63532 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-63533 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64897 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-64898 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64900 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-64902 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-64899 Microsoft Office Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-64903 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64901 Microsoft SharePoint Server Remote Code Execution Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Read Details
CVE-2026-64904 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64905 Microsoft Office Word Remote Code Execution Vulnerability Published on: August 11, 2026 Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64907 Microsoft Office Word Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64906 Microsoft Access Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64909 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64910 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64912 Microsoft Access Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64911 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64908 Microsoft Access Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64914 Microsoft Access Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64915 Microsoft Office Word Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64916 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-64920 Microsoft Access Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64917 Microsoft Office Word Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-64919 Microsoft Access Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64921 Microsoft SharePoint Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-62882 Microsoft Outlook Spoofing Vulnerability Published on: August 11, 2026 Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. Read Details
CVE-2026-65673 Microsoft Entra Connect Elevation of Privilege Vulnerability Published on: August 11, 2026 CVET-EOP Read Details
CVE-2026-65681 Windows iSCSI Target Service Denial of Service Vulnerability Published on: August 11, 2026 Information published. Read Details
CVE-2026-65680 Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65679 Windows iSCSI Target Service Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-65773 Windows Kernel Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65774 Windows Installer Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65775 Windows Win32k Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65776 Windows Win32k Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65777 Active Directory Security Feature Bypass Vulnerability Published on: August 11, 2026 Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network. Read Details
CVE-2026-65779 Windows Autopilot Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65780 Windows Autopilot Elevation of Privilege Vulnerability Published on: August 11, 2026 Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65778 Windows Autopilot Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65782 Windows Autopilot Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65781 Windows Autopilot Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65790 Windows Message Queuing Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65791 Windows iSCSI Target Service Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-65795 Windows DNS Elevation of Privilege Vulnerability Published on: August 11, 2026 No cwe for this issue in Windows DNS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65794 Windows SMB Client Information Disclosure Vulnerability Published on: August 11, 2026 Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-65797 Windows DNS Elevation of Privilege Vulnerability Published on: August 11, 2026 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65799 Windows DNS Elevation of Privilege Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65798 Windows DNS Elevation of Privilege Vulnerability Published on: August 11, 2026 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65796 Windows iSCSI Target Service Denial of Service Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network. Read Details
CVE-2026-65810 .NET Framework Elevation of Privilege Vulnerability Published on: August 11, 2026 Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. Read Details
CVE-2026-66802 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-66805 Microsoft SharePoint Server Remote Code Execution Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Read Details
CVE-2026-66806 Microsoft Office Word Information Disclosure Vulnerability Published on: August 11, 2026 Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-66808 Microsoft SharePoint Server Remote Code Execution Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Read Details
CVE-2026-66810 Microsoft Office Word Information Disclosure Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-66809 Microsoft Office Graphics Component Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-68797 Microsoft Excel Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-68798 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68799 Microsoft Excel Information Disclosure Vulnerability Published on: August 11, 2026 Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-68801 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68803 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68804 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68805 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68812 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68814 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68817 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-56179 Windows Network Address Translation (NAT) Spoofing Vulnerability Published on: August 11, 2026 Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. Read Details
CVE-2026-70130 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-70306 Microsoft Office SharePoint Spoofing Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Read Details
CVE-2026-70326 Microsoft SharePoint Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability Published on: August 11, 2026 Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally. Read Details
CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability Published on: August 11, 2026 Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-70354 .NET Core Remote Code Execution Vulnerability Published on: August 11, 2026 Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62738 Windows Management Instrumentation Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62898 Microsoft QUIC Information Disclosure Vulnerability Published on: August 11, 2026 Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-65767 Microsoft Teams for Android and iOS Spoofing Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-58639 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-62839 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-62917 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-59118 Copilot Cowork Elevation of Privilege Vulnerability Published on: August 11, 2026 Corrected CVE title. This is an informational change only. Read Details
CVE-2026-6727 MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability Published on: August 11, 2026 [CVE-2026-6727](https://www.cve.org/CVERecord?id=CVE-2026-6727) is an Information Disclosure vulnerability in the TPM 2.0 reference implementation involving an RSA OAEP timing side channel. MITRE assigned this CVE on behalf of the Trusted Computing Group. This document incorporates updates to Microsoft Windows that address this vulnerability. Please see [CVE-2026-6727](https://www.cve.org/CVERecord?id=CVE-2026-6727) for more information. Read Details
CVE-2026-6726 MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot Reuse Published on: August 11, 2026 [CVE-2026-6726](https://www.cve.org/CVERecord?id=CVE-2026-6726) is a Spoofing vulnerability in the TPM 2.0 reference implementation involving improper object-slot reuse. MITRE assigned this CVE on behalf of the Trusted Computing Group. This document incorporates updates to Microsoft Windows that address this vulnerability. Please see [CVE-2026-6726](https://www.cve.org/CVERecord?id=CVE-2026-6726) for more information. Read Details
CVE-2025-2308 HDF5 Scale-Offset Filter H5Z__scaleoffset_decompress_one_byte heap-based overflow Published on: August 11, 2026 Information published. Read Details
CVE-2025-2309 HDF5 Type Conversion Logic H5T__bit_copy heap-based overflow Published on: August 11, 2026 Information published. Read Details
CVE-2026-64581 xfrm: fix sk_dst_cache double-free in xfrm_user_policy() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68258 drm/amdkfd: Check bounds on CRIU restore queue type and mqd size Published on: August 11, 2026 Information published. Read Details
CVE-2026-68203 media: vivid: fix cleanup bugs in vivid_init() Published on: August 11, 2026 Information published. Read Details
CVE-2026-64653 GitHub CLI: Unescaped variable components in request URLs could allow path traversal Published on: August 11, 2026 Information published. Read Details
CVE-2026-68186 binfmt_misc: set have_execfd only once the interpreter is opened Published on: August 11, 2026 Information published. Read Details
CVE-2026-68114 drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68183 firmware: stratix10-svc: fix memory leaks and list corruption bugs Published on: August 11, 2026 Information published. Read Details
CVE-2026-68190 staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() Published on: August 11, 2026 Information published. Read Details
CVE-2026-64652 GitHub CLI: Partial token disclosure in `gh auth status` output Published on: August 11, 2026 Information published. Read Details
CVE-2026-68273 drm/amdgpu: Fix context pstate override handling Published on: August 11, 2026 Information published. Read Details
CVE-2026-68097 ksmbd: validate ACE size against SID sub-authorities Published on: August 11, 2026 Information published. Read Details
CVE-2026-68412 wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan() Published on: August 11, 2026 Information published. Read Details
CVE-2026-71497 jsoup: Cleaner may expose markup with custom raw-text elements Published on: August 11, 2026 Information published. Read Details
CVE-2026-61477 Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection Published on: August 11, 2026 Information published. Read Details
CVE-2026-68235 drm/amd/display: dce100: skip non-DP stream encoders for DP MST Published on: August 11, 2026 Information published. Read Details
CVE-2026-68407 wifi: nl80211: free RNR data on MBSSID mismatch Published on: August 11, 2026 Information published. Read Details
CVE-2026-71556 go-git: Worktree operations may follow symlinks Published on: August 11, 2026 Information published. Read Details
CVE-2026-68323 tipc: serialize udp bearer replicast list updates Published on: August 11, 2026 Information published. Read Details
CVE-2026-71557 go-git: Malicious reference names may modify files outside the reference storage Published on: August 11, 2026 Information published. Read Details
CVE-2026-68363 wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request Published on: August 11, 2026 Information published. Read Details
CVE-2026-65819 gopacket: Multiple layer decoders panic on crafted packets (out-of-bounds/underflow) enabling unauthenticated remote DoS via DecodingLayerParser Published on: August 11, 2026 Information published. Read Details
CVE-2026-68388 smb/client: handle overlapping allocated ranges in fallocate Published on: August 11, 2026 Information published. Read Details
CVE-2026-68288 net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD Published on: August 11, 2026 Information published. Read Details
CVE-2026-68256 drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference Published on: August 11, 2026 Information published. Read Details
CVE-2026-68242 drm/i915/gt: Fix NULL deref on sched_engine alloc failure Published on: August 11, 2026 Information published. Read Details
CVE-2026-68252 drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68374 usb: core: sysfs: add lock to bos_descriptors_read() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68353 wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler Published on: August 11, 2026 Information published. Read Details
CVE-2026-68187 exec: fix unsigned loop counter wrap in transfer_args_to_stack() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68411 wifi: mac80211_hwsim: clamp virtio RX length before skb_put Published on: August 11, 2026 Information published. Read Details
CVE-2026-68152 amt: fix use-after-free in AMT delayed works Published on: August 11, 2026 Information published. Read Details
CVE-2026-68189 Bluetooth: hci_sync: Protect UUID list traversal Published on: August 11, 2026 Information published. Read Details
CVE-2026-68351 wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read Published on: August 11, 2026 Information published. Read Details
CVE-2026-68136 net: gro: fix double aggregation of flush-marked skbs Published on: August 11, 2026 Information published. Read Details
CVE-2026-68083 ksmbd: fix path resolution in ksmbd_vfs_kern_path_create Published on: August 11, 2026 Information published. Read Details
CVE-2026-68352 wifi: ath6kl: fix OOB read from firmware IE lengths in connect event Published on: August 11, 2026 Information published. Read Details
CVE-2026-68254 drm/i915/vrr: require valid min/max vfreq for VRR Published on: August 11, 2026 Information published. Read Details
CVE-2026-68238 drm/amdgpu: Release VFCT ACPI table reference Published on: August 11, 2026 Information published. Read Details
CVE-2026-68241 drm/i915/mst: limit DP MST ESI service loop Published on: August 11, 2026 Information published. Read Details
CVE-2026-68362 wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin Published on: August 11, 2026 Information published. Read Details
CVE-2026-68315 sctp: validate stream count in sctp_process_strreset_inreq() Published on: August 11, 2026 Information published. Read Details
CVE-2026-15534 Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch Published on: August 11, 2026 Information published. Read Details
CVE-2026-68272 drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 Published on: August 11, 2026 Information published. Read Details
CVE-2026-68197 wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper Published on: August 11, 2026 Information published. Read Details
CVE-2026-68148 fscrypt: Add missing superblock check in find_or_insert_direct_key() Published on: August 11, 2026 Information published. Read Details
CVE-2026-66486 Improper Output Encoding in GNU cpio Published on: August 11, 2026 Information published. Read Details
CVE-2026-68249 drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68155 libceph: Reject monmaps advertising zero monitors Published on: August 11, 2026 Information published. Read Details
CVE-2026-68397 net/iucv: take a reference on the socket found in afiucv_hs_rcv() Published on: August 11, 2026 Information published. Read Details
CVE-2026-66484 Path Traversal in GNU cpio Published on: August 11, 2026 Information published. Read Details
CVE-2026-68312 cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths Published on: August 11, 2026 Information published. Read Details
CVE-2026-72522 libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions. Published on: August 11, 2026 Information published. Read Details
CVE-2026-68130 ksmbd: defer destroy_previous_session() until after NTLM authentication Published on: August 11, 2026 Information published. Read Details
CVE-2026-68350 wifi: carl9170: fix OOB read from off-by-two in TX status handler Published on: August 11, 2026 Information published. Read Details
CVE-2026-68337 bpf: Reject redirect helpers without a bpf_net_context Published on: August 11, 2026 Information published. Read Details
CVE-2026-68395 ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered Published on: August 11, 2026 Information published. Read Details
CVE-2026-68297 tipc: fix u16 MTU truncation in media and bearer MTU validation Published on: August 11, 2026 Information published. Read Details
CVE-2026-68141 net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68371 usb: musb: omap2430: Do not put borrowed of_node in probe Published on: August 11, 2026 Information published. Read Details
CVE-2026-68110 drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68206 media: v4l2-ctrls: validate HEVC active reference counts Published on: August 11, 2026 Information published. Read Details
CVE-2026-68195 wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses Published on: August 11, 2026 Information published. Read Details
CVE-2026-68143 net: slip: serialize receive against buffer reallocation Published on: August 11, 2026 Information published. Read Details
CVE-2026-68111 drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68355 wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68125 mac802154: llsec: reject frames shorter than the authentication tag Published on: August 11, 2026 Information published. Read Details
CVE-2026-68176 tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev Published on: August 11, 2026 Information published. Read Details
CVE-2026-68234 drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved Published on: August 11, 2026 Information published. Read Details
CVE-2026-68366 usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer Published on: August 11, 2026 Information published. Read Details
CVE-2026-68145 iomap: fix out-of-bounds bitmap_set() with zero-length range Published on: August 11, 2026 Information published. Read Details
CVE-2026-68278 drm/dp/mst: fix buffer overflows in sideband chunk accumulation Published on: August 11, 2026 Information published. Read Details
CVE-2026-68405 wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock Published on: August 11, 2026 Information published. Read Details
CVE-2026-68255 drm/virtio: bound EDID block reads to the response buffer Published on: August 11, 2026 Information published. Read Details
CVE-2026-68100 ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl Published on: August 11, 2026 Information published. Read Details
CVE-2026-68277 drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers Published on: August 11, 2026 Information published. Read Details
CVE-2026-68115 drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68414 wifi: cfg80211: cancel sched scan results work on unregister Published on: August 11, 2026 Information published. Read Details
CVE-2026-68158 libceph: Fix multiplication overflow in decode_new_up_state_weight() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68318 pds_core: fix use-after-free on workqueue during remove Published on: August 11, 2026 Information published. Read Details
CVE-2026-68222 media: msi2500: Return queued buffers on start_streaming() failure Published on: August 11, 2026 Information published. Read Details
CVE-2026-68413 wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68182 comedi: comedi_parport: deal with premature interrupt Published on: August 11, 2026 Information published. Read Details
CVE-2026-68280 drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68428 KVM: x86/mmu: Fix use-after-free on vendor module reload Published on: August 11, 2026 Information published. Read Details
CVE-2026-68331 dpaa2-eth: put MAC endpoint device on disconnect Published on: August 11, 2026 Information published. Read Details
CVE-2026-68231 media: airspy: Return queued buffers on start_streaming() failure Published on: August 11, 2026 Information published. Read Details
CVE-2026-68131 rbd: Reset positive result codes to zero in object map update path Published on: August 11, 2026 Information published. Read Details
CVE-2026-68118 tcp: challenge ACK for non-exact RST in SYN-RECEIVED Published on: August 11, 2026 Information published. Read Details
CVE-2026-68129 gve: fix Rx queue stall on alloc failure Published on: August 11, 2026 Information published. Read Details
CVE-2026-68112 drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68175 tracing: Fix resource leak on mmiotrace trace_pipe close Published on: August 11, 2026 Information published. Read Details
CVE-2026-68156 libceph: refresh auth->authorizer_buf{,_len} after authorizer update Published on: August 11, 2026 Information published. Read Details
CVE-2026-68328 nfp: Check resource mutex allocation Published on: August 11, 2026 Information published. Read Details
CVE-2026-68217 media: pwc: Drain fill_buf on start_streaming() failure Published on: August 11, 2026 Information published. Read Details
CVE-2026-68123 openvswitch: fix GSO userspace truncation underflow Published on: August 11, 2026 Information published. Read Details
CVE-2026-68218 media: pci: dm1105: Free allocated workqueue Published on: August 11, 2026 Information published. Read Details
CVE-2026-68250 drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68422 btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68404 wifi: cfg80211: use wiphy work for socket owner autodisconnect Published on: August 11, 2026 Information published. Read Details
CVE-2026-68284 bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68408 wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock Published on: August 11, 2026 Information published. Read Details
CVE-2026-68165 mm/damon/core: validate ranges in damon_set_regions() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68369 usb: gadget: printer: fix infinite loop in printer_read() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68137 net/x25: fix use-after-free in x25_kill_by_neigh() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68406 wifi: cfg80211: validate PMSR FTM preamble range Published on: August 11, 2026 Information published. Read Details
CVE-2026-68364 drm/amd/display: Fix ISM dc_lock deadlock during suspend Published on: August 11, 2026 Information published. Read Details
CVE-2026-68317 pds_core: fix auxiliary device add/del races Published on: August 11, 2026 Information published. Read Details
CVE-2026-68202 ALSA: seq: close a re-opened queue timer in the destructor Published on: August 11, 2026 Information published. Read Details
CVE-2026-68154 libceph: reject zero bucket types in crush_decode Published on: August 11, 2026 Information published. Read Details
CVE-2026-68417 RDMA/siw: publish QP after initialization Published on: August 11, 2026 Information published. Read Details
CVE-2026-68223 media: meson: vdec: Fix memory leak in error path of vdec_open Published on: August 11, 2026 Information published. Read Details
CVE-2026-68303 drm/vc4: hvs/v3d: Fix null dereference in unbind Published on: August 11, 2026 Information published. Read Details
CVE-2026-68199 wifi: ath6kl: fix OOB access from firmware ADDBA window size Published on: August 11, 2026 Information published. Read Details
CVE-2026-68320 sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid Published on: August 11, 2026 Information published. Read Details
CVE-2026-68109 drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68336 bonding: fix devconf_all NULL dereference when IPv6 is disabled Published on: August 11, 2026 Information published. Read Details
CVE-2026-68300 sctp: auth: verify auth requirement when auth_chunk is NULL Published on: August 11, 2026 Information published. Read Details
CVE-2026-68192 wifi: brcmfmac: make release_scratchbuffers idempotent Published on: August 11, 2026 Information published. Read Details
CVE-2026-68116 vxlan: mdb: Fix source list corruption on a failed replace Published on: August 11, 2026 Information published. Read Details
CVE-2026-68257 drm/amdkfd: fix 32-bit overflow in CWSR total size calculation Published on: August 11, 2026 Information published. Read Details
CVE-2026-68419 RDMA/irdma: Prevent rereg_mr for non-mem regions Published on: August 11, 2026 Information published. Read Details
CVE-2026-68099 ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL Published on: August 11, 2026 Information published. Read Details
CVE-2026-68426 xfrm: fix stale skb->prev after async crypto steals a GSO segment Published on: August 11, 2026 Information published. Read Details
CVE-2026-68157 libceph: guard missing CRUSH type name lookup Published on: August 11, 2026 Information published. Read Details
CVE-2026-68425 IB/mad: Drop unmatched RMPP responses before reassembly Published on: August 11, 2026 Information published. Read Details
CVE-2026-68354 firewire: net: Fix fragmented datagram reassembly Published on: August 11, 2026 Information published. Read Details
CVE-2026-68180 intel_th: fix MSC output device reference leak Published on: August 11, 2026 Information published. Read Details
CVE-2026-68392 Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync Published on: August 11, 2026 Information published. Read Details
CVE-2026-68409 wifi: mac80211: defer link RX stats percpu free to RCU Published on: August 11, 2026 Information published. Read Details
CVE-2026-68279 drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers Published on: August 11, 2026 Information published. Read Details
CVE-2026-68357 watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68113 drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68309 wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68368 usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68402 wifi: cfg80211: bound element ID read when checking non-inheritance Published on: August 11, 2026 Information published. Read Details
CVE-2026-68310 wifi: mt76: mt7915: guard HE capability lookups Published on: August 11, 2026 Information published. Read Details
CVE-2026-68367 usb: gadget: f_tcm: synchronize delayed set_alt with teardown Published on: August 11, 2026 Information published. Read Details
CVE-2026-68386 bpf, sockmap: Reject unhashed UDP sockets on sockmap update Published on: August 11, 2026 Information published. Read Details
CVE-2026-68140 net/iucv: fix use-after-free of a severed iucv_path Published on: August 11, 2026 Information published. Read Details
CVE-2026-68219 media: nxp: imx8-isi: Fix potential out-of-bounds issues Published on: August 11, 2026 Information published. Read Details
CVE-2026-68329 iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68396 scsi: core: wake eh reliably when using scsi_schedule_eh Published on: August 11, 2026 Information published. Read Details
CVE-2026-68248 drm/i915: Return NULL on error in active_instance Published on: August 11, 2026 Information published. Read Details
CVE-2026-68246 drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68376 sctp: fix auth_hmacs array size in struct sctp_cookie Published on: August 11, 2026 Information published. Read Details
CVE-2026-68269 drm/i915/gem: Add missing nospec on parallel submit slot Published on: August 11, 2026 Information published. Read Details
CVE-2026-68349 wifi: carl9170: fix buffer overflow in rx_stream failover path Published on: August 11, 2026 Information published. Read Details
CVE-2026-68301 net: hsr: fix memory leak on slave unregistration by removing synced VLANs Published on: August 11, 2026 Information published. Read Details
CVE-2026-68135 net: hip04: fix RX buffer leak on build_skb failure Published on: August 11, 2026 Information published. Read Details
CVE-2026-68326 wifi: mwifiex: bound uAP association event IEs to the event buffer Published on: August 11, 2026 Information published. Read Details
CVE-2026-68117 tipc: clear sock->sk on the failed-insert path in tipc_sk_create() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68106 drm/amdgpu: fix division by zero with invalid uvd dimensions Published on: August 11, 2026 Information published. Read Details
CVE-2026-68294 net: qrtr: restrict socket creation to the initial network namespace Published on: August 11, 2026 Information published. Read Details
CVE-2026-68293 net/mlx5: Fix MCIA register buffer overflow on 32 dword reads Published on: August 11, 2026 Information published. Read Details
CVE-2026-68149 fs: preserve ACL_DONT_CACHE state in forget_cached_acl() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68151 binfmt_elf_fdpic: only honour the first PT_INTERP Published on: August 11, 2026 Information published. Read Details
CVE-2026-68335 rds: drop incoming messages that cross network namespace boundaries Published on: August 11, 2026 Information published. Read Details
CVE-2026-68410 wifi: libertas: fix memory leak in helper_firmware_cb() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68212 media: saa7134: Fix a possible memory leak in saa7134_video_init1 Published on: August 11, 2026 Information published. Read Details
CVE-2026-68418 RDMA/irdma: Prevent user-triggered null deref on QP create Published on: August 11, 2026 Information published. Read Details
CVE-2026-68361 hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop Published on: August 11, 2026 Information published. Read Details
CVE-2026-68090 debugobjects: Plug race against a concurrent OOM disable Published on: August 11, 2026 Information published. Read Details
CVE-2026-68126 mac802154: hold an interface reference across the scan worker Published on: August 11, 2026 Information published. Read Details
CVE-2026-68416 mtd: fix double free and WARN_ON in add_mtd_device() error paths Published on: August 11, 2026 Information published. Read Details
CVE-2026-68247 drm/i915/bios: range check LFP Data Block panel_type2 Published on: August 11, 2026 Information published. Read Details
CVE-2026-68245 drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68377 net/sched: act_tunnel_key: Defer dst_release to RCU callback Published on: August 11, 2026 Information published. Read Details
CVE-2026-68103 drm/amdgpu: reject mapping a reserved doorbell to a new queue Published on: August 11, 2026 Information published. Read Details
CVE-2026-68147 fscrypt: Avoid dynamic allocation in fscrypt_get_devices() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68381 ksmbd: pin conn during async oplock break notification Published on: August 11, 2026 Information published. Read Details
CVE-2026-68343 smb: client: validate DFS referral PathConsumed Published on: August 11, 2026 Information published. Read Details
CVE-2026-68184 cdrom: fix stack out-of-bounds read in CDROMVOLCTRL Published on: August 11, 2026 Information published. Read Details
CVE-2026-68124 mctp: serial: handle zero-length frames to prevent rx buffer overflow Published on: August 11, 2026 Information published. Read Details
CVE-2026-68146 ftrace: Add global mutex to serialize trace_parser access Published on: August 11, 2026 Information published. Read Details
CVE-2026-68401 firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68322 rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled Published on: August 11, 2026 Information published. Read Details
CVE-2026-68373 wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68214 media: rtl2832: fix use-after-free in rtl2832_remove() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68327 wan: wanxl: Only reset hardware after BAR mapping Published on: August 11, 2026 Information published. Read Details
CVE-2026-68188 Bluetooth: RFCOMM: Fix session UAF in set_termios Published on: August 11, 2026 Information published. Read Details
CVE-2026-68360 hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop Published on: August 11, 2026 Information published. Read Details
CVE-2026-68271 drm/nouveau: fix reversed error cleanup order in ucopy functions Published on: August 11, 2026 Information published. Read Details
CVE-2026-68162 sctp: avoid auth_enable sysctl UAF during netns teardown Published on: August 11, 2026 Information published. Read Details
CVE-2026-68229 media: cedrus: skip invalid H.264 reference list entries Published on: August 11, 2026 Information published. Read Details
CVE-2026-68359 hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop Published on: August 11, 2026 Information published. Read Details
CVE-2026-68313 tipc: fix infinite loop in __tipc_nl_compat_dumpit Published on: August 11, 2026 Information published. Read Details
CVE-2026-68324 iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68121 pppoe: reload header pointer after dev_hard_header() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68132 super: fix emergency thaw deadlock on frozen block devices Published on: August 11, 2026 Information published. Read Details
CVE-2026-68209 media: sun4i-csi: Return queued buffers on start_streaming() failure Published on: August 11, 2026 Information published. Read Details
CVE-2026-20348 ClamAV XAR File Format Processing Memory Corruption Vulnerability Published on: August 11, 2026 Information published. Read Details
CVE-2026-68102 drm/amdgpu: fix aperture mapping leak Published on: August 11, 2026 Information published. Read Details
CVE-2026-68325 iommu/amd: Bound the early ACPI HID map Published on: August 11, 2026 Information published. Read Details
CVE-2026-68085 Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled Published on: August 11, 2026 Information published. Read Details
CVE-2026-68196 wifi: wilc1000: validate assoc response length before subtracting header Published on: August 11, 2026 Information published. Read Details
CVE-2026-68370 usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback Published on: August 11, 2026 Information published. Read Details
CVE-2026-68233 drm/vc4: Shut down BO cache timer before teardown Published on: August 11, 2026 Information published. Read Details
CVE-2026-64654 GitHub CLI: Terminal escape sequence injection in multiple `gh` commands Published on: August 11, 2026 Information published. Read Details
CVE-2026-68304 wifi: brcmfmac: fix 802.1X-SHA256 call trace warning Published on: August 11, 2026 Information published. Read Details
CVE-2026-68243 drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU Published on: August 11, 2026 Information published. Read Details
CVE-2026-20339 ClamAV PESpin File Format Processing Integer Overflow Vulnerability Published on: August 11, 2026 Information published. Read Details
CVE-2026-20338 ClamAV ZIP File Format Processing Memory Corruption Vulnerability Published on: August 11, 2026 Information published. Read Details
CVE-2026-20347 ClamAV Mach-O File Format Processing Memory Corruption Vulnerability Published on: August 11, 2026 Information published. Read Details
CVE-2026-20337 ClamAV ZIP File Format Processing Memory Corruption Vulnerability Published on: August 11, 2026 Information published. Read Details
CVE-2026-20346 ClamAV PDF File Format Processing Memory Corruption Vulnerability Published on: August 11, 2026 Information published. Read Details
CVE-2026-64563 rhashtable: clear stale iter->p on table restart Published on: August 11, 2026 Information published. Read Details
CVE-2026-64655 GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching Published on: August 11, 2026 Information published. Read Details
CVE-2026-68098 ksmbd: bound DACL dedup walk to copied ACEs Published on: August 11, 2026 Information published. Read Details
CVE-2026-68104 drm/amdgpu: invoke pm_genpd_remove() before freeing genpd Published on: August 11, 2026 Information published. Read Details
CVE-2026-68210 media: stm32: dcmi: unregister notifier on probe failure Published on: August 11, 2026 Information published. Read Details
CVE-2026-68399 bpf: Fix UAF in sock clone early bailouts Published on: August 11, 2026 Information published. Read Details
CVE-2026-68127 ila: reload IPv6 header after pskb_may_pull in checksum adjust Published on: August 11, 2026 Information published. Read Details
CVE-2026-68244 drm/i915/gem: Do not leak siblings[] on proto context error Published on: August 11, 2026 Information published. Read Details
CVE-2026-68171 arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates Published on: August 11, 2026 Information published. Read Details
CVE-2026-68289 tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68181 mei: bus: access mei_device under device_lock on cleanup Published on: August 11, 2026 Information published. Read Details
CVE-2026-68348 ASoC: tas2781: bound firmware description string parsing Published on: August 11, 2026 Information published. Read Details
CVE-2026-68308 wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68365 USB: serial: io_edgeport: cap received transmit credits Published on: August 11, 2026 Information published. Read Details
CVE-2026-68391 Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds Published on: August 11, 2026 Information published. Read Details
CVE-2026-68302 amt: re-read skb header pointers after every pull Published on: August 11, 2026 Information published. Read Details
CVE-2026-68286 drop_monitor: perform u64_stats updates under IRQ-disabled section Published on: August 11, 2026 Information published. Read Details
CVE-2026-68333 dpaa2-switch: put MAC endpoint device on disconnect Published on: August 11, 2026 Information published. Read Details
CVE-2026-68427 gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings Published on: August 11, 2026 Information published. Read Details
CVE-2026-66485 Uncontrolled Memory Allocation in GNU cpio Published on: August 11, 2026 Information published. Read Details
CVE-2026-68161 sctp: close UDP tunnel sockets during netns teardown Published on: August 11, 2026 Information published. Read Details
CVE-2026-68306 wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68338 net/packet: avoid fanout hook re-registration after unregister Published on: August 11, 2026 Information published. Read Details
CVE-2026-68185 LoongArch: Move jump_label_init() before parse_early_param() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68096 audit: fix recursive locking deadlock in audit_dupe_exe() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68287 drop_monitor: fix size calculations for 64-bit attributes Published on: August 11, 2026 Information published. Read Details
CVE-2026-68403 wifi: brcmfmac: initialize SDIO data work before cleanup Published on: August 11, 2026 Information published. Read Details
CVE-2026-68220 media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe Published on: August 11, 2026 Information published. Read Details
CVE-2026-68389 Bluetooth: hci_qca: Clear memdump state on invalid dump size Published on: August 11, 2026 Information published. Read Details
CVE-2026-68166 userfaultfd: prevent registration of special VMAs Published on: August 11, 2026 Information published. Read Details
CVE-2026-68198 wifi: ath6kl: fix use-after-free in aggr_reset_state() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68398 ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF Published on: August 11, 2026 Information published. Read Details
CVE-2026-68194 wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses Published on: August 11, 2026 Information published. Read Details
CVE-2026-68215 media: radio-si476x: Unregister v4l2_device on probe failure Published on: August 11, 2026 Information published. Read Details
CVE-2026-68091 HID: wacom: stop hardware after post-start probe failures Published on: August 11, 2026 Information published. Read Details
CVE-2026-68159 libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE Published on: August 11, 2026 Information published. Read Details
CVE-2026-68138 net/sched: serialize qdisc_rtab_list against concurrent get/put Published on: August 11, 2026 Information published. Read Details
CVE-2026-68299 vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets Published on: August 11, 2026 Information published. Read Details
CVE-2026-68205 media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68259 drm/amdkfd: Check bounds in allocate_event_notification_slot Published on: August 11, 2026 Information published. Read Details
CVE-2026-68207 media: ti: vpe: unwind v4l2 device registration on probe error Published on: August 11, 2026 Information published. Read Details
CVE-2026-68088 usb: gadget: function: rndis: add length check to response query Published on: August 11, 2026 Information published. Read Details
CVE-2026-68108 drm/amdgpu/vce: fix integer overflow in image size Published on: August 11, 2026 Information published. Read Details
CVE-2026-68226 media: cx23885: add ioremap return check and cleanup Published on: August 11, 2026 Information published. Read Details
CVE-2026-68142 geneve: require CAP_NET_ADMIN in the device netns for changelink Published on: August 11, 2026 Information published. Read Details
CVE-2026-68086 mm/khugepaged: write all dirty file folios when collapsing Published on: August 11, 2026 Information published. Read Details
CVE-2026-68160 ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68144 phonet: pep: fix use-after-free in pep_get_sb() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68164 mm/damon/core: disallow overlapping input ranges for damon_set_regions() Published on: August 11, 2026 Information published. Read Details
CVE-2026-68107 drm/amdgpu/vcn4: avoid rereading IB param length Published on: August 11, 2026 Information published. Read Details
CVE-2026-68204 media: vivid: check for vb2_is_busy() when toggling caps Published on: August 11, 2026 Information published. Read Details
CVE-2026-68236 drm/amd/display: set new_stream to NULL after release Published on: August 11, 2026 Information published. Read Details
CVE-2026-68340 hwmon: occ: validate poll response sensor blocks Published on: August 11, 2026 Information published. Read Details
CVE-2026-68253 drm/i915/hdcp: check streams[] bounds before overflow Published on: August 11, 2026 Information published. Read Details
CVE-2026-68339 Bluetooth: btusb: validate Realtek vendor event length Published on: August 11, 2026 Information published. Read Details
CVE-2026-68169 mptcp: pm: userspace: fix use-after-free in get_local_id Published on: August 11, 2026 Information published. Read Details
CVE-2026-68093 KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug Published on: August 11, 2026 Information published. Read Details
CVE-2026-68153 libceph: remove debugfs files before client teardown Published on: August 11, 2026 Information published. Read Details
CVE-2026-68084 staging: vme_user: fix location monitor leak in tsi148 bridge Published on: August 11, 2026 Information published. Read Details
CVE-2026-20345 ClamAV GPT File Format Processing Memory Corruption Vulnerability Published on: August 11, 2026 Information published. Read Details
CVE-2026-72568 Redis - Heap Out-of-Bounds Read in Cluster Bus PING Message Handler Published on: August 11, 2026 Information published. Read Details
CVE-2026-68105 drm/amdgpu: Fix kernel panic during driver load failure Published on: August 11, 2026 Information published. Read Details
CVE-2026-68216 media: pwc: Return queued buffers on start_streaming() failure Published on: August 11, 2026 Information published. Read Details
CVE-2026-68251 drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() Published on: August 11, 2026 Information published. Read Details
CVE-2024-42079 gfs2: Fix NULL pointer dereference in gfs2_log_flush Published on: August 11, 2026 Information published. Read Details
CVE-2026-64523 net/handshake: Take a long-lived file reference at submit Published on: August 11, 2026 Information published. Read Details
CVE-2026-64525 xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit Published on: August 11, 2026 Information published. Read Details
CVE-2026-64513 KVM: x86: Unconditionally recompute CR8 intercept on PPR update Published on: August 11, 2026 Information published. Read Details
CVE-2024-14040 net: nexthop: Increase weight to u16 Published on: August 11, 2026 Information published. Read Details
CVE-2026-55995 Double-free in the iSNS attribute decoder in open-iscsi Published on: August 11, 2026 Information published. Read Details
CVE-2026-43871 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit Published on: August 11, 2026 Information published. Read Details
CVE-2026-64377 cpufreq: qcom-cpufreq-hw: Fix possible double free Published on: August 11, 2026 Information published. Read Details
CVE-2026-64388 smb/client: fix chown/chgrp with SMB3 POSIX Extensions Published on: August 11, 2026 Information published. Read Details
CVE-2026-64539 Bluetooth: eir: Fix stack OOB write when prepending the Flags AD Published on: August 11, 2026 Information published. Read Details
CVE-2026-54332 GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS Published on: August 11, 2026 Information published. Read Details
CVE-2026-55969 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable() Published on: August 11, 2026 Information published. Read Details
CVE-2026-6879 Quadratic Behavior in xml.etree.ElementPath Index Predicates Published on: August 11, 2026 Information published. Read Details
CVE-2024-57895 ksmbd: set ATTR_CTIME flags when setting mtime Published on: August 11, 2026 Information published. Read Details
CVE-2024-57898 wifi: cfg80211: clear link ID from bitmap during link delete after clean up Published on: August 11, 2026 Information published. Read Details
CVE-2024-57893 ALSA: seq: oss: Fix races at processing SysEx messages Published on: August 11, 2026 Information published. Read Details
CVE-2024-57888 workqueue: Do not warn when cancelling WQ_MEM_RECLAIM work from !WQ_MEM_RECLAIM worker Published on: August 11, 2026 Information published. Read Details
CVE-2024-57795 RDMA/rxe: Remove the direct link to net_device Published on: August 11, 2026 Information published. Read Details
CVE-2024-52005 The sideband payload is passed unfiltered to the terminal in git Published on: August 11, 2026 Information published. Read Details
CVE-2025-21682 eth: bnxt: always recalculate features after XDP clearing, fix null-deref Published on: August 11, 2026 Information published. Read Details
CVE-2024-57857 RDMA/siw: Remove direct link to net_device Published on: August 11, 2026 Information published. Read Details
CVE-2025-21629 net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packets Published on: August 11, 2026 Information published. Read Details
CVE-2024-57899 wifi: mac80211: fix mbss changed flags corruption on 32 bit systems Published on: August 11, 2026 Information published. Read Details
CVE-2026-3087 shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs Published on: August 11, 2026 Information published. Read Details
CVE-2025-37853 drm/amdkfd: debugfs hang_hws skip GPU with MES Published on: August 11, 2026 Information published. Read Details
CVE-2025-37884 bpf: Fix deadlock between rcu_tasks_trace and event_mutex. Published on: August 11, 2026 Information published. Read Details
CVE-2025-37961 ipvs: fix uninit-value for saddr in do_output_route4 Published on: August 11, 2026 Information published. Read Details
CVE-2025-37920 xsk: Fix race condition in AF_XDP generic RX path Published on: August 11, 2026 Information published. Read Details
CVE-2025-37877 iommu: Clear iommu-dma ops on cleanup Published on: August 11, 2026 Information published. Read Details
CVE-2025-37931 btrfs: adjust subpage bit start based on sectorsize Published on: August 11, 2026 Information published. Read Details
CVE-2025-37856 btrfs: harden block_group::bg_list against list_del() races Published on: August 11, 2026 Information published. Read Details
CVE-2025-37842 spi: fsl-qspi: use devm function instead of driver remove Published on: August 11, 2026 Information published. Read Details
CVE-2025-37945 net: phy: allow MDIO bus PM ops to start/stop state machine for phylink-controlled PHY Published on: August 11, 2026 Information published. Read Details
CVE-2025-37849 KVM: arm64: Tear down vGIC on failed vCPU creation Published on: August 11, 2026 Information published. Read Details
CVE-2025-37852 drm/amdgpu: handle amdgpu_cgs_create_device() errors in amd_powerplay_create() Published on: August 11, 2026 Information published. Read Details
CVE-2025-37878 perf/core: Fix WARN_ON(!ctx) in __free_event() for partial init Published on: August 11, 2026 Information published. Read Details
CVE-2025-37879 9p/net: fix improper handling of bogus negative read/write replies Published on: August 11, 2026 Information published. Read Details
CVE-2025-37903 drm/amd/display: Fix slab-use-after-free in hdcp Published on: August 11, 2026 Information published. Read Details
CVE-2025-37938 tracing: Verify event formats that have "%*p.." Published on: August 11, 2026 Information published. Read Details
CVE-2025-37957 KVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception Published on: August 11, 2026 Information published. Read Details
CVE-2025-37980 block: fix resource leak in blk_register_queue() error path Published on: August 11, 2026 Information published. Read Details
CVE-2025-37861 scsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue Published on: August 11, 2026 Information published. Read Details
CVE-2025-37959 bpf: Scrub packet on bpf_redirect_peer Published on: August 11, 2026 Information published. Read Details
CVE-2024-21380 Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability Published on: August 10, 2026 Updated the build numbers. This is an informational update only. Read Details
CVE-2026-50309 Windows NTFS Remote Code Execution Vulnerability Published on: August 10, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-50357 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability Published on: August 10, 2026 Acknowledgement Updated Read Details
CVE-2026-40417 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability Published on: August 10, 2026 Updated the build numbers. This is an informational update only. Read Details
CVE-2025-29821 Microsoft Dynamics Business Central Information Disclosure Vulnerability Published on: August 10, 2026 Updated the build numbers. This is an informational update only. Read Details
CVE-2021-34474 Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability Published on: August 10, 2026 Updated the build numbers. This is an informational update only. Read Details
CVE-2021-40440 Microsoft Dynamics Business Central Cross-site Scripting Vulnerability Published on: August 10, 2026 Updated the build numbers. This is an informational update only. Read Details
CVE-2024-38225 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability Published on: August 10, 2026 Updated the build numbers. This is an informational update only. Read Details
CVE-2021-36946 Microsoft Dynamics Business Central Cross-site Scripting Vulnerability Published on: August 10, 2026 Updated the build numbers. This is an informational update only. Read Details
CVE-2026-54876 Client-Side Memory Leak in OCSP Response Checking Published on: August 10, 2026 Information published. Read Details
CVE-2026-64146 erofs: fix metabuf leak in inode xattr initialization Published on: August 10, 2026 Information published. Read Details
CVE-2026-26197 Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c Published on: August 10, 2026 Information published. Read Details
CVE-2026-64192 bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized Published on: August 10, 2026 Information published. Read Details
CVE-2026-64189 netfilter: ipset: fix race between dump and ip_set_list resize Published on: August 10, 2026 Information published. Read Details
CVE-2026-56145 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service Published on: August 10, 2026 Information published. Read Details
CVE-2026-63999 ethtool: rss: fix indir_table and hkey leak on get_rxfh failure Published on: August 10, 2026 Information published. Read Details
CVE-2026-63978 net/handshake: Drain pending requests at net namespace exit Published on: August 10, 2026 Information published. Read Details
CVE-2026-63974 Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close Published on: August 10, 2026 Information published. Read Details
CVE-2026-64082 riscv: Fix register corruption from uninitialized cregs on error Published on: August 10, 2026 Information published. Read Details
CVE-2026-38753 A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. Published on: August 10, 2026 Information published. Read Details
CVE-2026-38752 A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. Published on: August 10, 2026 Information published. Read Details
CVE-2026-26199 Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero Published on: August 10, 2026 Information published. Read Details
CVE-2026-64187 xfs: fail recovery on a committed log item with no regions Published on: August 10, 2026 Information published. Read Details
CVE-2026-64205 i2c: i801: fix hardware state machine corruption in error path Published on: August 10, 2026 Information published. Read Details
CVE-2026-64190 net: team: fix NULL pointer dereference in team_xmit during mode change Published on: August 10, 2026 Information published. Read Details
CVE-2026-64206 Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock Published on: August 10, 2026 Information published. Read Details
CVE-2026-39879 SQL injection in syslog-ng SQL destionation driver Published on: August 10, 2026 Information published. Read Details
CVE-2026-64572 ipv4: fib: free fib_alias with kfree_rcu() on insert error path Published on: August 09, 2026 Information published. Read Details
CVE-2026-64569 mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n Published on: August 09, 2026 Information published. Read Details
CVE-2026-64567 btrfs: reject free space cache with more entries than pages Published on: August 09, 2026 Information published. Read Details
CVE-2026-64577 gtp: check skb_pull_data() return in gtp1u_send_echo_resp() Published on: August 09, 2026 Information published. Read Details
CVE-2026-64561 KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Published on: August 09, 2026 Information published. Read Details
CVE-2026-64564 sctp: don't free the ASCONF's own transport in DEL-IP processing Published on: August 09, 2026 Information published. Read Details
CVE-2026-64562 KVM: nVMX: Hide shadow VMCS right after VMCLEAR Published on: August 09, 2026 Information published. Read Details
CVE-2026-18839 Popt-devel: popt-static: size_t underflow in singleoptionhelp Published on: August 09, 2026 Information published. Read Details
CVE-2026-64590 dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning Published on: August 09, 2026 Information published. Read Details
CVE-2026-64583 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown Published on: August 09, 2026 Information published. Read Details
CVE-2026-64584 usb: gadget: f_midi: cancel pending IN work before freeing the midi object Published on: August 09, 2026 Information published. Read Details
CVE-2026-64571 wifi: p54: validate RX frame length in p54_rx_eeprom_readback() Published on: August 09, 2026 Information published. Read Details
CVE-2026-64576 nexthop: initialize extack in nh_res_bucket_migrate() Published on: August 09, 2026 Information published. Read Details
CVE-2026-64676 Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memory Published on: August 09, 2026 Information published. Read Details
CVE-2026-47243 Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs Published on: August 09, 2026 Information published. Read Details
CVE-2025-49506 Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack Published on: August 09, 2026 Information published. Read Details
CVE-2026-34191 Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle Published on: August 09, 2026 Information published. Read Details
CVE-2026-34501 Apache Portable Runtime Utility: Heap buffer overflow in APR redis client Published on: August 09, 2026 Information published. Read Details
CVE-2026-34502 Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client Published on: August 09, 2026 Information published. Read Details
CVE-2026-68081 KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state Published on: August 09, 2026 Information published. Read Details
CVE-2026-68082 libceph: fix two unsafe bare decodes in decode_lockers() Published on: August 09, 2026 Information published. Read Details
CVE-2026-54876 Client-Side Memory Leak in OCSP Response Checking Published on: August 09, 2026 Information published. Read Details
CVE-2026-71225 Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries Published on: August 09, 2026 Information published. Read Details
CVE-2026-71226 Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path Published on: August 09, 2026 Information published. Read Details
CVE-2026-71227 Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return Published on: August 09, 2026 Information published. Read Details
CVE-2026-44605 Rpm: heap buffer overflow in ndb slot table parsing Published on: August 09, 2026 Information published. Read Details
CVE-2026-64574 wifi: mac80211: tear down new links on vif update error path Published on: August 09, 2026 Information published. Read Details
CVE-2026-64573 Bluetooth: qca: fix NVM tag length underflow in TLV parser Published on: August 09, 2026 Information published. Read Details
CVE-2026-64565 Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() Published on: August 09, 2026 Information published. Read Details
CVE-2026-64604 KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode Published on: August 09, 2026 Information published. Read Details
CVE-2026-64578 ksmbd: validate compound request size before reading StructureSize2 Published on: August 09, 2026 Information published. Read Details
CVE-2026-64579 xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert Published on: August 09, 2026 Information published. Read Details
CVE-2026-64580 xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() Published on: August 09, 2026 Information published. Read Details
CVE-2026-50540 Kata Containers: Config Path Annotation Arbitrary File Loading Published on: August 09, 2026 Information published. Read Details
CVE-2026-63140 Reachable Assertion in Elasticsearch Leading to Denial of Service Published on: August 09, 2026 Information published. Read Details
CVE-2026-63136 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service Published on: August 09, 2026 Information published. Read Details
CVE-2026-53910 Heap-based Buffer Overflow in GNU diffutils Published on: August 09, 2026 Information published. Read Details
CVE-2026-63308 Helm Files.Lines Denial of Service via Empty Chart Files Published on: August 09, 2026 Information published. Read Details
CVE-2026-15588 Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering Published on: August 09, 2026 Information published. Read Details
CVE-2026-26080 HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected. Published on: August 09, 2026 Information published. Read Details
CVE-2026-26081 HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected. Published on: August 09, 2026 Information published. Read Details
CVE-2026-15788 WCOW cache mount source selector resolves NTFS junctions outside of cache root Published on: August 09, 2026 Information published. Read Details
CVE-2026-64560 posix-cpu-timers: Prevent UAF caused by non-leader exec() race Published on: August 09, 2026 Information published. Read Details
CVE-2026-63263 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service Published on: August 09, 2026 Information published. Read Details
CVE-2026-62994 CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin Published on: August 09, 2026 Information published. Read Details
CVE-2026-64542 ipv6: ndisc: fix NULL deref in accept_untracked_na() Published on: August 09, 2026 Information published. Read Details
CVE-2025-62725 Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations Published on: August 08, 2026 Information published. Read Details
CVE-2026-68480 x86/bugs: Make Safe-RET robust against interrupt injection Published on: August 08, 2026 Information published. Read Details
CVE-2026-32597 PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) Published on: August 08, 2026 Information published. Read Details
CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys Published on: August 08, 2026 Information published. Read Details
CVE-2026-44509 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate. Published on: August 08, 2026 Information published. Read Details
CVE-2026-44508 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate. Published on: August 08, 2026 Information published. Read Details
CVE-2026-55995 Double-free in the iSNS attribute decoder in open-iscsi Published on: August 08, 2026 Information published. Read Details
CVE-2026-44943 remote limited file-write as root via discovery in open-iscsi Published on: August 08, 2026 Information published. Read Details
CVE-2026-44510 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate. Published on: August 08, 2026 Information published. Read Details
CVE-2026-44944 iscsiuio control-socket authentication bypass in open-iscsi Published on: August 08, 2026 Information published. Read Details
CVE-2026-6879 Quadratic Behavior in xml.etree.ElementPath Index Predicates Published on: August 08, 2026 Information published. Read Details
CVE-2026-48524 PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS) Published on: August 08, 2026 Information published. Read Details
CVE-2019-9924 rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell. Published on: August 07, 2026 Information published. Read Details
CVE-2019-9192 In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion Published on: August 07, 2026 Information published. Read Details
CVE-2019-6706 Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships. Published on: August 07, 2026 Information published. Read Details
CVE-2018-5407 Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'. Published on: August 07, 2026 Information published. Read Details
CVE-2018-1128 It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable. Published on: August 07, 2026 Information published. Read Details
CVE-2018-6829 cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation. Published on: August 07, 2026 Information published. Read Details
CVE-2016-2568 pkexec, when used with --user nonpriv, allows local users to escape to the parent session Published on: August 07, 2026 Information published. Read Details
CVE-2010-4052 Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD. Published on: August 07, 2026 Information published. Read Details
CVE-2007-3205 The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed. NOTE: it is not clear whether this is a design limitation of the function or a bug in PHP, although it is likely to be regarded as a bug in Hardened-PHP and Suhosin. Published on: August 07, 2026 Information published. Read Details
CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability Published on: August 07, 2026 Acknowledgement Updated Read Details
CVE-2026-50659 .NET Spoofing Vulnerability Published on: August 07, 2026 Acknowledgement Updated Read Details
CVE-2026-47303 ASP.NET Core Elevation of Privilege Vulnerability Published on: August 07, 2026 Acknowledgement Updated Read Details
CVE-2026-62836 Azure SQL Managed Instance Elevation of Privilege Vulnerability Published on: August 06, 2026 Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network. Read Details
CVE-2026-62896 Microsoft Teams Elevation of Privilege Vulnerability Published on: August 06, 2026 Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-65668 Microsoft Purview eDiscovery Elevation of Privilege Vulnerability Published on: August 06, 2026 Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-59118 Microsoft Power Apps Elevation of Privilege Vulnerability Published on: August 06, 2026 Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network. Read Details
CVE-2026-50516 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability Published on: August 06, 2026 Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. Read Details
CVE-2026-50481 Azure Active Directory Elevation of Privilege Vulnerability Published on: August 06, 2026 Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-62918 Microsoft Teams Spoofing Vulnerability Published on: August 06, 2026 Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network. Read Details
CVE-2026-59115 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability Published on: August 06, 2026 '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-49163 Application Insights Profiler Elevation of Privilege Vulnerability Published on: August 06, 2026 Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-68823 Azure Confidential Ledger Remote Code Execution Vulnerability Published on: August 06, 2026 Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. Read Details
CVE-2026-70332 Microsoft Office SharePoint Spoofing Vulnerability Published on: August 06, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Read Details
CVE-2026-56161 Azure Logic Apps Information Disclosure Vulnerability Published on: August 06, 2026 Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. Read Details
CVE-2026-62830 Azure SRE Agent Elevation of Privilege Vulnerability Published on: August 06, 2026 Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-65667 Microsoft Teams Elevation of Privilege Vulnerability Published on: August 06, 2026 Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. Read Details
CVE-2026-56162 Azure SQL Database Elevation of Privilege Vulnerability Published on: August 06, 2026 Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. Read Details
CVE-2026-50515 Azure Service Bus Remote Code Execution Vulnerability Published on: August 06, 2026 Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. Read Details
CVE-2026-62869 Azure Entra ID Spoofing Vulnerability Published on: August 06, 2026 Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-63522 Azure SQL Database Elevation of Privilege Vulnerability Published on: August 06, 2026 Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-63508 Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability Published on: August 06, 2026 Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. Read Details
CVE-2026-62873 Microsoft 365 Admin Center Elevation of Privilege Vulnerability Published on: August 06, 2026 Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. Read Details
CVE-2026-55050 Microsoft Word Information Disclosure Vulnerability Published on: August 06, 2026 Acknowledgement Updated Read Details
CVE-2026-50416 Win32k Information Disclosure Vulnerability Published on: August 03, 2026 Acknowledgement Updated Read Details
CVE-2026-50341 Windows NTFS Information Disclosure Vulnerability Published on: August 03, 2026 Acknowledgement Updated Read Details
CVE-2026-50493 DirectX Graphics Kernel Elevation of Privilege Vulnerability Published on: August 03, 2026 Acknowledgement Updated Read Details
CVE-2026-54128 Windows DHCP Client Remote Code Execution Vulnerability Published on: July 30, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-55129 Microsoft Office Remote Code Execution Vulnerability Published on: July 30, 2026 Acknowledgement Updated Read Details
CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution Vulnerability Published on: July 30, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability Published on: July 30, 2026 Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability Published on: July 30, 2026 Informational Change. CVE ID stays the same. Read Details
CVE-2026-24304 Azure Cosmos DB Remote Code Execution Vulnerability Published on: July 30, 2026 Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-50422 Windows NTFS Elevation of Privilege Vulnerability Published on: July 28, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-47301 Configuration Manager Elevation of Privilege Vulnerability Published on: July 28, 2026 Corrected Build Number in the Security Updates table. This is an informational change only. Read Details
CVE-2026-59117 Windows Terminal Remote Code Execution Vulnerability Published on: July 28, 2026 Change the name of the affected software from **Microsoft Power Apps** to **Microsoft Power Apps Desktop Client**. This is an informational change only. Read Details
Chromium: CVE-2026-13032 Use after free in WebGL Published on: July 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-13028 Use after free in WebGL Published on: July 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-13030 Uninitialized Use in GPU Published on: July 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-13037 Use after free in WebView Published on: July 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
CVE-2026-50333 Windows Spaceport.sys Elevation of Privilege Vulnerability Published on: July 27, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-50697 Windows Common Log File System Driver Elevation of Privilege Vulnerability Published on: July 27, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-50343 Microsoft Install Service Elevation of Privilege Vulnerability Published on: July 27, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-56159 DHCP Server Service Remote Code Execution Vulnerability Published on: July 27, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist() Published on: July 27, 2026 Information published. Read Details
CVE-2024-14040 net: nexthop: Increase weight to u16 Published on: July 27, 2026 Information published. Read Details
CVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle Published on: July 27, 2026 Information published. Read Details
CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting Published on: July 27, 2026 Information published. Read Details
CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file() Published on: July 27, 2026 Information published. Read Details
Chromium: CVE-2026-16804 Use after free in Input Published on: July 25, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-16805 Use after free in Blink Published on: July 25, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-16806 Use after free in WebMCP Published on: July 25, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-16807 Out of bounds write in Codecs Published on: July 25, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
CVE-2026-62835 Azure Portal Information Disclosure Vulnerability Published on: July 24, 2026 Corrected the CVE description and title. This is an informational change only. Read Details
CVE-2026-48561 Microsoft Edge Copilot Remote Code Execution Vulnerability Published on: July 24, 2026 Corrected the CVE description and title. This is an informational change only. Read Details
CVE-2026-59676 Local File Deletion Attack Vector in rm_rf() in seunshare Published on: July 24, 2026 Information published. Read Details
CVE-2026-59677 Process Kill Attack Vector in killall() in seunshare Published on: July 24, 2026 Information published. Read Details
CVE-2026-64600 xfs: resample the data fork mapping after cycling ILOCK Published on: July 24, 2026 Information published. Read Details
CVE-2026-56167 Azure AI Search Elevation of Privilege Vulnerability Published on: July 23, 2026 Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-56163 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability Published on: July 23, 2026 Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. Read Details
CVE-2026-56165 Microsoft Account Remote Code Execution Vulnerability Published on: July 23, 2026 Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-54120 Microsoft Surface Remote Code Execution Vulnerability Published on: July 23, 2026 Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. Read Details
CVE-2026-56160 Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability Published on: July 23, 2026 Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-35425 Azure API Management (APIM) Remote Code Execution Vulnerability Published on: July 23, 2026 Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. Read Details
CVE-2026-49159 Microsoft Graph Information Disclosure Vulnerability Published on: July 23, 2026 Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. Read Details
CVE-2026-50517 Microsoft M365 Copilot Remote Code Execution Vulnerability Published on: July 23, 2026 Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. Read Details
CVE-2026-56191 Microsoft Exchange Online Tampering Vulnerability Published on: July 23, 2026 Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. Read Details
CVE-2026-57106 Data Quality Elevation of Privilege Vulnerability Published on: July 23, 2026 Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. Read Details
CVE-2026-62825 Azure Key Vault Elevation of Privilege Vulnerability Published on: July 23, 2026 Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. Read Details
CVE-2026-58630 Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability Published on: July 23, 2026 Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. Read Details
CVE-2026-58275 Azure DNS Elevation of Privilege Vulnerability Published on: July 23, 2026 Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. Read Details
CVE-2026-62835 Online Services Information Disclosure Vulnerability Published on: July 23, 2026 Improper authorization in Online Services allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-47729 Squid: Memory disclosure in FTP gateway Published on: July 23, 2026 Information published. Read Details
CVE-2026-56145 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service Published on: July 23, 2026 Information published. Read Details
CVE-2026-63140 Reachable Assertion in Elasticsearch Leading to Denial of Service Published on: July 23, 2026 Information published. Read Details
CVE-2026-63136 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service Published on: July 23, 2026 Information published. Read Details
CVE-2026-53910 Heap-based Buffer Overflow in GNU diffutils Published on: July 23, 2026 Information published. Read Details
CVE-2026-55973 'dns-error-reporting: yes' leads to stack buffer overflow Published on: July 23, 2026 Information published. Read Details
CVE-2026-44687 Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN Published on: July 23, 2026 Information published. Read Details
CVE-2026-50248 BOGUS configured primary hostname accepted for XFR in auth/rpz zones Published on: July 23, 2026 Information published. Read Details
CVE-2026-55708 Privacy/configuration issue when adding local data in views through 'unbound-control' Published on: July 23, 2026 Information published. Read Details
CVE-2026-44621 Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated Published on: July 23, 2026 Information published. Read Details
CVE-2026-55717 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash Published on: July 23, 2026 Information published. Read Details
CVE-2026-40691 Packet of death for DNSCrypt over TCP Published on: July 23, 2026 Information published. Read Details
CVE-2026-32665 Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass Published on: July 23, 2026 Information published. Read Details
CVE-2026-46582 A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path Published on: July 23, 2026 Information published. Read Details
CVE-2026-42955 Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records Published on: July 23, 2026 Information published. Read Details
CVE-2026-50046 Possible heap use-after-free in an error path when a DoT forwarded query is jostled out Published on: July 23, 2026 Information published. Read Details
CVE-2026-55990 Packet of death for a DNSCrypt misconfigured Unbound Published on: July 23, 2026 Information published. Read Details
CVE-2026-55991 Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2 Published on: July 23, 2026 Information published. Read Details
CVE-2026-50251 Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush Published on: July 23, 2026 Information published. Read Details
CVE-2026-50252 Possible cache poisoning attack by mapping source port population per thread Published on: July 23, 2026 Information published. Read Details
CVE-2026-50243 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL Published on: July 23, 2026 Information published. Read Details
CVE-2026-63308 Helm Files.Lines Denial of Service via Empty Chart Files Published on: July 23, 2026 Information published. Read Details
CVE-2026-15588 Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering Published on: July 23, 2026 Information published. Read Details
CVE-2026-26080 HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected. Published on: July 23, 2026 Information published. Read Details
CVE-2026-26081 HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected. Published on: July 23, 2026 Information published. Read Details
CVE-2026-15788 WCOW cache mount source selector resolves NTFS junctions outside of cache root Published on: July 23, 2026 Information published. Read Details
CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys Published on: July 23, 2026 Information published. Read Details
CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist() Published on: July 23, 2026 Information published. Read Details
CVE-2026-44509 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate. Published on: July 23, 2026 Information published. Read Details
CVE-2026-44508 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate. Published on: July 23, 2026 Information published. Read Details
CVE-2026-50012 Squid: Memory corruption in cache_digest reply handling Published on: July 23, 2026 Information published. Read Details
CVE-2026-54171 Excon: redact additional sensitive/risky headers when following redirects Published on: July 23, 2026 Information published. Read Details
CVE-2026-38753 A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. Published on: July 23, 2026 Information published. Read Details
CVE-2026-38752 A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. Published on: July 23, 2026 Information published. Read Details
CVE-2026-63263 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service Published on: July 23, 2026 Information published. Read Details
CVE-2026-62994 CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin Published on: July 23, 2026 Information published. Read Details
CVE-2026-50045 'max-global-quota' reset by DNSSEC validation restarts Published on: July 23, 2026 Information published. Read Details
CVE-2026-44690 Cross-zone wildcard cache poisoning via RRSIG.labels manipulation Published on: July 23, 2026 Information published. Read Details
CVE-2026-52863 Memory corruption could lead to crash and denial of service Published on: July 23, 2026 Information published. Read Details
CVE-2026-56416 Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name Published on: July 23, 2026 Information published. Read Details
CVE-2026-56444 Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration Published on: July 23, 2026 Information published. Read Details
CVE-2026-54478 DNS Cookie bypass when combined with proxy-protocol use Published on: July 23, 2026 Information published. Read Details
CVE-2026-14586 Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments Published on: July 23, 2026 Information published. Read Details
CVE-2026-41637 Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries Published on: July 23, 2026 Information published. Read Details
CVE-2026-44510 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate. Published on: July 23, 2026 Information published. Read Details
CVE-2026-15028 Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header Published on: July 22, 2026 Information published. Read Details
CVE-2026-57219 RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations Published on: July 22, 2026 Information published. Read Details
CVE-2026-59884 pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs Published on: July 22, 2026 Information published. Read Details
CVE-2026-59886 pyasn1: Uncontrolled resource consumption when converting decoded REAL values Published on: July 22, 2026 Information published. Read Details
CVE-2026-42533 NGINX Map directive and Regex matching vulnerability Published on: July 22, 2026 Information published. Read Details
CVE-2026-56434 NGINX ngx_http_ssi_module vulnerability Published on: July 22, 2026 Information published. Read Details
CVE-2026-26197 Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c Published on: July 22, 2026 Information published. Read Details
CVE-2026-64192 bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized Published on: July 22, 2026 Information published. Read Details
CVE-2026-64189 netfilter: ipset: fix race between dump and ip_set_list resize Published on: July 22, 2026 Information published. Read Details
CVE-2026-64188 net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() Published on: July 22, 2026 Information published. Read Details
CVE-2026-57220 RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS Published on: July 22, 2026 Information published. Read Details
CVE-2026-57217 RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass Published on: July 22, 2026 Information published. Read Details
CVE-2026-57213 RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering Published on: July 22, 2026 Information published. Read Details
CVE-2026-57216 RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks Published on: July 22, 2026 Information published. Read Details
CVE-2026-57211 RabbitMQ: UNC SSRF affecting the management UI on Windows Published on: July 22, 2026 Information published. Read Details
CVE-2026-57215 RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom Published on: July 22, 2026 Information published. Read Details
CVE-2026-59885 pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service Published on: July 22, 2026 Information published. Read Details
CVE-2026-26199 Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero Published on: July 22, 2026 Information published. Read Details
CVE-2026-64187 xfs: fail recovery on a committed log item with no regions Published on: July 22, 2026 Information published. Read Details
CVE-2026-64205 i2c: i801: fix hardware state machine corruption in error path Published on: July 22, 2026 Information published. Read Details
CVE-2026-64190 net: team: fix NULL pointer dereference in team_xmit during mode change Published on: July 22, 2026 Information published. Read Details
CVE-2026-64206 Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock Published on: July 22, 2026 Information published. Read Details
CVE-2026-64191 i2c: stub: Reject I2C block transfers with invalid length Published on: July 22, 2026 Information published. Read Details
CVE-2026-39879 SQL injection in syslog-ng SQL destionation driver Published on: July 22, 2026 Information published. Read Details
CVE-2026-50407 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability Published on: July 22, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-50377 Windows Kernel Elevation of Privilege Vulnerability Published on: July 22, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-50466 Microsoft Brokering File System Elevation of Privilege Vulnerability Published on: July 22, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-50441 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability Published on: July 22, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-50458 Microsoft Brokering File System Elevation of Privilege Vulnerability Published on: July 22, 2026 Updated an acknowledgement. This is an informational change only. Read Details