CYBERSECURITYTRACKER
TRACKING3,014 stories541 vuln stories
Vendor patch cadence

Patch Day

Vendor patch releases, newest first. The lead section is Microsoft's Patch Tuesday, the Microsoft Security Response Center (MSRC) monthly release: in it, every row is Microsoft's own record (product, MSRC severity, and MSRC's exploitation assessment), and every Common Vulnerabilities and Exposures (CVE) identifier opens Microsoft's update guide. Below it, Cross-vendor Patch Day carries the other vendors that publish a machine-readable link from a CVE to its fix: today Android, from the Android Open Source Project, and Cisco. Some vendors are absent because no such feed exists: SAP requires a support login, and Adobe, Fortinet, and Ivanti publish their advisories as web pages only. Expanding any row opens the same detail panel the vulnerabilities table uses, with Known Exploited Vulnerabilities (KEV), Exploit Prediction Scoring System (EPSS), exploit intelligence, and references. Microsoft releases first published outside the month's second Tuesday appear with an Out-of-band badge.

Risk matrix, July 2026

Click a cell or header to filter the month's rows; click again to clear.
465 of these counts use a severity derived from CVSS because Microsoft assigned none.
465 of these counts use a severity derived from CVSS because Microsoft assigned none.
#

July 2026

Patch Tuesday July 14, 20261110 CVEs plus 305 Azure Linux package advisories · 76 critical · 3 exploitation detected · 4 in KEV1415 CVEs · 116 critical · 3 exploitation detected · 4 in KEV · includes 305 Azure Linux package advisories
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-58644 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Critical5%Exploitation detectedCISA KEVVulnCheckENISAKB5002873KB5002874
and 1 moreKB5002880
4 mentionsMicrosoft SharePoint Remote Code Execution Vulnerability
CVE-2026-56155 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant2%Exploitation detectedCISA KEVVulnCheckENISAKB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
5 mentionsActive Directory Federation Services Elevation of Privilege Vulnerability
CVE-2026-56164 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Moderate18%Exploitation detectedCISA KEVVulnCheckENISAKB5002882KB5002883
and 1 moreKB5002891
7 mentionsMicrosoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2026-15043 ↗2026-07-17azl3 perl-DBI 1.643-5 on Azure Linux 3.0CriticalOut-of-bandDBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text
CVE-2026-26145 ↗2026-07-02Azure SynapseCriticalOut-of-band0%Microsoft Azure Synapse Elevation of Privilege Vulnerability
CVE-2026-35425 ↗2026-07-23Azure API Management (APIM)CriticalOut-of-band0%Azure API Management (APIM) Remote Code Execution Vulnerability
CVE-2026-38968 ↗2026-07-09azl3 ntopng 5.2.1-6 on Azure Linux 3.0CriticalOut-of-bandntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.
CVE-2026-41106 ↗2026-07-02Microsoft 365 CopilotCriticalOut-of-band1%Microsoft 365 Copilot Elevation of Privilege Vulnerability
CVE-2026-42533 ↗2026-07-19azl3 nginx 1.28.3-6 on Azure Linux 3.0CriticalOut-of-band3%1 mentionsNGINX Map directive and Regex matching vulnerability
CVE-2026-42982 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5095051KB5099414
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
CVE-2026-45499 ↗2026-07-02Azure Open AICriticalOut-of-band1%Azure OpenAI Elevation of Privilege Vulnerability
CVE-2026-48561 ↗2026-07-14Microsoft Edge Copilot for AndroidCritical1%1 mentionsMicrosoft Edge Copilot Remote Code Execution Vulnerability
CVE-2026-48564 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5094041KB5094042
and 4 moreKB5099535KB5099536KB5099538KB5099540
1 mentionsDHCP Server Service Remote Code Execution Vulnerability
CVE-2026-49159 ↗2026-07-23Microsoft GraphCriticalOut-of-band1%Microsoft Graph Information Disclosure Vulnerability
CVE-2026-49164 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Active Directory Domain Services Remote Code Execution Vulnerability
CVE-2026-49796 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsWindows GDI+ Remote Code Execution Vulnerability
CVE-2026-50314 ↗2026-07-14Microsoft Office 365 for MacCritical0%KB50028871 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-50327 ↗2026-07-14Windows Server 2025 (Server Core installation)Critical0%More likelyKB5099536KB5101649
and 1 moreKB5101650
1 mentionsWindows Media Remote Code Execution Vulnerability
CVE-2026-50370 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%More likelyKB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
1 mentionsDHCP Server Service Remote Code Execution Vulnerability
CVE-2026-50380 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsWindows GDI+ Remote Code Execution Vulnerability
CVE-2026-50382 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
1 mentionsDirectX Graphics Kernel Remote Code Execution Vulnerability
CVE-2026-50392 ↗2026-07-14Windows 11 Version 25H2 for x64-based SystemsCritical0%KB5099536KB5101649
and 1 moreKB5101650
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
CVE-2026-50444 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
CVE-2026-50467 ↗2026-07-14Microsoft Office 2019 for 32-bit editionsCritical0%KB50028871 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-50474 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsRemote Desktop Client Remote Code Execution Vulnerability
CVE-2026-50517 ↗2026-07-23Microsoft 365 CopilotCriticalOut-of-band1%Microsoft M365 Copilot Remote Code Execution Vulnerability
CVE-2026-50518 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical11%More likelyKB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
1 mentionsWindows DHCP Server Remote Code Execution Vulnerability
CVE-2026-50522 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Critical57%More likelyCISA KEVVulnCheckENISAKB5002882KB5002883
and 1 moreKB5002891
3 mentionsMicrosoft SharePoint Remote Code Execution Vulnerability
CVE-2026-50655 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%More likelyKB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsMicrosoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2026-50680 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2026-50694 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2026-53374 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-banddrm/amdgpu: zero-initialize GART table on allocation
CVE-2026-53376 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-banddrm/amdkfd: Add upper bound check for num_of_nodes
CVE-2026-53384 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandserial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
CVE-2026-53386 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandiio: adc: ti-ads1298: add bounds check to pga_settings index
CVE-2026-53387 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandiio: light: veml6075: add bounds check to veml6075_it_ms index
CVE-2026-53403 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandfbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
CVE-2026-54117 ↗2026-07-14Microsoft SQL Server 2025 for x64-based Systems (GDR)Critical1%KB5101346KB5102333Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-54118 ↗2026-07-14Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature PackCritical1%KB5101346KB5101347
and 8 moreKB5102333KB5102334KB5102335KB5102336KB5102337KB5102338KB5102339KB5102340
Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-54120 ↗2026-07-23Surface Management ServicesCriticalOut-of-band1%Microsoft Surface Remote Code Execution Vulnerability
CVE-2026-54121 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
Active Directory Certificate Services Elevation of Privilege Vulnerability
CVE-2026-54127 ↗2026-07-14Windows Server 2022Critical0%KB5099536KB5099540
and 2 moreKB5101649KB5101650
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2026-54128 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsWindows DHCP Client Remote Code Execution Vulnerability
CVE-2026-54982 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsWindows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2026-54992 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsMicrosoft Message Queuing Queue Manager Remote Code Execution Vulnerability
CVE-2026-54995 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsWindows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2026-54998 ↗2026-07-02Microsoft Exchange OnlineCriticalOut-of-band1%Microsoft Exchange Online Elevation of Privilege Vulnerability
CVE-2026-54999 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows TCP/IP Remote Code Execution Vulnerability
CVE-2026-55008 ↗2026-07-14Microsoft Exchange Server 2016 Cumulative Update 23Critical1%More likelyKB5103212KB5103213
and 2 moreKB5103214KB5103215
Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-55010 ↗2026-07-14Minecraft Bedrock Dedicated ServerCritical1%More likely1 mentionsMinecraft Bedrock Dedicated Server Remote Code Execution Vulnerability
CVE-2026-55011 ↗2026-07-14Microsoft Malware Protection EngineCritical0%Microsoft Defender Remote Code Execution Vulnerability
CVE-2026-55012 ↗2026-07-14Microsoft Malware Protection EngineCritical0%Microsoft Defender Remote Code Execution Vulnerability
CVE-2026-55018 ↗2026-07-14Microsoft Office 365 for MacCritical0%KB50028871 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55022 ↗2026-07-14Microsoft Office 365 for MacCritical0%KB50028871 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55033 ↗2026-07-14Microsoft SharePoint Server 2019Critical0%KB5002882KB5002883
and 4 moreKB5002885KB5002890KB5002891KB5002892
1 mentionsMicrosoft Word Remote Code Execution Vulnerability
CVE-2026-55040 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Critical1%More likelyKB5002882KB5002883
and 1 moreKB5002891
3 mentionsMicrosoft SharePoint Server Security Feature Bypass Vulnerability
CVE-2026-55043 ↗2026-07-14Microsoft Office 365 for MacCritical0%KB50028671 mentionsMicrosoft PowerPoint Remote Code Execution Vulnerability
CVE-2026-55045 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Critical0%KB5002882KB5002883
and 4 moreKB5002885KB5002887KB5002891KB5002892
1 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55049 ↗2026-07-14Microsoft Office 2019 for 32-bit editionsCritical0%KB50027481 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55056 ↗2026-07-14Microsoft Office 2019 for 32-bit editionsCritical0%KB50028871 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55120 ↗2026-07-14Microsoft Office 2019 for 32-bit editionsCritical0%KB50028671 mentionsMicrosoft PowerPoint Remote Code Execution Vulnerability
CVE-2026-55123 ↗2026-07-14Microsoft Office 365 for MacCritical0%KB50028671 mentionsMicrosoft PowerPoint Remote Code Execution Vulnerability
CVE-2026-55127 ↗2026-07-14Microsoft SharePoint Server 2019Critical0%KB5002882KB5002883
and 4 moreKB5002885KB5002890KB5002891KB5002892
1 mentionsMicrosoft Word Remote Code Execution Vulnerability
CVE-2026-55129 ↗2026-07-14Microsoft Office 2019 for 32-bit editionsCritical0%KB50028871 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55132 ↗2026-07-14Microsoft Office 365 for MacCritical0%KB5002882KB5002883
and 4 moreKB5002885KB5002890KB5002891KB5002892
1 mentionsMicrosoft Word Remote Code Execution Vulnerability
CVE-2026-55140 ↗2026-07-14Microsoft Office 365 for MacCritical0%KB5002748KB50028301 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55944 ↗2026-07-14Microsoft Dynamics NAV 2018Critical1%More likely1 mentionsMicrosoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
CVE-2026-56000 ↗2026-07-09azl3 wayland 1.22.0-1 on Azure Linux 3.0CriticalOut-of-band0%xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()
CVE-2026-56159 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
1 mentionsDHCP Server Service Remote Code Execution Vulnerability
CVE-2026-56160 ↗2026-07-23Azure Red Hat OpenShift (ARO)CriticalOut-of-band1%Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability
CVE-2026-56163 ↗2026-07-23Azure Kubernetes ServiceCriticalOut-of-band1%Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
CVE-2026-56165 ↗2026-07-23Microsoft AccountCriticalOut-of-band1%Microsoft Account Remote Code Execution Vulnerability
CVE-2026-56167 ↗2026-07-23Azure AI SearchCriticalOut-of-band0%Azure AI Search Elevation of Privilege Vulnerability
CVE-2026-56188 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsWindows Server Network driver Remote Code Execution Vulnerability
CVE-2026-56189 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsMicrosoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2026-56191 ↗2026-07-23Microsoft Exchange OnlineCriticalOut-of-band1%Microsoft Exchange Online Tampering Vulnerability
CVE-2026-57087 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsMicrosoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2026-57090 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsMicrosoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2026-57092 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Microsoft Windows VMSwitch Elevation of Privilege Vulnerability
CVE-2026-57094 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsMicrosoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2026-57100 ↗2026-07-02Microsoft Entra Provisioning ServiceCriticalOut-of-band1%Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
CVE-2026-57106 ↗2026-07-23Microsoft Purview Data GovernanceCriticalOut-of-band1%Data Quality Elevation of Privilege Vulnerability
CVE-2026-57433 ↗2026-07-17azl3 perl 5.38.2-512 on Azure Linux 3.0CriticalOut-of-band0%Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record
CVE-2026-58275 ↗2026-07-23Azure DNSCriticalOut-of-band1%Azure DNS Elevation of Privilege Vulnerability
CVE-2026-58542 ↗2026-07-14Windows Server 2025 (Server Core installation)Critical0%KB5099536KB5101649
and 1 moreKB5101650
1 mentionsWindows Media Remote Code Execution Vulnerability
CVE-2026-58608 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Print Spooler Remote Code Execution Vulnerability
CVE-2026-58630 ↗2026-07-23Azure App Service for LinuxCriticalOut-of-band1%Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
CVE-2026-59873 ↗2026-07-12azl3 tar 1.35-2 on Azure Linux 3.0CriticalOut-of-band0%node-tar: Decompression/parse DoS via unlimited input
CVE-2026-60082 ↗2026-07-17azl3 perl-DBI 1.643-5 on Azure Linux 3.0CriticalOut-of-bandDBI versions before 1.651 for Perl do not enforce statement handle consistency with the row
CVE-2026-62825 ↗2026-07-23Azure Key VaultCriticalOut-of-band1%Azure Key Vault Elevation of Privilege Vulnerability
CVE-2026-62835 ↗2026-07-23Azure PortalCriticalOut-of-band1%Azure Portal Information Disclosure Vulnerability
CVE-2026-63797 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandrpmsg: char: Fix use-after-free on probe error path
CVE-2026-63800 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandpNFS: Fix use-after-free in pnfs_update_layout()
CVE-2026-63814 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandf2fs: validate ACL entry sizes in f2fs_acl_from_disk()
CVE-2026-63816 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandf2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode
CVE-2026-63818 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandf2fs: validate orphan inode entry count
CVE-2026-63822 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandwifi: ath11k: fix warning when unbinding
CVE-2026-63824 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandKEYS: fix overflow in keyctl_pkey_params_get_2()
CVE-2026-63827 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandapparmor: fix use-after-free in rawdata dedup loop
CVE-2026-63828 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandapparmor: mediate the implicit connect of TCP fast open sendmsg
CVE-2026-63833 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandntfs3: reject direct userspace writes to reserved $LX* xattrs
CVE-2026-63881 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-banddrm/amdkfd: fix a vulnerability of integer overflow in kfd debugger
CVE-2026-63882 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-banddrm/amdkfd: fix NULL pointer bug in svm_range_set_attr
CVE-2026-63958 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandusb: typec: ucsi: validate connector number in ucsi_connector_change()
CVE-2026-63959 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandusb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT
CVE-2026-63974 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandBluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close
CVE-2026-63979 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band1%net/handshake: hand off the pinned file reference to accept_doit
CVE-2026-63983 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandnet/sched: fix packet loop on netem when duplicate is on
CVE-2026-63999 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandethtool: rss: fix indir_table and hkey leak on get_rxfh failure
CVE-2026-64017 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandblk-mq: pop cached request if it is usable
CVE-2026-64070 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandpowerpc/hv-gpci: fix preempt count leak in sysfs show paths
CVE-2026-64076 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandnetfilter: bridge: eb_tables: close module init race
CVE-2026-64078 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandnetfilter: x_tables: add and use xtables_unregister_table_exit
CVE-2026-64079 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandnetfilter: x_tables: allocate hook ops while under mutex
CVE-2026-64111 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandlsm: hold cred_guard_mutex for lsm_set_self_attr()
CVE-2026-64138 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band0%ksmbd: validate SID in parent security descriptor during ACL inheritance
CVE-2026-8926 ↗2026-07-04azl3 curl 8.11.1-9 on Azure Linux 3.0CriticalOut-of-band0%password leak with netrc and user in URL
CVE-2026-9547 ↗2026-07-04azl3 cmake 3.30.3-14 on Azure Linux 3.0CriticalOut-of-bandSSH improper host validation
CVE-2026-12064 ↗2026-07-04azl3 curl 8.11.1-9 on Azure Linux 3.0ImportantOut-of-bandproto-default skips SSH verification
CVE-2026-12413 ↗2026-07-04azl3 libreswan 4.15-1 on Azure Linux 3.0ImportantOut-of-bandIKEv2 Denial of Service via malformed fragmentation
CVE-2026-14191 ↗2026-07-09azl3 clamav 1.5.2-3 on Azure Linux 3.0ImportantOut-of-bandWinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader
CVE-2026-14380 ↗2026-07-11azl3 perl-DBI 1.643-5 on Azure Linux 3.0ImportantOut-of-bandDBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile
CVE-2026-14739 ↗2026-07-11azl3 perl-DBI 1.643-5 on Azure Linux 3.0ImportantOut-of-band0%DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders
CVE-2026-14740 ↗2026-07-11azl3 perl-DBI 1.643-5 on Azure Linux 3.0ImportantOut-of-bandDBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment
CVE-2026-15308 ↗2026-07-12azl3 python3 3.12.9-13 on Azure Linux 3.0ImportantOut-of-band1%Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
CVE-2026-15392 ↗2026-07-17azl3 perl-DBI 1.643-5 on Azure Linux 3.0ImportantOut-of-bandDBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location
CVE-2026-15709 ↗2026-07-17azl3 libsoup 3.4.4-16 on Azure Linux 3.0ImportantOut-of-bandSoupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of service
CVE-2026-15711 ↗2026-07-17azl3 libsoup 3.4.4-16 on Azure Linux 3.0ImportantOut-of-bandLibsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol violation
CVE-2026-20213 ↗2026-07-11azl3 clamav 1.5.2-3 on Azure Linux 3.0ImportantOut-of-bandClamAV PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability
CVE-2026-20214 ↗2026-07-11azl3 clamav 1.5.2-3 on Azure Linux 3.0ImportantOut-of-bandClamAV FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability
CVE-2026-20215 ↗2026-07-11azl3 clamav 1.5.2-3 on Azure Linux 3.0ImportantOut-of-bandClamAV 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability
CVE-2026-20216 ↗2026-07-11azl3 clamav 1.5.2-3 on Azure Linux 3.0ImportantOut-of-bandClamAV InstallShield File Format Processing Resource Exhaustion Vulnerability
CVE-2026-20217 ↗2026-07-11azl3 clamav 1.5.2-3 on Azure Linux 3.0ImportantOut-of-bandClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability
CVE-2026-20243 ↗2026-07-11azl3 clamav 1.5.2-3 on Azure Linux 3.0ImportantOut-of-bandClamAV ALZ Archive Processing Denial of Service Vulnerability
CVE-2026-20244 ↗2026-07-11azl3 clamav 1.5.2-3 on Azure Linux 3.0ImportantOut-of-bandClamAV DMG File Processing Denial of Service Vulnerability
CVE-2026-33842 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099414KB5099444
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows File Explorer Information Disclosure Vulnerability
CVE-2026-34328 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099414KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Audio Service Information Disclosure Vulnerability
CVE-2026-34346 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099414KB5099444
and 8 moreKB5099445KB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
CVE-2026-34348 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5089548KB5099414
and 6 moreKB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Event Logging Service Information Disclosure Vulnerability
CVE-2026-34349 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Media Information Disclosure Vulnerability
CVE-2026-3842 ↗2026-07-19azl3 qemu 9.1.0-10 on Azure Linux 3.0ImportantOut-of-band0%Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write
CVE-2026-38754 ↗2026-07-19azl3 busybox 1.36.1-24 on Azure Linux 3.0ImportantOut-of-band0%A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
CVE-2026-38755 ↗2026-07-19azl3 busybox 1.36.1-24 on Azure Linux 3.0ImportantOut-of-band0%A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
CVE-2026-39822 ↗2026-07-15azl3 golang 1.25.11-3 on Azure Linux 3.0ImportantOut-of-band0%Root escape via symlink plus trailing slash in os
CVE-2026-39879 ↗2026-07-22azl3 syslog-ng 4.3.1-3 on Azure Linux 3.0ImportantOut-of-bandSQL injection in syslog-ng SQL destionation driver
CVE-2026-40378 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5095051KB5099414
and 9 moreKB5099444KB5099445KB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2026-40400 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows PowerShell Remote Code Execution Vulnerability
CVE-2026-40422 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows File Explorer Information Disclosure Vulnerability
CVE-2026-41087 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows File Explorer Information Disclosure Vulnerability
CVE-2026-41109 ↗2026-07-14Visual Studio CodeImportant1%GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-42900 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Microsoft Windows App Store Elevation of Privilege Vulnerability
CVE-2026-42975 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Bluetooth Port Driver Remote Code Execution
CVE-2026-42990 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5094041KB5094042
and 9 moreKB5095051KB5099414KB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
SQL Server ODBC driver Elevation of Privilege Vulnerability
CVE-2026-44800 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5095051KB5099414
and 3 moreKB5099536KB5101649KB5101650
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-44806 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Secure Channel Denial of Service Vulnerability
CVE-2026-45496 ↗2026-07-14Visual Studio CodeImportant0%Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-45646 ↗2026-07-14Microsoft.AspNet.ODataImportant1%OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability
CVE-2026-47282 ↗2026-07-14Visual Studio CodeImportant1%GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
CVE-2026-47290 ↗2026-07-14Microsoft Office 2019 for 32-bit editionsImportant0%KB5002273Microsoft Office Remote Code Execution Vulnerability
CVE-2026-47295 ↗2026-07-14Microsoft SQL Server 2022 for x64-based Systems (CU 25)Important1%KB5101346KB5101347
and 8 moreKB5102333KB5102334KB5102335KB5102336KB5102337KB5102338KB5102339KB5102340
Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-47296 ↗2026-07-14Microsoft SQL Server 2022 for x64-based Systems (CU 25)Important0%KB5101346KB5101347
and 8 moreKB5102333KB5102334KB5102335KB5102336KB5102337KB5102338KB5102339KB5102340
Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-47300 ↗2026-07-14.NET 10.0 installed on LinuxImportant1%KB5104032KB5104033
and 1 moreKB5104034
ASP.NET Core Elevation of Privilege Vulnerability
CVE-2026-47301 ↗2026-07-14Microsoft Configuration Manager 2509Important1%Configuration Manager Elevation of Privilege Vulnerability
CVE-2026-47303 ↗2026-07-14.NET 10.0 installed on LinuxImportant1%KB5104032KB5104033
and 1 moreKB5104034
ASP.NET Core Elevation of Privilege Vulnerability
CVE-2026-47305 ↗2026-07-14Microsoft Visual Studio 2026 version 18.7Important0%Visual Studio Remote Code Execution Vulnerability
CVE-2026-47632 ↗2026-07-14Azure Monitor Agent Metrics ExtensionImportant0%Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability
CVE-2026-47642 ↗2026-07-14Microsoft Office 365 for MacImportant0%KB5002884Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-48571 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5095051KB5099414
and 3 moreKB5099536KB5101649KB5101650
Windows App Package Installer Elevation of Privilege Vulnerability
CVE-2026-48572 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5095051KB5099414
and 3 moreKB5099536KB5101649KB5101650
Windows App Package Installer Elevation of Privilege Vulnerability
CVE-2026-48580 ↗2026-07-14Office Online ServerImportant0%KB5002884KB5002886Microsoft Excel Information Disclosure Vulnerability
CVE-2026-48581 ↗2026-07-14Surface Windows Dev KitImportant0%Surface Broker SDMA Elevation of Privilege Vulnerability
CVE-2026-48863 ↗2026-07-17azl3 libsolv 0.7.28-4 on Azure Linux 3.0ImportantOut-of-band0%Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service
CVE-2026-49162 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2026-49165 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Microsoft Windows App Store Information Disclosure Vulnerability
CVE-2026-49166 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Print Configuration Elevation of Privilege Vulnerability
CVE-2026-49167 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-49168 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Storage Spaces Direct Elevation of Privilege Vulnerability
CVE-2026-49169 ↗2026-07-14Windows Server 2025 (Server Core installation)Important1%KB5099536Windows DNS Server Remote Code Execution Vulnerability
CVE-2026-49170 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant3%More likelyKB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows StateRepository API Server file Elevation of Privilege Vulnerability
CVE-2026-49171 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Speech Runtime Elevation of Privilege Vulnerability
CVE-2026-49172 ↗2026-07-14Windows 11 Version 25H2 for x64-based SystemsImportant1%KB5099414KB5099535
and 6 moreKB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows FTP Service Remote Code Execution Vulnerability
CVE-2026-49173 ↗2026-07-14Windows 11 version 26H1 for x64-based SystemsImportant0%KB5101649Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-49174 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
DNS Client Tampering Vulnerability
CVE-2026-49175 ↗2026-07-14Windows Server 2022Important0%KB5099536KB5099539
and 3 moreKB5099540KB5101649KB5101650
Windows DNS Client Elevation of Privilege Vulnerability
CVE-2026-49176 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows WalletService Elevation of Privilege Vulnerability
CVE-2026-49177 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows TCP/IP Information Disclosure Vulnerability
CVE-2026-49178 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Active Directory Domain Services Remote Code Execution Vulnerability
CVE-2026-49180 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
CVE-2026-49181 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
Windows DHCP Client Elevation of Privilege Vulnerability
CVE-2026-49183 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Clipboard Server Elevation of Privilege Vulnerability
CVE-2026-49184 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-49783 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Secure Boot Security Feature Bypass Vulnerability
CVE-2026-49784 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Microsoft Windows App Store Elevation of Privilege Vulnerability
CVE-2026-49787 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
HTTP.sys Denial of Service Vulnerability
CVE-2026-49788 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
HTTP/2 Denial of Service Vulnerability
CVE-2026-49789 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NTFS Elevation of Privilege Vulnerability
CVE-2026-49790 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-49791 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
CVE-2026-49792 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
CVE-2026-49793 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
CVE-2026-49794 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows USB Audio Class Driver Information Disclosure Vulnerability
CVE-2026-49795 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-49797 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-49798 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-49799 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2026-49800 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant2%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability
CVE-2026-49801 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows SMB Information Disclosure Vulnerability
CVE-2026-49802 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows USB Print Driver Elevation of Privilege Vulnerability
CVE-2026-49803 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows AppX Deployment Extensions Elevation of Privilege Vulnerability
CVE-2026-49804 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 6 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101650
Windows USB Video Driver Elevation of Privilege Vulnerability
CVE-2026-49805 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant3%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Win32k Elevation of Privilege Vulnerability
CVE-2026-49806 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows USB Print Driver Elevation of Privilege Vulnerability
CVE-2026-49807 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows DirectX Information Disclosure Vulnerability
CVE-2026-49808 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-50293 ↗2026-07-14Windows 10 Version 21H2 for 32-bit SystemsImportant0%KB5099536KB5099539
and 2 moreKB5101649KB5101650
Windows Internal Task Bar Elevation of Privilege Vulnerability
CVE-2026-50294 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Kernel Information Disclosure Vulnerability
CVE-2026-50295 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Zero Trust DNS Security Feature Bypass Vulnerability
CVE-2026-50296 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2026-50297 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Win32k Elevation of Privilege Vulnerability
CVE-2026-50298 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Spaceport.sys Elevation of Privilege Vulnerability
CVE-2026-50299 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099535
and 6 moreKB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Storage Spaces Direct Remote Code Execution Vulnerability
CVE-2026-50300 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows DWM Core Library Information Disclosure Vulnerability
CVE-2026-50301 ↗2026-07-14Microsoft Office 2019 for 32-bit editionsImportant0%KB5002887Microsoft Office Remote Code Execution Vulnerability
CVE-2026-50302 ↗2026-07-14Windows Server 2022Important0%KB5099536KB5099539
and 3 moreKB5099540KB5101649KB5101650
Windows Cryptographic Services Security Feature Bypass Vulnerability
CVE-2026-50303 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Key Guard Security Feature Bypass Vulnerability
CVE-2026-50304 ↗2026-07-14Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit SystemsImportant1%KB5099444KB5099445
and 19 moreKB5099535KB5099536KB5099538KB5099540KB5100989KB5100990KB5100991KB5100998KB5101000KB5101001KB5101002KB5101004KB5101005KB5101006KB5101007KB5101008KB5101009KB5101010KB5101011
Windows Active Directory Federation Services Denial of Service Vulnerability
CVE-2026-50305 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2026-50306 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-50307 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-50308 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-50309 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-50310 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Human Interface Device Information Disclosure Vulnerability
CVE-2026-50311 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Server Elevation of Privilege Vulnerability
CVE-2026-50312 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-50313 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-50315 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Image Acquisition Elevation of Privilege Vulnerability
CVE-2026-50316 ↗2026-07-14Windows Server 2022Important0%KB5099536KB5099539
and 3 moreKB5099540KB5101649KB5101650
Windows Kernel Information Disclosure Vulnerability
CVE-2026-50317 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Operating Systems Elevation of Privilege Vulnerability
CVE-2026-50318 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVE-2026-50321 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows USB Driver Elevation of Privilege Vulnerability
CVE-2026-50322 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Runtime Elevation of Privilege Vulnerability
CVE-2026-50323 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Runtime Elevation of Privilege Vulnerability
CVE-2026-50324 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099535
and 18 moreKB5099536KB5099538KB5099540KB5100989KB5100990KB5100991KB5100998KB5101000KB5101001KB5101002KB5101004KB5101005KB5101006KB5101007KB5101008KB5101009KB5101010KB5101011
Windows Active Directory Federation Services Denial of Service Vulnerability
CVE-2026-50325 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Win32k Elevation of Privilege Vulnerability
CVE-2026-50326 ↗2026-07-14Windows 10 Version 21H2 for 32-bit SystemsImportant0%KB5099536KB5099539
and 2 moreKB5101649KB5101650
Windows Unified Consent System Elevation of Privilege Vulnerability
CVE-2026-50328 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
Windows Server Update Service (WSUS) Tampering Vulnerability
CVE-2026-50329 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-50330 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Remote Desktop Client Elevation of Privilege Vulnerability
CVE-2026-50331 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Application Model Core API Elevation of Privilege Vulnerability
CVE-2026-50332 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-50333 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Spaceport.sys Elevation of Privilege Vulnerability
CVE-2026-50334 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Push Notification Information Disclosure Vulnerability
CVE-2026-50335 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Operating Systems Elevation of Privilege Vulnerability
CVE-2026-50336 ↗2026-07-14Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5101649KB5101650Windows Media Elevation of Privilege Vulnerability
CVE-2026-50337 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Notification Elevation of Privilege Vulnerability
CVE-2026-50338 ↗2026-07-14Azure Spring AppsImportant0%Azure Spring Apps Elevation of Privilege Vulnerability
CVE-2026-50339 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Push Notification Information Disclosure Vulnerability
CVE-2026-50340 ↗2026-07-14Windows Server 2025 (Server Core installation)Important1%KB5099536KB5101649
and 1 moreKB5101650
Windows Runtime Elevation of Privilege Vulnerability
CVE-2026-50341 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NTFS Information Disclosure Vulnerability
CVE-2026-50342 ↗2026-07-14Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5101649KB5101650Windows MIDI Service Module Elevation of Privileges Vulnerability
CVE-2026-50343 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant4%More likelyKB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Microsoft Install Service Elevation of Privilege Vulnerability
CVE-2026-50344 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows OLE Elevation of Privilege Vulnerability
CVE-2026-50345 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Runtime Elevation of Privilege Vulnerability
CVE-2026-50346 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Netlogon RPC Elevation of Privilege Vulnerability
CVE-2026-50347 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Data.dll Remote Code Execution Vulnerability
CVE-2026-50348 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Runtime Elevation of Privilege Vulnerability
CVE-2026-50350 ↗2026-07-14Windows 10 Version 21H2 for 32-bit SystemsImportant0%KB5099536KB5099539
and 2 moreKB5101649KB5101650
Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability
CVE-2026-50351 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant3%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability
CVE-2026-50352 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Cryptographic Services Information Disclosure Vulnerability
CVE-2026-50353 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2026-50354 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-50355 ↗2026-07-14Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit SystemsImportant1%KB5099444KB5099445
and 19 moreKB5099535KB5099536KB5099538KB5099540KB5100989KB5100990KB5100991KB5100998KB5101000KB5101001KB5101002KB5101004KB5101005KB5101006KB5101007KB5101008KB5101009KB5101010KB5101011
Windows Active Directory Federation Services Denial of Service Vulnerability
CVE-2026-50356 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Microsoft Windows App Store Elevation of Privilege Vulnerability
CVE-2026-50357 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVE-2026-50358 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Media Elevation of Privilege Vulnerability
CVE-2026-50359 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Microsoft XML Core Services Elevation of Privilege Vulnerability
CVE-2026-50360 ↗2026-07-14Windows Server 2022Important1%KB5099536KB5099539
and 3 moreKB5099540KB5101649KB5101650
Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-50361 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2026-50362 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
CVE-2026-50363 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099535
and 6 moreKB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-50364 ↗2026-07-14Windows 10 Version 21H2 for 32-bit SystemsImportant0%KB5099539KB5101649
and 1 moreKB5101650
Windows Backup Service Elevation of Privilege Vulnerability
CVE-2026-50365 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability
CVE-2026-50366 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Active Directory Domain Services Denial of Service Vulnerability
CVE-2026-50367 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Sensor Data Service Elevation of Privilege Vulnerability
CVE-2026-50368 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 19 moreKB5099535KB5099536KB5099538KB5099540KB5100989KB5100990KB5100991KB5100998KB5101000KB5101001KB5101002KB5101004KB5101005KB5101006KB5101007KB5101008KB5101009KB5101010KB5101011
Windows Active Directory Federation Services Denial of Service Vulnerability
CVE-2026-50369 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVE-2026-50371 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability
CVE-2026-50372 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability
CVE-2026-50373 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Search Service Elevation of Privilege Vulnerability
CVE-2026-50374 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-50375 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2026-50376 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Remote Desktop Client Information Disclosure Vulnerability
CVE-2026-50377 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-50378 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Key Guard Elevation of Privilege Vulnerability
CVE-2026-50379 ↗2026-07-14Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5101649KB5101650Windows Media Elevation of Privilege Vulnerability
CVE-2026-50381 ↗2026-07-14Windows Server 2022Important0%KB5099536KB5099539
and 3 moreKB5099540KB5101649KB5101650
Composite Image File System driver (cimfs.sys) Information Disclosure Vulnerability
CVE-2026-50383 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Print Spooler Information Disclosure Vulnerability
CVE-2026-50384 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Clip Service Elevation of Privilege Vulnerability
CVE-2026-50385 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Runtime Elevation of Privilege Vulnerability
CVE-2026-50386 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-50387 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows GDI Elevation of Privilege Vulnerability
CVE-2026-50388 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-50389 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows File Explorer Information Disclosure Vulnerability
CVE-2026-50390 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-50391 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Group Policy Elevation of Privilege Vulnerability
CVE-2026-50393 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2026-50394 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099535
and 6 moreKB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Media Information Disclosure Vulnerability
CVE-2026-50396 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2026-50397 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-50398 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Media Elevation of Privilege Vulnerability
CVE-2026-50399 ↗2026-07-14Windows Server 2022Important0%KB5099536KB5099539
and 3 moreKB5099540KB5101649KB5101650
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-50400 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows App Package Installer Elevation of Privilege Vulnerability
CVE-2026-50401 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability
CVE-2026-50402 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
NTFS Elevation of Privilege Vulnerability
CVE-2026-50403 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Runtime Elevation of Privilege Vulnerability
CVE-2026-50404 ↗2026-07-14Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5101649KB5101650Windows Media Elevation of Privilege Vulnerability
CVE-2026-50405 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Filtering Platform Elevation of Privilege Vulnerability
CVE-2026-50406 ↗2026-07-14Windows 10 Version 21H2 for 32-bit SystemsImportant0%KB5099539KB5101649
and 1 moreKB5101650
Windows Backup Engine Elevation of Privilege Vulnerability
CVE-2026-50407 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVE-2026-50408 ↗2026-07-14Office Online ServerImportant0%KB5002884KB5002886Microsoft Excel Information Disclosure Vulnerability
CVE-2026-50409 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Overlay Filter Information Disclosure Vulnerability
CVE-2026-50410 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Runtime Elevation of Privilege Vulnerability
CVE-2026-50412 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NTFS Elevation of Privilege Vulnerability
CVE-2026-50413 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Runtime Elevation of Privilege Vulnerability
CVE-2026-50414 ↗2026-07-14Windows Server 2025 (Server Core installation)Important1%KB5099536KB5101649
and 1 moreKB5101650
Windows Media Elevation of Privilege Vulnerability
CVE-2026-50415 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Media Information Disclosure Vulnerability
CVE-2026-50416 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Win32k Information Disclosure Vulnerability
CVE-2026-50417 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-50418 ↗2026-07-14Windows Server 2022Important0%KB5099536KB5099540
and 2 moreKB5101649KB5101650
Windows System Secure Feature Bypass Vulnerability
CVE-2026-50419 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Kernel Information Disclosure Vulnerability
CVE-2026-50420 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
HTTP.sys Information Disclosure Vulnerability
CVE-2026-50421 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
CVE-2026-50422 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NTFS Elevation of Privilege Vulnerability
CVE-2026-50423 ↗2026-07-14Windows Server 2022Important3%More likelyKB5099536KB5099539
and 3 moreKB5099540KB5101649KB5101650
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-50424 ↗2026-07-14Windows Server 2025 (Server Core installation)Important1%KB5099536KB5101649
and 1 moreKB5101650
Windows Domain Controller Denial of Service Vulnerability
CVE-2026-50425 ↗2026-07-14Windows 10 Version 21H2 for 32-bit SystemsImportant0%KB5099536KB5099539
and 2 moreKB5101649KB5101650
Windows Internal System User Profile Elevation of Privilege Vulnerability
CVE-2026-50426 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
Windows DNS Server Remote Code Execution Vulnerability
CVE-2026-50427 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 3 moreKB5099539KB5101649KB5101650
Content Delivery Manager Elevation of Privilege Vulnerability
CVE-2026-50428 ↗2026-07-14Windows 11 version 26H1 for x64-based SystemsImportant0%KB5101649Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability
CVE-2026-50429 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Kernel Information Disclosure Vulnerability
CVE-2026-50430 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Push Notification Information Disclosure Vulnerability
CVE-2026-50431 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
CVE-2026-50432 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Window Virtual Filtering Platform (VFP) Denial of Service Vulnerability
CVE-2026-50433 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Media Elevation of Privilege Vulnerability
CVE-2026-50434 ↗2026-07-14Windows Server 2022Important0%KB5099536KB5099539
and 3 moreKB5099540KB5101649KB5101650
Windows Push Notification Information Disclosure Vulnerability
CVE-2026-50435 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099535
and 6 moreKB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Overlay Filter Elevation of Privilege Vulnerability
CVE-2026-50436 ↗2026-07-14Windows Server 2025 (Server Core installation)Important2%More likelyKB5099536KB5101649
and 1 moreKB5101650
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-50437 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows DWM Core Library Information Disclosure Vulnerability
CVE-2026-50438 ↗2026-07-14Microsoft PC ManagerImportant0%Microsoft PC Manager Elevation of Privilege Vulnerability
CVE-2026-50439 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability
CVE-2026-50440 ↗2026-07-14Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5101649KB5101650Windows Audio Service Elevation of Privilege Vulnerability
CVE-2026-50441 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVE-2026-50442 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows File Explorer Information Disclosure Vulnerability
CVE-2026-50445 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-50447 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability
CVE-2026-50448 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-50449 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Runtime Elevation of Privilege Vulnerability
CVE-2026-50450 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Network Connections Service Elevation of Privilege Vulnerability
CVE-2026-50451 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
CVE-2026-50452 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Runtime Elevation of Privilege Vulnerability
CVE-2026-50453 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows USB Audio Class Driver Information Disclosure Vulnerability
CVE-2026-50454 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%More likelyKB5099536KB5101649
and 1 moreKB5101650
Windows User Interface Core Elevation of Privilege Vulnerability
CVE-2026-50455 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
CVE-2026-50456 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows File Explorer Information Disclosure Vulnerability
CVE-2026-50457 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 3 moreKB5099539KB5101649KB5101650
Windows Runtime Elevation of Privilege Vulnerability
CVE-2026-50458 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2026-50459 ↗2026-07-14Windows Server 2022Important0%KB5099536KB5099539
and 3 moreKB5099540KB5101649KB5101650
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-50460 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Runtime Elevation of Privilege Vulnerability
CVE-2026-50461 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-50462 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-50463 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Kernel Information Disclosure Vulnerability
CVE-2026-50465 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows DNS Client Tampering Vulnerability
CVE-2026-50466 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2026-50468 ↗2026-07-14Microsoft SQL Server 2025 for x64-based Systems (CU6)Important1%KB5101346KB5102333Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-50469 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-50470 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Network Policy Server SNMP Information Disclosure Vulnerability
CVE-2026-50471 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099414KB5099444
and 8 moreKB5099445KB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-50473 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows File Explorer Information Disclosure Vulnerability
CVE-2026-50475 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Kernel Information Disclosure Vulnerability
CVE-2026-50476 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Network Connections Service Elevation of Privilege Vulnerability
CVE-2026-50477 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-50478 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-50479 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 2 moreKB5099539KB5099540
Windows USB Hub Driver Elevation of Privilege Vulnerability
CVE-2026-50480 ↗2026-07-14Windows 10 Version 1607 for 32-bit SystemsImportant0%KB5099415KB5099444
and 2 moreKB5099445KB5099535
Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability
CVE-2026-50482 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-50483 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Graphics Component Information Disclosure Vulnerability
CVE-2026-50484 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-50485 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Hyper-V Denial of Service Vulnerability
CVE-2026-50486 ↗2026-07-14Windows 10 Version 21H2 for 32-bit SystemsImportant0%KB5099536KB5099539
and 2 moreKB5101649KB5101650
Windows Runtime Elevation of Privilege Vulnerability
CVE-2026-50487 ↗2026-07-14Windows Server 2025 (Server Core installation)Important1%KB5099536KB5101649
and 1 moreKB5101650
Windows DNS Client Elevation of Privilege Vulnerability
CVE-2026-50488 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101650Clipboard User Service Elevation of Privilege Vulnerability
CVE-2026-50489 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Win32k Elevation of Privilege Vulnerability
CVE-2026-50490 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Installer Elevation of Privilege Vulnerability
CVE-2026-50491 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability
CVE-2026-50492 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
CVE-2026-50493 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2026-50494 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-50495 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
DNS Client Tampering Vulnerability
CVE-2026-50496 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Network Policy Server SNMP Information Disclosure Vulnerability
CVE-2026-50497 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-50498 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-50499 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2026-50500 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Netlogon Elevation of Privilege Vulnerability
CVE-2026-50501 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
CVE-2026-50502 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Event Logging Service Remote Code Execution Vulnerability
CVE-2026-50503 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Runtime Elevation of Privilege Vulnerability
CVE-2026-50504 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Remote Desktop Client Information Disclosure Vulnerability
CVE-2026-50505 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability
CVE-2026-50506 ↗2026-07-14Microsoft.AspNetCore.ODataImportant1%OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability
CVE-2026-50509 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant3%More likelyKB5099535KB5099536
and 4 moreKB5099538KB5099539KB5101649KB5101650
Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
CVE-2026-50510 ↗2026-07-14GitHub Copilot Plugin for JetBrains IDEsImportant0%GitHub Copilot Remote Code Execution Vulnerability
CVE-2026-50520 ↗2026-07-14Visual Studio CodeImportant0%Visual Studio Code Remote Code Execution Vulnerability
CVE-2026-50524 ↗2026-07-14Microsoft Visual Studio 2026 version 18.7Important1%KB5104032KB5104033
and 1 moreKB5104034
.NET Framework Denial of Service Vulnerability
CVE-2026-50526 ↗2026-07-14Microsoft Visual Studio 2022 version 17.12Important0%KB5104032KB5104033
and 1 moreKB5104034
.NET Tampering Vulnerability
CVE-2026-50528 ↗2026-07-14Microsoft Visual Studio 2022 version 17.12Important1%KB5104032KB5104033
and 1 moreKB5104034
.NET Security Feature Bypass Vulnerability
CVE-2026-50651 ↗2026-07-14.NET 10.0 installed on Mac OSImportant1%KB5104032KB5104033
and 1 moreKB5104034
.NET Denial of Service Vulnerability
CVE-2026-50657 ↗2026-07-14Microsoft Defender for Endpoint for MacImportant0%Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability
CVE-2026-50658 ↗2026-07-14Microsoft Defender for Endpoint for MacImportant0%Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability
CVE-2026-50661 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
2 mentionsWindows BitLocker Security Feature Bypass Vulnerability
CVE-2026-50663 ↗2026-07-14Age of Empires II: Definitive Edition GameImportant1%Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability
CVE-2026-50665 ↗2026-07-14Microsoft Office 2019 for 32-bit editionsImportant0%KB5002887Microsoft Office Information Disclosure Vulnerability
CVE-2026-50666 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099535
and 6 moreKB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Remote Access Elevation of Privilege Vulnerability
CVE-2026-50667 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2026-50668 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVE-2026-50669 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Telephony Server Elevation of Privilege Vulnerability
CVE-2026-50670 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-50672 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows NTFS Elevation of Privilege Vulnerability
CVE-2026-50673 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-50674 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows USB Print Driver Elevation of Privilege Vulnerability
CVE-2026-50675 ↗2026-07-14Office Online ServerImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-50676 ↗2026-07-14Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5101649KB5101650Windows Media Elevation of Privilege Vulnerability
CVE-2026-50677 ↗2026-07-14Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5101649KB5101650Windows Media Elevation of Privilege Vulnerability
CVE-2026-50678 ↗2026-07-14Office Online ServerImportant0%KB5002884KB5002886Microsoft Excel Information Disclosure Vulnerability
CVE-2026-50679 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Search Service Elevation of Privilege Vulnerability
CVE-2026-50681 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Secure Channel Information Disclosure Vulnerability
CVE-2026-50682 ↗2026-07-14Windows Server 2022Important1%KB5099536KB5099539
and 3 moreKB5099540KB5101649KB5101650
Active Directory Denial of Service Vulnerability
CVE-2026-50683 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
Windows DHCP Client Elevation of Privilege Vulnerability
CVE-2026-50684 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
Active Directory Federation Server Spoofing Vulnerability
CVE-2026-50685 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
Windows DHCP Server Remote Code Execution Vulnerability
CVE-2026-50686 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099535
and 6 moreKB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows OLE Remote Code Execution Vulnerability
CVE-2026-50687 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-50688 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-50689 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Clipboard Server Elevation of Privilege Vulnerability
CVE-2026-50690 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows SMB Information Disclosure Vulnerability
CVE-2026-50692 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-50695 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Active Directory Federation Services Denial of Service Vulnerability
CVE-2026-50696 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability
CVE-2026-50697 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2026-50721 ↗2026-07-04azl3 libreswan 4.15-1 on Azure Linux 3.0ImportantOut-of-bandIKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload
CVE-2026-50722 ↗2026-07-04azl3 libreswan 4.15-1 on Azure Linux 3.0ImportantOut-of-bandIKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload
CVE-2026-53329 ↗2026-07-02azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/amd/display: Use krealloc_array() in dal_vector_reserve()
CVE-2026-53343 ↗2026-07-02azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow
CVE-2026-53354 ↗2026-07-02azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandarm64: errata: Mitigate TLBI errata on various Arm CPUs
CVE-2026-53356 ↗2026-07-02azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/i915/gem: Fix phys BO pread/pwrite with offset
CVE-2026-53359 ↗2026-07-05azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandKVM: x86: Fix shadow paging use-after-free due to unexpected role
CVE-2026-53362 ↗2026-07-05azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandipv6: account for fraggap on the paged allocation path
CVE-2026-53366 ↗2026-07-17azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandipv4: account for fraggap on the paged allocation path
CVE-2026-53368 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandf2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage
CVE-2026-53375 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/amdgpu/vce: Prevent partial address patches
CVE-2026-53381 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandvirtiofs: fix UAF on submount umount
CVE-2026-53383 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandksmbd: reject non-VALID session in compound request branch
CVE-2026-53388 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandfuse: re-lock request before replacing page cache folio
CVE-2026-53390 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandksmbd: fix out-of-bounds read in smb_check_perm_dacl()
CVE-2026-53400 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandi2c: core: fix adapter registration race
CVE-2026-53401 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandfbdev: omap2: fix use-after-free in omapfb_mmap
CVE-2026-53402 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandfbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
CVE-2026-54107 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-54108 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important1%KB5002882KB5002883
and 1 moreKB5002891
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-54109 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
CVE-2026-54111 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Universal Print Management Service Elevation of Privilege Vulnerability
CVE-2026-54112 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-54114 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-54115 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability
CVE-2026-54116 ↗2026-07-14Microsoft SQL Server 2025 for x64-based Systems (GDR)Important1%KB5101346KB5102333Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-54119 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Active Directory Denial of Service Vulnerability
CVE-2026-54122 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsWindows GDI+ Remote Code Execution Vulnerability
CVE-2026-54124 ↗2026-07-14Windows Server 2022Important0%KB5099536KB5099539
and 3 moreKB5099540KB5101649KB5101650
Windows Terminal Remote Code Execution Vulnerability
CVE-2026-54125 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Runtime Elevation of Privilege Vulnerability
CVE-2026-54126 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099445KB5099535
and 6 moreKB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-54129 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2026-54131 ↗2026-07-14Office Online ServerImportant0%KB5002884Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-54132 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099538
and 3 moreKB5099539KB5101649KB5101650
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-54983 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Active Directory Federation Services Denial of Service Vulnerability
CVE-2026-54986 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-54987 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099535
and 6 moreKB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Overlay Filter Elevation of Privilege Vulnerability
CVE-2026-54988 ↗2026-07-14Microsoft Office 365 for MacImportant0%KB5002884KB5002886Microsoft Excel Information Disclosure Vulnerability
CVE-2026-54989 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability
CVE-2026-54990 ↗2026-07-14Windows Server 2025 (Server Core installation)Important1%KB5099536KB5101649
and 1 moreKB5101650
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-54991 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows USB Print Driver Elevation of Privilege Vulnerability
CVE-2026-54993 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2026-54996 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows USB Print Driver Elevation of Privilege Vulnerability
CVE-2026-54997 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows SMB Information Disclosure Vulnerability
CVE-2026-55000 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows USB Print Driver Elevation of Privilege Vulnerability
CVE-2026-55001 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 2 moreKB5099538KB5099540
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2026-55002 ↗2026-07-14Microsoft SQL Server 2019 for x64-based Systems (GDR)Important0%KB5101346KB5101347
and 8 moreKB5102333KB5102334KB5102335KB5102336KB5102337KB5102338KB5102339KB5102340
Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-55003 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-55004 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Print Configuration Elevation of Privilege Vulnerability
CVE-2026-55005 ↗2026-07-14Microsoft Exchange Server 2016 Cumulative Update 23Important1%KB5103212KB5103213
and 2 moreKB5103214KB5103215
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2026-55006 ↗2026-07-14Microsoft Exchange Server 2019 Cumulative Update 14Important0%KB5103212KB5103213
and 2 moreKB5103214KB5103215
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2026-55009 ↗2026-07-14Microsoft Exchange Server 2016 Cumulative Update 23Important2%KB5103212KB5103213
and 2 moreKB5103214KB5103215
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2026-55014 ↗2026-07-14Windows Remote HelpImportant0%Windows Remote Help Defense Elevation of Privilege Vulnerability
CVE-2026-55016 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002882KB5002883
and 1 moreKB5002891
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-55017 ↗2026-07-14Microsoft Office 2019 for 32-bit editionsImportant0%KB5002273Microsoft Office Remote Code Execution Vulnerability
CVE-2026-55019 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002882KB5002883
and 1 moreKB5002891
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-55020 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002882KB5002883
and 1 moreKB5002891
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-55021 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important1%KB5002882KB5002883
and 1 moreKB5002891
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-55023 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002882KB5002883
and 4 moreKB5002885KB5002887KB5002891KB5002892
Microsoft Office Information Disclosure Vulnerability
CVE-2026-55024 ↗2026-07-14Microsoft Office 365 for MacImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-55025 ↗2026-07-14Office Online ServerImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-55026 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002882KB5002883
and 4 moreKB5002885KB5002887KB5002891KB5002892
Microsoft Office Information Disclosure Vulnerability
CVE-2026-55027 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002882KB5002883
and 4 moreKB5002885KB5002887KB5002891KB5002892
Microsoft Office Information Disclosure Vulnerability
CVE-2026-55028 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002882KB5002883
and 4 moreKB5002885KB5002887KB5002891KB5002892
Microsoft Office Information Disclosure Vulnerability
CVE-2026-55029 ↗2026-07-14Office Online ServerImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-55030 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002882KB5002883
and 1 moreKB5002891
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-55031 ↗2026-07-14Microsoft Office 365 for MacImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-55032 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002882KB5002883
and 4 moreKB5002885KB5002890KB5002891KB5002892
Microsoft Word Remote Code Execution Vulnerability
CVE-2026-55034 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important1%KB5002882KB5002883
and 1 moreKB5002891
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-55035 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002882KB5002883
and 4 moreKB5002885KB5002887KB5002891KB5002892
Microsoft Office Information Disclosure Vulnerability
CVE-2026-55036 ↗2026-07-14Office Online ServerImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-55037 ↗2026-07-14Microsoft Office 365 for MacImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-55038 ↗2026-07-14Microsoft Office 365 for MacImportant0%KB5002882KB5002883
and 4 moreKB5002885KB5002890KB5002891KB5002892
Microsoft Word Remote Code Execution Vulnerability
CVE-2026-55039 ↗2026-07-14Office Online ServerImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-55041 ↗2026-07-14Office Online ServerImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-55042 ↗2026-07-14Microsoft Office 365 for MacImportant0%KB5002887Microsoft Office Information Disclosure Vulnerability
CVE-2026-55044 ↗2026-07-14Office Online ServerImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-55046 ↗2026-07-14Microsoft Office 365 for MacImportant0%KB5002884KB5002886Microsoft Excel Information Disclosure Vulnerability
CVE-2026-55047 ↗2026-07-14Microsoft Office 365 for MacImportant0%KB5002882KB5002883
and 4 moreKB5002885KB5002887KB5002891KB5002892
Microsoft Office Information Disclosure Vulnerability
CVE-2026-55048 ↗2026-07-14Office Online ServerImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-55050 ↗2026-07-14Microsoft Office 365 for MacImportant0%KB5002882KB5002883
and 4 moreKB5002885KB5002890KB5002891KB5002892
Microsoft Word Information Disclosure Vulnerability
CVE-2026-55051 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important1%KB5002882KB5002883
and 1 moreKB5002891
Microsoft SharePoint Server Information Disclosure Vulnerability
CVE-2026-55052 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important1%KB5002882KB5002883
and 1 moreKB5002891
Microsoft SharePoint Elevation of Privilege Vulnerability
CVE-2026-55053 ↗2026-07-14Microsoft Office 365 for MacImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-55054 ↗2026-07-14Office Online ServerImportant1%KB5002884KB5002886Microsoft Excel Information Disclosure Vulnerability
CVE-2026-55055 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002882KB5002883
and 4 moreKB5002885KB5002890KB5002891KB5002892
Microsoft Word Remote Code Execution Vulnerability
CVE-2026-55057 ↗2026-07-14Microsoft Office 2019 for 32-bit editionsImportant0%KB5002887Microsoft Office Information Disclosure Vulnerability
CVE-2026-55058 ↗2026-07-14Office Online ServerImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-55121 ↗2026-07-14Microsoft Office 365 for MacImportant0%KB5002882KB5002883
and 4 moreKB5002885KB5002887KB5002891KB5002892
Microsoft Office Information Disclosure Vulnerability
CVE-2026-55122 ↗2026-07-14Microsoft Office 365 for MacImportant0%KB5002884KB5002886Microsoft Excel Information Disclosure Vulnerability
CVE-2026-55124 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002882KB5002883
and 4 moreKB5002885KB5002890KB5002891KB5002892
Microsoft Word Information Disclosure Vulnerability
CVE-2026-55125 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002882KB5002883
and 4 moreKB5002885KB5002887KB5002891KB5002892
Microsoft Office Remote Code Execution Vulnerability
CVE-2026-55126 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002882KB5002883
and 1 moreKB5002891
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-55128 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002882KB5002883
and 4 moreKB5002885KB5002890KB5002891KB5002892
Microsoft Word Remote Code Execution Vulnerability
CVE-2026-55130 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002882KB5002883
and 4 moreKB5002885KB5002890KB5002891KB5002892
Microsoft Word Remote Code Execution Vulnerability
CVE-2026-55131 ↗2026-07-14Microsoft Office 365 for MacImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-55133 ↗2026-07-14Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft OneNote Remote Code Execution Vulnerability
CVE-2026-55134 ↗2026-07-14Microsoft Office 365 for MacImportant0%KB5002882KB5002883
and 4 moreKB5002885KB5002890KB5002891KB5002892
Microsoft Word Remote Code Execution Vulnerability
CVE-2026-55135 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002882KB5002883
and 1 moreKB5002891
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-55136 ↗2026-07-14Office Online ServerImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-55137 ↗2026-07-14Office Online ServerImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-55138 ↗2026-07-14Office Online ServerImportant0%KB5002884KB5002886Microsoft Excel Information Disclosure Vulnerability
CVE-2026-55139 ↗2026-07-14Microsoft Office 2019 for 32-bit editionsImportant0%KB5002887Microsoft Office Information Disclosure Vulnerability
CVE-2026-55141 ↗2026-07-14Office Online ServerImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-55142 ↗2026-07-14Microsoft Office 365 for MacImportant0%KB5002882KB5002883
and 4 moreKB5002885KB5002890KB5002891KB5002892
Microsoft Word Information Disclosure Vulnerability
CVE-2026-55144 ↗2026-07-14Windows Server 2022Important0%KB5099536KB5099540
and 2 moreKB5101649KB5101650
Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability
CVE-2026-55898 ↗2026-07-14Microsoft Office 365 for MacImportant0%KB5002884KB5002886Microsoft Excel Information Disclosure Vulnerability
CVE-2026-55899 ↗2026-07-14Microsoft Office 365 for MacImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-55947 ↗2026-07-14Microsoft Office 365 for MacImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-55948 ↗2026-07-14Microsoft Office 365 for MacImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-55949 ↗2026-07-14Office Online ServerImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-55952 ↗2026-07-07azl3 erlang 26.2.5.21-2 on Azure Linux 3.0ImportantOut-of-bandTLS 1.3 server denial of service via malformed ClientHello pre-shared key extension
CVE-2026-55999 ↗2026-07-09azl3 wayland 1.22.0-1 on Azure Linux 3.0ImportantOut-of-band0%xorg-server / xwayland glamor font atlas Heap Buffer Overflow
CVE-2026-56001 ↗2026-07-09azl3 libXfont2 2.0.6-1 on Azure Linux 3.0ImportantOut-of-band0%libXfont2 BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow
CVE-2026-56002 ↗2026-07-09azl3 libXfont2 2.0.6-1 on Azure Linux 3.0ImportantOut-of-band0%libXfont2 PCF Font Parsing Heap Buffer Overflow
CVE-2026-56003 ↗2026-07-09azl3 libXfont2 2.0.6-1 on Azure Linux 3.0ImportantOut-of-band0%libXfont2 computeProps Property Buffer Heap Buffer Overflow
CVE-2026-56156 ↗2026-07-14Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-56157 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002882KB5002883
and 1 moreKB5002891
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-56168 ↗2026-07-14Windows Server 2022Important1%KB5099536KB5099539
and 3 moreKB5099540KB5101649KB5101650
Windows SMB Server Denial of Service Vulnerability
CVE-2026-56169 ↗2026-07-14Windows Admin CenterImportant1%Windows Admin Center Elevation of Privilege Vulnerability
CVE-2026-56170 ↗2026-07-14.NET 10.0 installed on Mac OSImportant1%KB5104032KB5104033
and 1 moreKB5104034
ASP.NET Core Denial of Service Vulnerability
CVE-2026-56171 ↗2026-07-16Windows Admin CenterImportantOut-of-band0%Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-56173 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099414KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows WebView Elevation of Privilege Vulnerability
CVE-2026-56175 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NTFS Elevation of Privilege Vulnerability
CVE-2026-56176 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-56178 ↗2026-07-14Microsoft Defender for Endpoint for MacImportant0%Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability
CVE-2026-56182 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NTFS Elevation of Privilege Vulnerability
CVE-2026-56183 ↗2026-07-14Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5101649KB5101650Windows MIDI Service Module Elevation of Privileges Vulnerability
CVE-2026-56184 ↗2026-07-14Windows Server 2022Important0%KB5099536KB5099539
and 3 moreKB5099540KB5101649KB5101650
Win32k Information Disclosure Vulnerability
CVE-2026-56185 ↗2026-07-14Windows Admin CenterImportant1%Windows Admin Center Information Disclosure Vulnerability
CVE-2026-56186 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Secure Channel Information Disclosure Vulnerability
CVE-2026-56187 ↗2026-07-14Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5101649KB5101650Windows MIDI Service Module Elevation of Privileges Vulnerability
CVE-2026-56190 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Remote Desktop Protocol Remote Code Execution Vulnerability
CVE-2026-56192 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002882KB5002883
and 4 moreKB5002885KB5002887KB5002891KB5002892
Microsoft Office Information Disclosure Vulnerability
CVE-2026-56193 ↗2026-07-14Microsoft Office 2019 for 32-bit editionsImportant0%KB5002887Microsoft Office Information Disclosure Vulnerability
CVE-2026-56194 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NFS Server Elevation of Privilege Vulnerability
CVE-2026-56195 ↗2026-07-14Microsoft Office 2019 for 32-bit editionsImportant0%KB5002887Microsoft Office Information Disclosure Vulnerability
CVE-2026-56196 ↗2026-07-14Windows Admin CenterImportant1%Windows Admin Center (WAC) Remote Code Execution Vulnerability
CVE-2026-56197 ↗2026-07-14Windows Admin CenterImportant1%Windows Admin Center (WAC) Remote Code Execution Vulnerability
CVE-2026-56434 ↗2026-07-19azl3 nginx 1.28.3-6 on Azure Linux 3.0ImportantOut-of-band0%NGINX ngx_http_ssi_module vulnerability
CVE-2026-56642 ↗2026-07-14Fabric Data WarehouseImportant1%Microsoft Fabric Data Warehouse Remote Code Execution Vulnerability
CVE-2026-56643 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2026-56644 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2026-56645 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band1%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-56646 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band1%Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-56647 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099535
and 6 moreKB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerability
CVE-2026-56648 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NFS Server Elevation of Privilege Vulnerability
CVE-2026-56649 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Network File System Remote Code Execution Vulnerability
CVE-2026-56650 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Network File System Elevation of Privilege Vulnerability
CVE-2026-57083 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Media Photo Codec Information Disclosure Vulnerability
CVE-2026-57084 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows File Explorer Information Disclosure Vulnerability
CVE-2026-57085 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Print Spooler Information Disclosure Vulnerability
CVE-2026-57088 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 1 moreKB5099540
Extensible Storage Engine (ESENT) Elevation of Privilege Vulnerability
CVE-2026-57089 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability
CVE-2026-57091 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows File History Service Elevation of Privilege Vulnerability
CVE-2026-57093 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-57095 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Win32k Elevation of Privilege Vulnerability
CVE-2026-57096 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099535
and 6 moreKB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
CVE-2026-57097 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Microsoft XML Security Feature Bypass Vulnerability
CVE-2026-57101 ↗2026-07-14Visual Studio CodeImportant0%Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-57102 ↗2026-07-14Visual Studio CodeImportant1%Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-57107 ↗2026-07-14Windows Admin CenterImportant0%Windows Admin Center Elevation of Privilege Vulnerability
CVE-2026-57108 ↗2026-07-14.NET 10.0 installed on LinuxImportant1%KB5104032KB5104033
and 1 moreKB5104034
.NET Denial of Service Vulnerability
CVE-2026-57215 ↗2026-07-15azl3 rabbitmq-server 3.13.7-6 on Azure Linux 3.0ImportantOut-of-bandRabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom
CVE-2026-57217 ↗2026-07-15azl3 rabbitmq-server 3.13.7-6 on Azure Linux 3.0ImportantOut-of-bandRabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass
CVE-2026-57219 ↗2026-07-15azl3 rabbitmq-server 3.13.7-6 on Azure Linux 3.0ImportantOut-of-bandRabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations
CVE-2026-57220 ↗2026-07-15azl3 rabbitmq-server 3.13.7-6 on Azure Linux 3.0ImportantOut-of-bandRabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS
CVE-2026-57432 ↗2026-07-15azl3 perl 5.38.2-512 on Azure Linux 3.0ImportantOut-of-bandPerl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack
CVE-2026-57968 ↗2026-07-14Windows Subsystem for Linux (WSL2)Important0%Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability
CVE-2026-57969 ↗2026-07-14Azure CycleCloud 8.9.1Important1%Azure CycleCloud Elevation of Privilege Vulnerability
CVE-2026-57973 ↗2026-07-14Windows Subsystem for Linux (WSL2)Important0%Windows Subsystem for Linux (WSL2) Kernel Tampering Vulnerability
CVE-2026-57974 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band1%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-57975 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-57976 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Active Directory Domain Services Denial of Service Vulnerability
CVE-2026-57977 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-57978 ↗2026-07-24Microsoft Edge (Chromium-based)ImportantOut-of-bandMicrosoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-57979 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099535
and 6 moreKB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-57980 ↗2026-07-16Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Tampering Vulnerability
CVE-2026-57981 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band1%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-57982 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-57983 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2026-57984 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-57985 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-57986 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-57987 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band1%Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-57988 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band1%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-57989 ↗2026-07-24Microsoft Edge (Chromium-based)ImportantOut-of-bandMicrosoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-57990 ↗2026-07-24Microsoft Edge (Chromium-based)ImportantOut-of-bandMicrosoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-57991 ↗2026-07-02Microsoft Edge (Chromium-based)ImportantOut-of-band1%Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-57992 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band1%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-57993 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band1%Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-58207 ↗2026-07-11azl3 telegraf 1.31.0-23 on Azure Linux 3.0ImportantOut-of-bandNATS Server: Remote crash via integer overflow in Connz pagination
CVE-2026-58253 ↗2026-07-11azl3 telegraf 1.31.0-23 on Azure Linux 3.0ImportantOut-of-bandNATS Server: Route API Auth Bypass
CVE-2026-58276 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58277 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Important1%KB5002883KB5002891Microsoft SharePoint Elevation of Privilege Vulnerability
CVE-2026-58278 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-58279 ↗2026-07-14Azure CycleCloud 8.9.1Important0%Azure CycleCloud Elevation of Privilege Vulnerability
CVE-2026-58281 ↗2026-07-11Microsoft Edge (Chromium-based)ImportantOut-of-band1%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58282 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-58283 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-58284 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58285 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58286 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-58287 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58288 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58289 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band1%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58290 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58291 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band1%Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-58292 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58293 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58294 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58295 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2026-58296 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-58297 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-58298 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-58299 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge for Android Remote Code Execution Vulnerability
CVE-2026-58300 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-58522 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-58523 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge for Android Security Feature Bypass Vulnerability
CVE-2026-58524 ↗2026-07-03Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-58525 ↗2026-07-08Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2026-58526 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Storage Elevation of Privilege Vulnerability
CVE-2026-58527 ↗2026-07-14Windows Server 2022Important0%KB5099536KB5099540
and 2 moreKB5101649KB5101650
Windows Runtime Elevation of Privilege Vulnerability
CVE-2026-58528 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows USB Audio Class Driver Information Disclosure Vulnerability
CVE-2026-58529 ↗2026-07-14Windows 11 version 26H1 for x64-based SystemsImportant1%KB5101649Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability
CVE-2026-58530 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
CVE-2026-58531 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows SMB Elevation of Privilege Vulnerability
CVE-2026-58532 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-58533 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Remote Desktop Client Information Disclosure Vulnerability
CVE-2026-58534 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Input Method Editor (IME) Elevation of Privilege Vulnerability
CVE-2026-58535 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Remote Desktop Client Information Disclosure Vulnerability
CVE-2026-58536 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-58537 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege Vulnerability
CVE-2026-58538 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Bluetooth Service Elevation of Privilege Vulnerability
CVE-2026-58539 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Remote Desktop Client Information Disclosure Vulnerability
CVE-2026-58540 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Installer Elevation of Privilege Vulnerability
CVE-2026-58541 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-58543 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Universal Print Management Service Elevation of Privilege Vulnerability
CVE-2026-58544 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-58545 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Kernel Security Feature Bypass Vulnerability
CVE-2026-58546 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Remote Desktop Client Information Disclosure Vulnerability
CVE-2026-58547 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability
CVE-2026-58594 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-58595 ↗2026-07-14Microsoft Bing Search for iOSImportant0%Microsoft Bing App for IOS Spoofing Vulnerability
CVE-2026-58596 ↗2026-07-11Microsoft Edge (Chromium-based)ImportantOut-of-band0%More likelyMicrosoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2026-58598 ↗2026-07-16Windows 10 Version 21H2 for 32-bit SystemsImportantOut-of-band0%KB5099539KB5101649
and 1 moreKB5101650
Windows Backup Service Elevation of Privilege Vulnerability
CVE-2026-58601 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099414KB5099535
and 6 moreKB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability
CVE-2026-58602 ↗2026-07-14Windows Server 2025 (Server Core installation)Important0%KB5099536KB5101649
and 1 moreKB5101650
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2026-58609 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-58610 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2026-58613 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-58614 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Kernel Security Feature Bypass Vulnerability
CVE-2026-58617 ↗2026-07-14Microsoft 365 Copilot for iOSImportant1%M365 Copilot for iOS Elevation of Privilege Vulnerability
CVE-2026-58618 ↗2026-07-14Office Online ServerImportant0%KB5002884KB5002886Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-58619 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Sensor Data Service Elevation of Privilege Vulnerability
CVE-2026-58626 ↗2026-07-14Windows Server 2022Important1%KB5099536KB5099539
and 3 moreKB5099540KB5101649KB5101650
Windows Remote Desktop Services Remote Code Execution Vulnerability
CVE-2026-58627 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
Windows DHCP Server Denial of Service Vulnerability
CVE-2026-58628 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Wireless Network Manager Elevation of Privilege Vulnerability
CVE-2026-58629 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099414KB5099444
and 8 moreKB5099445KB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2026-58631 ↗2026-07-14Windows Admin CenterImportant0%More likelyWindows Admin Center (WAC) Remote Code Execution Vulnerability
CVE-2026-58632 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
CVE-2026-58633 ↗2026-07-14Windows 11 version 26H1 for x64-based SystemsImportant0%More likelyKB5101649Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-58634 ↗2026-07-14Windows 11 version 26H1 for x64-based SystemsImportant0%KB5101649Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-58635 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Narrator Braille Elevation of Privilege Vulnerability
CVE-2026-58636 ↗2026-07-14Microsoft PC ManagerImportant0%Microsoft PC Manager Elevation of Privilege Vulnerability
CVE-2026-58637 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Client-Side Caching Elevation of Privilege Vulnerability
CVE-2026-58638 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Boot Loader Security Feature Bypass Vulnerability
CVE-2026-58640 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5099414KB5099444
and 8 moreKB5099445KB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-58643 ↗2026-07-16Windows Admin CenterImportantOut-of-band0%Windows Admin Center Spoofing Vulnerability
CVE-2026-58647 ↗2026-07-14Power BI Report ServerImportant0%Microsoft PowerBI Report Server Spoofing Vulnerability
CVE-2026-59117 ↗2026-07-16Windows Terminal AppImportantOut-of-band0%Windows Terminal Remote Code Execution Vulnerability
CVE-2026-59856 ↗2026-07-11azl3 vim 9.2.0735-1 on Azure Linux 3.0ImportantOut-of-bandVim: Arbitrary Code Execution via PHP Omni-Completion
CVE-2026-59869 ↗2026-07-11azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-band0%js-yaml: YAML merge-key chains can force quadratic CPU consumption
CVE-2026-59874 ↗2026-07-12azl3 tar 1.35-2 on Azure Linux 3.0ImportantOut-of-band0%node-tar: Negative tar entry size causes infinite loop in archive replace
CVE-2026-59884 ↗2026-07-17azl3 python-pyasn1 0.4.8-2 on Azure Linux 3.0ImportantOut-of-band0%pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
CVE-2026-59885 ↗2026-07-17azl3 python-pyasn1 0.4.8-2 on Azure Linux 3.0ImportantOut-of-band0%pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
CVE-2026-59886 ↗2026-07-17azl3 python-pyasn1 0.4.8-2 on Azure Linux 3.0ImportantOut-of-band0%pyasn1: Uncontrolled resource consumption when converting decoded REAL values
CVE-2026-59922 ↗2026-07-11azl3 python-mistune 3.3.0-1 on Azure Linux 3.0ImportantOut-of-band0%Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
CVE-2026-59925 ↗2026-07-11azl3 python-mistune 3.3.0-1 on Azure Linux 3.0ImportantOut-of-band0%inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
CVE-2026-59928 ↗2026-07-11azl3 python-mistune 3.3.0-1 on Azure Linux 3.0ImportantOut-of-band0%Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
CVE-2026-60002 ↗2026-07-09azl3 openssh 9.8p1-8 on Azure Linux 3.0ImportantOut-of-band0%ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
CVE-2026-60005 ↗2026-07-19azl3 nginx 1.28.3-6 on Azure Linux 3.0ImportantOut-of-band1%NGINX ngx_http_slice_module vulnerability
CVE-2026-60081 ↗2026-07-17azl3 perl-DBI 1.643-5 on Azure Linux 3.0ImportantOut-of-bandDBI::ProfileData versions before 1.651 for Perl do not limit the path index
CVE-2026-62309 ↗2026-07-18azl3 coredns 1.11.4-17 on Azure Linux 3.0ImportantOut-of-bandCoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — single 28-byte packet remote DoS
CVE-2026-62389 ↗2026-07-19azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-band0%ws < 8.21.1 Default maxFragments Allows Memory Exhaustion DoS
CVE-2026-62826 ↗2026-07-16Microsoft SharePoint Enterprise Server 2016ImportantOut-of-band0%KB5002882KB5002883
and 1 moreKB5002891
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-63793 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandntfs: serialize volume label accesses
CVE-2026-63794 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandKVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path
CVE-2026-63796 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandocfs2: reject oversized group bitmap descriptors
CVE-2026-63801 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandtipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
CVE-2026-63802 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandblk-cgroup: fix UAF in __blkcg_rstat_flush()
CVE-2026-63803 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandhdlc_ppp: sync per-proto timers before freeing hdlc state
CVE-2026-63804 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandgfs2: fix use-after-free in gfs2_qd_dealloc
CVE-2026-63805 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandcrypto: nx - fix nx_crypto_ctx_exit argument
CVE-2026-63806 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandKVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()
CVE-2026-63807 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandKVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level
CVE-2026-63808 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandexfat: fix potential use-after-free in exfat_find_dir_entry()
CVE-2026-63810 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandblock: Avoid mounting the bdev pseudo-filesystem in userspace
CVE-2026-63817 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandf2fs: validate compress cache inode only when enabled
CVE-2026-63823 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandkeys: Pin request_key_auth payload in instantiate paths
CVE-2026-63826 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandfbdev: fix use-after-free in store_modes()
CVE-2026-63829 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandnet: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-63831 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandmac802154: llsec: add skb_cow_data() before in-place crypto
CVE-2026-63832 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: mt76: add wcid publish check in mt76_sta_add
CVE-2026-63836 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandbatman-adv: tp_meter: avoid divide-by-zero for dec_cwnd
CVE-2026-63853 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring
CVE-2026-63858 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandnetfilter: nf_tables: add hook transactions for device deletions
CVE-2026-63872 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandesp: fix page frag reference leak on skb_to_sgvec failure
CVE-2026-63879 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/amdgpu: fix amdgpu_hmm_range_get_pages
CVE-2026-63940 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%KVM: SEV: Ignore Port I/O requests of length '0'
CVE-2026-63961 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandusb: typec: altmodes/displayport: validate count before reading Status Update VDO
CVE-2026-63963 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandusb: typec: tcpm: validate VDO count in Discover Identity ACK handlers
CVE-2026-63978 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band1%net/handshake: Drain pending requests at net namespace exit
CVE-2026-64015 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandsecurity/keys: fix missed RCU read section on lookup
CVE-2026-64112 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%rbd: eliminate a race in lock_dwork draining on unmap
CVE-2026-64117 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb
CVE-2026-64133 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%ALSA: asihpi: Fix potential OOB array access at reading cache
CVE-2026-64146 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-banderofs: fix metabuf leak in inode xattr initialization
CVE-2026-64154 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/msm/adreno: Fix a reference leak in a6xx_gpu_init()
CVE-2026-64189 ↗2026-07-22azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandnetfilter: ipset: fix race between dump and ip_set_list resize
CVE-2026-64191 ↗2026-07-22azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandi2c: stub: Reject I2C block transfers with invalid length
CVE-2026-64192 ↗2026-07-22azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandbpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
CVE-2026-64600 ↗2026-07-24azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandxfs: resample the data fork mapping after cycling ILOCK
CVE-2026-8286 ↗2026-07-04azl3 curl 8.11.1-9 on Azure Linux 3.0ImportantOut-of-bandwrong STARTTLS connection reuse
CVE-2026-8924 ↗2026-07-04azl3 curl 8.11.1-9 on Azure Linux 3.0ImportantOut-of-band1%trailing dot domain super cookie
CVE-2026-8932 ↗2026-07-04azl3 cmake 3.30.3-14 on Azure Linux 3.0ImportantOut-of-bandincomplete mTLS config matching in conn reuse
CVE-2026-9079 ↗2026-07-04azl3 curl 8.11.1-9 on Azure Linux 3.0ImportantOut-of-band1%stale proxy password leak
CVE-2026-9545 ↗2026-07-04azl3 curl 8.11.1-9 on Azure Linux 3.0ImportantOut-of-bandexposing HTTP/3 early data
CVE-2026-10536 ↗2026-07-04azl3 rust 1.75.0-30 on Azure Linux 3.0ModerateOut-of-band1%HTTP/2 stream-dependency tree UAF
CVE-2026-11856 ↗2026-07-04azl3 curl 8.11.1-9 on Azure Linux 3.0ModerateOut-of-band1%cross-origin Digest auth state leak
CVE-2026-12080 ↗2026-07-23azl3 qemu 9.1.0-10 on Azure Linux 3.0ModerateOut-of-band0%Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys
CVE-2026-12480 ↗2026-07-07azl3 keras 3.3.3-7 on Azure Linux 3.0ModerateOut-of-bandArbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/keras
CVE-2026-13221 ↗2026-07-15azl3 perl 5.38.2-512 on Azure Linux 3.0ModerateOut-of-band0%Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk
CVE-2026-14258 ↗2026-07-03azl3 dhcpcd 10.0.8-2 on Azure Linux 3.0ModerateOut-of-bandDhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling
CVE-2026-14355 ↗2026-07-05azl3 openssl 3.3.7-3 on Azure Linux 3.0ModerateOut-of-bandext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD
CVE-2026-14461 ↗2026-07-11azl3 mtr 0.95-3 on Azure Linux 3.0ModerateOut-of-bandOut-of-bound read in mtr
CVE-2026-14586 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0ModerateOut-of-bandAssertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments
CVE-2026-15588 ↗2026-07-23azl3 glib 2.78.6-9 on Azure Linux 3.0ModerateOut-of-bandGdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering
CVE-2026-15712 ↗2026-07-17azl3 libsoup 3.4.4-16 on Azure Linux 3.0ModerateOut-of-bandSoupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over-read via invalid nul-termination assumption
CVE-2026-15713 ↗2026-07-17azl3 libsoup 3.4.4-16 on Azure Linux 3.0ModerateOut-of-bandLibsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via memory leak
CVE-2026-15714 ↗2026-07-17azl3 libsoup 3.4.4-16 on Azure Linux 3.0ModerateOut-of-bandLibsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary string
CVE-2026-15788 ↗2026-07-23azl3 moby-engine 25.0.3-18 on Azure Linux 3.0ModerateOut-of-bandWCOW cache mount source selector resolves NTFS junctions outside of cache root
CVE-2026-16277 ↗2026-07-23azl3 rpcbind 1.2.6-1 on Azure Linux 3.0ModerateOut-of-bandRpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()
CVE-2026-26081 ↗2026-07-23azl3 haproxy 2.9.11-7 on Azure Linux 3.0ModerateOut-of-bandHAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.
CVE-2026-26197 ↗2026-07-22azl3 hdf5 1.14.6-2 on Azure Linux 3.0ModerateOut-of-bandArray full size, element count, and element size are not checked to make sure they match in H5Odtype.c
CVE-2026-26199 ↗2026-07-22azl3 hdf5 1.14.6-2 on Azure Linux 3.0ModerateOut-of-bandBuffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero
CVE-2026-32665 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0ModerateOut-of-band0%Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass
CVE-2026-38753 ↗2026-07-21azl3 busybox 1.36.1-24 on Azure Linux 3.0ModerateOut-of-bandA use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
CVE-2026-38969 ↗2026-07-09azl3 ruby 3.3.5-8 on Azure Linux 3.0ModerateOut-of-bandruby webrick through v1.9.2 WEBrick reparses trailer Content-Length into canonical request state, enabling request smuggling.
CVE-2026-40467 ↗2026-07-14azl3 gawk 5.2.2-1 on Azure Linux 3.0ModerateUse after free in gawk
CVE-2026-40469 ↗2026-07-14azl3 gawk 5.2.2-1 on Azure Linux 3.0ModerateHeap buffer overflow in gawk
CVE-2026-40553 ↗2026-07-14azl3 gawk 5.2.2-1 on Azure Linux 3.0ModerateStack-based buffer overflow in gawk
CVE-2026-40691 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0ModerateOut-of-band0%Packet of death for DNSCrypt over TCP
CVE-2026-42505 ↗2026-07-15azl3 golang 1.25.11-3 on Azure Linux 3.0ModerateOut-of-bandInvoking Encrypted Client Hello privacy leak in crypto/tls
CVE-2026-44508 ↗2026-07-23azl3 rsync 3.4.3-1 on Azure Linux 3.0ModerateOut-of-bandRejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate.
CVE-2026-44509 ↗2026-07-23azl3 rsync 3.4.3-1 on Azure Linux 3.0ModerateOut-of-bandRejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate.
CVE-2026-44510 ↗2026-07-23azl3 rsync 3.4.3-1 on Azure Linux 3.0ModerateOut-of-bandRejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate.
CVE-2026-44621 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0ModerateOut-of-bandLibunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated
CVE-2026-44690 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0ModerateOut-of-band0%Cross-zone wildcard cache poisoning via RRSIG.labels manipulation
CVE-2026-45488 ↗2026-07-03Microsoft Edge (Chromium-based)ModerateOut-of-band0%Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-45489 ↗2026-07-03Microsoft Edge (Chromium-based)ModerateOut-of-band0%Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-45784 ↗2026-07-19azl3 rpm-ostree 2024.4-11 on Azure Linux 3.0ModerateOut-of-bandrust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
CVE-2026-47729 ↗2026-07-18azl3 squid 6.13-4 on Azure Linux 3.0ModerateOut-of-bandSquid: Memory disclosure in FTP gateway
CVE-2026-49090 ↗2026-07-03azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandUncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
CVE-2026-50012 ↗2026-07-18azl3 squid 6.13-4 on Azure Linux 3.0ModerateOut-of-bandSquid: Memory corruption in cache_digest reply handling
CVE-2026-50045 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0ModerateOut-of-band'max-global-quota' reset by DNSSEC validation restarts
CVE-2026-50046 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0ModerateOut-of-bandPossible heap use-after-free in an error path when a DoT forwarded query is jostled out
CVE-2026-50243 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0ModerateOut-of-band'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL
CVE-2026-50248 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0ModerateOut-of-bandBOGUS configured primary hostname accepted for XFR in auth/rpz zones
CVE-2026-50251 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0ModerateOut-of-bandAttacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush
CVE-2026-50252 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0ModerateOut-of-bandPossible cache poisoning attack by mapping source port population per thread
CVE-2026-52863 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0ModerateOut-of-bandMemory corruption could lead to crash and denial of service
CVE-2026-53327 ↗2026-07-02azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-banddebugobjects: Do not fill_pool() if pi_blocked_on
CVE-2026-53332 ↗2026-07-02azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandslimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd
CVE-2026-53336 ↗2026-07-02azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnvmem: layouts: onie-tlv: fix hang on unknown types
CVE-2026-53337 ↗2026-07-02azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: bonding: fix NULL pointer dereference in bond_do_ioctl()
CVE-2026-53339 ↗2026-07-02azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandi2c: qcom-cci: Fix NULL pointer dereference in cci_remove()
CVE-2026-53345 ↗2026-07-02azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying
CVE-2026-53347 ↗2026-07-02azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/virtio: Fix driver removal with disabled KMS
CVE-2026-53349 ↗2026-07-02azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nf_conntrack: destroy stale expectfn expectations on unregister
CVE-2026-53352 ↗2026-07-02azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandsignal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads()
CVE-2026-53353 ↗2026-07-02azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandhsr: Remove WARN_ONCE() in hsr_addr_is_self().
CVE-2026-53355 ↗2026-07-02azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: rds: clear i_sends on setup unwind
CVE-2026-53357 ↗2026-07-03azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()
CVE-2026-53361 ↗2026-07-05azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandaf_unix: Set gc_in_progress to true in unix_gc().
CVE-2026-53377 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/msm: always recover the gpu
CVE-2026-53382 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandmedia: vidtv: fix NULL pointer dereference in vidtv_mux_push_si
CVE-2026-53385 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandvc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write
CVE-2026-53391 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
CVE-2026-53392 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandNFSv4/flexfiles: reject zero filehandle version count
CVE-2026-53393 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandnfsd: reset write verifier on deferred writeback errors
CVE-2026-53397 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandnfsd: fix posix_acl leak on SETACL decode failure
CVE-2026-53398 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNFSD: Fix SECINFO_NO_NAME decode error cleanup
CVE-2026-53399 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandnfsd: release layout stid on setlease failure
CVE-2026-54171 ↗2026-07-19azl3 rubygem-excon 0.102.0-1 on Azure Linux 3.0ModerateOut-of-bandExcon: redact additional sensitive/risky headers when following redirects
CVE-2026-54886 ↗2026-07-07azl3 erlang 26.2.5.21-2 on Azure Linux 3.0ModerateOut-of-bandSSH SFTP server denial of service via extended channel data infinite loop
CVE-2026-54891 ↗2026-07-07azl3 erlang 26.2.5.21-2 on Azure Linux 3.0ModerateOut-of-bandPlaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl
CVE-2026-54908 ↗2026-07-09azl3 telegraf 1.31.0-23 on Azure Linux 3.0ModerateOut-of-bandPion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
CVE-2026-55145 ↗2026-07-14Microsoft CopilotModerate0%Outlook Copilot Tampering Vulnerability
CVE-2026-55717 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0ModerateOut-of-band'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash
CVE-2026-55945 ↗2026-07-03Microsoft Edge (Chromium-based)ModerateOut-of-band0%Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-55973 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0ModerateOut-of-band0%'dns-error-reporting: yes' leads to stack buffer overflow
CVE-2026-55990 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0ModerateOut-of-bandPacket of death for a DNSCrypt misconfigured Unbound
CVE-2026-55991 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0ModerateOut-of-bandRemote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
CVE-2026-56145 ↗2026-07-23azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandUncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
CVE-2026-56149 ↗2026-07-03azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandAllocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service
CVE-2026-56181 ↗2026-07-14Windows Server 2025 (Server Core installation)Moderate0%KB5099536KB5101649
and 1 moreKB5101650
Windows Network Address Translation (NAT) Spoofing Vulnerability
CVE-2026-56288 ↗2026-07-10azl3 kpatch 0.9.8-3 on Azure Linux 3.0ModerateOut-of-bandNULL Pointer Dereference in GNU patch
CVE-2026-56289 ↗2026-07-10azl3 kpatch 0.9.8-3 on Azure Linux 3.0ModerateOut-of-bandLoop with Unreachable Exit Condition in GNU patch
CVE-2026-56416 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0ModerateOut-of-bandPossible heap buffer overflow when validator canonicalizes RDATA that contains domain name
CVE-2026-56444 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0ModerateOut-of-bandDegradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration
CVE-2026-57211 ↗2026-07-15azl3 rabbitmq-server 3.13.7-6 on Azure Linux 3.0ModerateOut-of-bandRabbitMQ: UNC SSRF affecting the management UI on Windows
CVE-2026-57213 ↗2026-07-15azl3 rabbitmq-server 3.13.7-6 on Azure Linux 3.0ModerateOut-of-bandRabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering
CVE-2026-57216 ↗2026-07-15azl3 rabbitmq-server 3.13.7-6 on Azure Linux 3.0ModerateOut-of-bandRabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks
CVE-2026-58208 ↗2026-07-11azl3 telegraf 1.31.0-23 on Azure Linux 3.0ModerateOut-of-bandNATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled
CVE-2026-58209 ↗2026-07-11azl3 telegraf 1.31.0-23 on Azure Linux 3.0ModerateOut-of-bandNATS Server: MQTT retained and QoS replay bypass subscribe deny filters
CVE-2026-58250 ↗2026-07-11azl3 telegraf 1.31.0-23 on Azure Linux 3.0ModerateOut-of-bandNATS Server: Pre-auth server crash via double INFO in leafnode handshake
CVE-2026-58251 ↗2026-07-11azl3 telegraf 1.31.0-23 on Azure Linux 3.0ModerateOut-of-bandNATS Server: Queue Subscribe Authz Bypass
CVE-2026-58252 ↗2026-07-11azl3 telegraf 1.31.0-23 on Azure Linux 3.0ModerateOut-of-bandNATS Server: Subscribe Authz Bypass via Wildcard-Overlap
CVE-2026-59676 ↗2026-07-24azl3 checkpolicy 3.6-1 on Azure Linux 3.0ModerateOut-of-bandLocal File Deletion Attack Vector in rm_rf() in seunshare
CVE-2026-59677 ↗2026-07-24azl3 checkpolicy 3.6-1 on Azure Linux 3.0ModerateOut-of-bandProcess Kill Attack Vector in killall() in seunshare
CVE-2026-59818 ↗2026-07-10azl3 etcd 3.5.30-2 on Azure Linux 3.0ModerateOut-of-bandetcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation
CVE-2026-59831 ↗2026-07-15azl3 gh 2.62.0-18 on Azure Linux 3.0ModerateOut-of-bandGitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace
CVE-2026-59871 ↗2026-07-12azl3 tar 1.35-2 on Azure Linux 3.0ModerateOut-of-bandnode-tar: Process crash via PAX numeric path type confusion
CVE-2026-59875 ↗2026-07-15azl3 tar 1.35-2 on Azure Linux 3.0ModerateOut-of-bandnode-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
CVE-2026-59890 ↗2026-07-11azl3 python-pip 24.2-9 on Azure Linux 3.0ModerateOut-of-bandsetuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
CVE-2026-59926 ↗2026-07-11azl3 python-mistune 3.3.0-1 on Azure Linux 3.0ModerateOut-of-bandMistune: XSS via unescaped class option in Admonition directive
CVE-2026-59930 ↗2026-07-11azl3 python-mistune 3.3.0-1 on Azure Linux 3.0ModerateOut-of-bandMistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content
CVE-2026-59995 ↗2026-07-09azl3 openssh 9.8p1-8 on Azure Linux 3.0ModerateOut-of-bandsftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
CVE-2026-59996 ↗2026-07-09azl3 openssh 9.8p1-8 on Azure Linux 3.0ModerateOut-of-bandscp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
CVE-2026-59997 ↗2026-07-09azl3 openssh 9.8p1-8 on Azure Linux 3.0ModerateOut-of-bandinternal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.
CVE-2026-59998 ↗2026-07-11azl3 openssh 9.8p1-8 on Azure Linux 3.0ModerateOut-of-bandsshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
CVE-2026-59999 ↗2026-07-09azl3 openssh 9.8p1-8 on Azure Linux 3.0ModerateOut-of-bandIn sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
CVE-2026-60001 ↗2026-07-09azl3 openssh 9.8p1-8 on Azure Linux 3.0ModerateOut-of-bandsshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
CVE-2026-62299 ↗2026-07-18azl3 coredns 1.11.4-17 on Azure Linux 3.0ModerateOut-of-bandCoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record
CVE-2026-63136 ↗2026-07-23azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandUncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
CVE-2026-63140 ↗2026-07-23azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandReachable Assertion in Elasticsearch Leading to Denial of Service
CVE-2026-63263 ↗2026-07-23azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandUncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
CVE-2026-63308 ↗2026-07-23azl3 cert-manager 1.12.15-9 on Azure Linux 3.0ModerateOut-of-bandHelm Files.Lines Denial of Service via Empty Chart Files
CVE-2026-63795 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-band9p: avoid putting oldfid in p9_client_walk() error path
CVE-2026-63798 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandirqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove
CVE-2026-63809 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: use kvfree() for replaced sysctl write buffer
CVE-2026-63811 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandf2fs: read COW data with the original inode during atomic write
CVE-2026-63812 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()
CVE-2026-63815 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandf2fs: bound i_inline_xattr_size for non-inline-xattr inodes
CVE-2026-63819 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix to do sanity check on f2fs_get_node_folio_ra()
CVE-2026-63821 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: rtw88: usb: fix memory leaks on USB write failures
CVE-2026-63825 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandgcov: use atomic counter updates to fix concurrent access crashes
CVE-2026-63830 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: skmsg: preserve sg.copy across SG transforms
CVE-2026-63834 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandbatman-adv: tp_meter: restrict number of unacked list entries
CVE-2026-63835 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandbatman-adv: v: prevent OGM aggregation on disabled hardif
CVE-2026-63871 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls
CVE-2026-63954 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandhpfs: fix a crash if hpfs_map_dnode_bitmap fails
CVE-2026-63960 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer()
CVE-2026-63962 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()
CVE-2026-63964 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: typec: ucsi: ccg: reject firmware images without a ':' record header
CVE-2026-64001 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: pcm: oss: Fix setup list UAF on proc write error
CVE-2026-64036 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandcgroup/rstat: validate cpu before css_rstat_cpu() access
CVE-2026-64038 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandhwmon: (lm90) Stop work before releasing hwmon device
CVE-2026-64060 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfs: Fix leak of request in netfs_write_begin() error handling
CVE-2026-64077 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: ebtables: move to two-stage removal scheme
CVE-2026-64082 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandriscv: Fix register corruption from uninitialized cregs on error
CVE-2026-64097 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Validate GPIO pin LUT table size before iterating
CVE-2026-64160 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-band0%netfs: Fix potential for tearing in ->remote_i_size and ->zero_point
CVE-2026-64187 ↗2026-07-22azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandxfs: fail recovery on a committed log item with no regions
CVE-2026-64188 ↗2026-07-22azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
CVE-2026-64190 ↗2026-07-22azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: team: fix NULL pointer dereference in team_xmit during mode change
CVE-2026-64205 ↗2026-07-22azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandi2c: i801: fix hardware state machine corruption in error path
CVE-2026-64206 ↗2026-07-22azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: L2CAP: cancel pending_rx_work before taking conn->lock
CVE-2026-8458 ↗2026-07-04azl3 curl 8.11.1-9 on Azure Linux 3.0ModerateOut-of-bandwrong reuse for different services
CVE-2026-8925 ↗2026-07-04azl3 mysql 8.0.46-1 on Azure Linux 3.0ModerateOut-of-band1%SASL double-free
CVE-2026-8927 ↗2026-07-04azl3 cmake 3.30.3-14 on Azure Linux 3.0ModerateOut-of-band0%env-set cross-proxy Digest auth state leak
CVE-2026-14647 ↗2026-07-07azl3 pytorch 2.2.2-15 on Azure Linux 3.0LowOut-of-bandonnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-bounds
CVE-2026-15028 ↗2026-07-15azl3 cmake 3.30.3-14 on Azure Linux 3.0LowOut-of-bandLibarchive: heap overflow oob read while parsing a tar archive contains a pax extended header
CVE-2026-26080 ↗2026-07-23azl3 haproxy 2.9.11-7 on Azure Linux 3.0LowOut-of-bandHAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.
CVE-2026-38752 ↗2026-07-21azl3 busybox 1.36.1-24 on Azure Linux 3.0LowOut-of-band0%A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
CVE-2026-40468 ↗2026-07-14azl3 gawk 5.2.2-1 on Azure Linux 3.0LowHeap buffer overflow in gawk
CVE-2026-41579 ↗2026-07-02azl3 runc 1.3.3-2 on Azure Linux 3.0LowOut-of-bandrunc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
CVE-2026-41637 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0LowOut-of-bandDegradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries
CVE-2026-42955 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0LowOut-of-bandExtra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records
CVE-2026-44687 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0LowOut-of-bandOff-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN
CVE-2026-46582 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0LowOut-of-bandA wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path
CVE-2026-53910 ↗2026-07-23azl3 diffutils 3.10-1 on Azure Linux 3.0LowOut-of-bandHeap-based Buffer Overflow in GNU diffutils
CVE-2026-54478 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0LowOut-of-bandDNS Cookie bypass when combined with proxy-protocol use
CVE-2026-55708 ↗2026-07-23azl3 unbound 1.25.1-1 on Azure Linux 3.0LowOut-of-bandPrivacy/configuration issue when adding local data in views through 'unbound-control'
CVE-2026-58597 ↗2026-07-03Microsoft Edge (Chromium-based)LowOut-of-band0%Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-60000 ↗2026-07-09azl3 openssh 9.8p1-8 on Azure Linux 3.0LowOut-of-bandsshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.
CVE-2026-62994 ↗2026-07-23azl3 coredns 1.11.4-17 on Azure Linux 3.0LowOut-of-bandCoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin
CVE-2026-9080 ↗2026-07-04azl3 mysql 8.0.46-1 on Azure Linux 3.0LowOut-of-bandUAF after pause in socket callback
CVE-2026-13774 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13774 Use after free in Extensions
CVE-2026-13775 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13775 Use after free in GPU
CVE-2026-13776 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13776 Type Confusion in Dawn
CVE-2026-13777 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13777 Insufficient validation of untrusted input in iOSWeb
CVE-2026-13778 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13778 Use after free in WebUSB
CVE-2026-13779 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13779 Use after free in Chromoting
CVE-2026-13780 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13780 Insufficient validation of untrusted input in ANGLE
CVE-2026-13781 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13781 Insufficient validation of untrusted input in Skia
CVE-2026-13782 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13782 Use after free in Browser
CVE-2026-13783 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13783 Use after free in Views
CVE-2026-13784 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13784 Use after free in Views
CVE-2026-13785 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13785 Use after free in Bluetooth
CVE-2026-13786 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13786 Use after free in Ozone
CVE-2026-13787 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13787 Use after free in Chromoting
CVE-2026-13788 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13788 Use after free in Fullscreen
CVE-2026-13790 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13790 Side-channel information leakage in Scroll
CVE-2026-13791 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13791 Insufficient validation of untrusted input in Downloads
CVE-2026-13792 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13792 Use after free in Touchbar
CVE-2026-13793 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13793 Insufficient policy enforcement in SVG
CVE-2026-13794 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13794 Insufficient validation of untrusted input in WebAppInstalls
CVE-2026-13795 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13795 Insufficient policy enforcement in Chrome for iOS
CVE-2026-13796 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13796 Integer overflow in Chromecast
CVE-2026-13797 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13797 Insufficient validation of untrusted input in Chromecast
CVE-2026-13798 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13798 Heap buffer overflow in Chromecast
CVE-2026-13799 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13799 Use after free in QUIC
CVE-2026-13800 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13800 Inappropriate implementation in Updater
CVE-2026-13801 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13801 Integer overflow in Chromecast
CVE-2026-13802 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13802 Use after free in Views
CVE-2026-13803 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13803 Type Confusion in Chrome Tabs
CVE-2026-13804 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13804 Use after free in Chromecast
CVE-2026-13805 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13805 Use after free in GFX
CVE-2026-13806 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13806 Insufficient validation of untrusted input in Accessibility
CVE-2026-13807 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13807 Use after free in Import
CVE-2026-13808 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13808 Insufficient data validation in Chrome for iOS
CVE-2026-13809 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13809 Side-channel information leakage in Safe Browsing
CVE-2026-13810 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13810 Inappropriate implementation in Input
CVE-2026-13811 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13811 Use after free in IME
CVE-2026-13812 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13812 Insufficient validation of untrusted input in Chrome for iOS
CVE-2026-13813 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13813 Insufficient validation of untrusted input in Chrome for iOS
CVE-2026-13814 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13814 Use after free in Views
CVE-2026-13815 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13815 Use after free in Blink
CVE-2026-13816 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13816 Insufficient validation of untrusted input in File Input
CVE-2026-13817 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13817 Insufficient validation of untrusted input in Glic
CVE-2026-13818 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13818 Inappropriate implementation in Passwords
CVE-2026-13819 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13819 Out of bounds read in ANGLE
CVE-2026-13820 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13820 Out of bounds read in Skia
CVE-2026-13821 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13821 Use after free in Canvas
CVE-2026-13822 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13822 Inappropriate implementation in Extensions
CVE-2026-13823 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13823 Use after free in Glic
CVE-2026-13824 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13824 Insufficient validation of untrusted input in Extensions
CVE-2026-13825 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13825 Uninitialized Use in Dawn
CVE-2026-13826 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13826 Inappropriate implementation in Autofill
CVE-2026-13827 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13827 Use after free in Updater
CVE-2026-13828 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13828 Inappropriate implementation in Enterprise
CVE-2026-13829 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13829 Insufficient validation of untrusted input in Settings
CVE-2026-13830 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13830 Use after free in Chromoting
CVE-2026-13831 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13831 Use after free in GPU
CVE-2026-13832 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13832 Use after free in Headless
CVE-2026-13833 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13833 Uninitialized Use in ANGLE
CVE-2026-13834 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13834 Insufficient validation of untrusted input in ANGLE
CVE-2026-13835 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13835 Inappropriate implementation in XML
CVE-2026-13836 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13836 Inappropriate implementation in CSS
CVE-2026-13837 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13837 Inappropriate implementation in CSS
CVE-2026-13838 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13838 Inappropriate implementation in CSS
CVE-2026-13839 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13839 Inappropriate implementation in CSS
CVE-2026-13840 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13840 Insufficient policy enforcement in Canvas
CVE-2026-13841 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13841 Integer overflow in Skia
CVE-2026-13842 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13842 Incorrect security UI in Chrome for iOS
CVE-2026-13843 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13843 Insufficient validation of untrusted input in Chrome for iOS
CVE-2026-13844 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13844 Use after free in Updater
CVE-2026-13845 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13845 Use after free in DOM
CVE-2026-13846 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13846 Use after free in USB
CVE-2026-13847 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13847 Insufficient validation of untrusted input in Chrome for iOS
CVE-2026-13848 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13848 Use after free in Forms
CVE-2026-13849 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13849 Insufficient validation of untrusted input in Chromoting
CVE-2026-13850 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13850 Insufficient validation of untrusted input in Chrome for iOS
CVE-2026-13851 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13851 Insufficient validation of untrusted input in WebAppInstalls
CVE-2026-13852 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13852 Insufficient validation of untrusted input in WebAppInstalls
CVE-2026-13853 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13853 Use after free in Journeys
CVE-2026-13854 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13854 Use after free in Ozone
CVE-2026-13855 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13855 Use after free in Ozone
CVE-2026-13856 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13856 Insufficient validation of untrusted input in Speech
CVE-2026-13857 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13857 Inappropriate implementation in Geometry
CVE-2026-13858 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13858 Out of bounds read in FFmpeg
CVE-2026-13859 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13859 Inappropriate implementation in ANGLE
CVE-2026-13860 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13860 Incorrect security UI in Autofill
CVE-2026-13861 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13861 Use after free in Core
CVE-2026-13862 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%CVE-2026-13862
CVE-2026-13863 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13863 Insufficient validation of untrusted input in CustomTabs
CVE-2026-13864 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13864 Insufficient policy enforcement in WebHID
CVE-2026-13865 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13865 Insufficient validation of untrusted input in Enterprise
CVE-2026-13866 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13866 Insufficient validation of untrusted input in Input
CVE-2026-13867 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13867 Inappropriate implementation in Geolocation
CVE-2026-13868 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13868 Inappropriate implementation in Network
CVE-2026-13869 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13869 Use after free in Device
CVE-2026-13870 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13870 Use after free in WebView
CVE-2026-13871 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13871 Insufficient data validation in GuestView
CVE-2026-13872 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13872 Insufficient validation of untrusted input in WebAppInstalls
CVE-2026-13873 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13873 Out of bounds memory access in Layout
CVE-2026-13874 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13874 Inappropriate implementation in DataTransfer
CVE-2026-13875 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13875 Insufficient validation of untrusted input in GPU
CVE-2026-13876 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13876 Inappropriate implementation in Network
CVE-2026-13877 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13877 Insufficient validation of untrusted input in ANGLE
CVE-2026-13878 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13878 Use after free in Bluetooth
CVE-2026-13879 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13879 Use after free in Bluetooth
CVE-2026-13880 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13880 Use after free in USB
CVE-2026-13881 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13881 Insufficient data validation in WebAppInstalls
CVE-2026-13882 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13882 Inappropriate implementation in USB
CVE-2026-13883 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13883 Type Confusion in ANGLE
CVE-2026-13884 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13884 Heap buffer overflow in Chromecast
CVE-2026-13885 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13885 Use after free in Skia
CVE-2026-13886 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13886 Policy bypass in Isolated Web Apps
CVE-2026-13887 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13887 Insufficient policy enforcement in NFC
CVE-2026-13888 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13888 Use after free in Extensions
CVE-2026-13889 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13889 Insufficient validation of untrusted input in WebAuthentication
CVE-2026-13890 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13890 Out of bounds read in Chromecast
CVE-2026-13891 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13891 Insufficient validation of untrusted input in Extensions
CVE-2026-13892 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13892 Inappropriate implementation in Chrome for iOS
CVE-2026-13893 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13893 Insufficient validation of untrusted input in WebUI
CVE-2026-13894 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13894 Insufficient policy enforcement in Network
CVE-2026-13895 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13895 Inappropriate implementation in Autofill
CVE-2026-13896 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13896 Insufficient policy enforcement in Glic
CVE-2026-13897 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13897 Insufficient policy enforcement in Chromecast
CVE-2026-13898 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13898 Use after free in Cast Receiver
CVE-2026-13899 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13899 Use after free in HTML
CVE-2026-13900 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13900 Insufficient validation of untrusted input in Chromecast
CVE-2026-13901 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13901 Insufficient validation of untrusted input in Serial
CVE-2026-13902 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13902 Inappropriate implementation in Chrome for iOS
CVE-2026-13903 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13903 Insufficient policy enforcement in Bluetooth
CVE-2026-13904 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13904 Incorrect security UI in Safe Browsing
CVE-2026-13905 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13905 Incorrect security UI in Chrome for iOS
CVE-2026-13906 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13906 Out of bounds read in Codecs
CVE-2026-13907 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13907 Inappropriate implementation in iOSWeb
CVE-2026-13908 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13908 Insufficient validation of untrusted input in Omnibox
CVE-2026-13909 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13909 Insufficient policy enforcement in DevTools
CVE-2026-13910 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13910 Insufficient policy enforcement in WebXR
CVE-2026-13911 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13911 Insufficient data validation in Spellcheck
CVE-2026-13912 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13912 Incorrect security UI in Safe Browsing
CVE-2026-13913 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13913 Insufficient policy enforcement in Autofill
CVE-2026-13914 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13914 Inappropriate implementation in Passwords
CVE-2026-13915 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13915 Use after free in Chrome for iOS
CVE-2026-13916 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13916 Inappropriate implementation in Chrome for iOS
CVE-2026-13917 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13917 Insufficient validation of untrusted input in Chrome for iOS
CVE-2026-13918 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13918 Use after free in Chrome for iOS
CVE-2026-13919 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13919 Insufficient data validation in Extensions
CVE-2026-13920 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13920 Insufficient validation of untrusted input in Media
CVE-2026-13921 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13921 Insufficient validation of untrusted input in DeviceBoundSessionCredentials
CVE-2026-13922 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13922 Side-channel information leakage in Paint
CVE-2026-13923 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13923 Uninitialized Use in GPU
CVE-2026-13924 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13924 Insufficient validation of untrusted input in WebView
CVE-2026-13925 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13925 Inappropriate implementation in Downloads
CVE-2026-13926 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13926 Insufficient validation of untrusted input in Network
CVE-2026-13927 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13927 Insufficient validation of untrusted input in UI
CVE-2026-13928 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13928 Insufficient validation of untrusted input in Enterprise
CVE-2026-13929 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13929 Insufficient validation of untrusted input in DevTools
CVE-2026-13930 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13930 Insufficient policy enforcement in Actor
CVE-2026-13931 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13931 Inappropriate implementation in Media
CVE-2026-13932 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13932 Inappropriate implementation in Sharing
CVE-2026-13933 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13933 Insufficient policy enforcement in Passwords
CVE-2026-13934 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13934 Insufficient validation of untrusted input in Dawn
CVE-2026-13935 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13935 Side-channel information leakage in ComputePressure
CVE-2026-13936 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13936 Inappropriate implementation in Passwords
CVE-2026-13937 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13937 Insufficient policy enforcement in Passwords
CVE-2026-13938 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13938 Integer overflow in Fonts
CVE-2026-13939 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13939 Insufficient validation of untrusted input in WebShare
CVE-2026-13940 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13940 Uninitialized Use in Cast
CVE-2026-13941 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13941 Inappropriate implementation in SiteSettings
CVE-2026-13942 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13942 Insufficient validation of untrusted input in Video Capture
CVE-2026-13943 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13943 Uninitialized Use in CSS
CVE-2026-13944 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13944 Inappropriate implementation in DataTransfer
CVE-2026-13945 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13945 Insufficient policy enforcement in Extensions
CVE-2026-13946 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13946 Inappropriate implementation in ScriptInjections
CVE-2026-13947 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13947 Uninitialized Use in XR
CVE-2026-13948 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13948 Insufficient policy enforcement in Extensions
CVE-2026-13949 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13949 Insufficient policy enforcement in Payments
CVE-2026-13950 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13950 Uninitialized Use in GPU
CVE-2026-13951 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13951 Policy bypass in USB
CVE-2026-13952 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13952 Inappropriate implementation in PerformanceAPIs
CVE-2026-13953 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13953 Inappropriate implementation in SplitView
CVE-2026-13954 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13954 Insufficient policy enforcement in XML
CVE-2026-13955 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13955 Insufficient validation of untrusted input in CustomTabs
CVE-2026-13956 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13956 Incorrect security UI in PageInfo
CVE-2026-13957 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13957 Incorrect security UI in Extensions
CVE-2026-13958 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13958 Uninitialized Use in Codecs
CVE-2026-13959 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13959 Insufficient validation of untrusted input in Blink
CVE-2026-13960 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13960 Inappropriate implementation in Passwords
CVE-2026-13961 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13961 Insufficient validation of untrusted input in DevTools
CVE-2026-13962 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13962 Insufficient data validation in PDF
CVE-2026-13963 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13963 Inappropriate implementation in DevTools
CVE-2026-13964 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13964 Insufficient policy enforcement in WebView
CVE-2026-13965 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13965 Use after free in Oilpan
CVE-2026-13966 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13966 Inappropriate implementation in History
CVE-2026-13967 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13967 Type Confusion in V8
CVE-2026-13968 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13968 Insufficient validation of untrusted input in DevTools
CVE-2026-13969 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13969 Uninitialized Use in UI
CVE-2026-13970 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13970 Uninitialized Use in Media
CVE-2026-13971 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13971 Uninitialized Use in Skia
CVE-2026-13972 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13972 Inappropriate implementation in Paint
CVE-2026-13973 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13973 Inappropriate implementation in UI
CVE-2026-13974 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13974 Integer overflow in Safe Browsing
CVE-2026-13975 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13975 Out of bounds read in ANGLE
CVE-2026-13976 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13976 Heap buffer overflow in Storage
CVE-2026-13977 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13977 Inappropriate implementation in HTMLParser
CVE-2026-13978 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13978 Insufficient policy enforcement in PageInfo
CVE-2026-13979 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13979 Inappropriate implementation in Paint
CVE-2026-13980 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13980 Incorrect security UI in Chrome for iOS
CVE-2026-13981 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13981 Inappropriate implementation in Chrome for iOS
CVE-2026-13982 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13982 Incorrect security UI in Passwords
CVE-2026-13983 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13983 Incorrect security UI in Chrome for iOS
CVE-2026-13984 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13984 Incorrect security UI in TabStrip
CVE-2026-13985 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13985 Inappropriate implementation in MediaCapture
CVE-2026-13986 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13986 Inappropriate implementation in Media UI
CVE-2026-13987 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13987 Incorrect security UI in Mobile
CVE-2026-13988 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13988 Inappropriate implementation in Paint
CVE-2026-13989 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13989 Insufficient policy enforcement in PageInfo
CVE-2026-13990 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13990 Insufficient validation of untrusted input in DataTransfer
CVE-2026-13991 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13991 Insufficient validation of untrusted input in Chrome for iOS
CVE-2026-13992 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13992 Inappropriate implementation in UI
CVE-2026-13993 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13993 Incorrect security UI in WebAppInstalls
CVE-2026-13994 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13994 Inappropriate implementation in Credential Management
CVE-2026-13995 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13995 Insufficient validation of untrusted input in Autofill
CVE-2026-13996 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13996 Incorrect security UI in Permissions
CVE-2026-13997 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13997 Incorrect security UI in Extensions
CVE-2026-13998 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13998 Incorrect security UI in File Input
CVE-2026-13999 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13999 Inappropriate implementation in Extensions
CVE-2026-14000 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14000 Inappropriate implementation in XML
CVE-2026-14001 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14001 Inappropriate implementation in Network
CVE-2026-14002 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14002 Inappropriate implementation in Geolocation
CVE-2026-14003 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14003 Insufficient policy enforcement in Extensions
CVE-2026-14004 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14004 Inappropriate implementation in CSS
CVE-2026-14005 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14005 Use after free in Omnibox
CVE-2026-14006 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14006 Use after free in Navigation
CVE-2026-14007 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14007 Insufficient policy enforcement in PermissionsPolicy
CVE-2026-14008 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14008 Uninitialized Use in WebXR
CVE-2026-14009 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14009 Insufficient data validation in Passwords
CVE-2026-14010 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14010 Uninitialized Use in Codecs
CVE-2026-14011 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14011 Out of bounds read in SurfaceCapture
CVE-2026-14012 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14012 Side-channel information leakage in CSS
CVE-2026-14013 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14013 Inappropriate implementation in SVG
CVE-2026-14014 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14014 Inappropriate implementation in Paint
CVE-2026-14015 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14015 Inappropriate implementation in WebRTC
CVE-2026-14016 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14016 Insufficient policy enforcement in SVG
CVE-2026-14017 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14017 Inappropriate implementation in Navigation
CVE-2026-14018 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14018 Use after free in Updater
CVE-2026-14019 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14019 Inappropriate implementation in Passwords
CVE-2026-14020 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14020 Insufficient validation of untrusted input in WebXR
CVE-2026-14021 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14021 Insufficient validation of untrusted input in StorageAccessAPI
CVE-2026-14022 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14022 Insufficient validation of untrusted input in Network
CVE-2026-14023 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14023 Insufficient validation of untrusted input in SanitizerAPI
CVE-2026-14024 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14024 Use after free in Ozone
CVE-2026-14025 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14025 Use after free in Views
CVE-2026-14026 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14026 Incorrect security UI in SplitView
CVE-2026-14027 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14027 Use after free in SignIn
CVE-2026-14028 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14028 Incorrect security UI in Chrome for iOS
CVE-2026-14030 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14030 Incorrect security UI in SplitView
CVE-2026-14031 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14031 Incorrect security UI in File Input
CVE-2026-14032 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14032 Use after free in Bluetooth
CVE-2026-14033 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14033 Insufficient policy enforcement in Media
CVE-2026-14034 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14034 Inappropriate implementation in WebXR
CVE-2026-14035 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14035 Insufficient policy enforcement in Bluetooth
CVE-2026-14036 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14036 Insufficient policy enforcement in Bluetooth
CVE-2026-14037 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14037 Insufficient policy enforcement in GPU
CVE-2026-14038 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14038 Insufficient validation of untrusted input in New Tab Page
CVE-2026-14039 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14039 Insufficient policy enforcement in GetUserMedia
CVE-2026-14040 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14040 Use after free in BrowserTag
CVE-2026-14041 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14041 Insufficient policy enforcement in Serial
CVE-2026-14042 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14042 Inappropriate implementation in Isolated Web Apps
CVE-2026-14043 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14043 Use after free in GetUserMedia
CVE-2026-14044 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14044 Use after free in ANGLE
CVE-2026-14045 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14045 Insufficient validation of untrusted input in Network
CVE-2026-14046 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14046 Inappropriate implementation in CustomTabs
CVE-2026-14047 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14047 Insufficient policy enforcement in Extensions
CVE-2026-14048 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14048 Use after free in Chromecast
CVE-2026-14049 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14049 Inappropriate implementation in GPU
CVE-2026-14050 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14050 Insufficient policy enforcement in Passwords
CVE-2026-14051 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14051 Uninitialized Use in GamepadAPI
CVE-2026-14052 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14052 Insufficient policy enforcement in FileSystem
CVE-2026-14053 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14053 Insufficient policy enforcement in Extensions
CVE-2026-14054 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14054 Insufficient policy enforcement in Network
CVE-2026-14055 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14055 Insufficient validation of untrusted input in Device Trust
CVE-2026-14056 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14056 Insufficient validation of untrusted input in Media
CVE-2026-14057 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14057 Insufficient policy enforcement in FedCM
CVE-2026-14058 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14058 Policy bypass in Parser
CVE-2026-14059 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14059 Insufficient policy enforcement in Related-Website-Sets
CVE-2026-14060 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14060 Insufficient validation of untrusted input in Chromoting
CVE-2026-14061 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14061 Inappropriate implementation in Dawn
CVE-2026-14062 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14062 Inappropriate implementation in Views
CVE-2026-14063 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14063 Out of bounds memory access in Chromecast
CVE-2026-14064 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14064 Use after free in PageInfo
CVE-2026-14065 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14065 Insufficient validation of untrusted input in PageInfo
CVE-2026-14066 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14066 Insufficient validation of untrusted input in Chrome for iOS
CVE-2026-14067 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14067 Use after free in Chrome for iOS
CVE-2026-14068 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14068 Inappropriate implementation in Omnibox
CVE-2026-14069 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14069 Integer overflow in WebNN
CVE-2026-14070 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14070 Uninitialized Use in WebNN
CVE-2026-14071 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14071 Side-channel information leakage in WebAudio
CVE-2026-14072 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14072 Incorrect security UI in SplitView
CVE-2026-14073 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14073 Insufficient policy enforcement in WebXR
CVE-2026-14074 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14074 Side-channel information leakage in WebAuthentication
CVE-2026-14075 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14075 Policy bypass in Chrome for iOS
CVE-2026-14076 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14076 Policy bypass in Network
CVE-2026-14077 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14077 Incorrect security UI in Select
CVE-2026-14078 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14078 Policy bypass in WebRTC
CVE-2026-14079 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14079 Policy bypass in Network
CVE-2026-14080 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14080 Insufficient validation of untrusted input in TabSwitcher
CVE-2026-14081 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14081 Insufficient policy enforcement in DevTools
CVE-2026-14082 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14082 Race in Storage
CVE-2026-14083 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14083 Insufficient validation of untrusted input in HTML
CVE-2026-14084 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14084 Insufficient validation of untrusted input in Chromoting
CVE-2026-14085 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14085 Side-channel information leakage in CSS
CVE-2026-14086 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14086 Insufficient policy enforcement in HID
CVE-2026-14087 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14087 Insufficient validation of untrusted input in WebNN
CVE-2026-14088 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14088 Uninitialized Use in Canvas
CVE-2026-14089 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14089 Insufficient validation of untrusted input in PopupBlocker
CVE-2026-14090 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14090 Out of bounds read in CameraCapture
CVE-2026-14091 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14091 Use after free in DevTools
CVE-2026-14092 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14092 Insufficient policy enforcement in Privacy
CVE-2026-14093 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14093 Use after free in Cast
CVE-2026-14094 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14094 Use after free in Installer
CVE-2026-14095 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14095 Insufficient validation of untrusted input in Browser
CVE-2026-14096 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14096 Object lifecycle issue in Input
CVE-2026-14097 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14097 Inappropriate implementation in WebAppInstalls
CVE-2026-14098 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14098 Inappropriate implementation in CSS
CVE-2026-14099 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14099 Use after free in Chrome for iOS
CVE-2026-14100 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14100 Insufficient data validation in NetworkCache
CVE-2026-14101 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14101 Insufficient policy enforcement in Sandbox
CVE-2026-14102 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14102 Use after free in Passwords
CVE-2026-14103 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14103 Use after free in SSL
CVE-2026-14104 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14104 Insufficient validation of untrusted input in WebAppInstalls
CVE-2026-14105 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14105 Insufficient policy enforcement in Speech
CVE-2026-14106 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14106 Insufficient validation of untrusted input in Text
CVE-2026-14107 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14107 Use after free in Scheduling
CVE-2026-14108 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14108 Use after free in PDFium
CVE-2026-14109 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14109 Insufficient policy enforcement in Mojo
CVE-2026-14110 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14110 Inappropriate implementation in DarkMode
CVE-2026-14111 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14111 Use after free in WebProtect
CVE-2026-14112 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14112 Inappropriate implementation in Enterprise
CVE-2026-14113 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14113 Use after free in Updater
CVE-2026-14114 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14114 Inappropriate implementation in WebAppInstalls
CVE-2026-14115 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14115 Insufficient validation of untrusted input in Cast
CVE-2026-14116 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14116 Insufficient validation of untrusted input in DevTools
CVE-2026-14117 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14117 Insufficient validation of untrusted input in DevTools
CVE-2026-14118 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14118 Insufficient data validation in DevTools
CVE-2026-14119 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14119 Type Confusion in Bluetooth
CVE-2026-14120 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14120 Inappropriate implementation in DevTools
CVE-2026-14121 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14121 Use after free in Chromoting
CVE-2026-14122 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14122 Insufficient validation of untrusted input in WebAppInstalls
CVE-2026-14123 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14123 Incorrect security UI in Chrome for iOS
CVE-2026-14124 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14124 Inappropriate implementation in CredentialProvider
CVE-2026-14125 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14125 Uninitialized Use in ANGLE
CVE-2026-14126 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14126 Incorrect security UI in UI
CVE-2026-14127 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14127 Inappropriate implementation in Printing
CVE-2026-14128 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14128 Insufficient data validation in Chrome for iOS
CVE-2026-14129 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14129 Incorrect security UI in PreviewTab
CVE-2026-14130 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14130 Incorrect security UI in Omnibox
CVE-2026-14131 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14131 Insufficient validation of untrusted input in WebAppInstalls
CVE-2026-14132 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14132 Inappropriate implementation in WebXR
CVE-2026-14133 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14133 Race in History Embeddings
CVE-2026-14134 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14134 Inappropriate implementation in Autofill
CVE-2026-14135 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14135 Insufficient validation of untrusted input in Network
CVE-2026-14136 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14136 Incorrect security UI in Chrome for iOS
CVE-2026-14137 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14137 Insufficient validation of untrusted input in Chrome for iOS
CVE-2026-14138 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14138 Inappropriate implementation in WebAppInstalls
CVE-2026-14139 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14139 Inappropriate implementation in TabStrip
CVE-2026-14140 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14140 Insufficient validation of untrusted input in Input
CVE-2026-14141 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14141 Incorrect security UI in Document Picture-in-Picture
CVE-2026-14142 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14142 Inappropriate implementation in Extensions
CVE-2026-14143 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14143 Incorrect security UI in Passwords
CVE-2026-14144 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14144 Incorrect security UI in Views
CVE-2026-14145 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14145 Inappropriate implementation in CSS
CVE-2026-14146 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14146 Inappropriate implementation in CSS
CVE-2026-14147 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14147 Inappropriate implementation in CSS
CVE-2026-14148 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14148 Type Confusion in CSS
CVE-2026-14149 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14149 Use after free in Audio
CVE-2026-14150 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14150 Insufficient validation of untrusted input in Speech
CVE-2026-14151 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14151 Inappropriate implementation in AI
CVE-2026-14152 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14152 Out of bounds write in ANGLE
CVE-2026-14153 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14153 Inappropriate implementation in Glic
CVE-2026-14154 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14154 Inappropriate implementation in DevTools
CVE-2026-14155 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14155 Insufficient policy enforcement in StorageAccessAPI
CVE-2026-14156 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14156 Policy bypass in StorageAccessAPI
CVE-2026-14382 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14382 Insufficient validation of untrusted input in ANGLE
CVE-2026-14385 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14385 Heap buffer overflow in ANGLE
CVE-2026-14386 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14386 Out of bounds read in ANGLE
CVE-2026-14388 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14388 Out of bounds read in ANGLE
CVE-2026-14390 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14390 Use after free in ANGLE
CVE-2026-14391 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14391 Integer overflow in ANGLE
CVE-2026-14392 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14392 Out of bounds write in Tint
CVE-2026-14393 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14393 Use after free in V8
CVE-2026-14394 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14394 Use after free in V8
CVE-2026-14395 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14395 Out of bounds write in V8
CVE-2026-14396 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14396 Out of bounds read in ANGLE
CVE-2026-14397 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14397 Out of bounds write in ANGLE
CVE-2026-14398 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14398 Use after free in ANGLE
CVE-2026-14399 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14399 Uninitialized Use in Dawn
CVE-2026-14400 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14400 Out of bounds write in ANGLE
CVE-2026-14401 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14401 Insufficient validation of untrusted input in ANGLE
CVE-2026-14402 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14402 Uninitialized Use in ANGLE
CVE-2026-14403 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14403 Use after free in V8
CVE-2026-14404 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14404 Inappropriate implementation in PDFium
CVE-2026-14405 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14405 Uninitialized Use in V8
CVE-2026-14406 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14406 Out of bounds read in V8
CVE-2026-14407 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14407 Inappropriate implementation in V8
CVE-2026-14408 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14408 Uninitialized Use in Dawn
CVE-2026-14409 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14409 Inappropriate implementation in V8
CVE-2026-14410 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14410 Inappropriate implementation in Skia
CVE-2026-14411 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14411 Insufficient validation of untrusted input in ANGLE
CVE-2026-14412 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14412 Insufficient validation of untrusted input in ANGLE
CVE-2026-14413 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14413 Uninitialized Use in ANGLE
CVE-2026-14414 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14414 Insufficient validation of untrusted input in Skia
CVE-2026-14415 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14415 Inappropriate implementation in V8
CVE-2026-14416 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14416 Out of bounds read in Dawn
CVE-2026-14417 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14417 Use after free in Dawn
CVE-2026-14418 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14418 Uninitialized Use in ANGLE
CVE-2026-14419 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14419 Use after free in Skia
CVE-2026-14420 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14420 Out of bounds read and write in Dawn
CVE-2026-14421 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14421 Uninitialized Use in Dawn
CVE-2026-14422 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14422 Out of bounds read and write in Tint
CVE-2026-14423 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14423 Type Confusion in Tint
CVE-2026-14424 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14424 Use after free in Dawn
CVE-2026-14425 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14425 Use after free in ANGLE
CVE-2026-14426 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14426 Use after free in V8
CVE-2026-14427 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14427 Heap buffer overflow in Skia
CVE-2026-14428 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14428 Insufficient validation of untrusted input in Dawn
CVE-2026-14429 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14429 Insufficient validation of untrusted input in Skia
CVE-2026-14430 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14430 Integer overflow in V8
CVE-2026-14431 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14431 Type Confusion in V8
CVE-2026-14432 ↗2026-07-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14432 Use after free in V8
CVE-2026-15764 ↗2026-07-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15764 Use after free in Ozone
CVE-2026-15765 ↗2026-07-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15765 Use after free in Ozone
CVE-2026-15766 ↗2026-07-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15766 Uninitialized Use in Skia
CVE-2026-15768 ↗2026-07-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15768 Insufficient policy enforcement in HTML-in-Canvas
CVE-2026-15769 ↗2026-07-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15769 Insufficient validation of untrusted input in Linux Toolkit Theming
CVE-2026-15770 ↗2026-07-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15770 Uninitialized Use in V8
CVE-2026-15771 ↗2026-07-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15771 Insufficient validation of untrusted input in Media
CVE-2026-15772 ↗2026-07-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15772 Use after free in GPU
CVE-2026-15773 ↗2026-07-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15773 Use after free in Core
CVE-2026-15774 ↗2026-07-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15774 Use after free in Skia
CVE-2026-15775 ↗2026-07-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15775 Insufficient policy enforcement in V8
CVE-2026-15776 ↗2026-07-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15776 Type Confusion in V8
CVE-2026-15777 ↗2026-07-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15777 Use after free in UI
CVE-2026-15778 ↗2026-07-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15778 Insufficient validation of untrusted input in Navigation
CVE-2026-15899 ↗2026-07-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15899 Use after free in CameraCapture
CVE-2026-15900 ↗2026-07-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15900 Use after free in GPU
CVE-2026-15901 ↗2026-07-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15901 Use after free in Network
CVE-2026-15902 ↗2026-07-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15902 Use after free in Cast
CVE-2026-15903 ↗2026-07-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15903 Out of bounds read and write in V8
CVE-2026-15904 ↗2026-07-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15904 Use after free in Ozone
CVE-2026-15905 ↗2026-07-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-15905 Use after free in Aura
CVE-2026-16413 ↗2026-07-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-16413 Out of bounds write in ANGLE
CVE-2026-16414 ↗2026-07-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-16414 Insufficient validation of untrusted input in Chromecast
CVE-2026-16415 ↗2026-07-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-16415 Insufficient validation of untrusted input in Extensions
CVE-2026-16416 ↗2026-07-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-16416 Integer overflow in Chromecast
CVE-2026-16417 ↗2026-07-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-16417 Uninitialized Use in Skia
CVE-2026-16418 ↗2026-07-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-16418 Stack buffer overflow in V8
CVE-2026-16419 ↗2026-07-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-16419 Out of bounds read and write in ANGLE
CVE-2026-16420 ↗2026-07-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-16420 Type Confusion in WebAudio
CVE-2026-16421 ↗2026-07-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-16421 Inappropriate implementation in WebAudio
CVE-2026-16422 ↗2026-07-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-16422 Insufficient validation of untrusted input in Certificate
CVE-2026-16423 ↗2026-07-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-16423 Use after free in UI
CVE-2026-16424 ↗2026-07-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-16424 Use after free in GPU
CVE-2026-16804 ↗2026-07-25Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-16804 Use after free in Input
CVE-2026-16805 ↗2026-07-25Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-16805 Use after free in Blink
CVE-2026-16806 ↗2026-07-25Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-16806 Use after free in WebMCP
CVE-2026-16807 ↗2026-07-25Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-16807 Out of bounds write in Codecs
#

June 2026

Patch Tuesday June 9, 2026765 CVEs plus 517 Azure Linux package advisories · 50 critical · 0 exploitation detected · 1 in KEV1282 CVEs · 89 critical · 0 exploitation detected · 1 in KEV · includes 517 Azure Linux package advisories
Risk matrix, June 2026
540 of these counts use a severity derived from CVSS because Microsoft assigned none.
540 of these counts use a severity derived from CVSS because Microsoft assigned none.
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2025-10263 ↗2026-06-09Windows 11 Version 26H1 for ARM64-based SystemsCritical1%KB5093998KB5094126
and 2 moreKB5094127KB5095051
ARM: CVE-2025-10263 Completion of affected memory accesses might not be guaranteed by completion of a TLBI [kernel]
CVE-2026-26142 ↗2026-06-09Nuance PowerScribe 360 version 4.0.5Critical2%Nuance PowerScribe Remote Code Execution Vulnerability
CVE-2026-32174 ↗2026-06-18Azure AI Bot ServiceCriticalOut-of-band0%Azure Bot Service Elevation of Privilege Vulnerability
CVE-2026-32193 ↗2026-06-09Azure Kubernetes ServiceCritical0%Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability
CVE-2026-32208 ↗2026-06-18Microsoft Edge (Chromium-based)CriticalOut-of-band1%Microsoft Entra ID Spoofing Vulnerability
CVE-2026-33828 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5093998KB5094122
and 6 moreKB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability
CVE-2026-34182 ↗2026-06-13azl3 cloud-hypervisor 51.1.56-1 on Azure Linux 3.0CriticalOut-of-bandCMS AuthEnvelopedData Processing May Accept Forged Messages
CVE-2026-42824 ↗2026-06-04Microsoft 365 CopilotCriticalOut-of-band8%M365 Copilot Information Disclosure Vulnerability
CVE-2026-42895 ↗2026-06-18Microsoft 365 CopilotCriticalOut-of-band0%Microsoft Copilot Tampering Vulnerability
CVE-2026-42985 ↗2026-06-09Windows App Client for Windows DesktopCritical1%More likelyKB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-42987 ↗2026-06-09Windows Server 2019Critical1%KB5094041KB5094042
and 4 moreKB5094122KB5094123KB5094125KB5094128
Windows Deployment Services (WDS) Remote Code Execution
CVE-2026-42992 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5093998KB5094122
and 6 moreKB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-44799 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-44801 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-44803 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsCritical1%More likelyKB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-44810 ↗2026-06-09Windows Server 2022Critical0%KB5093998KB5094125
and 3 moreKB5094126KB5094128KB5095051
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
CVE-2026-44812 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsCritical1%More likelyKB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-44815 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
DHCP Client Service Remote Code Execution Vulnerability
CVE-2026-45456 ↗2026-06-09Microsoft Office 365 for MacCritical0%KB5002873KB5002874
and 4 moreKB5002876KB5002879KB5002880KB5002881
Microsoft Outlook and Word Remote Code Execution Vulnerability
CVE-2026-45458 ↗2026-06-09Microsoft Office 365 for MacCritical0%KB5002873KB5002874
and 4 moreKB5002876KB5002879KB5002880KB5002881
Microsoft Outlook and Word Remote Code Execution Vulnerability
CVE-2026-45460 ↗2026-06-09Microsoft Office for AndroidCritical0%Microsoft Office Information Disclosure Vulnerability
CVE-2026-45461 ↗2026-06-09Microsoft Office for AndroidCritical0%KB5002878Microsoft Office Remote Code Execution Vulnerability
CVE-2026-45463 ↗2026-06-09Microsoft Office 365 for MacCritical0%KB5002878Microsoft Office Remote Code Execution Vulnerability
CVE-2026-45472 ↗2026-06-09Microsoft Office 2019 for 32-bit editionsCritical0%KB5002878Microsoft Office Remote Code Execution Vulnerability
CVE-2026-45474 ↗2026-06-09Microsoft Office 365 for MacCritical0%KB5002878Microsoft Office Remote Code Execution Vulnerability
CVE-2026-45476 ↗2026-06-09Linux kernel - Microsoft MANA Network DriverCritical0%Microsoft Azure Network Adapter Elevation of Privilege Vulnerability
CVE-2026-45480 ↗2026-06-18Azure Active DirectoryCriticalOut-of-band1%Azure Active Directory Elevation of Privilege Vulnerability
CVE-2026-45497 ↗2026-06-04Microsoft 365 CopilotCriticalOut-of-band0%Microsoft M365 Copilot Remote Code Execution Vulnerability
CVE-2026-45607 ↗2026-06-09Windows 10 Version 1809 for x64-based SystemsCritical0%KB5093998KB5094122
and 6 moreKB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-45641 ↗2026-06-09Windows Server 2022Critical0%KB5093998KB5094125
and 4 moreKB5094126KB5094127KB5094128KB5095051
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-45648 ↗2026-06-09Windows Server 2022Critical1%KB5094125KB5094128Windows Active Directory Domain Services Remote Code Execution Vulnerability
CVE-2026-45657 ↗2026-06-09Windows Server 2022Critical15%KB5093998KB5094125
and 3 moreKB5094126KB5094128KB5095051
Windows Kernel Remote Code Execution Vulnerability
CVE-2026-47288 ↗2026-06-09Windows Server 2019Critical0%KB5094041KB5094042
and 4 moreKB5094122KB5094123KB5094125KB5094128
Windows Kerberos Key Distribution Center (KDC) Remote Code Execution
CVE-2026-47289 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-47291 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsCritical23%More likelyKB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
1 mentionsHTTP.sys Remote Code Execution Vulnerability
CVE-2026-47633 ↗2026-06-18Microsoft Cost ManagementCriticalOut-of-band1%Microsoft Cost Management Information Disclosure Vulnerability
CVE-2026-47635 ↗2026-06-09Microsoft Office LTSC 2024 for 32-bit editionsCritical0%Microsoft Outlook and Word Remote Code Execution Vulnerability
CVE-2026-47644 ↗2026-06-04Copilot Chat (Microsoft Edge)CriticalOut-of-band1%Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
CVE-2026-47645 ↗2026-06-18Microsoft 365 CopilotCriticalOut-of-band1%Microsoft 365 Copilot's Business Chat Elevation of Privilege Vulnerability
CVE-2026-47646 ↗2026-06-18Dynamics 365 Customer VoiceCriticalOut-of-band0%Dynamics 365 Customer Voice Spoofing Vulnerability
CVE-2026-47647 ↗2026-06-18Microsoft Dynamics 365CriticalOut-of-band1%Dynamics 365 Elevation of Privilege Vulnerability
CVE-2026-47652 ↗2026-06-09Windows Server 2022Critical0%KB5093998KB5094125
and 3 moreKB5094126KB5094128KB5095051
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-47654 ↗2026-06-09Windows Server 2019Critical1%KB5094122KB5094123
and 2 moreKB5094125KB5094128
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-47655 ↗2026-06-04Microsoft GraphCriticalOut-of-band1%Microsoft Graph Information Disclosure Vulnerability
CVE-2026-48563 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5093998KB5094123
and 5 moreKB5094125KB5094126KB5094127KB5094128KB5095051
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-48567 ↗2026-06-04Azure HorizonDBCriticalOut-of-band1%Azure HorizonDB Elevation of Privilege Vulnerability
CVE-2026-48574 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Media Remote Code Execution Vulnerability
CVE-2026-48579 ↗2026-06-04Microsoft Exchange OnlineCriticalOut-of-band1%Microsoft Exchange Online Information Disclosure Vulnerability
CVE-2026-48582 ↗2026-06-18Microsoft Exchange OnlineCriticalOut-of-band1%Microsoft Exchange Online Elevation of Privilege Vulnerability
CVE-2026-48584 ↗2026-06-18Azure SynapseCriticalOut-of-band1%Microsoft Azure Synapse Elevation of Privilege Vulnerability
CVE-2026-52913 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-bandbatman-adv: v: stop OGMv2 on disabled interface
CVE-2026-52919 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-bandbatman-adv: fix tp_meter counter underflow during shutdown
CVE-2026-52922 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-bandbatman-adv: dat: handle forward allocation error
CVE-2026-52931 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-bandbatman-adv: tp_meter: avoid use of uninit sender vars
CVE-2026-52934 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-bandbatman-adv: tvlv: reject oversized TVLV packets
CVE-2026-52944 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-bandksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE
CVE-2026-52947 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-bandnet: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove
CVE-2026-52953 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandiommu/vt-d: Fix oops due to out of scope access
CVE-2026-52956 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-bandlibceph: Fix potential out-of-bounds access in __ceph_x_decrypt()
CVE-2026-52962 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-bandceph: fix a buffer leak in __ceph_setxattr()
CVE-2026-52989 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-bandnvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers
CVE-2026-52991 ↗2026-06-27azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandsched/psi: fix race between file release and pressure write
CVE-2026-52993 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-bandtipc: fix double-free in tipc_buf_append()
CVE-2026-53000 ↗2026-06-27azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandnetfilter: nat: use kfree_rcu to release ops
CVE-2026-53002 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-bandnetfilter: conntrack: remove sprintf usage
CVE-2026-53009 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandice: fix double-free of tx_buf skb
CVE-2026-53010 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-bandksmbd: fix use-after-free in smb2_open during durable reconnect
CVE-2026-53017 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-bandf2fs: fix data loss caused by incorrect use of nat_entry flag
CVE-2026-53018 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandf2fs: avoid reading already updated pages during GC
CVE-2026-53025 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandgreybus: raw: fix use-after-free on cdev close
CVE-2026-53027 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-bandfs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked()
CVE-2026-53036 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-bandbpf, arm64: Fix off-by-one in check_imm signed range check
CVE-2026-53043 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-bandocfs2/dlm: validate qr_numregions in dlm_match_regions()
CVE-2026-53045 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-bandmemory: tegra124-emc: Fix dll_change check
CVE-2026-53049 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-bandgfs2: add some missing log locking
CVE-2026-53052 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-bandASoC: qcom: qdsp6: topology: check widget type before accessing data
CVE-2026-53053 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-bandiommu/amd: Fix clone_alias() to use the original device's devid
CVE-2026-53062 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-banddm cache policy smq: fix missing locks in invalidating cache blocks
CVE-2026-53075 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-bandppp: require CAP_NET_ADMIN in target netns for unattached ioctls
CVE-2026-53077 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-bandnet/rds: Restrict use of RDS/IB to the initial network namespace
CVE-2026-53086 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-bandnet: bcmgenet: fix racing timeout handler
CVE-2026-53089 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandbpf: Fix use-after-free in offloaded map/prog info fill
CVE-2026-53107 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0CriticalOut-of-bandwifi: libertas: don't kill URBs in interrupt context
CVE-2026-53108 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandpowerpc/64s: Fix unmap race with PMD migration entries
CVE-2026-53130 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-bandfs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START
CVE-2026-53309 ↗2026-06-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-bandocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison
CVE-2026-54130 ↗2026-06-18Microsoft 365 CopilotCriticalOut-of-band1%M365 Copilot Information Disclosure Vulnerability
CVE-2026-55200 ↗2026-06-27azl3 libssh2 1.11.1-3 on Azure Linux 3.0CriticalOut-of-bandlibssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
CVE-2026-56123 ↗2026-06-27azl3 socat 1.7.4.4-2 on Azure Linux 3.0CriticalOut-of-bandsocat 1.8.0.0 - 1.8.1.1 Heap Buffer Overflow via SOCKS5 Reply Parser
CVE-2026-10097 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ImportantOut-of-bandML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and static private-key recovery
CVE-2026-10846 ↗2026-06-11azl3 ldns 1.8.3-2 on Azure Linux 3.0ImportantOut-of-bandInsufficient verification that responses belong to a query
CVE-2026-10879 ↗2026-06-09azl3 perl-DBI 1.643-3 on Azure Linux 3.0ImportantDBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders
CVE-2026-11310 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ImportantOut-of-bandX.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring
CVE-2026-11332 ↗2026-06-07azl3 ansible 2.17.11-1 on Azure Linux 3.0ImportantOut-of-bandAnsible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution
CVE-2026-11463 ↗2026-06-09azl3 cereal 1.3.2-1 on Azure Linux 3.0ImportantUSCiLab Cereal Shared Pointer type confusion
CVE-2026-11816 ↗2026-06-25azl3 keras 3.3.3-7 on Azure Linux 3.0ImportantOut-of-bandPath Traversal in keras-team/keras
CVE-2026-11822 ↗2026-06-11azl3 sqlite 3.44.0-3 on Azure Linux 3.0ImportantOut-of-bandSQLite before 3.53.2 Memory Corruption in FTS5 Extension
CVE-2026-11824 ↗2026-06-11azl3 sqlite 3.44.0-3 on Azure Linux 3.0ImportantOut-of-bandSQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate
CVE-2026-11972 ↗2026-06-27azl3 tensorflow 2.16.1-11 on Azure Linux 3.0ImportantOut-of-bandtarfile opened in streaming mode mishandles EOF
CVE-2026-11999 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ImportantOut-of-bandX.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert()
CVE-2026-12087 ↗2026-06-19azl3 perl 5.38.2-509 on Azure Linux 3.0ImportantOut-of-bandSocket versions before 2.041 for Perl have an out-of-bounds heap read
CVE-2026-12143 ↗2026-06-17azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandform-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
CVE-2026-12505 ↗2026-06-27azl3 cifs-utils 7.3-1 on Azure Linux 3.0ImportantOut-of-bandCifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall
CVE-2026-12912 ↗2026-07-03azl3 libtiff 4.6.0-13 on Azure Linux 3.0ImportantOut-of-bandLibtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed tiff image
CVE-2026-13325 ↗2026-07-01azl3 kubevirt 1.7.1-7 on Azure Linux 3.0ImportantOut-of-bandVirt-handler-rhel9: kubevirt: kubevirt: disabletls migration setting removes authentication, exposing unauthenticated virtqemud proxy on all interfaces
CVE-2026-14164 ↗2026-07-03azl3 libarchive 3.7.7-6 on Azure Linux 3.0ImportantOut-of-bandLibarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack()
CVE-2026-29167 ↗2026-06-11azl3 httpd 2.4.67-1 on Azure Linux 3.0ImportantOut-of-bandApache HTTP Server: mod_ldap per-dir use-after-free
CVE-2026-3195 ↗2026-06-27azl3 qemu 9.1.0-8 on Azure Linux 3.0ImportantOut-of-bandQemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for cve-2024-7730)
CVE-2026-33113 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002873KB5002874
and 1 moreKB5002880
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-34180 ↗2026-06-13azl3 shim-unsigned-aarch64 16.1-2 on Azure Linux 3.0ImportantOut-of-bandHeap Buffer Over-read in ASN.1 Content Parsing
CVE-2026-34181 ↗2026-06-13azl3 cloud-hypervisor 51.1.56-1 on Azure Linux 3.0ImportantOut-of-bandPKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys
CVE-2026-34183 ↗2026-06-13azl3 cloud-hypervisor 51.1.56-1 on Azure Linux 3.0ImportantOut-of-bandUnbounded Memory Growth in the QUIC PATH_CHALLENGE Handler
CVE-2026-34335 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-37460 ↗2026-06-07azl3 frr 10.5.4-1 on Azure Linux 3.0ImportantOut-of-bandMissing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
CVE-2026-40371 ↗2026-06-09Microsoft Dynamics 365 (on-premises) version 9.1Important1%Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability
CVE-2026-40376 ↗2026-06-09Visual Studio CodeImportant1%Visual Studio Code Elevation of Privilege Vulnerability
CVE-2026-40404 ↗2026-06-09Windows Server 2022 (Server Core installation)Important0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-40409 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-41092 ↗2026-06-09Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Microsoft Kinect Elevation of Privilege Vulnerability
CVE-2026-41098 ↗2026-06-09Azure Stack EdgeImportant1%Azure Stack Edge Spoofing Vulnerability
CVE-2026-41108 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows DNS Client Elevation of Privilege Vulnerability
CVE-2026-42055 ↗2026-07-01azl3 nginx 1.28.3-5 on Azure Linux 3.0ImportantOut-of-bandNGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
CVE-2026-42504 ↗2026-06-05azl3 tensorflow 2.16.1-11 on Azure Linux 3.0ImportantOut-of-bandQuadratic complexity in WordDecoder.DecodeHeader in mime
CVE-2026-42536 ↗2026-06-11azl3 httpd 2.4.67-1 on Azure Linux 3.0ImportantOut-of-bandApache HTTP Server: mod_xml2enc heap overflow
CVE-2026-42764 ↗2026-06-13azl3 cloud-hypervisor 51.1.56-1 on Azure Linux 3.0ImportantOut-of-bandNULL Pointer Dereference in QUIC Server Initial Packet Handling
CVE-2026-42828 ↗2026-06-09Windows Server 2022Important0%KB5093998KB5094123
and 5 moreKB5094125KB5094126KB5094127KB5094128KB5095051
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-42829 ↗2026-06-09Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5094126KB5095051Windows Administrator Protection Secure Feature Bypass Vulnerability
CVE-2026-42835 ↗2026-06-09Microsoft Teams for AndroidImportant1%Microsoft Teams for Android Information Disclosure Vulnerability
CVE-2026-42836 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
CVE-2026-42837 ↗2026-06-09Windows Server 2019 (Server Core installation)Important0%KB5093998KB5094123
and 5 moreKB5094125KB5094126KB5094127KB5094128KB5095051
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-42902 ↗2026-06-09Microsoft PowerToysImportant0%Microsoft PowerToys Elevation of Privilege Vulnerability
CVE-2026-42903 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Kerberos Denial of Service Vulnerability
CVE-2026-42904 ↗2026-06-09Windows Server 2022Important0%KB5093998KB5094125
and 4 moreKB5094126KB5094127KB5094128KB5095051
Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-42905 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-42906 ↗2026-06-09Windows Server 2022Important0%KB5093998KB5094125
and 4 moreKB5094126KB5094127KB5094128KB5095051
Windows Shell Information Disclosure Vulnerability
CVE-2026-42907 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5093998KB5094123
and 5 moreKB5094125KB5094126KB5094127KB5094128KB5095051
Windows Shell Information Disclosure Vulnerability
CVE-2026-42908 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-42909 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-42910 ↗2026-06-09Windows Server 2025 (Server Core installation)Important0%KB5094125KB5094126
and 1 moreKB5095051
Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability
CVE-2026-42911 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-42912 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-42913 ↗2026-06-09Remote Desktop client for Windows DesktopImportant0%KB5093998KB5094125
and 3 moreKB5094126KB5094128KB5095051
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-42914 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Kerberos Denial of Service Vulnerability
CVE-2026-42915 ↗2026-06-09Windows Server 2022Important0%KB5093998KB5094125
and 4 moreKB5094126KB5094127KB5094128KB5095051
Microsoft Windows VMSwitch Denial of Service Vulnerability
CVE-2026-42916 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
NT OS Kernel Elevation of Privilege Vulnerability
CVE-2026-42968 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Telephony Server Information Disclosure Vulnerability
CVE-2026-42969 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094122
and 6 moreKB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Push Notification Information Disclosure Vulnerability
CVE-2026-42970 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Push Notification Information Disclosure Vulnerability
CVE-2026-42971 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094122
and 6 moreKB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Push Notification Information Disclosure Vulnerability
CVE-2026-42972 ↗2026-06-09Windows 10 Version 1809 for x64-based SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Hyper-V Information Disclosure Vulnerability
CVE-2026-42973 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094122
and 6 moreKB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Push Notification Information Disclosure Vulnerability
CVE-2026-42974 ↗2026-06-09Windows Server 2022Important1%KB5093998KB5094125
and 3 moreKB5094126KB5094128KB5095051
Windows Performance Monitor Remote Code Execution Vulnerability
CVE-2026-42977 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094123
and 5 moreKB5094125KB5094126KB5094127KB5094128KB5095051
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-42978 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094123
and 5 moreKB5094125KB5094126KB5094127KB5094128KB5095051
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-42979 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094123
and 5 moreKB5094125KB5094126KB5094127KB5094128KB5095051
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-42980 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant7%More likelyKB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
NT OS Kernel Elevation of Privilege Vulnerability
CVE-2026-42981 ↗2026-06-09Windows Server 2022Important1%KB5093998KB5094125
and 3 moreKB5094126KB5094128KB5095051
Windows Performance Monitor Remote Code Execution Vulnerability
CVE-2026-42983 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094123
and 5 moreKB5094125KB5094126KB5094127KB5094128KB5095051
Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-42984 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094123
and 5 moreKB5094125KB5094126KB5094127KB5094128KB5095051
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-42986 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Microsoft Graphics Component Elevation of Privilege Vulnerability
CVE-2026-42989 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Winlogon Elevation of Privilege Vulnerability
CVE-2026-42991 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094123
and 5 moreKB5094125KB5094126KB5094127KB5094128KB5095051
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-42993 ↗2026-06-09Windows Server 2022Important0%KB5093998KB5094125
and 4 moreKB5094126KB5094127KB5094128KB5095051
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-43958 ↗2026-06-07azl3 ntopng 5.2.1-6 on Azure Linux 3.0ImportantOut-of-bandRrdtool: rrdtool: stack buffer overflow allows local code execution or denial of service
CVE-2026-44185 ↗2026-06-11azl3 httpd 2.4.67-1 on Azure Linux 3.0ImportantOut-of-bandApache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request`
CVE-2026-44631 ↗2026-06-11azl3 httpd 2.4.67-1 on Azure Linux 3.0ImportantOut-of-bandApache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow
CVE-2026-44705 ↗2026-06-13azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandtmp: Path Traversal via unsanitized prefix/postfix enables directory escape
CVE-2026-44802 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094123
and 5 moreKB5094125KB5094126KB5094127KB5094128KB5095051
Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-44804 ↗2026-06-09Windows 11 version 26H1 for x64-based SystemsImportant0%KB5095051Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-44805 ↗2026-06-09Windows Server 2019Important0%KB5094123KB5094125
and 1 moreKB5094128
Windows Network Controller (NC) Host Agent Denial of Service Vulnerability
CVE-2026-44807 ↗2026-06-09Windows 11 version 26H1 for x64-based SystemsImportant0%KB5095051Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-44808 ↗2026-06-09Windows 11 version 26H1 for x64-based SystemsImportant0%KB5095051Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-44809 ↗2026-06-09Windows Server 2025 (Server Core installation)Important0%KB5094125KB5094126
and 1 moreKB5095051
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2026-44811 ↗2026-06-09Windows 11 version 26H1 for x64-based SystemsImportant0%KB5095051Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-44813 ↗2026-06-09Windows 11 version 26H1 for x64-based SystemsImportant0%KB5095051Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-44814 ↗2026-06-09Windows 11 version 26H1 for x64-based SystemsImportant0%KB5095051Windows DWM Core Library Information Disclosure Vulnerability
CVE-2026-44817 ↗2026-06-09Microsoft Office 365 for MacImportant0%KB5002875KB5002877Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-44818 ↗2026-06-09Microsoft Office 365 for MacImportant0%KB5002875KB5002877Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-44819 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002873KB5002874
and 4 moreKB5002876KB5002878KB5002880KB5002881
Microsoft Office Remote Code Execution Vulnerability
CVE-2026-44820 ↗2026-06-09Microsoft Office 365 for MacImportant0%KB5002875KB5002877Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-44821 ↗2026-06-09Microsoft SharePoint Server Subscription EditionImportant0%KB5002873KB5002874
and 4 moreKB5002876KB5002878KB5002880KB5002881
Microsoft Office Information Disclosure Vulnerability
CVE-2026-44822 ↗2026-06-09Microsoft Office 365 for MacImportant1%KB5002875KB5002877Microsoft Excel Information Disclosure Vulnerability
CVE-2026-44823 ↗2026-06-09Microsoft Office 365 for MacImportant0%KB5002875KB5002877Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-44824 ↗2026-06-09Microsoft Office 365 for MacImportant0%KB5002873KB5002874
and 4 moreKB5002876KB5002878KB5002880KB5002881
Microsoft Office Remote Code Execution Vulnerability
CVE-2026-45445 ↗2026-06-13azl3 openssl 3.3.7-1 on Azure Linux 3.0ImportantOut-of-bandAES-OCB IV Ignored on EVP_Cipher() Path
CVE-2026-45447 ↗2026-06-13azl3 openssl 3.3.7-3 on Azure Linux 3.0ImportantOut-of-bandHeap Use-After-Free in the PKCS7_verify() Function
CVE-2026-45453 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002873KB5002874
and 1 moreKB5002880
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-45454 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important1%KB5002873KB5002874
and 1 moreKB5002880
Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2026-45455 ↗2026-06-09Office Online ServerImportant1%KB5002875KB5002877Microsoft Excel Information Disclosure Vulnerability
CVE-2026-45457 ↗2026-06-09Microsoft Office 365 for MacImportant0%Microsoft Word Remote Code Execution Vulnerability
CVE-2026-45459 ↗2026-06-09Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft Excel Security Feature Bypass Vulnerability
CVE-2026-45462 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002873KB5002874
and 1 moreKB5002880
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-45464 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002873KB5002874
and 1 moreKB5002880
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-45465 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002873KB5002874
and 1 moreKB5002880
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-45466 ↗2026-06-09Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft Word Information Disclosure Vulnerability
CVE-2026-45467 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002873KB5002874
and 1 moreKB5002880
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-45468 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002873KB5002874
and 1 moreKB5002880
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-45469 ↗2026-06-09Microsoft Office 365 for MacImportant0%KB5002875KB5002877Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-45471 ↗2026-06-09Microsoft Office 365 for MacImportant0%KB5002873KB5002874
and 4 moreKB5002876KB5002879KB5002880KB5002881
Microsoft Word Remote Code Execution Vulnerability
CVE-2026-45475 ↗2026-06-09Microsoft Office 365 for MacImportant0%KB5002873KB5002874
and 4 moreKB5002876KB5002878KB5002880KB5002881
Microsoft Office Remote Code Execution Vulnerability
CVE-2026-45479 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002873KB5002874
and 1 moreKB5002880
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-45481 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important1%More likelyKB5002873KB5002874
and 1 moreKB5002880
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-45482 ↗2026-06-09Microsoft Visual Studio Code CoPilot Chat ExtensionImportant0%Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability
CVE-2026-45483 ↗2026-06-09Microsoft SharePoint Server Subscription EditionImportant0%KB5002873KB5002874
and 1 moreKB5002880
Microsoft Office Project Server Spoofing Vulnerability
CVE-2026-45484 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important27%KB5002873KB5002874
and 1 moreKB5002880
Microsoft SharePoint Elevation of Privilege Vulnerability
CVE-2026-45485 ↗2026-06-09Microsoft Office 365 for MacImportant0%KB5002873KB5002874
and 4 moreKB5002876KB5002878KB5002880KB5002881
Microsoft Office Information Disclosure Vulnerability
CVE-2026-45486 ↗2026-06-09Microsoft Office 365 for MacImportant0%Microsoft Word Remote Code Execution Vulnerability
CVE-2026-45487 ↗2026-06-09Windows Server 2022Important0%KB5093998KB5094125
and 4 moreKB5094126KB5094127KB5094128KB5095051
Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability
CVE-2026-45490 ↗2026-06-09.NET 10.0 installed on WindowsImportant0%KB5097148KB5097149
and 1 moreKB5097150
.NET SDK Elevation of Privilege Vulnerability
CVE-2026-45491 ↗2026-06-09.NET 10.0 installed on WindowsImportant0%KB5097148KB5097149
and 1 moreKB5097150
.NET Tampering Vulnerability
CVE-2026-45500 ↗2026-06-09Microsoft Exchange Server 2019 Cumulative Update 14Important0%KB5094139KB5094140
and 2 moreKB5094142KB5094144
Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-45501 ↗2026-06-09Microsoft Exchange Server Subscription Edition RTMImportant0%KB5094139KB5094140
and 2 moreKB5094142KB5094144
Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-45502 ↗2026-06-09Microsoft Exchange Server 2019 Cumulative Update 14Important20%KB5094139KB5094140
and 2 moreKB5094142KB5094144
Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2026-45503 ↗2026-06-09Microsoft Exchange Server 2016 Cumulative Update 23Important0%KB5094139KB5094140
and 2 moreKB5094142KB5094144
Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2026-45504 ↗2026-06-09Microsoft Exchange Server Subscription Edition RTMImportant1%KB5094139KB5094140
and 2 moreKB5094142KB5094144
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2026-45583 ↗2026-06-09Microsoft Exchange Server 2016 Cumulative Update 23Important0%KB5094139KB5094140
and 2 moreKB5094142KB5094144
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2026-45586 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant4%More likelyVulnCheckKB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
1 mentionsWindows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability
CVE-2026-45588 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Secure Boot Security Feature Bypass Vulnerability
CVE-2026-45591 ↗2026-06-09Microsoft Visual Studio 2026 version 18.6Important2%KB5097148KB5097149
and 1 moreKB5097150
ASP.NET Core Denial of Service Vulnerability
CVE-2026-45592 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094006
and 8 moreKB5094041KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Internet (wininet.dll) Elevation of Privilege Vulnerability
CVE-2026-45593 ↗2026-06-09Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5093998KB5094123
and 5 moreKB5094125KB5094126KB5094127KB5094128KB5095051
Windows SDK Elevation of Privilege Vulnerability
CVE-2026-45594 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094122
and 6 moreKB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Application Identity (AppID) Information Disclosure Vulnerability
CVE-2026-45595 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 7 moreKB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Mark of the Web Security Feature Bypass Vulnerability
CVE-2026-45596 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-45597 ↗2026-06-09Windows Server 2022Important0%KB5093998KB5094125
and 3 moreKB5094126KB5094128KB5095051
Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability
CVE-2026-45598 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-45599 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows UPnP Device Host Remote Code Execution Vulnerability
CVE-2026-45600 ↗2026-06-09Windows Server 2025 (Server Core installation)Important0%KB5094125KB5094126
and 1 moreKB5095051
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2026-45601 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-45602 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability
CVE-2026-45603 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-45604 ↗2026-06-09Windows Server 2025 (Server Core installation)Important0%KB5093998KB5094125
and 2 moreKB5094126KB5095051
Windows Managed Installer Information Disclosure Vulnerability
CVE-2026-45605 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094122
and 6 moreKB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Bluetooth Service Elevation of Privilege Vulnerability
CVE-2026-45606 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability
CVE-2026-45608 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows DHCP Client Information Disclosure Vulnerability
CVE-2026-45634 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows DHCP Client Information Disclosure Vulnerability
CVE-2026-45635 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows UPnP Device Host Remote Code Execution Vulnerability
CVE-2026-45636 ↗2026-06-09Windows Server 2022 (Server Core installation)Important0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-45637 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094123
and 5 moreKB5094125KB5094126KB5094127KB5094128KB5095051
Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-45638 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-45639 ↗2026-06-09Windows App Client for Windows DesktopImportant1%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-45640 ↗2026-06-09Windows Server 2022Important0%KB5093998KB5094125
and 4 moreKB5094126KB5094127KB5094128KB5095051
Windows Bluetooth Port Driver Elevation of Privilege Vulnerability
CVE-2026-45642 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability
CVE-2026-45643 ↗2026-06-09Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft Word Remote Code Execution Vulnerability
CVE-2026-45644 ↗2026-06-09Microsoft Live Share Canvas SDKImportant1%Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability
CVE-2026-45645 ↗2026-06-09Microsoft Office 365 for MacImportant0%KB5002852Microsoft Office Remote Code Execution Vulnerability
CVE-2026-45647 ↗2026-06-09Microsoft Defender for Endpoint for MacImportant0%Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability
CVE-2026-45649 ↗2026-06-09Microsoft Excel for AndroidImportant0%Office for Android Spoofing Vulnerability
CVE-2026-45650 ↗2026-06-09Microsoft Bing Search for AndroidImportant1%Microsoft Bing Search Spoofing Vulnerability
CVE-2026-45653 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-45654 ↗2026-06-09Windows 11 version 26H1 for x64-based SystemsImportant0%KB5094125KB5094126
and 1 moreKB5095051
Secure Boot Security Feature Bypass Vulnerability
CVE-2026-45655 ↗2026-06-09Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-45656 ↗2026-06-09Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
UEFI Secure Boot Security Feature Bypass Vulnerability
CVE-2026-45658 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-46243 ↗2026-06-03azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-bandsmb: client: reject userspace cifs.spnego descriptions
CVE-2026-46244 ↗2026-06-05azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandnetfilter: nft_inner: Fix IPv6 inner_thoff desync
CVE-2026-46274 ↗2026-06-10azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandio-wq: check that the predecessor is hashed in io_wq_remove_pending()
CVE-2026-46275 ↗2026-06-10azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandBluetooth: hci_uart: fix UAFs and race conditions in close and init paths
CVE-2026-46285 ↗2026-06-10azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandmtd: docg3: fix use-after-free in docg3_release()
CVE-2026-46293 ↗2026-06-10azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandclk: microchip: mpfs-ccc: fix out of bounds access during output registration
CVE-2026-46301 ↗2026-06-10azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandspi: topcliff-pch: fix use-after-free on unbind
CVE-2026-46306 ↗2026-06-10azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandflow_dissector: do not dissect PPPoE PFC frames
CVE-2026-46319 ↗2026-06-10azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandnet/sched: act_ct: Only release RCU read lock after ct_ft
CVE-2026-46320 ↗2026-06-10azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandtap: free page on error paths in tap_get_user_xdp()
CVE-2026-46324 ↗2026-06-10azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandnetfilter: nf_tables: use list_del_rcu for netlink hooks
CVE-2026-46330 ↗2026-06-10azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandRevert "net/smc: Introduce TCP ULP support"
CVE-2026-46331 ↗2026-06-17azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandnet/sched: fix pedit partial COW leading to page cache corruption
CVE-2026-46643 ↗2026-06-12azl3 snappy 1.1.10-2 on Azure Linux 3.0ImportantOut-of-bandSnappy: Binary path is never shell-escaped due to an inverted is_executable check
CVE-2026-47162 ↗2026-06-13azl3 vim 9.2.0488-1 on Azure Linux 3.0ImportantOut-of-bandVim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name
CVE-2026-47281 ↗2026-06-09Visual Studio CodeImportant1%Visual Studio Code Elevation of Privilege Vulnerability
CVE-2026-47284 ↗2026-06-09Visual Studio CodeImportant1%Visual Studio Code Information Disclosure Vulnerability
CVE-2026-47287 ↗2026-06-09Visual Studio CodeImportant1%Visual Studio Code Tampering Vulnerability
CVE-2026-47292 ↗2026-06-09Visual Studio Code - MSSQL ExtensionImportant0%Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability
CVE-2026-47293 ↗2026-06-09Microsoft Office 2019 for 32-bit editionsImportant0%Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
CVE-2026-47298 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002873KB5002874
and 1 moreKB5002880
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-47631 ↗2026-06-09Microsoft Exchange Server 2016 Cumulative Update 23Important0%KB5094139KB5094140
and 2 moreKB5094142KB5094144
Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-47634 ↗2026-06-09Microsoft SharePoint Server 2019Important1%More likelyKB5002873KB5002874Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-47636 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002873KB5002874
and 1 moreKB5002880
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-47637 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002873KB5002874
and 1 moreKB5002880
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-47638 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002873KB5002874
and 1 moreKB5002880
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-47639 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002873KB5002874
and 1 moreKB5002880
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-47640 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002873KB5002874
and 1 moreKB5002880
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-47641 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002873KB5002874
and 1 moreKB5002880
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-47643 ↗2026-06-09Azure Stack EdgeImportant1%Azure Stack Edge Remote Code Execution Vulnerability
CVE-2026-47648 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Storage Elevation of Privilege Vulnerability
CVE-2026-47653 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-47656 ↗2026-06-09Windows Server 2019Important0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Boot Manager Security Feature Bypass Vulnerability
CVE-2026-48560 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important1%KB5002873KB5002874
and 1 moreKB5002880
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-48562 ↗2026-06-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002873KB5002874
and 1 moreKB5002880
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-48565 ↗2026-06-09Windows Narrator BrailleImportant0%Windows Narrator Braille Elevation of Privilege Vulnerability
CVE-2026-48566 ↗2026-06-09Windows Server 2025 (Server Core installation)Important0%KB5087423KB5087539
and 3 moreKB5089466KB5089548KB5089549
Windows DWM Core Library Information Disclosure Vulnerability
CVE-2026-48568 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Secure Boot Security Feature Bypass Vulnerability
CVE-2026-48569 ↗2026-06-09Visual Studio CodeImportant0%Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-48570 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Secure Boot Security Feature Bypass Vulnerability
CVE-2026-48573 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Secure Boot Security Feature Bypass Vulnerability
CVE-2026-48575 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Secure Boot Security Feature Bypass Vulnerability
CVE-2026-48576 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Secure Boot Security Feature Bypass Vulnerability
CVE-2026-48578 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Secure Boot Security Feature Bypass Vulnerability
CVE-2026-48583 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5093998KB5094122
and 6 moreKB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-48715 ↗2026-06-27azl3 radvd 2.19-1 on Azure Linux 3.0ImportantOut-of-bandradvdump's Route Information Option Parser has a Stack Buffer Overflow
CVE-2026-48779 ↗2026-07-01azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandws: Memory exhaustion DoS from tiny fragments and data chunks
CVE-2026-48854 ↗2026-06-18azl3 grpc 1.62.3-1 on Azure Linux 3.0ImportantOut-of-bandUnbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc
CVE-2026-48856 ↗2026-06-17azl3 erlang 26.2.5.20-1 on Azure Linux 3.0ImportantOut-of-bandhttpc leaks Authorization header to cross-origin redirect targets
CVE-2026-48860 ↗2026-06-17azl3 erlang 26.2.5.20-1 on Azure Linux 3.0ImportantOut-of-bandDistribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist
CVE-2026-49160 ↗2026-06-09Windows Server 2019 (Server Core installation)Important54%More likelyKB5093998KB5094122
and 6 moreKB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
1 mentionsHTTP.sys Denial of Service Vulnerability
CVE-2026-49161 ↗2026-06-09Microsoft PC ManagerImportant0%Microsoft PC Manager Security Feature Bypass Vulnerability
CVE-2026-49759 ↗2026-06-17azl3 erlang 26.2.5.20-1 on Azure Linux 3.0ImportantOut-of-bandStack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crash
CVE-2026-49839 ↗2026-06-27azl3 jq 1.7.1-8 on Azure Linux 3.0ImportantOut-of-bandjq --rawfile invalid-state reuse after String too long causes heap-buffer-overflow
CVE-2026-49851 ↗2026-06-27azl3 python-mistune 3.2.1-1 on Azure Linux 3.0ImportantOut-of-band0%Mistune: Potential DoS via quadratic-time parsing in parse_link_text
CVE-2026-49975 ↗2026-06-09azl3 nginx 1.28.3-4 on Azure Linux 3.0ImportantApache HTTP Server: mod_http2 denial of service
CVE-2026-50031 ↗2026-06-04azl3 freeipmi 1.6.17-1 on Azure Linux 3.0ImportantOut-of-bandipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Two subcommands "ipmi-oem dell get-active-directory-config" and "ipmi-oem fujitsu get-sel-entry-long-text" were found to have exploitable buffer overflows on response messages.
CVE-2026-50256 ↗2026-06-09azl3 xorg-x11-server-Xwayland 24.1.6-4 on Azure Linux 3.0ImportantXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libxfont2 name length mismatch
CVE-2026-50258 ↗2026-06-09azl3 xorg-x11-server-Xwayland 24.1.6-4 on Azure Linux 3.0ImportantXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shift levels
CVE-2026-50259 ↗2026-06-09azl3 xorg-x11-server-Xwayland 24.1.6-4 on Azure Linux 3.0ImportantXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexing
CVE-2026-50261 ↗2026-06-09azl3 xorg-x11-server-Xwayland 24.1.6-4 on Azure Linux 3.0ImportantXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter()
CVE-2026-50292 ↗2026-06-06azl3 libinput 1.25.0-1 on Azure Linux 3.0ImportantOut-of-bandIn libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
CVE-2026-50507 ↗2026-06-09Windows 10 Version 1809 for 32-bit SystemsImportant5%More likelyKB5093998KB5094041
and 6 moreKB5094122KB5094123KB5094126KB5094127KB5094128KB5095051
1 mentionsWindows BitLocker Security Feature Bypass Vulnerability
CVE-2026-50508 ↗2026-06-09Windows Server 2022Important9%More likelyKB5093998KB5094041
and 4 moreKB5094042KB5094122KB5094127KB5094128
Windows NTLM Spoofing Vulnerability
CVE-2026-50511 ↗2026-06-09Microsoft PC ManagerImportant0%Microsoft PC Manager Elevation of Privilege Vulnerability
CVE-2026-50512 ↗2026-06-09Microsoft PC ManagerImportant0%Microsoft PC Manager Elevation of Privilege Vulnerability
CVE-2026-50519 ↗2026-06-09GitHub Copilot ChatImportant1%Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability
CVE-2026-50521 ↗2026-06-26Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-50656 ↗2026-06-16Microsoft Malware Protection EngineImportantOut-of-band11%More likely1 mentionsMicrosoft Defender Elevation of Privilege Vulnerability
CVE-2026-52858 ↗2026-06-13azl3 vim 9.2.0488-1 on Azure Linux 3.0ImportantOut-of-bandVim: Arbitrary Code Execution via Python Omni-Completion
CVE-2026-52860 ↗2026-06-13azl3 vim 9.2.0488-1 on Azure Linux 3.0ImportantOut-of-bandVim: Arbitrary Code Execution via Python Omni-Completion
CVE-2026-52908 ↗2026-06-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandRDMA: During rereg_mr ensure that REREG_ACCESS is compatible
CVE-2026-52909 ↗2026-06-29azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandip6_vti: set netns_immutable on the fallback device.
CVE-2026-52910 ↗2026-06-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandbpf: Free reuseport cBPF prog after RCU grace period.
CVE-2026-52911 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandksmbd: scope conn->binding slowpath to bound sessions only
CVE-2026-52912 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-bandnetfilter: nf_queue: hold bridge skb->dev while queued
CVE-2026-52923 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-bandipc: limit next_id allocation to the valid ID range
CVE-2026-52926 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-bandbatman-adv: clear current gateway during teardown
CVE-2026-52935 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-bandxfrm: espintcp: do not reuse an in-progress partial send
CVE-2026-52943 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-bandnet: skbuff: fix missing zerocopy reference in pskb_carve helpers
CVE-2026-52972 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandcrypto: af_alg - Cap AEAD AD length to 0x80000000
CVE-2026-53005 ↗2026-06-27azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandaf_unix: Drop all SCM attributes for SOCKMAP.
CVE-2026-53023 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandfs/ntfs3: terminate the cached volume label after UTF-8 conversion
CVE-2026-53039 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandocfs2: validate group add input before caching
CVE-2026-53068 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/komeda: fix integer overflow in AFBC framebuffer size check
CVE-2026-53097 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work()
CVE-2026-53143 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
CVE-2026-53157 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-bandnet: phonet: free phonet_device after RCU grace period
CVE-2026-53159 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-bandmisc: fastrpc: fix DMA address corruption due to find_vma misuse
CVE-2026-53160 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-bandmisc: fastrpc: fix use-after-free race in fastrpc_map_create
CVE-2026-53176 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-bandIB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN
CVE-2026-53194 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-bandUSB: serial: kl5kusb105: fix bulk-out buffer overflow
CVE-2026-53196 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-bandUSB: serial: io_ti: fix heap overflow in get_manuf_info()
CVE-2026-53198 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL
CVE-2026-53215 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-bandnet: mvpp2: refill RX buffers before XDP or skb use
CVE-2026-53246 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-bandsctp: validate cached peer INIT chunk length in COOKIE_ECHO processing
CVE-2026-53247 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-bandnet: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown
CVE-2026-53262 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-bandl2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()
CVE-2026-53284 ↗2026-06-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandbtrfs: only release the dirty pages io tree after successful writes
CVE-2026-53303 ↗2026-06-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandf2fs: protect extension_list reading with sb_lock in f2fs_sbi_show()
CVE-2026-53306 ↗2026-06-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandtty: hvc_iucv: fix off-by-one in number of supported devices
CVE-2026-54369 ↗2026-06-30azl3 acl 2.3.1-2 on Azure Linux 3.0ImportantOut-of-bandacl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions
CVE-2026-55199 ↗2026-06-27azl3 libssh 0.10.6-8 on Azure Linux 3.0ImportantOut-of-bandlibssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler
CVE-2026-55203 ↗2026-06-27azl3 haproxy 2.9.11-6 on Azure Linux 3.0ImportantOut-of-bandHAProxy - Integer Overflow in FCGI Demux Record Length Field
CVE-2026-55204 ↗2026-06-27azl3 haproxy 2.9.11-6 on Azure Linux 3.0ImportantOut-of-bandHAProxy - NULL Pointer Dereference in hpack_dht_insert Function
CVE-2026-55958 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ImportantOut-of-bandRenesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage
CVE-2026-55960 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ImportantOut-of-bandUn-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing chain validation
CVE-2026-55961 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ImportantOut-of-bandwolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 with no signer
CVE-2026-57231 ↗2026-07-01azl3 libcontainers-common 20240213-3 on Azure Linux 3.0ImportantOut-of-bandPodman: Malformed Image can trick podman run into leaking host environment variables into the container
CVE-2026-57235 ↗2026-06-27azl3 rubygem-nokogiri 1.15.4-1 on Azure Linux 3.0ImportantOut-of-bandNokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
CVE-2026-57236 ↗2026-06-27azl3 rubygem-nokogiri 1.15.4-1 on Azure Linux 3.0ImportantOut-of-bandNokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception
CVE-2026-57434 ↗2026-06-27azl3 rubygem-nokogiri 1.15.4-1 on Azure Linux 3.0ImportantOut-of-bandNokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes
CVE-2026-57435 ↗2026-06-27azl3 rubygem-nokogiri 1.15.4-1 on Azure Linux 3.0ImportantOut-of-bandNokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
CVE-2026-57456 ↗2026-06-27azl3 vim 9.2.0488-1 on Azure Linux 3.0ImportantOut-of-bandVim: Arbitrary Code Execution via Python Omni-Completion Docstrings
CVE-2026-57585 ↗2026-07-03azl3 python-msgpack 1.0.5-2 on Azure Linux 3.0ImportantOut-of-bandMessagePack: Out-of-bounds read/crash on Unpacker reuse after caught error
CVE-2026-57918 ↗2026-07-01azl3 libnfs 5.0.2-2 on Azure Linux 3.0ImportantOut-of-bandlibnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker.
CVE-2026-58014 ↗2026-07-01azl3 glib 2.78.6-9 on Azure Linux 3.0ImportantOut-of-bandGlib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"
CVE-2026-58050 ↗2026-06-29azl3 libssh 0.10.6-8 on Azure Linux 3.0ImportantOut-of-bandlibssh2 - Integer Overflow in publickey Subsystem Attribute Allocation
CVE-2026-58051 ↗2026-06-29azl3 nmap 7.95-3 on Azure Linux 3.0ImportantOut-of-bandlibssh2 - Free of Uninitialized Pointer in publickey List Cleanup
CVE-2026-6893 ↗2026-06-17azl3 dracut 102-13 on Azure Linux 3.0ImportantOut-of-bandDracut: dracut: root code execution via dhcp options command injection
CVE-2026-7383 ↗2026-06-13azl3 cloud-hypervisor 51.1.56-1 on Azure Linux 3.0ImportantOut-of-bandPossible Heap Buffer Overflow in ASN.1 Multibyte String Conversion
CVE-2026-8829 ↗2026-06-07azl3 perl-HTML-Parser 3.82-1 on Azure Linux 3.0ImportantOut-of-bandHTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities
CVE-2026-8863 ↗2026-06-09Windows Server 2019Important0%KB5093998KB5094041
and 8 moreKB5094042KB5094122KB5094123KB5094125KB5094126KB5094127KB5094128KB5095051
UEFI Secure Boot Security Feature Bypass Vulnerability
CVE-2026-9076 ↗2026-06-13azl3 cloud-hypervisor 51.1.56-1 on Azure Linux 3.0ImportantOut-of-bandOut-of-Bounds Read in CMS Password-Based Decryption
CVE-2026-9675 ↗2026-06-27azl3 nodejs 24.14.1-3 on Azure Linux 3.0ImportantOut-of-bandundici WebSocket client vulnerable to denial of service via cumulative fragment bypass
CVE-2026-9697 ↗2026-06-27azl3 nodejs 24.14.1-3 on Azure Linux 3.0ImportantOut-of-bandundici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
CVE-2026-9698 ↗2026-06-17azl3 perl-DBI 1.643-3 on Azure Linux 3.0ImportantOut-of-bandDBI versions before 1.648 for Perl saved errors in a limited-sized buffer
CVE-2025-15661 ↗2026-06-27azl3 libssh2 1.11.1-2 on Azure Linux 3.0ModerateOut-of-bandlibssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c
CVE-2025-71313 ↗2026-06-05azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandPCI: endpoint: Add missing NULL check for alloc_workqueue()
CVE-2025-71315 ↗2026-06-10azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/vkms: Convert to DRM's vblank timer
CVE-2026-0864 ↗2026-06-27azl3 python3 3.12.9-11 on Azure Linux 3.0ModerateOut-of-bandConfiguration Injection via Carriage Return (\r) in write() method
CVE-2026-10098 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ModerateOut-of-bandOCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status
CVE-2026-10592 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ModerateOut-of-bandWildcard DNS SAN bypasses CA name-constraint checks
CVE-2026-11526 ↗2026-06-15azl3 gd 2.3.3-4 on Azure Linux 3.0ModerateOut-of-bandGD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle
CVE-2026-11625 ↗2026-07-01azl3 perl-Bytes-Random-Secure 0.29-22 on Azure Linux 3.0ModerateOut-of-bandBytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes
CVE-2026-11703 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ModerateOut-of-bandMissing SNI/ALPN binding on stateful (session-ID) TLS session resumption
CVE-2026-12003 ↗2026-06-21azl3 python3 3.12.9-11 on Azure Linux 3.0ModerateOut-of-bandCPython >3.11 Insecure Input Validation resulting in privilege escalation
CVE-2026-12340 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ModerateOut-of-bandOut-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation
CVE-2026-12725 ↗2026-06-27azl3 dnsmasq 2.92-1 on Azure Linux 3.0ModerateOut-of-bandDnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies
CVE-2026-12969 ↗2026-06-27azl3 dnsmasq 2.92-1 on Azure Linux 3.0ModerateOut-of-bandDnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation
CVE-2026-13201 ↗2026-06-27azl3 kubevirt 1.7.1-7 on Azure Linux 3.0ModerateOut-of-bandKubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level vm disruption
CVE-2026-13208 ↗2026-07-01azl3 kubevirt 1.7.1-7 on Azure Linux 3.0ModerateOut-of-bandKubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request body
CVE-2026-13218 ↗2026-07-01azl3 kubevirt 1.7.1-7 on Azure Linux 3.0ModerateOut-of-bandKubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcher
CVE-2026-13318 ↗2026-07-01azl3 kubevirt 1.7.1-7 on Azure Linux 3.0ModerateOut-of-bandVirt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-agent-reported ip
CVE-2026-13595 ↗2026-07-01azl3 util-linux 2.40.2-4 on Azure Linux 3.0ModerateOut-of-bandUtil-linux: util-linux: heap use-after-free in libblkid nested partition probing
CVE-2026-13757 ↗2026-07-03azl3 p11-kit 0.25.0-1 on Azure Linux 3.0ModerateOut-of-bandP11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing
CVE-2026-27145 ↗2026-06-06azl3 gcc 13.2.0-7 on Azure Linux 3.0ModerateOut-of-bandInefficient candidate hostname parsing in crypto/x509
CVE-2026-29170 ↗2026-06-11azl3 httpd 2.4.67-1 on Azure Linux 3.0ModerateOut-of-bandApache HTTP Server: mod_proxy_ftp XSS
CVE-2026-3196 ↗2026-06-27azl3 qemu 9.1.0-8 on Azure Linux 3.0ModerateOut-of-bandQemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation
CVE-2026-3276 ↗2026-06-07azl3 python3 3.12.9-13 on Azure Linux 3.0ModerateOut-of-bandPotential DoS via quadratic complexity in unicodedata.normalize()
CVE-2026-34355 ↗2026-06-11azl3 httpd 2.4.67-1 on Azure Linux 3.0ModerateOut-of-bandApache HTTP Server: mod_proxy_html buffer overflow
CVE-2026-34356 ↗2026-06-11azl3 httpd 2.4.67-1 on Azure Linux 3.0ModerateOut-of-bandApache HTTP Server: ProxyPassReverseCookieMap buffer overflow
CVE-2026-40930 ↗2026-06-09azl3 libpng 1.6.58-1 on Azure Linux 3.0ModerateLIBPNG: Chunk smuggling in push-mode APNG parser via unconsumed chunk body
CVE-2026-41992 ↗2026-06-30azl3 gzip 1.13-1 on Azure Linux 3.0ModerateOut-of-bandGlobal Buffer Overflow in GNU gzip
CVE-2026-42014 ↗2026-06-19azl3 gnutls 3.8.3-11 on Azure Linux 3.0ModerateOut-of-bandGnutls: fix use-after-free in gnutls_pkcs11_token_set_pin
CVE-2026-42507 ↗2026-06-05azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandArbitrary inputs are included in errors without any escaping in net/textproto
CVE-2026-42535 ↗2026-06-11azl3 httpd 2.4.67-1 on Azure Linux 3.0ModerateOut-of-bandApache HTTP Server: mod_dav_fs protected directory access
CVE-2026-42766 ↗2026-06-13azl3 cloud-hypervisor 51.1.56-1 on Azure Linux 3.0ModerateOut-of-bandPossible NULL Dereference in Password-Based CMS Decryption
CVE-2026-42767 ↗2026-06-13azl3 cloud-hypervisor 51.1.56-1 on Azure Linux 3.0ModerateOut-of-bandNULL Pointer Dereference in CRMF EncryptedValue Decryption
CVE-2026-42769 ↗2026-06-13azl3 nodejs 24.14.1-3 on Azure Linux 3.0ModerateOut-of-bandTrust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate
CVE-2026-4367 ↗2026-06-25azl3 libXpm 3.5.17-1 on Azure Linux 3.0ModerateOut-of-bandLibxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing
CVE-2026-43951 ↗2026-06-11azl3 httpd 2.4.67-1 on Azure Linux 3.0ModerateOut-of-bandApache HTTP Server: OOB Read in `merge_response_headers` can cause crash
CVE-2026-43973 ↗2026-06-17azl3 rabbitmq-server 3.13.7-6 on Azure Linux 3.0ModerateOut-of-bandgun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion
CVE-2026-44119 ↗2026-06-11azl3 httpd 2.4.67-1 on Azure Linux 3.0ModerateOut-of-bandApache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules
CVE-2026-44186 ↗2026-06-11azl3 httpd 2.4.67-1 on Azure Linux 3.0ModerateOut-of-bandApache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp
CVE-2026-44889 ↗2026-06-28azl3 python-webob 1.8.8-1 on Azure Linux 3.0ModerateOut-of-bandWebOb: Location header normalization during redirect leads to open redirect
CVE-2026-44967 ↗2026-06-14azl3 ceph 18.2.2-12 on Azure Linux 3.0ModerateOut-of-bandopentelemetry-cpp: OTLP HTTP exporters read unbounded HTTP response
CVE-2026-45446 ↗2026-06-13azl3 cloud-hypervisor 51.1.56-1 on Azure Linux 3.0ModerateOut-of-bandIncorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes
CVE-2026-46245 ↗2026-06-05azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Fix dc_link NULL handling in HPD init
CVE-2026-46250 ↗2026-06-05azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandMIPS: Work around LLVM bug when gp is used as global register variable
CVE-2026-46254 ↗2026-06-05azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandAppArmor: Allow apparmor to handle unaligned dfa tables
CVE-2026-46273 ↗2026-06-05azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandibmveth: Disable GSO for packets with small MSS
CVE-2026-46280 ↗2026-06-10azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandlib: test_hmm: evict device pages on file close to avoid use-after-free
CVE-2026-46282 ↗2026-06-10azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandiio: frequency: admv1013: fix NULL pointer dereference on str
CVE-2026-46287 ↗2026-06-10azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: txgbe: fix RTNL assertion warning when remove module
CVE-2026-46289 ↗2026-06-10azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandlib/scatterlist: fix length calculations in extract_kvec_to_sg
CVE-2026-46291 ↗2026-06-10azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: caam - guard HMAC key hex dumps in hash_digest_key
CVE-2026-46292 ↗2026-06-10azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandpmdomain: core: Fix detach procedure for virtual devices in genpd
CVE-2026-46296 ↗2026-06-10azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: s3c64xx: fix NULL-deref on driver unbind
CVE-2026-46299 ↗2026-06-10azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandhfsplus: fix held lock freed on hfsplus_fill_super()
CVE-2026-46302 ↗2026-06-10azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandselinux: allow multiple opens of /sys/fs/selinux/policy
CVE-2026-46303 ↗2026-06-10azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandisofs: validate Rock Ridge CE continuation extent against volume size
CVE-2026-46304 ↗2026-06-10azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free
CVE-2026-46307 ↗2026-06-10azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: ath5k: do not access array OOB
CVE-2026-46312 ↗2026-06-10azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmedia: videobuf2: Set vma_flags in vb2_dma_sg_mmap
CVE-2026-46314 ↗2026-06-10azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/v3d: Reject empty multisync extension to prevent infinite loop
CVE-2026-46321 ↗2026-06-10azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandtun: free page on short-frame rejection in tun_xdp_one()
CVE-2026-46322 ↗2026-06-10azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandtun: free page on build_skb failure in tun_xdp_one()
CVE-2026-46323 ↗2026-06-10azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: gro: don't merge zcopy skbs
CVE-2026-46325 ↗2026-06-10azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE
CVE-2026-46433 ↗2026-06-11azl3 lldpd 1.0.17-2 on Azure Linux 3.0ModerateOut-of-bandlldpd: Heap OOB Read in VLAN Decapsulation memmove
CVE-2026-46683 ↗2026-06-12azl3 snappy 1.1.10-2 on Azure Linux 3.0ModerateOut-of-bandSnappy: SSRF and local file read via the xsl-style-sheet option
CVE-2026-47167 ↗2026-06-13azl3 vim 9.2.0488-1 on Azure Linux 3.0ModerateOut-of-bandVim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regex
CVE-2026-47240 ↗2026-06-27azl3 ruby 3.3.5-8 on Azure Linux 3.0ModerateOut-of-bandNet::IMAP: Command Injection via non-synchronizing literal in "raw" argument
CVE-2026-47242 ↗2026-06-27azl3 ruby 3.3.5-8 on Azure Linux 3.0ModerateOut-of-bandNet::IMAP: Command Injection via ID command argument
CVE-2026-47770 ↗2026-06-27azl3 jq 1.7.1-6 on Azure Linux 3.0ModerateOut-of-bandjq: stack overflow in deep structural equality
CVE-2026-48142 ↗2026-06-27azl3 nginx 1.28.3-4 on Azure Linux 3.0ModerateOut-of-bandNGINX ngx_http_charset_module vulnerability
CVE-2026-48858 ↗2026-06-17azl3 erlang 26.2.5.20-1 on Azure Linux 3.0ModerateOut-of-bandftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacks
CVE-2026-48913 ↗2026-06-11azl3 httpd 2.4.67-1 on Azure Linux 3.0ModerateOut-of-bandApache HTTP Server: mod_http2 memory corruption when file handles exhausted
CVE-2026-48914 ↗2026-06-17azl3 qemu 9.1.0-8 on Azure Linux 3.0ModerateOut-of-bandQemu-kvm: heap buffer overflow in virtio-blk scsi request handling
CVE-2026-49760 ↗2026-06-17azl3 erlang 26.2.5.20-1 on Azure Linux 3.0ModerateOut-of-bandStack Buffer Overflow in ei_s_print_term at Very Large Integer
CVE-2026-49762 ↗2026-06-10azl3 elixir 1.16.1-1 on Azure Linux 3.0ModerateOut-of-bandUnbounded integer parsing in the Version module enables CPU and memory exhaustion denial of service
CVE-2026-50219 ↗2026-06-05azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-bandlibexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
CVE-2026-50257 ↗2026-06-09azl3 xorg-x11-server-Xwayland 24.1.6-4 on Azure Linux 3.0ModerateXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in misyncdestroyfence()
CVE-2026-50260 ↗2026-06-09azl3 xorg-x11-server-Xwayland 24.1.6-4 on Azure Linux 3.0ModerateXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter()
CVE-2026-50262 ↗2026-06-09azl3 xorg-x11-server-Xwayland 24.1.6-4 on Azure Linux 3.0ModerateXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes
CVE-2026-50263 ↗2026-06-09azl3 xorg-x11-server-Xwayland 24.1.6-4 on Azure Linux 3.0ModerateXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow()
CVE-2026-50265 ↗2026-06-09azl3 libinput 1.25.0-1 on Azure Linux 3.0ModerateRejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292
CVE-2026-52859 ↗2026-06-13azl3 vim 9.2.0488-1 on Azure Linux 3.0ModerateOut-of-bandVim: Out-of-bounds Read in Terminal Screen Snapshot
CVE-2026-52915 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: ip6t_hbh: reject oversized option lists
CVE-2026-52916 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandbatman-adv: frag: disallow unicast fragment in fragment
CVE-2026-52917 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandsctp: diag: reject stale associations in dump_one path
CVE-2026-52918 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: serialize accept_q access
CVE-2026-52920 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: xt_policy: fix strict mode inbound policy matching
CVE-2026-52921 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: ipset: stop hash:* range iteration at end
CVE-2026-52924 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandsctp: purge outqueue on stale COOKIE-ECHO handling
CVE-2026-52925 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandvrf: Fix a potential NPD when removing a port from a VRF
CVE-2026-52927 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: ebtables: fix OOB read in compat_mtw_from_user
CVE-2026-52928 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandaf_unix: Reject SIOCATMARK on non-stream sockets
CVE-2026-52929 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandsctp: stream: fully roll back denied add-stream state
CVE-2026-52930 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandipc/shm: serialize orphan cleanup with shm_nattch updates
CVE-2026-52933 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandio_uring/poll: fix signed comparison in io_poll_get_ownership()
CVE-2026-52936 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: jitterentropy - replace long-held spinlock with mutex
CVE-2026-52937 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandtap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR
CVE-2026-52941 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint
CVE-2026-52942 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nf_log: validate MAC header was set before dumping it
CVE-2026-52946 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandfs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
CVE-2026-52948 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandi2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl
CVE-2026-52954 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandlibceph: handle rbtree insertion error in decode_choose_args()
CVE-2026-52955 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandlibceph: Fix potential out-of-bounds access in crush_decode()
CVE-2026-52957 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandlibceph: Fix potential null-ptr-deref in decode_choose_args()
CVE-2026-52958 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandlibceph: Fix potential out-of-bounds access in osdmap_decode()
CVE-2026-52960 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandceph: put folios not suitable for writeback
CVE-2026-52961 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size
CVE-2026-52963 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: usb-audio: Bound MIDI endpoint descriptor scans
CVE-2026-52964 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans
CVE-2026-52967 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandsmb/client: fix possible infinite loop and oob read in symlink_data()
CVE-2026-52968 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic
CVE-2026-52969 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: Reject wrapped offset in kvm_reset_dirty_gfn()
CVE-2026-52970 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nft_ct: fix missing expect put in obj eval
CVE-2026-52974 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: tls: fix strparser anchor skb leak on offload RX setup failure
CVE-2026-52975 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbonding: 3ad: implement proper RCU rules for port->aggregator
CVE-2026-52977 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandfutex: Prevent lockup in requeue-PI during signal/ timeout wakeup
CVE-2026-52981 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandneigh: let neigh_xmit take skb ownership
CVE-2026-52982 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()
CVE-2026-52984 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/sched: netem: fix queue limit check to include reordered packets
CVE-2026-52985 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetdevsim: zero initialize struct iphdr in dummy sk_buff
CVE-2026-52986 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nf_conntrack_sip: don't use simple_strtoul
CVE-2026-52988 ↗2026-06-27azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nf_tables: join hook list via splice_list_rcu() in commit phase
CVE-2026-52992 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandfs/adfs: validate nzones in adfs_validate_bblk()
CVE-2026-52996 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: fix durable fd leak on ClientGUID mismatch in durable v2 open
CVE-2026-52998 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nfnetlink_osf: fix potential NULL dereference in ttl check
CVE-2026-52999 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nfnetlink_osf: fix out-of-bounds read on option matching
CVE-2026-53003 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandpppoe: drop PFC frames
CVE-2026-53006 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandipv6: fix possible UAF in icmpv6_rcv()
CVE-2026-53011 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/sched: taprio: fix use-after-free in advance_sched() on schedule switch
CVE-2026-53012 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnexthop: fix IPv6 route referencing IPv4 nexthop
CVE-2026-53013 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmacvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF
CVE-2026-53015 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-banderofs: unify lcn as u64 for 32-bit platforms
CVE-2026-53016 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: ccp - copy IV using skcipher ivsize
CVE-2026-53021 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: target: core: Fix integer overflow in UNMAP bounds check
CVE-2026-53022 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandplatform/x86: dell-wmi-sysman: bound enumeration string aggregation
CVE-2026-53024 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandgreybus: raw: fix use-after-free if write is called after disconnect
CVE-2026-53032 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Fix NULL deref in map_kptr_match_type for scalar regs
CVE-2026-53034 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf, sockmap: Fix af_unix null-ptr-deref in proto update
CVE-2026-53035 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf, sockmap: Fix af_unix iter deadlock
CVE-2026-53037 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandHID: usbhid: fix deadlock in hid_post_reset()
CVE-2026-53041 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandocfs2: fix listxattr handling when the buffer is full
CVE-2026-53046 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: fix use-after-free from async crypto on Qualcomm crypto engine
CVE-2026-53047 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandefi/capsule-loader: fix incorrect sizeof in phys array reallocation
CVE-2026-53048 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandgfs2: prevent NULL pointer dereference during unmount
CVE-2026-53050 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandquota: Fix race of dquot_scan_active() with quota deactivation
CVE-2026-53056 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/msm/dpu: fix mismatch between power and frequency
CVE-2026-53058 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier in atomic_enable()
CVE-2026-53059 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddm log: fix out-of-bounds write due to region_count overflow
CVE-2026-53060 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddm cache metadata: fix memory leak on metadata abort retry
CVE-2026-53061 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddm cache: fix dirty mapping checking in passthrough mode switching
CVE-2026-53063 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddm cache: fix write hang in passthrough mode
CVE-2026-53064 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddm cache: fix null-deref with concurrent writes in passthrough mode
CVE-2026-53065 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandASoC: sti: use managed regmap_field allocations
CVE-2026-53066 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/sun4i: backend: fix error pointer dereference
CVE-2026-53070 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandsctp: disable BH before calling udp_tunnel_xmit_skb()
CVE-2026-53071 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp
CVE-2026-53072 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER
CVE-2026-53073 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error
CVE-2026-53074 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb
CVE-2026-53076 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Fix OOB in pcpu_init_value
CVE-2026-53078 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Fix same-register dst/src OOB read and pointer leak in sock_ops
CVE-2026-53080 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/sched: cls_fw: fix NULL dereference of "old" filters before change()
CVE-2026-53082 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: hamradio: 6pack: fix uninit-value in sixpack_receive_buf
CVE-2026-53088 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: bcmgenet: fix off-by-one in bcmgenet_put_txcb
CVE-2026-53091 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: pull headers in qdisc_pkt_len_segs_init()
CVE-2026-53093 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: brcmfmac: Fix error pointer dereference
CVE-2026-53094 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Fix stale offload->prog pointer after constant blinding
CVE-2026-53096 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path
CVE-2026-53098 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work()
CVE-2026-53102 ↗2026-06-27azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req()
CVE-2026-53106 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Do not allow deleting local storage in NMI
CVE-2026-53109 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandpowerpc/pgtable-frag: Fix bad page state in pte_frag_destroy
CVE-2026-53110 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bands390/bpf: Zero-extend bpf prog return values and kfunc arguments
CVE-2026-53111 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap
CVE-2026-53112 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet
CVE-2026-53113 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: ath11k: fix memory leaks in beacon template setup
CVE-2026-53115 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandbus: fsl-mc: use generic driver_override infrastructure
CVE-2026-53118 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandvdpa: use generic driver_override infrastructure
CVE-2026-53120 ↗2026-06-27azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandPCI: use generic driver_override infrastructure
CVE-2026-53122 ↗2026-06-27azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix deadlock between reflink and transaction commit when using flushoncommit
CVE-2026-53126 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandblk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current()
CVE-2026-53128 ↗2026-06-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrbd: Balance RCU calls in drbd_adm_dump_devices()
CVE-2026-53129 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandfs/mbcache: cancel shrink work before destroying the cache
CVE-2026-53131 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: require Ethernet MAC header before using eth_hdr()
CVE-2026-53132 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandvsock/virtio: fix potential unbounded skb queue
CVE-2026-53133 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/umem: Fix truncation for block sizes >= 4G
CVE-2026-53135 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs
CVE-2026-53136 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Clamp VBIOS HDMI retimer register count to array size
CVE-2026-53137 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size
CVE-2026-53138 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Bound VBIOS record-chain walk loops
CVE-2026-53139 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/v3d: Skip CSD when it has zeroed workgroups
CVE-2026-53146 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandthunderbolt: Limit XDomain response copy to actual frame size
CVE-2026-53147 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandthunderbolt: Validate XDomain request packet size before type cast
CVE-2026-53148 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandthunderbolt: Clamp XDomain response data copy to allocation size
CVE-2026-53149 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandthunderbolt: Bound root directory content to block size
CVE-2026-53150 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandthunderbolt: Reject zero-length property entries in validator
CVE-2026-53151 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandrxrpc: Fix the ACK parser to extract the SACK table for parsing
CVE-2026-53154 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandmm/hugetlb: restore reservation on error in hugetlb folio copy paths
CVE-2026-53156 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandnvmem: core: fix use-after-free bugs in error paths
CVE-2026-53158 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandmisc: fastrpc: Fix NULL pointer dereference in rpmsg callback
CVE-2026-53161 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandmisc: fastrpc: fix use-after-free of fastrpc_user in workqueue context
CVE-2026-53163 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandlocking/rtmutex: Skip remove_waiter() when waiter is not enqueued
CVE-2026-53166 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandfutex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlock
CVE-2026-53167 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandfuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios
CVE-2026-53168 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandfuse: reject fuse_notify() pagecache ops on directories
CVE-2026-53177 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandbnxt_en: Fix NULL pointer dereference
CVE-2026-53178 ↗2026-06-27azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandstaging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction
CVE-2026-53179 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandstaging: rtl8723bs: fix buffer over-read in rtw_update_protection
CVE-2026-53181 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandvsock/vmci: fix sk_ack_backlog leak on failed handshake
CVE-2026-53182 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: nl80211: reject oversized EMA RNR lists
CVE-2026-53183 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandmptcp: allow subflow rcv wnd to shrink
CVE-2026-53184 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandudp: clear skb->dev before running a sockmap verdict
CVE-2026-53186 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/srp: bound SRP_RSP sense copy by the received length
CVE-2026-53190 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait()
CVE-2026-53192 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: timer: Fix UAF at snd_timer_user_params()
CVE-2026-53195 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandUSB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()
CVE-2026-53199 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandhv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf
CVE-2026-53207 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandmm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison
CVE-2026-53208 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig
CVE-2026-53209 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: hci_sync: reject oversized Broadcast Announcement prepend
CVE-2026-53212 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nft_tunnel: fix use-after-free on object destroy
CVE-2026-53213 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/vc4: fix krealloc() memory leak
CVE-2026-53214 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandipv6: Fix a potential NPD in cleanup_prefix_route()
CVE-2026-53217 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: mvpp2: sync RX data at the hardware packet offset
CVE-2026-53218 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nft_exthdr: fix register tracking for F_PRESENT flag
CVE-2026-53219 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: x_tables: avoid leaking percpu counter pointers
CVE-2026-53220 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: revalidate bridge ports
CVE-2026-53221 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()
CVE-2026-53223 ↗2026-07-04azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: guard timestamp cmsgs to real error queue skbs
CVE-2026-53225 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandsctp: fix uninit-value in __sctp_rcv_asconf_lookup()
CVE-2026-53226 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandgpio: rockchip: fix generic IRQ chip leak on remove
CVE-2026-53227 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: openvswitch: fix possible kfree_skb of ERR_PTR
CVE-2026-53228 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandipv6: sit: reload inner IPv6 header after GSO offloads
CVE-2026-53229 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure
CVE-2026-53230 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list
CVE-2026-53232 ↗2026-06-27azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: phy: clean the sfp upstream if phy probing fails
CVE-2026-53236 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandtcp: restrict SO_ATTACH_FILTER to priv users
CVE-2026-53237 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandgpio: mvebu: fix NULL pointer dereference in suspend/resume
CVE-2026-53238 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetlabel: validate unlabeled address and mask attribute lengths
CVE-2026-53239 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandxfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()
CVE-2026-53242 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
CVE-2026-53245 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr
CVE-2026-53249 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandipv4: restrict IPOPT_SSRR and IPOPT_LSRR options
CVE-2026-53252 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: fix memory leak in error path of hci_alloc_dev()
CVE-2026-53253 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: bnep: reject short frames before parsing
CVE-2026-53254 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: RFCOMM: validate skb length in MCC handlers
CVE-2026-53255 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: MGMT: validate advertising TLV before type checks
CVE-2026-53258 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: fix leak if split 6 GHz scanning fails
CVE-2026-53263 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-band6lowpan: fix off-by-one in multicast context address compression
CVE-2026-53264 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/sched: act_api: use RCU with deferred freeing for action lifecycle
CVE-2026-53265 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-banddm cache policy smq: check allocation under invalidate lock
CVE-2026-53266 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: bridge: make ebt_snat ARP rewrite writable
CVE-2026-53267 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nft_ct: bail out on template ct in get eval
CVE-2026-53268 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: conntrack_irc: fix possible out-of-bounds read
CVE-2026-53269 ↗2026-07-09azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: synproxy: add mutex to guard hook reference counting
CVE-2026-53270 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandipvs: clear the svc scheduler ptr early on edit
CVE-2026-53274 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS
CVE-2026-53275 ↗2026-06-27azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandipv6: mcast: Fix use-after-free when processing MLD queries
CVE-2026-53279 ↗2026-06-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/gma500/oaktrail_lvds: fix hang on init failure
CVE-2026-53287 ↗2026-06-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandaudit: fix incorrect inheritable capability in CAPSET records
CVE-2026-53289 ↗2026-06-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandice: fix NULL pointer dereference in ice_reset_all_vfs()
CVE-2026-53291 ↗2026-06-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: hda/conexant: Fix missing error check for jack detection
CVE-2026-53292 ↗2026-06-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: phonet: do not BUG_ON() in pn_socket_autobind() on failed bind
CVE-2026-53293 ↗2026-06-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG
CVE-2026-53294 ↗2026-06-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmailbox: mailbox-test: don't free the reused channel
CVE-2026-53295 ↗2026-06-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmailbox: add sanity check for channel array
CVE-2026-53296 ↗2026-06-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmailbox: mailbox-test: free channels on probe error
CVE-2026-53297 ↗2026-06-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: mana: Guard mana_remove against double invocation
CVE-2026-53304 ↗2026-06-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: sg: Resolve soft lockup issue when opening /dev/sgX
CVE-2026-53313 ↗2026-06-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths
CVE-2026-53314 ↗2026-06-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandpadata: Put CPU offline callback in ONLINE section to allow failure
CVE-2026-53317 ↗2026-07-08azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mt76: mt7921: Place upper limit on station AID
CVE-2026-53320 ↗2026-06-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty()
CVE-2026-53325 ↗2026-06-30azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandagp/amd64: Fix broken error propagation in agp_amd64_probe()
CVE-2026-53655 ↗2026-06-28azl3 tar 1.35-2 on Azure Linux 3.0ModerateOut-of-bandnode-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)
CVE-2026-53689 ↗2026-06-19azl3 libnfs 5.0.2-1 on Azure Linux 3.0ModerateOut-of-band
CVE-2026-54371 ↗2026-06-30azl3 acl 2.3.1-2 on Azure Linux 3.0ModerateOut-of-bandattr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr
CVE-2026-54411 ↗2026-06-16azl3 pam 1.5.3-5 on Azure Linux 3.0ModerateOut-of-bandLinux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.
CVE-2026-54679 ↗2026-06-27azl3 jq 1.7.1-6 on Azure Linux 3.0ModerateOut-of-bandjq: potential integer overflow in jvp_string_append
CVE-2026-55653 ↗2026-06-27azl3 openssh 9.8p1-6 on Azure Linux 3.0ModerateOut-of-bandOpenssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service
CVE-2026-55655 ↗2026-06-27azl3 openssh 9.8p1-6 on Azure Linux 3.0ModerateOut-of-bandOpenssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions
CVE-2026-55693 ↗2026-06-27azl3 vim 9.2.0620-1 on Azure Linux 3.0ModerateOut-of-bandVim: Out-of-bounds Write in Spell File Word Count
CVE-2026-55892 ↗2026-06-27azl3 vim 9.2.0488-1 on Azure Linux 3.0ModerateOut-of-bandVim: Out-of-bounds Write in Spell File Prefix Dump
CVE-2026-55895 ↗2026-06-27azl3 vim 9.2.0488-1 on Azure Linux 3.0ModerateOut-of-bandVim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename
CVE-2026-55962 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ModerateOut-of-bandTLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerify
CVE-2026-55964 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ModerateOut-of-bandChain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temporary CA exemption)
CVE-2026-56115 ↗2026-06-27azl3 dhcpcd 10.0.8-1 on Azure Linux 3.0ModerateOut-of-bandBootimus 0.1.70 Broken Access Control via JWTMiddleware Authorization Bypass
CVE-2026-56116 ↗2026-06-27azl3 dhcpcd 10.0.8-4 on Azure Linux 3.0ModerateOut-of-banddhcpcd Memory Leak DoS via IPv6 Router Advertisement Handling
CVE-2026-56131 ↗2026-06-27azl3 cmake 3.30.3-13 on Azure Linux 3.0ModerateOut-of-bandlibexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
CVE-2026-56132 ↗2026-06-27azl3 cmake 3.30.3-13 on Azure Linux 3.0ModerateOut-of-bandIn libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.
CVE-2026-56403 ↗2026-06-27azl3 python3 3.12.9-11 on Azure Linux 3.0ModerateOut-of-bandlibexpat before 2.8.2 has an integer overflow in storeAtts.
CVE-2026-56404 ↗2026-06-27azl3 python3 3.12.9-13 on Azure Linux 3.0ModerateOut-of-bandlibexpat before 2.8.2 has an integer overflow in addBinding.
CVE-2026-56405 ↗2026-06-27azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-bandlibexpat before 2.8.2 has an integer overflow in getAttributeId.
CVE-2026-56406 ↗2026-06-27azl3 cmake 3.30.3-13 on Azure Linux 3.0ModerateOut-of-bandlibexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
CVE-2026-56407 ↗2026-06-27azl3 python3 3.12.9-11 on Azure Linux 3.0ModerateOut-of-bandlibexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
CVE-2026-56409 ↗2026-06-27azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-bandxmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
CVE-2026-56410 ↗2026-06-27azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-bandxmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
CVE-2026-56411 ↗2026-06-27azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-bandxmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
CVE-2026-56412 ↗2026-06-27azl3 cmake 3.30.3-14 on Azure Linux 3.0ModerateOut-of-bandlibexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.
CVE-2026-57436 ↗2026-06-27azl3 rubygem-nokogiri 1.15.4-1 on Azure Linux 3.0ModerateOut-of-bandNokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
CVE-2026-57437 ↗2026-06-27azl3 rubygem-nokogiri 1.15.4-1 on Azure Linux 3.0ModerateOut-of-bandNokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
CVE-2026-57438 ↗2026-06-27azl3 rubygem-nokogiri 1.15.4-1 on Azure Linux 3.0ModerateOut-of-bandNokogiri: Possible Use-After-Free in XInclude Processing
CVE-2026-57451 ↗2026-06-27azl3 vim 9.2.0620-1 on Azure Linux 3.0ModerateOut-of-bandVim: Out-of-bounds Read in Text Property Count
CVE-2026-57452 ↗2026-06-27azl3 vim 9.2.0488-1 on Azure Linux 3.0ModerateOut-of-bandVim: Out-of-bounds Read with libsodium-encrypted Files
CVE-2026-57453 ↗2026-06-27azl3 vim 9.2.0620-1 on Azure Linux 3.0ModerateOut-of-bandVim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction
CVE-2026-57454 ↗2026-06-27azl3 vim 9.2.0488-1 on Azure Linux 3.0ModerateOut-of-bandVim: Out-of-bounds Read with Text Properties
CVE-2026-57455 ↗2026-06-27azl3 vim 9.2.0488-1 on Azure Linux 3.0ModerateOut-of-bandVim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argument
CVE-2026-58010 ↗2026-07-01azl3 glib 2.78.6-9 on Azure Linux 3.0ModerateOut-of-bandGlib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()
CVE-2026-58011 ↗2026-07-01azl3 glib 2.78.6-9 on Azure Linux 3.0ModerateOut-of-bandGlib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime
CVE-2026-58012 ↗2026-07-01azl3 glib 2.78.6-9 on Azure Linux 3.0ModerateOut-of-bandGlib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()
CVE-2026-58013 ↗2026-07-01azl3 glib 2.78.6-9 on Azure Linux 3.0ModerateOut-of-bandGlib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"
CVE-2026-58015 ↗2026-07-01azl3 glib 2.78.6-9 on Azure Linux 3.0ModerateOut-of-bandGlib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive
CVE-2026-58016 ↗2026-07-01azl3 glib 2.78.6-9 on Azure Linux 3.0ModerateOut-of-bandGlib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
CVE-2026-58055 ↗2026-06-29azl3 fluent-bit 3.1.10-6 on Azure Linux 3.0ModerateOut-of-bandnghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length
CVE-2026-58058 ↗2026-06-29azl3 nmap 7.95-4 on Azure Linux 3.0ModerateOut-of-bandNmap - Integer Underflow in IPv6 Extension Header Parsing
CVE-2026-6091 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ModerateOut-of-bandPartial-chain verification accepts untrusted intermediate as trust anchor
CVE-2026-6094 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ModerateOut-of-bandHeap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedData
CVE-2026-6291 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ModerateOut-of-bandBleichenbacher padding oracle in PKCS#7 KTRI RSA PKCS#1 v1.5 decryption
CVE-2026-6329 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ModerateOut-of-bandPKCS#12 MAC verification uses attacker-controlled comparison length
CVE-2026-6330 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ModerateOut-of-bandML-KEM ARM64 NEON ciphertext comparison only compares half of the input
CVE-2026-6731 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ModerateOut-of-bandX.509 name constraint bypass via Subject CN treated as a DNS name
CVE-2026-7511 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ModerateOut-of-bandPKCS7_verify signer confusion allows forged signatures to be accepted
CVE-2026-7532 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ModerateOut-of-bandiPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined
CVE-2026-7774 ↗2026-06-07azl3 python3 3.12.9-11 on Azure Linux 3.0ModerateOut-of-bandtarfile.data_filter path traversal bypass allows writing outside the extraction directory
CVE-2026-8643 ↗2026-06-04azl3 python-virtualenv 20.36.1-4 on Azure Linux 3.0ModerateOut-of-bandpip can extract console_scripts and gui_scripts outside installation directory
CVE-2026-8720 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0ModerateOut-of-bandHMAC-BLAKE2 final discards message when key length exceeds block size
CVE-2026-9539 ↗2026-06-27azl3 libslirp 4.7.0-1 on Azure Linux 3.0ModerateOut-of-bandlibslirp TCP URG OOB Read Information Leak
CVE-2026-9669 ↗2026-06-19azl3 python3 3.12.9-11 on Azure Linux 3.0ModerateOut-of-bandbz2.BZ2Decompressor reuse after error can cause a stack buffer overflow
CVE-2026-10275 ↗2026-06-05azl3 opensc 0.27.1-2 on Azure Linux 3.0LowOut-of-bandOpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer overflow
CVE-2026-10512 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0LowOut-of-bandX25519 x86_64 assembly final reduction leaves non-canonical field element
CVE-2026-10722 ↗2026-06-07azl3 containerd2 2.2.4-2 on Azure Linux 3.0LowOut-of-bandcilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow
CVE-2026-11525 ↗2026-06-27azl3 nodejs 24.17.0-1 on Azure Linux 3.0LowOut-of-bandundici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
CVE-2026-11623 ↗2026-06-21azl3 tmux 3.4-2 on Azure Linux 3.0LowOut-of-bandtmux image.c image_free use after free
CVE-2026-11979 ↗2026-06-30azl3 libxml2 2.11.5-10 on Azure Linux 3.0LowOut-of-bandStack-Based Buffer Overflow in libxml2
CVE-2026-13322 ↗2026-07-01azl3 kubevirt 1.7.1-7 on Azure Linux 3.0LowOut-of-bandKubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of service
CVE-2026-41991 ↗2026-06-30azl3 gzip 1.13-1 on Azure Linux 3.0LowOut-of-bandPredictable Temporary File in GNU gzip
CVE-2026-42768 ↗2026-06-13azl3 openssl 3.3.7-1 on Azure Linux 3.0LowOut-of-bandMulti-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()
CVE-2026-42770 ↗2026-07-21azl3 openssl 3.3.7-3 on Azure Linux 3.0LowOut-of-bandFFC-DH Peer Validation Uses Attacker-Supplied q
CVE-2026-4360 ↗2026-07-03azl3 python3 3.12.9-13 on Azure Linux 3.0LowOut-of-bandTarfile.extract() doesn't fully respect filter parameter
CVE-2026-43966 ↗2026-06-19azl3 rabbitmq-server 3.13.7-5 on Azure Linux 3.0LowOut-of-bandHTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2
CVE-2026-46252 ↗2026-06-05azl3 kernel 6.6.141.1-1 on Azure Linux 3.0LowOut-of-bandregulator: core: fix locking in regulator_resolve_supply() error path
CVE-2026-46272 ↗2026-06-05azl3 kernel 6.6.139.1-1 on Azure Linux 3.0LowOut-of-bandcoresight: tmc-etr: Fix race condition between sysfs and perf mode
CVE-2026-47241 ↗2026-06-27azl3 ruby 3.3.5-8 on Azure Linux 3.0LowOut-of-bandNet::IMAP: Denial of Service via incomplete raw argument validation
CVE-2026-48855 ↗2026-06-17azl3 erlang 26.2.5.20-1 on Azure Linux 3.0LowOut-of-bandSFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is Configured
CVE-2026-49356 ↗2026-06-27azl3 babel 2.15.0-1 on Azure Linux 3.0LowOut-of-bandBabel: Arbitrary File Read via sourceMappingURL Comment in @babel/core
CVE-2026-5419 ↗2026-06-07azl3 gnutls 3.8.3-11 on Azure Linux 3.0LowOut-of-bandGuntls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal
CVE-2026-54905 ↗2026-06-27azl3 rubygem-concurrent-ruby 1.2.2-1 on Azure Linux 3.0LowOut-of-bandconcurrent-ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity
CVE-2026-54906 ↗2026-06-27azl3 rubygem-concurrent-ruby 1.2.2-1 on Azure Linux 3.0LowOut-of-bandconcurrent-ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption
CVE-2026-55967 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0LowOut-of-bandAES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enabling counter wrap and keystream reuse
CVE-2026-57062 ↗2026-06-27azl3 gnupg2 2.4.9-2 on Azure Linux 3.0LowOut-of-bandCMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.
CVE-2026-57234 ↗2026-06-27azl3 rubygem-nokogiri 1.15.4-1 on Azure Linux 3.0LowOut-of-bandNokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
CVE-2026-6092 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0LowOut-of-bandEncrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configured
CVE-2026-6325 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0LowOut-of-bandOut-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms list
CVE-2026-6331 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0LowOut-of-bandHMAC zero-length tag forgery in EVP_DigestVerifyFinal
CVE-2026-6412 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0LowOut-of-bandContinued acceptance of SHA-1/MD5 digests in certificate processing
CVE-2026-6450 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0LowOut-of-bandCRL critical extension bypass in ParseCRL_Extensions
CVE-2026-6678 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0LowOut-of-bandInteger underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info
CVE-2026-7531 ↗2026-07-01azl3 mariadb 10.11.18-1 on Azure Linux 3.0LowOut-of-bandUse-after-free in PQC hybrid key-share handling
CVE-2026-10881 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10881 Out of bounds read and write in ANGLE
CVE-2026-10882 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10882 Use after free in Network
CVE-2026-10883 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-10883 Out of bounds write in ANGLE
CVE-2026-10884 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10884 Use after free in Chromecast
CVE-2026-10886 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10886 Use after free in FileSystem
CVE-2026-10887 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10887 Use after free in Chromoting
CVE-2026-10888 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10888 Use after free in Cast Streaming
CVE-2026-10889 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10889 Out of bounds read in ANGLE
CVE-2026-10890 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10890 Use after free in Cast
CVE-2026-10891 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10891 Use after free in GFX
CVE-2026-10892 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-10892 Out of bounds write in GPU
CVE-2026-10893 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10893 Use after free in Chromoting
CVE-2026-10894 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10894 Use after free in Printing
CVE-2026-10895 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10895 Use after free in Ozone
CVE-2026-10897 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10897 Out of bounds write in GPU
CVE-2026-10898 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10898 Stack buffer overflow in GPU
CVE-2026-10899 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10899 Use after free in Ozone
CVE-2026-10900 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10900 Use after free in Passwords
CVE-2026-10901 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10901 Use after free in Passwords
CVE-2026-10902 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10902 Use after free in Ozone
CVE-2026-10903 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10903 Use after free in WebRTC
CVE-2026-10904 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10904 Inappropriate implementation in V8
CVE-2026-10905 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10905 Use after free in Network
CVE-2026-10906 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10906 Use after free in WebAuthentication
CVE-2026-10907 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10907 Out of bounds write in ANGLE
CVE-2026-10908 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10908 Use after free in FullScreen
CVE-2026-10909 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10909 Use after free in Dawn
CVE-2026-10910 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10910 Type Confusion in V8
CVE-2026-10911 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10911 Insufficient validation of untrusted input in Media
CVE-2026-10912 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10912 Insufficient validation of untrusted input in Extensions
CVE-2026-10913 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10913 Use after free in ANGLE
CVE-2026-10914 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10914 Use after free in ANGLE
CVE-2026-10916 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10916 Insufficient validation of untrusted input in DevTools
CVE-2026-10917 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10917 Insufficient validation of untrusted input in Media
CVE-2026-10918 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10918 Use after free in Viz
CVE-2026-10919 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10919 Use after free in ANGLE
CVE-2026-10920 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10920 Insufficient validation of untrusted input in WebShare
CVE-2026-10921 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10921 Integer overflow in Dawn
CVE-2026-10922 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10922 Insufficient validation of untrusted input in DevTools
CVE-2026-10923 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-10923 Use after free in WebAppInstalls
CVE-2026-10924 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10924 Integer overflow in Chromecast
CVE-2026-10925 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10925 Out of bounds write in Skia
CVE-2026-10926 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10926 Use after free in Cast
CVE-2026-10927 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10927 Out of bounds read in Dawn
CVE-2026-10928 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10928 Script injection in Headless
CVE-2026-10929 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-10929 Heap buffer overflow in ANGLE
CVE-2026-10930 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10930 Out of bounds read in ANGLE
CVE-2026-10931 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10931 Use after free in FileSystem
CVE-2026-10932 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10932 Use after free in UI
CVE-2026-10933 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10933 Use after free in Audio
CVE-2026-10934 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-10934 Use after free in Autofill
CVE-2026-10935 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10935 Inappropriate implementation in V8
CVE-2026-10936 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10936 Type Confusion in V8
CVE-2026-10937 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10937 Inappropriate implementation in Passwords
CVE-2026-10938 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10938 Insufficient validation of untrusted input in Input
CVE-2026-10939 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10939 Use after free in WebRTC
CVE-2026-10940 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10940 Race in Codecs
CVE-2026-10941 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10941 Out of bounds memory access in Skia
CVE-2026-10942 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10942 Insufficient validation of untrusted input in UI
CVE-2026-10943 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10943 Use after free in WebRTC
CVE-2026-10945 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10945 Use after free in PDF
CVE-2026-10946 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10946 Heap buffer overflow in Media
CVE-2026-10947 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10947 Use after free in WebRTC
CVE-2026-10948 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10948 Use after free in WebRTC
CVE-2026-10949 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10949 Heap buffer overflow in Video
CVE-2026-10953 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-10953 Use after free in Core
CVE-2026-10954 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10954 Use after free in Actor
CVE-2026-10955 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10955 Type Confusion in ANGLE
CVE-2026-10956 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10956 Use after free in MimeHandlerView
CVE-2026-10957 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10957 Use after free in Glic
CVE-2026-10959 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-10959 Use after free in Input
CVE-2026-10960 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10960 Uninitialized Use in Codecs
CVE-2026-10962 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10962 Type Confusion in Media
CVE-2026-10963 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10963 Integer overflow in V8
CVE-2026-10964 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10964 Integer overflow in V8
CVE-2026-10965 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10965 Integer overflow in DevTools
CVE-2026-10966 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10966 Insufficient validation of untrusted input in Codecs
CVE-2026-10967 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-10967 Use after free in SurfaceCapture
CVE-2026-10968 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10968 Insufficient validation of untrusted input in Dawn
CVE-2026-10969 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10969 Insufficient validation of untrusted input in Extensions
CVE-2026-10970 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10970 Insufficient validation of untrusted input in InterestGroups
CVE-2026-10971 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10971 Insufficient validation of untrusted input in Printing
CVE-2026-10972 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10972 Use after free in Ozone
CVE-2026-10973 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band1%Chromium: CVE-2026-10973 Uninitialized Use in Dawn
CVE-2026-10974 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10974 Insufficient validation of untrusted input in ANGLE
CVE-2026-10975 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10975 Use after free in WebRTC
CVE-2026-10976 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10976 Uninitialized Use in Dawn
CVE-2026-10977 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10977 Uninitialized Use in Skia
CVE-2026-10978 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10978 Use after free in Chromoting
CVE-2026-10979 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10979 Out of bounds read in ANGLE
CVE-2026-10980 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10980 Insufficient validation of untrusted input in DevTools
CVE-2026-10981 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10981 Insufficient validation of untrusted input in Codecs
CVE-2026-10982 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10982 Use after free in WebXR
CVE-2026-10983 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10983 Insufficient validation of untrusted input in Dawn
CVE-2026-10984 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-10984 Inappropriate implementation in Accessibility
CVE-2026-10985 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10985 Out of bounds read in Skia
CVE-2026-10986 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10986 Integer overflow in Media
CVE-2026-10987 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10987 Integer overflow in V8
CVE-2026-10988 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10988 Use after free in Views
CVE-2026-10989 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10989 Inappropriate implementation in V8
CVE-2026-10990 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10990 Use after free in Glic
CVE-2026-10991 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10991 Use after free in V8
CVE-2026-10992 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10992 Insufficient data validation in Animation
CVE-2026-10993 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10993 Heap buffer overflow in Skia
CVE-2026-10994 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10994 Uninitialized Use in ANGLE
CVE-2026-10995 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10995 Heap buffer overflow in TabStrip
CVE-2026-10996 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10996 Inappropriate implementation in Workers
CVE-2026-10997 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10997 Insufficient policy enforcement in Extensions
CVE-2026-10998 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10998 Out of bounds read in Media
CVE-2026-10999 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10999 Out of bounds memory access in ANGLE
CVE-2026-11000 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11000 Use after free in Fonts
CVE-2026-11001 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11001 Incorrect security UI in Payments
CVE-2026-11002 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11002 Use after free in Autofill
CVE-2026-11003 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11003 Use after free in WebRTC
CVE-2026-11004 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11004 Out of bounds read in ANGLE
CVE-2026-11005 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11005 Out of bounds read in ANGLE
CVE-2026-11006 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11006 Out of bounds read in Dawn
CVE-2026-11007 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11007 Insufficient validation of untrusted input in WebView
CVE-2026-11008 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11008 Insufficient validation of untrusted input in WebAppInstalls
CVE-2026-11009 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11009 Use after free in USB
CVE-2026-11010 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11010 Use after free in WebShare
CVE-2026-11011 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11011 Insufficient policy enforcement in Password Manager
CVE-2026-11012 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11012 Use after free in Serial
CVE-2026-11013 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11013 Insufficient validation of untrusted input in Network
CVE-2026-11014 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11014 Insufficient policy enforcement in Extensions
CVE-2026-11015 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11015 Out of bounds read in WebGPU
CVE-2026-11016 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11016 Insufficient validation of untrusted input in Network
CVE-2026-11017 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11017 Inappropriate implementation in Link Preview
CVE-2026-11018 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11018 Insufficient policy enforcement in Actor
CVE-2026-11019 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11019 Inappropriate implementation in Payments
CVE-2026-11020 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11020 Inappropriate implementation in Extensions
CVE-2026-11021 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11021 Insufficient validation of untrusted input in GPU
CVE-2026-11022 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11022 Insufficient validation of untrusted input in DevTools
CVE-2026-11023 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11023 Insufficient validation of untrusted input in WebAppInstalls
CVE-2026-11024 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11024 Stack buffer overflow in Skia
CVE-2026-11025 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11025 Insufficient policy enforcement in Navigation
CVE-2026-11026 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11026 Insufficient policy enforcement in Extensions
CVE-2026-11027 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11027 Insufficient validation of untrusted input in Glic
CVE-2026-11028 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11028 Use after free in Media
CVE-2026-11029 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11029 Insufficient validation of untrusted input in Drag and Drop
CVE-2026-11030 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11030 Use after free in Network
CVE-2026-11031 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11031 Insufficient validation of untrusted input in Password Manager
CVE-2026-11032 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11032 Insufficient data validation in Password Manager
CVE-2026-11033 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11033 Uninitialized Use in WebML
CVE-2026-11034 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11034 Insufficient validation of untrusted input in Tab Group Sync
CVE-2026-11035 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11035 Insufficient validation of untrusted input in Custom Tabs
CVE-2026-11036 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11036 Inappropriate implementation in DOM
CVE-2026-11037 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11037 Out of bounds write in Codecs
CVE-2026-11038 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11038 Insufficient validation of untrusted input in Subresource Integrity
CVE-2026-11039 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11039 Uninitialized Use in Skia
CVE-2026-11040 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11040 Use after free in ANGLE
CVE-2026-11041 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11041 Insufficient validation of untrusted input in Media
CVE-2026-11042 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11042 Use after free in Views
CVE-2026-11043 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11043 Out of bounds write in ANGLE
CVE-2026-11044 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11044 Integer overflow in ANGLE
CVE-2026-11045 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11045 Insufficient validation of untrusted input in GPU
CVE-2026-11046 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11046 Insufficient validation of untrusted input in Media
CVE-2026-11047 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11047 Insufficient validation of untrusted input in Base
CVE-2026-11048 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11048 Inappropriate implementation in Extensions
CVE-2026-11049 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11049 Use after free in Password Manager
CVE-2026-11050 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11050 Use after free in V8
CVE-2026-11051 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11051 Out of bounds read in ANGLE
CVE-2026-11052 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11052 Type Confusion in GPU
CVE-2026-11053 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-bandChromium: CVE-2026-11053 VULNERABILITY in WebRTC
CVE-2026-11054 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11054 Use after free in WebRTC
CVE-2026-11055 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11055 Use after free in ANGLE
CVE-2026-11056 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11056 Insufficient validation of untrusted input in SiteIsolation
CVE-2026-11057 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11057 Uninitialized Use in Skia
CVE-2026-11058 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11058 Integer overflow in CredentialProvider
CVE-2026-11059 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11059 Use after free in Blink
CVE-2026-11060 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11060 Use after free in Media
CVE-2026-11061 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11061 Out of bounds read in ANGLE
CVE-2026-11062 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11062 Insufficient policy enforcement in Extensions
CVE-2026-11063 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11063 Insufficient validation of untrusted input in WebNN
CVE-2026-11064 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11064 Uninitialized Use in GPU
CVE-2026-11065 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11065 Use after free in ANGLE
CVE-2026-11066 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11066 Insufficient validation of untrusted input in ANGLE
CVE-2026-11067 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11067 Uninitialized Use in Dawn
CVE-2026-11068 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11068 Use after free in WebSockets
CVE-2026-11069 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11069 Insufficient validation of untrusted input in Cast
CVE-2026-11070 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11070 Insufficient validation of untrusted input in Chromoting
CVE-2026-11071 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11071 Use after free in Base
CVE-2026-11072 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11072 Use after free in WebView
CVE-2026-11073 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11073 Use after free in WebGL
CVE-2026-11074 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11074 Use after free in WebRTC
CVE-2026-11075 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11075 Out of bounds read in V8
CVE-2026-11076 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11076 Type Confusion in CSS
CVE-2026-11077 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11077 Out of bounds read in Dawn
CVE-2026-11078 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11078 Insufficient validation of untrusted input in FileSystem
CVE-2026-11079 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11079 Insufficient validation of untrusted input in Codecs
CVE-2026-11080 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11080 Use after free in WebView
CVE-2026-11081 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11081 Policy bypass in Canvas
CVE-2026-11082 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11082 Use after free in GPU
CVE-2026-11083 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11083 Inappropriate implementation in Password Manager
CVE-2026-11084 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11084 Inappropriate implementation in Password Manager
CVE-2026-11085 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11085 Integer overflow in GPU
CVE-2026-11086 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11086 Insufficient validation of untrusted input in Dawn
CVE-2026-11087 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11087 Uninitialized Use in ANGLE
CVE-2026-11088 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11088 Integer overflow in ANGLE
CVE-2026-11089 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11089 Uninitialized Use in Media
CVE-2026-11090 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11090 Uninitialized Use in ANGLE
CVE-2026-11091 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11091 Inappropriate implementation in Dawn
CVE-2026-11092 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11092 Insufficient policy enforcement in DevTools
CVE-2026-11093 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11093 Insufficient validation of untrusted input in Printing
CVE-2026-11094 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11094 Use after free in Codecs
CVE-2026-11095 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11095 Insufficient validation of untrusted input in Codecs
CVE-2026-11096 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11096 Out of bounds read in WebRTC
CVE-2026-11097 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11097 Inappropriate implementation in WebView
CVE-2026-11098 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11098 Insufficient validation of untrusted input in GPU
CVE-2026-11099 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-bandChromium: CVE-2026-11099 Vulnerability in Skia
CVE-2026-11100 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11100 Use after free in File Input
CVE-2026-11101 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11101 Uninitialized Use in Dawn
CVE-2026-11102 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11102 Inappropriate implementation in Isolated Web Apps
CVE-2026-11103 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11103 Inappropriate implementation in Installer
CVE-2026-11104 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11104 Uninitialized Use in ANGLE
CVE-2026-11105 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11105 Insufficient validation of untrusted input in WebUI
CVE-2026-11106 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11106 Inappropriate implementation in Media
CVE-2026-11107 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11107 Inappropriate implementation in Downloads
CVE-2026-11108 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11108 Inappropriate implementation in NFC
CVE-2026-11109 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11109 Uninitialized Use in ANGLE
CVE-2026-11110 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11110 Uninitialized Use in ANGLE
CVE-2026-11111 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11111 Out of bounds read in ANGLE
CVE-2026-11112 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11112 Insufficient validation of untrusted input in Chromoting
CVE-2026-11113 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11113 Insufficient validation of untrusted input in ANGLE
CVE-2026-11114 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11114 Use after free in Device Trust
CVE-2026-11115 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11115 Use after free in Updater
CVE-2026-11116 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11116 Use after free in Chromoting
CVE-2026-11117 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11117 Use after free in Views
CVE-2026-11118 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11118 Use after free in WebRTC
CVE-2026-11119 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11119 Insufficient validation of untrusted input in GPU
CVE-2026-11120 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11120 Insufficient validation of untrusted input in Enterprise Reporting
CVE-2026-11121 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11121 Insufficient validation of untrusted input in Skia
CVE-2026-11122 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11122 Inappropriate implementation in Keyboard
CVE-2026-11123 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11123 Uninitialized Use in ANGLE
CVE-2026-11124 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11124 Heap buffer overflow in Skia
CVE-2026-11125 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11125 Use after free in Compositing
CVE-2026-11126 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11126 Insufficient validation of untrusted input in DevTools
CVE-2026-11127 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11127 Inappropriate implementation in WebAPKs
CVE-2026-11128 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11128 Insufficient validation of untrusted input in Web Share
CVE-2026-11129 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11129 Inappropriate implementation in Extensions
CVE-2026-11130 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11130 Use after free in Media
CVE-2026-11131 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11131 Use after free in Autofill
CVE-2026-11132 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11132 Policy bypass in Paint
CVE-2026-11133 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11133 Insufficient policy enforcement in Paint
CVE-2026-11134 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11134 Insufficient data validation in Media
CVE-2026-11135 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11135 Insufficient policy enforcement in Autofill
CVE-2026-11136 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11136 Use after free in Canvas
CVE-2026-11137 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11137 Uninitialized Use in ANGLE
CVE-2026-11138 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11138 Uninitialized Use in ANGLE
CVE-2026-11139 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11139 Policy bypass in Paint
CVE-2026-11140 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11140 Insufficient validation of untrusted input in Chromecast
CVE-2026-11141 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11141 Uninitialized Use in Audio
CVE-2026-11142 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11142 Policy bypass in Paint
CVE-2026-11143 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11143 Heap buffer overflow in Extensions
CVE-2026-11144 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11144 Use after free in Media
CVE-2026-11145 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11145 Race in Geolocation
CVE-2026-11146 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11146 Insufficient validation of untrusted input in Chromoting
CVE-2026-11147 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11147 Use after free in WebML
CVE-2026-11148 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11148 Inappropriate implementation in Payments
CVE-2026-11149 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11149 Insufficient validation of untrusted input in Extensions
CVE-2026-11150 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11150 Inappropriate implementation in XML
CVE-2026-11151 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11151 Insufficient validation of untrusted input in Password Manager
CVE-2026-11152 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11152 Object lifecycle issue in Dawn
CVE-2026-11153 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11153 Side-channel information leakage in Forms
CVE-2026-11154 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11154 Use after free in Dawn
CVE-2026-11155 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11155 Insufficient policy enforcement in CSS
CVE-2026-11156 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11156 Inappropriate implementation in CSS
CVE-2026-11157 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11157 Script injection in Accessibility
CVE-2026-11158 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11158 Insufficient validation of untrusted input in Downloads
CVE-2026-11159 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11159 Uninitialized Use in Skia
CVE-2026-11160 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11160 Out of bounds read in Input
CVE-2026-11161 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11161 Insufficient data validation in DataTransfer
CVE-2026-11162 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11162 Insufficient policy enforcement in CSS
CVE-2026-11163 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11163 Use after free in Messages
CVE-2026-11164 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11164 Use after free in Blink
CVE-2026-11166 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11166 Inappropriate implementation in SVG
CVE-2026-11167 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11167 Inappropriate implementation in WebView
CVE-2026-11168 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11168 Insufficient policy enforcement in Extensions
CVE-2026-11169 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11169 Inappropriate implementation in XML
CVE-2026-11170 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11170 Inappropriate implementation in Chromoting
CVE-2026-11171 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11171 Integer overflow in Blink
CVE-2026-11172 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11172 Incorrect security UI in Contact Picker
CVE-2026-11173 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11173 Out of bounds write in V8
CVE-2026-11174 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11174 Insufficient policy enforcement in Site Isolation
CVE-2026-11175 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11175 Incorrect security UI in Messages
CVE-2026-11176 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11176 Inappropriate implementation in Media
CVE-2026-11177 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11177 Use after free in Omnibox
CVE-2026-11178 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11178 Policy bypass in WebView
CVE-2026-11179 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11179 Inappropriate implementation in ORB
CVE-2026-11180 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11180 Policy bypass in SVG
CVE-2026-11181 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11181 Inappropriate implementation in Media Session
CVE-2026-11182 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11182 Inappropriate implementation in SVG
CVE-2026-11184 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11184 Insufficient policy enforcement in Actor
CVE-2026-11185 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11185 Use after free in V8
CVE-2026-11186 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11186 Inappropriate implementation in CSS
CVE-2026-11187 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11187 Insufficient policy enforcement in Glic
CVE-2026-11188 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11188 Use after free in USB
CVE-2026-11189 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11189 Insufficient validation of untrusted input in DevTools
CVE-2026-11190 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11190 Insufficient policy enforcement in Extensions
CVE-2026-11191 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11191 Out of bounds memory access in ANGLE
CVE-2026-11192 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11192 Insufficient validation of untrusted input in Password Manager
CVE-2026-11193 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11193 Insufficient policy enforcement in Password Manager
CVE-2026-11194 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11194 Inappropriate implementation in Network
CVE-2026-11195 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11195 Inappropriate implementation in MHTML
CVE-2026-11196 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11196 Type Confusion in XML
CVE-2026-11197 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11197 Insufficient policy enforcement in Workers
CVE-2026-11198 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11198 Insufficient validation of untrusted input in Codecs
CVE-2026-11199 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11199 Insufficient validation of untrusted input in WebRTC
CVE-2026-11200 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11200 Inappropriate implementation in WebRTC
CVE-2026-11201 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11201 Use after free in ServiceWorker
CVE-2026-11203 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11203 Policy bypass in GPU
CVE-2026-11206 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11206 Policy bypass in ServiceWorker
CVE-2026-11207 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11207 Insufficient validation of untrusted input in Autofill
CVE-2026-11208 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11208 Use after free in Codecs
CVE-2026-11209 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11209 Insufficient policy enforcement in Passwords
CVE-2026-11210 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11210 Insufficient policy enforcement in Safe Browsing
CVE-2026-11211 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11211 Integer overflow in V8
CVE-2026-11212 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11212 Insufficient policy enforcement in DevTools
CVE-2026-11213 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11213 Insufficient validation of untrusted input in Reading Mode
CVE-2026-11215 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11215 Inappropriate implementation in Cronet
CVE-2026-11216 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11216 Incorrect security UI in File Input
CVE-2026-11217 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11217 Insufficient policy enforcement in Fenced Frames
CVE-2026-11218 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11218 Inappropriate implementation in PlatformIntegration
CVE-2026-11219 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11219 Insufficient data validation in Navigation
CVE-2026-11220 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11220 Insufficient validation of untrusted input in Navigation
CVE-2026-11221 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11221 Insufficient validation of untrusted input in PointerLock
CVE-2026-11222 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11222 Incorrect security UI in Tab Strip
CVE-2026-11223 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11223 Insufficient validation of untrusted input in Network
CVE-2026-11224 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11224 Use after free in Chromoting
CVE-2026-11225 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11225 Incorrect security UI in WebUI
CVE-2026-11226 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11226 Insufficient policy enforcement in PreviewTab
CVE-2026-11227 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11227 Incorrect security UI in Tab Hover Cards
CVE-2026-11228 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11228 Incorrect security UI in File Input
CVE-2026-11229 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11229 Insufficient policy enforcement in Enterprise
CVE-2026-11230 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11230 Use after free in Extensions
CVE-2026-11231 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11231 Inappropriate implementation in Safe Browsing
CVE-2026-11232 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11232 Inappropriate implementation in TabGroups
CVE-2026-11233 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11233 Insufficient validation of untrusted input in FoldableAPIs
CVE-2026-11234 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11234 Insufficient policy enforcement in FoldableAPIs
CVE-2026-11235 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11235 Insufficient validation of untrusted input in Compositing
CVE-2026-11236 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11236 Insufficient policy enforcement in Web Bluetooth
CVE-2026-11237 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11237 Insufficient validation of untrusted input in Media
CVE-2026-11238 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11238 Inappropriate implementation in DevTools
CVE-2026-11239 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11239 Insufficient validation of untrusted input in Extensions
CVE-2026-11240 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11240 Insufficient validation of untrusted input in Loader
CVE-2026-11241 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11241 Insufficient validation of untrusted input in Cast
CVE-2026-11242 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11242 Insufficient validation of untrusted input in Plugins
CVE-2026-11243 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11243 Incorrect security UI in Downloads
CVE-2026-11244 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11244 Insufficient validation of untrusted input in WebAuthentication
CVE-2026-11245 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11245 Inappropriate implementation in Payments
CVE-2026-11246 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11246 Insufficient validation of untrusted input in IndexedDB
CVE-2026-11247 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11247 Insufficient policy enforcement in CustomTabs
CVE-2026-11248 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11248 Policy bypass in Google Lens
CVE-2026-11249 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11249 Use after free in Network
CVE-2026-11250 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11250 Inappropriate implementation in DevTools
CVE-2026-11251 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11251 Insufficient validation of untrusted input in Password Manager
CVE-2026-11252 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11252 Policy bypass in Content Settings
CVE-2026-11253 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11253 Race in Permissions
CVE-2026-11254 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11254 Inappropriate implementation in Permissions
CVE-2026-11255 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11255 Insufficient validation of untrusted input in Storage Access API
CVE-2026-11256 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11256 Out of bounds read in GPU
CVE-2026-11257 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11257 Inappropriate implementation in Browser
CVE-2026-11258 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11258 Inappropriate implementation in File System Access
CVE-2026-11259 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11259 Insufficient validation of untrusted input in Cast
CVE-2026-11260 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11260 Policy bypass in Permissions
CVE-2026-11261 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11261 Insufficient validation of untrusted input in PDF
CVE-2026-11262 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11262 Use after free in TabStrip
CVE-2026-11263 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11263 Insufficient policy enforcement in WebAuthentication
CVE-2026-11264 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11264 Policy bypass in Content Security Policy
CVE-2026-11265 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11265 Insufficient data validation in Autofill
CVE-2026-11266 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11266 Policy bypass in SafeBrowsing
CVE-2026-11267 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11267 Insufficient policy enforcement in Extensions
CVE-2026-11268 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11268 Uninitialized Use in ANGLE
CVE-2026-11269 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11269 Inappropriate implementation in Extensions
CVE-2026-11270 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11270 Inappropriate implementation in UI
CVE-2026-11271 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11271 Incorrect security UI in Passwords
CVE-2026-11273 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11273 Insufficient validation of untrusted input in Omnibox
CVE-2026-11275 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11275 Insufficient policy enforcement in Page Info
CVE-2026-11276 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11276 Inappropriate implementation in Cast
CVE-2026-11278 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11278 Inappropriate implementation in CustomTabs
CVE-2026-11279 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11279 Out of bounds read in DevTools
CVE-2026-11281 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11281 Integer overflow in Chromoting
CVE-2026-11282 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11282 Policy bypass in Sandbox
CVE-2026-11283 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11283 Policy bypass in Shortcuts
CVE-2026-11284 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11284 Side-channel information leakage in PerformanceAPIs
CVE-2026-11286 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11286 Insufficient validation of untrusted input in Wallet
CVE-2026-11287 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11287 Insufficient validation of untrusted input in Navigation
CVE-2026-11288 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11288 Policy bypass in CSS
CVE-2026-11289 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11289 Side-channel information leakage in Paint
CVE-2026-11290 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11290 Integer overflow in WebView
CVE-2026-11291 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11291 Policy bypass in Android Autofill
CVE-2026-11292 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11292 Policy bypass in Blink
CVE-2026-11293 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11293 Use after free in Input
CVE-2026-11294 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11294 Inappropriate implementation in Passwords
CVE-2026-11295 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11295 Inappropriate implementation in WebView
CVE-2026-11296 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11296 Inappropriate implementation in ImageCapture
CVE-2026-11297 ↗2026-06-09Microsoft Edge (Chromium-based)N/A0%Chromium: CVE-2026-11297 Insufficient validation of untrusted input in Reader Mode
CVE-2026-11299 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11299 Out of bounds read in Fonts
CVE-2026-11300 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11300 Inappropriate implementation in Permissions
CVE-2026-11301 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11301 Out of bounds read in LiveCaption
CVE-2026-11303 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11303 Use after free in PDFium
CVE-2026-11304 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11304 Use after free in PDFium
CVE-2026-11305 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11305 Use after free in PDFium
CVE-2026-11306 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11306 Use after free in PDFium
CVE-2026-11307 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11307 Use after free in PDFium
CVE-2026-11308 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11308 Inappropriate implementation in Extensions
CVE-2026-11309 ↗2026-06-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11309 Insufficient policy enforcement in History
CVE-2026-11628 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11628 Use after free in Ozone
CVE-2026-11629 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11629 Use after free in Ozone
CVE-2026-11630 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11630 Use after free in File Input
CVE-2026-11631 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11631 Use after free in Aura
CVE-2026-11632 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11632 Use after free in TabStrip
CVE-2026-11633 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11633 Use after free in Bluetooth
CVE-2026-11634 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11634 Use after free in Gamepad
CVE-2026-11635 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11635 Use after free in Bluetooth
CVE-2026-11636 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11636 Use after free in Autofill
CVE-2026-11637 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11637 Use after free in Views
CVE-2026-11638 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11638 Use after free in Printing
CVE-2026-11639 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11639 Use after free in Compositing
CVE-2026-11640 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11640 Integer overflow in libyuv
CVE-2026-11641 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11641 Use after free in Bluetooth
CVE-2026-11642 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11642 Use after free in Web Apps
CVE-2026-11643 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11643 Use after free in Proxy
CVE-2026-11644 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11644 Use after free in Views
CVE-2026-11645 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band2%CISA KEVVulnCheckENISAChromium: CVE-2026-11645 Out of bounds memory access in V8
CVE-2026-11646 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11646 Use after free in ViewTransitions
CVE-2026-11647 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11647 Use after free in Printing
CVE-2026-11648 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11647 Use after free in Printing
CVE-2026-11649 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11648 Use after free in FullScreen
CVE-2026-11650 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11649 Use after free in V8
CVE-2026-11651 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11650 Use after free in V8
CVE-2026-11652 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11651 Use after free in Network
CVE-2026-11653 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11652 Use after free in Extensions
CVE-2026-11654 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11653 Insufficient validation of untrusted input in Extensions
CVE-2026-11655 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11654 Use after free in CameraCapture
CVE-2026-11656 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11655 Integer overflow in Media
CVE-2026-11657 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11656 Use after free in ServiceWorker
CVE-2026-11658 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11657 Use after free in Payments
CVE-2026-11659 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11658 Insufficient validation of untrusted input in Extensions
CVE-2026-11660 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11659 Insufficient validation of untrusted input in UI
CVE-2026-11661 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11660 Insufficient validation of untrusted input in New Tab Page
CVE-2026-11662 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11661 Use after free in Views
CVE-2026-11663 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11662 Type Confusion in Bindings
CVE-2026-11664 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11663 Use after free in Skia
CVE-2026-11665 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11664 Use after free in Payments
CVE-2026-11666 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11665 Out of bounds read in Dawn
CVE-2026-11667 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11666 Insufficient validation of untrusted input in Input
CVE-2026-11668 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11667 Out of bounds read in WebRTC
CVE-2026-11669 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11668 Uninitialized Use in Codecs
CVE-2026-11670 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11669 Integer overflow in Media
CVE-2026-11671 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11670 Use after free in PDF
CVE-2026-11672 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11671 Use after free in Navigation
CVE-2026-11673 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11672 Out of bounds write in GPU
CVE-2026-11674 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11673 Use after free in InterestGroups
CVE-2026-11675 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11674 Use after free in Guest View
CVE-2026-11676 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11675 Insufficient validation of untrusted input in Skia
CVE-2026-11677 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11676 Insufficient validation of untrusted input in Dawn
CVE-2026-11678 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11677 Race in Network
CVE-2026-11679 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11678 Integer overflow in libyuv
CVE-2026-11680 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11679 Use after free in Codecs
CVE-2026-11681 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11680 Use after free in Media
CVE-2026-11682 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11681 Use after free in Ozone
CVE-2026-11683 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11682 Insufficient validation of untrusted input in Views
CVE-2026-11684 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11683 Use after free in WebCodecs
CVE-2026-11685 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11684 Insufficient policy enforcement in Network
CVE-2026-11686 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11685 Insufficient data validation in MediaCapture
CVE-2026-11687 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11686 Insufficient validation of untrusted input in Dawn
CVE-2026-11688 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11687 Use after free in Dawn
CVE-2026-11689 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11688 Object lifecycle issue in SVG
CVE-2026-11690 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11689 Insufficient validation of untrusted input in Passwords
CVE-2026-11691 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11690 Out of bounds read and write in Media
CVE-2026-11692 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11691 Insufficient validation of untrusted input in New Tab Page
CVE-2026-11693 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11692 Use after free in Read Anything
CVE-2026-11694 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11693 Inappropriate implementation in Plugins
CVE-2026-11695 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11694 Use after free in ServiceWorker
CVE-2026-11696 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11695 Inappropriate implementation in Passwords
CVE-2026-11697 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11696 Uninitialized Use in Video
CVE-2026-11698 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11697 Insufficient validation of untrusted input in UI
CVE-2026-11699 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11698 Use after free in Bluetooth
CVE-2026-11700 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11699 Use after free in Bluetooth
CVE-2026-11701 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-11700 Use after free in Tracing
CVE-2026-12007 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12007 Use after free  Core
CVE-2026-12008 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12008 Use after free  DigitalCredentials
CVE-2026-12009 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12009 Insufficient validation of untrusted input  Accessibility
CVE-2026-12010 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12010 Heap buffer overflow  GPU
CVE-2026-12011 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12011 Use after free  WebMIDI
CVE-2026-12012 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12012 Use after free  Network
CVE-2026-12013 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-bandChromium: CVE-2026-12013 Use after free  Media
CVE-2026-12014 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12014 Use after free  Cast
CVE-2026-12015 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12015 Use after free  Autofill
CVE-2026-12016 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12016 Insufficient validation of untrusted input  DevTools
CVE-2026-12017 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12017 Insufficient validation of untrusted input  Extensions
CVE-2026-12018 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12018 Inappropriate implementation  Mojo
CVE-2026-12019 ↗2026-06-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12019 Out of bounds write  Codecs
CVE-2026-12028 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12028 Use after free  GPU
CVE-2026-12030 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12031 Inappropriate implementation  Views
CVE-2026-12032 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12032 Inappropriate implementation  Passwords
CVE-2026-12437 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12437 Use after free in WebShare
CVE-2026-12438 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12438 Inappropriate implementation in WebView
CVE-2026-12439 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12439 Use after free in Digital Credentials
CVE-2026-12440 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12440 Use after free in DigitalCredentials
CVE-2026-12441 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12441 Use after free in File Input
CVE-2026-12442 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12442 Use after free in Passwords
CVE-2026-12443 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band1%Chromium: CVE-2026-12443 Use after free in Web Authentication
CVE-2026-12444 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12444 Out of bounds read in Chromoting
CVE-2026-12445 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12445 Use after free in Extensions
CVE-2026-12446 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12446 Insufficient data validation in Passwords
CVE-2026-12447 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12447 Heap buffer overflow in WebRTC
CVE-2026-12448 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12448 Inappropriate implementation in WebView
CVE-2026-12449 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12449 Use after free in Chromoting
CVE-2026-12451 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12451 Use after free in DigitalCredentials
CVE-2026-12452 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12452 Use after free in Downloads
CVE-2026-12453 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12453 Insufficient validation of untrusted input in Input
CVE-2026-12454 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12454 Race in Safe Browsing
CVE-2026-12455 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12455 Use after free in Tab Strip
CVE-2026-12456 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12456 Insufficient validation of untrusted input in Extensions
CVE-2026-12457 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12457 Insufficient data validation in Extensions
CVE-2026-12458 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12458 Incorrect security UI in Passwords
CVE-2026-12459 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12459 Inappropriate implementation in Serial
CVE-2026-12460 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12460 Insufficient policy enforcement in File System Access
CVE-2026-12461 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12461 Out of bounds read in WebRTC
CVE-2026-12462 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12462 Use after free in Media
CVE-2026-12463 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12463 Inappropriate implementation in Views
CVE-2026-12464 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12464 Use after free in Browser
CVE-2026-12465 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12465 Insufficient validation of untrusted input in Metrics
CVE-2026-12466 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12466 Heap buffer overflow in WebRTC
CVE-2026-12467 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12467 Use after free in Extensions
CVE-2026-12468 ↗2026-06-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12468 Inappropriate implementation in Updater
CVE-2026-12469 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-12469 Uninitialized Use in GPU
CVE-2026-13021 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13021 Inappropriate implementation in DeviceBoundSessionCredentials
CVE-2026-13022 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13022 Inappropriate implementation in Autofill
CVE-2026-13023 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13023 Uninitialized Use in GPU
CVE-2026-13024 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13024 Insufficient validation of untrusted input in Navigation
CVE-2026-13025 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13025 Insufficient validation of untrusted input in DevTools
CVE-2026-13026 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13026 Use after free in Digital Credentials
CVE-2026-13027 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13027 Use after free in FileSystem
CVE-2026-13029 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13029 Use after free in Web Authentication
CVE-2026-13031 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13031 Use after free in Blink
CVE-2026-13033 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13033 Out of bounds read in Blink>InterestGroups
CVE-2026-13034 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13034 Inappropriate implementation in Passwords
CVE-2026-13035 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13035 Use after free in Bluetooth
CVE-2026-13036 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13036 Use after free in Blink
CVE-2026-13038 ↗2026-06-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13038 Use after free in Autofill
#

May 2026

Patch Tuesday May 12, 2026531 CVEs plus 592 Azure Linux package advisories · 46 critical · 3 exploitation detected · 4 in KEV1123 CVEs · 63 critical · 3 exploitation detected · 4 in KEV · includes 592 Azure Linux package advisories
Risk matrix, May 2026
365 of these counts use a severity derived from CVSS because Microsoft assigned none.
365 of these counts use a severity derived from CVSS because Microsoft assigned none.
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-42897 ↗2026-05-14Microsoft Exchange Server 2016 Cumulative Update 23CriticalOut-of-band6%Exploitation detectedCISA KEVVulnCheckENISAKB5094139KB5094140
and 2 moreKB5094142KB5094144
1 mentionsMicrosoft Exchange Server Spoofing Vulnerability
CVE-2026-41091 ↗2026-05-19Microsoft Malware Protection EngineImportantOut-of-band10%Exploitation detectedCISA KEVVulnCheckENISA1 mentionsMicrosoft Defender Elevation of Privilege Vulnerability
CVE-2026-45498 ↗2026-05-19Microsoft Defender Antimalware PlatformLowOut-of-band63%Exploitation detectedCISA KEVVulnCheckENISA1 mentionsMicrosoft Defender Denial of Service Vulnerability
CVE-2025-71305 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-banddrm/display/dp_mst: Add protection against 0 vcpi
CVE-2026-23652 ↗2026-05-21Microsoft Power PagesCriticalOut-of-band1%Microsoft Power Pages Remote Code Execution Vulnerability
CVE-2026-23663 ↗2026-05-21Microsoft Global Secure Access (GSA)CriticalOut-of-band1%Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability
CVE-2026-26129 ↗2026-05-07Microsoft 365 Copilot's Business ChatCriticalOut-of-band1%M365 Copilot Information Disclosure Vulnerability
CVE-2026-26147 ↗2026-05-21Azure Stack HCICriticalOut-of-band1%Azure Stack HCI Information Disclosure Vulnerability
CVE-2026-26164 ↗2026-05-07Microsoft 365 Copilot's Business ChatCriticalOut-of-band1%M365 Copilot Information Disclosure Vulnerability
CVE-2026-31705 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0CriticalOut-of-bandksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment
CVE-2026-31718 ↗2026-05-08azl3 kernel 6.6.137.1-2 on Azure Linux 3.0CriticalOut-of-bandksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger
CVE-2026-32161 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability
CVE-2026-32207 ↗2026-05-07Azure Machine LearningCriticalOut-of-band1%Azure Machine Learning Notebook Spoofing Vulnerability
CVE-2026-33109 ↗2026-05-07Azure Managed Instance for Apache CassandraCriticalOut-of-band1%Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
CVE-2026-33111 ↗2026-05-07Copilot Chat (Microsoft Edge)CriticalOut-of-band1%Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
CVE-2026-33278 ↗2026-05-21azl3 unbound 1.19.1-5 on Azure Linux 3.0CriticalOut-of-bandPossible arbitrary code execution during DNSSEC validation
CVE-2026-33821 ↗2026-05-07Dynamics 365 Customer InsightsCriticalOut-of-band1%Microsoft Dynamics 365 Customer Insights Elevation of Privilege Vulnerability
CVE-2026-33823 ↗2026-05-07Microsoft TeamsCriticalOut-of-band1%Microsoft Team Events Portal Information Disclosure Vulnerability
CVE-2026-33843 ↗2026-05-21Microsoft Entra IDCriticalOut-of-band0%Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
CVE-2026-33844 ↗2026-05-07Azure Managed Instance for Apache CassandraCriticalOut-of-band1%Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
CVE-2026-34327 ↗2026-05-07Microsoft Partner CenterCriticalOut-of-band1%Microsoft Partner Center Spoofing Vulnerability
CVE-2026-35421 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows GDI Remote Code Execution Vulnerability
CVE-2026-35428 ↗2026-05-07Azure Cloud ShellCriticalOut-of-band1%Azure Cloud Shell Spoofing Vulnerability
CVE-2026-35430 ↗2026-05-21Azure Privileged Identity Management (PIM)CriticalOut-of-band0%Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability
CVE-2026-35435 ↗2026-05-07Azure AI FoundryCriticalOut-of-band1%More likelyAzure AI Foundry Elevation of Privilege Vulnerability
CVE-2026-39821 ↗2026-05-27azl3 application-gateway-kubernetes-ingress 1.7.7-3 on Azure Linux 3.0CriticalOut-of-bandInvoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
CVE-2026-39824 ↗2026-05-27azl3 application-gateway-kubernetes-ingress 1.7.7-3 on Azure Linux 3.0CriticalOut-of-bandInvoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows
CVE-2026-39830 ↗2026-05-27azl3 cert-manager 1.12.15-6 on Azure Linux 3.0CriticalOut-of-bandInvoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh
CVE-2026-39831 ↗2026-05-27azl3 cert-manager 1.12.15-6 on Azure Linux 3.0CriticalOut-of-bandInvoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh
CVE-2026-39832 ↗2026-05-27azl3 docker-buildx 0.14.0-11 on Azure Linux 3.0CriticalOut-of-bandInvoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
CVE-2026-39833 ↗2026-05-27azl3 docker-buildx 0.14.0-11 on Azure Linux 3.0CriticalOut-of-bandInvoking key constraints not enforced in golang.org/x/crypto/ssh/agent
CVE-2026-39834 ↗2026-05-27azl3 cert-manager 1.12.15-6 on Azure Linux 3.0CriticalOut-of-bandInvoking infinite loop on large channel writes in golang.org/x/crypto/ssh
CVE-2026-40358 ↗2026-05-12Microsoft Office 2019 for 32-bit editionsCritical0%KB5002866Microsoft Office Remote Code Execution Vulnerability
CVE-2026-40361 ↗2026-05-12Microsoft Office 2019 for 32-bit editionsCritical1%More likelyKB5002858Microsoft Outlook and Word Remote Code Execution Vulnerability
CVE-2026-40363 ↗2026-05-12Microsoft Office 2019 for 32-bit editionsCritical0%KB5002866Microsoft Office Remote Code Execution Vulnerability
CVE-2026-40364 ↗2026-05-12Microsoft Office 2019 for 32-bit editionsCritical4%More likelyKB5002858Microsoft Word Remote Code Execution Vulnerability
CVE-2026-40365 ↗2026-05-12Microsoft SharePoint Enterprise Server 2016Critical1%KB5002863KB5002868
and 1 moreKB5002870
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-40366 ↗2026-05-12Microsoft Office 2019 for 32-bit editionsCritical0%KB5002858Microsoft Word Remote Code Execution Vulnerability
CVE-2026-40367 ↗2026-05-12Microsoft SharePoint Enterprise Server 2016Critical0%KB5002858KB5002863
and 4 moreKB5002868KB5002869KB5002870KB5002872
Microsoft Word Remote Code Execution Vulnerability
CVE-2026-40379 ↗2026-05-07Microsoft Entra IDCriticalOut-of-band1%Azure Entra ID Spoofing Vulnerability
CVE-2026-40402 ↗2026-05-12Windows Server 2022Critical0%KB5087420KB5087424
and 2 moreKB5087545KB5093998
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2026-40403 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-40411 ↗2026-05-21Azure Virtual Network GatewayCriticalOut-of-band1%Azure Virtual Network Gateway Remote Code Execution Vulnerability
CVE-2026-40412 ↗2026-05-21Azure Orbital SpatioCriticalOut-of-band1%Azure Orbital Spatio Remote Code Execution Vulnerability
CVE-2026-41089 ↗2026-05-12Windows Server 2019Critical80%VulnCheckKB5087423KB5087424
and 7 moreKB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087545
Windows Netlogon Remote Code Execution Vulnerability
CVE-2026-41090 ↗2026-05-21Microsoft 365 Copilot for iOSCriticalOut-of-band0%Microsoft Copilot Tampering Vulnerability
CVE-2026-41096 ↗2026-05-12Windows Server 2025 (Server Core installation)Critical2%KB5087420KB5087423
and 6 moreKB5087539KB5087541KB5089466KB5089548KB5089549KB5093998
Windows DNS Client Remote Code Execution Vulnerability
CVE-2026-41103 ↗2026-05-12Microsoft JIRA SAML SSO pluginCritical5%More likelyMicrosoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability
CVE-2026-41104 ↗2026-05-21Microsoft Planetary Computer Pro (GeoCatalog)CriticalOut-of-band1%Microsoft Planetary Computer Pro Information Disclosure Vulnerability
CVE-2026-41105 ↗2026-05-07Azure Monitor Action Group notification systemCriticalOut-of-band1%Azure Monitor Action Group Notification System Elevation of Privilege Vulnerability
CVE-2026-41615 ↗2026-05-14Microsoft Authenticator for AndroidCriticalOut-of-band1%Microsoft Authenticator Information Disclosure Vulnerability
CVE-2026-42508 ↗2026-05-27azl3 libcontainers-common 20240213-3 on Azure Linux 3.0CriticalOut-of-bandInvoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts
CVE-2026-42822 ↗2026-05-18Azure LocalCriticalOut-of-band0%More likelyAzure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability
CVE-2026-42826 ↗2026-05-07Azure DevOpsCriticalOut-of-band1%Azure DevOps Information Disclosure Vulnerability
CVE-2026-42827 ↗2026-05-21Microsoft 365 CopilotCriticalOut-of-band1%M365 Copilot Information Disclosure Vulnerability
CVE-2026-42831 ↗2026-05-12Microsoft Office LTSC for Mac 2021Critical0%Microsoft Office Remote Code Execution Vulnerability
CVE-2026-42898 ↗2026-05-12Microsoft Dynamics 365 (on-premises) version 9.1Critical1%KB5078943Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
CVE-2026-42901 ↗2026-05-21Microsoft Entra IDCriticalOut-of-band0%Microsoft Entra ID Elevation of Privilege Vulnerability
CVE-2026-42945 ↗2026-05-16azl3 nginx 1.28.3-1 on Azure Linux 3.0CriticalOut-of-band61%VulnCheck1 mentionsNGINX ngx_http_rewrite_module vulnerability
CVE-2026-45584 ↗2026-05-19Microsoft Malware Protection EngineCriticalOut-of-band1%Microsoft Defender Remote Code Execution Vulnerability
CVE-2026-45899 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-bandext4: drop extent cache when splitting extent fails
CVE-2026-46595 ↗2026-05-27azl3 docker-buildx 0.14.0-11 on Azure Linux 3.0CriticalOut-of-bandInvoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh
CVE-2026-47280 ↗2026-05-21Azure Resource ManagerCriticalOut-of-band0%Azure Resource Manager Elevation of Privilege Vulnerability
CVE-2026-6722 ↗2026-05-11azl3 php 8.3.29-1 on Azure Linux 3.0CriticalOut-of-bandUse-After-Free in SOAP using Apache map
CVE-2026-7374 ↗2026-05-31azl3 kubevirt 1.7.1-2 on Azure Linux 3.0CriticalOut-of-bandKubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability
CVE-2025-14179 ↗2026-05-11azl3 php 8.3.29-1 on Azure Linux 3.0ImportantOut-of-bandSQL injection in pdo_firebird via NUL bytes in quoted strings
CVE-2025-54518 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5078737KB5087420
and 12 moreKB5087423KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
AMD: CVE-2025-54518 CPU OP Cache Corruption
CVE-2026-21530 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5002578KB5087420
and 15 moreKB5087423KB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Rich Text Edit Elevation of Privilege Vulnerability
CVE-2026-23479 ↗2026-05-08azl3 valkey 8.0.7-1 on Azure Linux 3.0ImportantOut-of-bandredis-server use-after-free in unblock client flow may allow remote code execution
CVE-2026-23918 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ImportantOut-of-bandApache HTTP Server: http2: double free and possible RCE on early reset
CVE-2026-24072 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ImportantOut-of-bandApache HTTP Server: mod_rewrite elevation of privileges via ap_expr
CVE-2026-25243 ↗2026-05-08azl3 valkey 8.0.9-1 on Azure Linux 3.0ImportantOut-of-bandredis-server RESTORE invalid memory access may allow remote code execution
CVE-2026-25588 ↗2026-05-08azl3 valkey 8.0.7-1 on Azure Linux 3.0ImportantOut-of-bandRedisTimeSeries RESTORE invalid memory access may allow remote code execution
CVE-2026-25589 ↗2026-05-08azl3 valkey 8.0.7-1 on Azure Linux 3.0ImportantOut-of-bandRedisBloom RESTORE invalid memory access may allow remote code execution
CVE-2026-29168 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ImportantOut-of-bandApache HTTP Server: mod_md unrestricted OCSP response
CVE-2026-29169 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ImportantOut-of-bandApache HTTP Server: mod_dav_lock indirect lock crash
CVE-2026-29518 ↗2026-05-21azl3 rsync 3.4.1-2 on Azure Linux 3.0ImportantOut-of-bandRsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write
CVE-2026-3039 ↗2026-05-23azl3 bind 9.20.21-1 on Azure Linux 3.0ImportantOut-of-bandBIND 9 server memory exhaustion during GSS-API TKEY negotiation
CVE-2026-31694 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandfuse: reject oversized dirents in page cache
CVE-2026-31697 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandcrypto: ccp: Don't attempt to copy ID to userspace if PSP command failed
CVE-2026-31698 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandcrypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed
CVE-2026-31699 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandcrypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed
CVE-2026-31700 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandnet/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd()
CVE-2026-31702 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandf2fs: fix use-after-free of sbi in f2fs_compress_write_end_io()
CVE-2026-31704 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandksmbd: use check_add_overflow() to prevent u16 DACL size overflow
CVE-2026-31706 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl()
CVE-2026-31707 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandksmbd: validate response sizes in ipc_validate_msg()
CVE-2026-31708 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandsmb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path
CVE-2026-31709 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandsmb: client: validate the whole DACL before rewriting it in cifsacl
CVE-2026-31711 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandsmb: server: fix active_num_conn leak on transport allocation failure
CVE-2026-31712 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandksmbd: require minimum ACE size in smb_check_perm_dacl()
CVE-2026-31717 ↗2026-05-08azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ImportantOut-of-bandksmbd: validate owner of durable handle on reconnect
CVE-2026-31721 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandusb: gadget: f_hid: move list and spinlock inits from bind to alloc
CVE-2026-31722 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandusb: gadget: f_rndis: Fix net_device lifecycle with device_move
CVE-2026-31723 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandusb: gadget: f_subset: Fix net_device lifecycle with device_move
CVE-2026-31724 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandusb: gadget: f_eem: Fix net_device lifecycle with device_move
CVE-2026-31725 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandusb: gadget: f_ecm: Fix net_device lifecycle with device_move
CVE-2026-31729 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandusb: typec: ucsi: validate connector number in ucsi_notify_common()
CVE-2026-31771 ↗2026-05-02azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-bandBluetooth: hci_event: move wake reason storage into validated event handlers
CVE-2026-31777 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandALSA: ctxfi: Check the error for index mapping
CVE-2026-32170 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Rich Text Edit Elevation of Privilege Vulnerability
CVE-2026-32175 ↗2026-05-12.NET 10.0 installed on WindowsImportant1%KB5093446KB5093447
and 1 moreKB5093448
.NET Core Tampering Vulnerability
CVE-2026-32185 ↗2026-05-12Microsoft Teams for AndroidImportant0%Microsoft Teams Spoofing Vulnerability
CVE-2026-32204 ↗2026-05-12Azure Monitor AgentImportant0%Azure Monitor Agent Elevation of Privilege Vulnerability
CVE-2026-32209 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Filtering Platform (WFP) Security Feature Bypass Vulnerability
CVE-2026-32934 ↗2026-05-07azl3 coredns 1.11.4-15 on Azure Linux 3.0ImportantOut-of-bandCoreDNS DNS-over-QUIC unbounded goroutine growth leads to denial of service
CVE-2026-32936 ↗2026-05-07azl3 coredns 1.11.4-15 on Azure Linux 3.0ImportantOut-of-bandCoreDNS DoH GET path missing size validation causes CPU and memory amplification
CVE-2026-33079 ↗2026-05-10azl3 python-mistune 3.0.2-1 on Azure Linux 3.0ImportantOut-of-bandMistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles
CVE-2026-33110 ↗2026-05-12Microsoft SharePoint Enterprise Server 2016Important1%KB5002863KB5002868
and 1 moreKB5002870
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-33112 ↗2026-05-12Microsoft SharePoint Enterprise Server 2016Important2%KB5002863KB5002868
and 1 moreKB5002870
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-33117 ↗2026-05-12Azure SDK for JavaImportant0%Azure SDK for Java Security Feature Bypass Vulnerability
CVE-2026-33190 ↗2026-05-07azl3 coredns 1.11.4-15 on Azure Linux 3.0ImportantOut-of-bandCoreDNS TSIG authentication bypass on encrypted DNS transports
CVE-2026-33489 ↗2026-05-07azl3 coredns 1.11.4-15 on Azure Linux 3.0ImportantOut-of-bandCoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison
CVE-2026-33811 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ImportantOut-of-bandCrash when handling long CNAME response in net
CVE-2026-33814 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ImportantOut-of-bandInfinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
CVE-2026-33833 ↗2026-05-12Azure Machine LearningImportant0%Azure Machine Learning Notebook Spoofing Vulnerability
CVE-2026-33834 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Event Logging Service Elevation of Privilege Vulnerability
CVE-2026-33835 ↗2026-05-12Windows Server 2019Important2%More likelyKB5087420KB5087423
and 11 moreKB5087424KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-33837 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows TCP/IP Local Elevation of Privilege Vulnerability
CVE-2026-33838 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability
CVE-2026-33839 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 11 moreKB5087424KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Win32k Elevation of Privilege Vulnerability
CVE-2026-33840 ↗2026-05-12Windows Server 2025 (Server Core installation)Important2%More likelyKB5087423KB5087539
and 3 moreKB5089466KB5089548KB5089549
Win32k Elevation of Privilege Vulnerability
CVE-2026-33841 ↗2026-05-12Windows Server 2022Important0%More likelyKB5087420KB5087423
and 10 moreKB5087424KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-34059 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ImportantOut-of-bandApache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data()
CVE-2026-34329 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2026-34330 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Win32k Elevation of Privilege Vulnerability
CVE-2026-34331 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Win32k Elevation of Privilege Vulnerability
CVE-2026-34332 ↗2026-05-12Windows Server 2025 (Server Core installation)Important1%KB5087423KB5087539Windows Kernel-Mode Driver Remote Code Execution Vulnerability
CVE-2026-34333 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-34334 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-34336 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 12 moreKB5087424KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-34337 ↗2026-05-12Windows Server 2022Important0%KB5087420KB5087423
and 11 moreKB5087424KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-34338 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-34339 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 12 moreKB5087424KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
CVE-2026-34340 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 11 moreKB5087424KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-34341 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege Vulnerability
CVE-2026-34342 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2026-34343 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability
CVE-2026-34344 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-34345 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 12 moreKB5087424KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-34347 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-34350 ↗2026-05-12Windows Server 2025 (Server Core installation)Important1%KB5087423KB5087539Windows Storport Miniport Driver Denial of Service Vulnerability
CVE-2026-34351 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-35415 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 13 moreKB5087424KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Storage Spaces Controller Elevation of Privilege Vulnerability
CVE-2026-35416 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-35417 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5087420KB5087423
and 11 moreKB5087424KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-35418 ↗2026-05-12Windows Server 2022Important0%KB5087420KB5087423
and 11 moreKB5087424KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-35419 ↗2026-05-12Windows Server 2025 (Server Core installation)Important0%KB5087423KB5087539
and 3 moreKB5089466KB5089548KB5089549
Windows DWM Core Library Information Disclosure Vulnerability
CVE-2026-35420 ↗2026-05-12Windows Server 2019Important0%KB5087423KB5087424
and 7 moreKB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087545
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-35422 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows TCP/IP Driver Security Feature Bypass Vulnerability
CVE-2026-35423 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows 11 Telnet Client Information Disclosure Vulnerability
CVE-2026-35424 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability
CVE-2026-35436 ↗2026-05-12Microsoft Office 2019 for 32-bit editionsImportant0%Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
CVE-2026-35438 ↗2026-05-12Windows Admin CenterImportant1%Windows Admin Center Elevation of Privilege Vulnerability
CVE-2026-35439 ↗2026-05-12Microsoft SharePoint Enterprise Server 2016Important2%KB5002863KB5002868
and 1 moreKB5002870
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-35440 ↗2026-05-12Microsoft Office 2019 for 32-bit editionsImportant0%KB5002858Microsoft Word Information Disclosure Vulnerability
CVE-2026-35579 ↗2026-05-07azl3 coredns 1.11.4-15 on Azure Linux 3.0ImportantOut-of-bandCoreDNS TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transports
CVE-2026-3593 ↗2026-05-23azl3 bind 9.20.21-1 on Azure Linux 3.0ImportantOut-of-bandHeap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
CVE-2026-37457 ↗2026-05-05cbl2 frr 8.5.5-5 on CBL Mariner 2.0ImportantOut-of-bandAn off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
CVE-2026-39820 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ImportantOut-of-bandQuadratic string concatentation in consumeComment in net/mail
CVE-2026-39829 ↗2026-05-27azl3 cert-manager 1.12.15-6 on Azure Linux 3.0ImportantOut-of-bandInvoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh
CVE-2026-39836 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ImportantOut-of-bandPanic in Dial and LookupPort when handling NUL byte on Windows in net
CVE-2026-40034 ↗2026-05-31azl3 rust 1.75.0-29 on Azure Linux 3.0ImportantOut-of-bandgitoxide - Command Injection via Partial .gitmodules Override in gix-submodule
CVE-2026-40357 ↗2026-05-12Microsoft SharePoint Enterprise Server 2016Important1%KB5002863KB5002868
and 1 moreKB5002870
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-40359 ↗2026-05-12Office Online ServerImportant0%KB5002865KB5002871Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-40360 ↗2026-05-12Office Online ServerImportant0%KB5002865KB5002871Microsoft Excel Information Disclosure Vulnerability
CVE-2026-40362 ↗2026-05-12Office Online ServerImportant0%KB5002865KB5002871Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-40368 ↗2026-05-12Microsoft SharePoint Enterprise Server 2016Important1%KB5002863KB5002868
and 1 moreKB5002870
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-40369 ↗2026-05-12Windows Server 2025 (Server Core installation)Important5%More likelyKB5087423KB5087539
and 3 moreKB5089466KB5089548KB5089549
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-40370 ↗2026-05-12Microsoft SQL Server 2025 for x64-based Systems (CU4)Important1%KB5089270KB5089271
and 8 moreKB5089899KB5089900KB5090347KB5090354KB5090407KB5090408KB5091158KB5091223
SQL Server Remote Code Execution Vulnerability
CVE-2026-40374 ↗2026-05-12Power Automate for DesktopImportant1%Microsoft Power Automate Desktop Information Disclosure Vulnerability
CVE-2026-40377 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
CVE-2026-40380 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Volume Manager Extension Driver Remote Code Execution Vulnerability
CVE-2026-40381 ↗2026-05-12Azure Connected Machine AgentImportant0%Azure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2026-40382 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-40397 ↗2026-05-12Windows 10 Version 1809 for x64-based SystemsImportant0%More likelyKB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2026-40398 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVE-2026-40399 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 12 moreKB5087424KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-40401 ↗2026-05-12Windows 10 Version 1809 for x64-based SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows TCP/IP Denial of Service Vulnerability
CVE-2026-40405 ↗2026-05-12Windows Server 2025 (Server Core installation)Important1%KB5087423KB5087539
and 3 moreKB5089466KB5089548KB5089549
Windows TCP/IP Denial of Service Vulnerability
CVE-2026-40406 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows TCP/IP Information Disclosure Vulnerability
CVE-2026-40407 ↗2026-05-12Windows Server 2022 (Server Core installation)Important0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2026-40408 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows WAN ARP Driver Elevation of Privilege Vulnerability
CVE-2026-40410 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5087420KB5087423
and 13 moreKB5087424KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows SMB Client Elevation of Privilege Vulnerability
CVE-2026-40413 ↗2026-05-12Windows 10 Version 1809 for x64-based SystemsImportant0%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows TCP/IP Denial of Service Vulnerability
CVE-2026-40414 ↗2026-05-12Windows 10 Version 1809 for x64-based SystemsImportant1%KB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows TCP/IP Denial of Service Vulnerability
CVE-2026-40415 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5087420KB5087423
and 11 moreKB5087424KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows TCP/IP Remote Code Execution Vulnerability
CVE-2026-40417 ↗2026-05-12Microsoft Dynamics 365 Business Central 2026 Release Wave 1Important0%KB5086068KB5086069
and 2 moreKB5086070KB5093780
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
CVE-2026-40418 ↗2026-05-12Microsoft Office 2019 for 32-bit editionsImportant0%Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
CVE-2026-40419 ↗2026-05-12Microsoft Office 2019 for 32-bit editionsImportant0%Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
CVE-2026-40420 ↗2026-05-12Microsoft Office 2019 for 32-bit editionsImportant0%Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
CVE-2026-40421 ↗2026-05-12Microsoft Office 2019 for 32-bit editionsImportant1%KB5002858Microsoft Word Information Disclosure Vulnerability
CVE-2026-41054 ↗2026-05-23azl3 haveged 1.9.17-1 on Azure Linux 3.0ImportantOut-of-bandMissing exit out of permission check in haveged could lead to root exploit
CVE-2026-41086 ↗2026-05-12Windows Admin Center in Azure PortalImportant0%Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability
CVE-2026-41088 ↗2026-05-12Windows Server 2022Important0%KB5087420KB5087423
and 10 moreKB5087424KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-41094 ↗2026-05-12Microsoft Data FormulatorImportant1%Microsoft Data Formulator Remote Code Execution Vulnerability
CVE-2026-41095 ↗2026-05-12Windows Server 2025 (Server Core installation)Important0%KB5087423KB5087424
and 6 moreKB5087471KB5087537KB5087538KB5087539KB5087541KB5087545
Data Deduplication Elevation of Privilege Vulnerability
CVE-2026-41097 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5087420KB5087423
and 11 moreKB5087424KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Secure Boot Security Feature Bypass Vulnerability
CVE-2026-41100 ↗2026-05-12Microsoft 365 Copilot for AndroidImportant0%Microsoft 365 Copilot for Android Spoofing Vulnerability
CVE-2026-41101 ↗2026-05-12Microsoft Word for AndroidImportant0%Microsoft Word for Android Spoofing Vulnerability
CVE-2026-41102 ↗2026-05-12Microsoft PowerPoint for AndroidImportant0%Microsoft PowerPoint for Android Spoofing Vulnerability
CVE-2026-41109 ↗2026-05-12Visual Studio CodeImportant1%GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-41401 ↗2026-05-27azl3 libyang 2.1.148-1 on Azure Linux 3.0ImportantOut-of-bandlibyang - Heap Use-After-Free Write in XML Metadata Parsing
CVE-2026-41610 ↗2026-05-12Visual Studio CodeImportant1%Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-41611 ↗2026-05-12Visual Studio CodeImportant0%Visual Studio Code Remote Code Execution Vulnerability
CVE-2026-41612 ↗2026-05-12Visual Studio Code - Live Preview extensionImportant0%Visual Studio Code Information Disclosure Vulnerability
CVE-2026-41613 ↗2026-05-12Visual Studio CodeImportant1%Visual Studio Code Elevation of Privilege Vulnerability
CVE-2026-41614 ↗2026-05-12M365 Copilot for DesktopImportant0%M365 Copilot for Desktop Spoofing Vulnerability
CVE-2026-41672 ↗2026-05-08azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandxmldom: XML node injection through unvalidated comment serialization
CVE-2026-41673 ↗2026-05-08azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandxmldom: Denial of service via uncontrolled recursion in XML serialization
CVE-2026-41674 ↗2026-05-08azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandxmldom: XML injection through unvalidated DocumentType serialization
CVE-2026-41675 ↗2026-05-08azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandxmldom: XML node injection through unvalidated processing instruction serialization
CVE-2026-42012 ↗2026-05-31azl3 gnutls 3.8.3-8 on Azure Linux 3.0ImportantOut-of-bandGnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans
CVE-2026-42013 ↗2026-05-31azl3 gnutls 3.8.3-8 on Azure Linux 3.0ImportantOut-of-bandGnutls: gnutls: certificate validation bypass due to oversized subject alternative name
CVE-2026-42151 ↗2026-05-07cbl2 prometheus 2.37.9-7 on CBL Mariner 2.0ImportantOut-of-bandPrometheus Azure AD remote write OAuth client secret exposed via config API
CVE-2026-42154 ↗2026-05-07cbl2 prometheus 2.37.9-7 on CBL Mariner 2.0ImportantOut-of-bandPrometheus: remote read endpoint allows denial of service via crafted snappy payload
CVE-2026-42246 ↗2026-05-11azl3 ruby 3.3.5-8 on Azure Linux 3.0ImportantOut-of-bandnet-imap vulnerable to STARTTLS stripping via invalid response timing
CVE-2026-42304 ↗2026-05-15azl3 python-twisted 22.10.0-4 on Azure Linux 3.0ImportantOut-of-bandTwisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
CVE-2026-42496 ↗2026-05-29azl3 perl 5.38.2-509 on Azure Linux 3.0ImportantOut-of-bandArchive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory
CVE-2026-42499 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ImportantOut-of-bandQuadratic string concatenation in consumePhrase in net/mail
CVE-2026-42501 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ImportantOut-of-bandMalicious module proxy can bypass checksum database in cmd/go
CVE-2026-42789 ↗2026-05-31azl3 erlang 26.2.5.20-1 on Azure Linux 3.0ImportantOut-of-bandNon-CA certificate accepted as intermediate issuer in public_key path validation
CVE-2026-42790 ↗2026-05-31azl3 erlang 26.2.5.20-1 on Azure Linux 3.0ImportantOut-of-bandnameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification
CVE-2026-42823 ↗2026-05-12Azure Logic AppsImportant1%Azure Logic Apps Elevation of Privilege Vulnerability
CVE-2026-42825 ↗2026-05-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5078737KB5087420
and 14 moreKB5087423KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-42830 ↗2026-05-12Azure Monitor Agent Metrics ExtensionImportant0%Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability
CVE-2026-42832 ↗2026-05-12Microsoft Word for AndroidImportant0%Microsoft Office Spoofing Vulnerability
CVE-2026-42833 ↗2026-05-12Microsoft Dynamics 365 (on-premises) version 9.1Important1%KB5078943Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
CVE-2026-42834 ↗2026-05-19Windows Admin Center in Azure PortalImportantOut-of-band0%Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability
CVE-2026-42838 ↗2026-05-11Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2026-42893 ↗2026-05-12Microsoft Outlook for iOSImportant0%Microsoft Outlook for iOS Tampering Vulnerability
CVE-2026-42896 ↗2026-05-12Windows Server 2025 (Server Core installation)Important0%KB5087423KB5087539
and 3 moreKB5089466KB5089548KB5089549
Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-42899 ↗2026-05-12.NET 8.0 installed on WindowsImportant2%KB5093446KB5093447
and 1 moreKB5093448
ASP.NET Core Denial of Service Vulnerability
CVE-2026-42946 ↗2026-05-16azl3 nginx 1.28.3-1 on Azure Linux 3.0ImportantOut-of-bandNGINX ngx_http_scgi_module and ngx_http_uwsgi_module vulnerability
CVE-2026-43009 ↗2026-05-02azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ImportantOut-of-bandbpf: Fix incorrect pruning due to atomic fetch precision tracking
CVE-2026-43019 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandBluetooth: hci_conn: fix potential UAF in set_cig_params_sync
CVE-2026-43033 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandcrypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption
CVE-2026-43037 ↗2026-05-06cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandip6_tunnel: clear skb2->cb[] in ip4ip6_err()
CVE-2026-43042 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandmpls: add seqcount to protect the platform_label{,s} pair
CVE-2026-43048 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandHID: core: Mitigate potential OOB by removing bogus memset()
CVE-2026-43049 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandHID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure
CVE-2026-43052 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandwifi: mac80211: check tdls flag in ieee80211_tdls_oper
CVE-2026-43058 ↗2026-05-03azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandmedia: vidtv: fix pass-by-value structs causing MSAN warnings
CVE-2026-43059 ↗2026-06-10azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-bandBluetooth: MGMT: Fix list corruption and UAF in command complete handlers
CVE-2026-43125 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-banddlm: validate length in dlm_search_rsb_tree
CVE-2026-43176 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-bandwifi: rtw89: pci: validate release report content before using for RTL8922DE
CVE-2026-43213 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-bandwifi: rtw89: pci: validate sequence number of TX release report
CVE-2026-43219 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-bandnet: cpsw_new: Fix potential unregister of netdev that has not been registered yet
CVE-2026-43228 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-bandhfs: Replace BUG_ON with error handling for CNID count checks
CVE-2026-43249 ↗2026-05-13azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ImportantOut-of-band9p/xen: protect xen_9pfs_front_free against concurrent calls
CVE-2026-43258 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-bandalpha: fix user-space corruption during memory compaction
CVE-2026-43267 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-bandwifi: rtw89: fix potential zero beacon interval in beacon tracking
CVE-2026-43284 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-band93%VulnCheckxfrm: esp: avoid in-place decrypt on shared skb frags
CVE-2026-43298 ↗2026-05-09azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/amdgpu: Skip vcn poison irq release on VF
CVE-2026-43318 ↗2026-05-09azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notify
CVE-2026-43321 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-bandbpf: Properly mark live registers for indirect jumps
CVE-2026-43353 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-bandi3c: mipi-i3c-hci: Fix race in DMA ring dequeue
CVE-2026-43490 ↗2026-05-16azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ImportantOut-of-bandksmbd: validate inherited ACE SID length
CVE-2026-43493 ↗2026-05-20azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandcrypto: pcrypt - Fix handling of MAY_BACKLOG requests
CVE-2026-43497 ↗2026-05-22azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandfbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free
CVE-2026-43499 ↗2026-05-22azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandrtmutex: Use waiter::task instead of current in remove_waiter()
CVE-2026-43500 ↗2026-05-12azl3 kernel 6.6.138.1-1 on Azure Linux 3.0Important93%VulnCheckrxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
CVE-2026-43503 ↗2026-05-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandnet: skbuff: propagate shared-frag marker through frag-transfer helpers
CVE-2026-43618 ↗2026-05-21azl3 rsync 3.4.1-2 on Azure Linux 3.0ImportantOut-of-bandRsync < 3.4.3 Integer Overflow Information Disclosure
CVE-2026-43869 ↗2026-05-08azl3 thrift 0.15.0-5 on Azure Linux 3.0ImportantOut-of-bandApache Thrift: TSSLTransportFactory.java hostname verification
CVE-2026-43870 ↗2026-05-07cbl2 ceph 16.2.10-11 on CBL Mariner 2.0ImportantOut-of-bandApache Thrift: Node.js web_server.js multi-vulnerability
CVE-2026-44307 ↗2026-05-14azl3 python-mako 1.2.4-3 on Azure Linux 3.0ImportantOut-of-bandMako: Path traversal via backslash URI on Windows in TemplateLookup
CVE-2026-44431 ↗2026-05-16azl3 python-urllib3 2.0.7-4 on Azure Linux 3.0ImportantOut-of-bandurllib3: Sensitive headers forwarded across origins in proxied low-level redirects
CVE-2026-44673 ↗2026-05-16azl3 libyang 2.1.148-1 on Azure Linux 3.0ImportantOut-of-bandlibyang: lyb_read_string() integer overflow → heap buffer overflow
CVE-2026-45495 ↗2026-05-15Microsoft Edge (Chromium-based)ImportantOut-of-band1%More likelyMicrosoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-45585 ↗2026-05-19Windows Server 2025 (Server Core installation)ImportantOut-of-band1%More likelyKB5094125KB5094126
and 1 moreKB5095051
Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-45659 ↗2026-05-21Microsoft SharePoint Enterprise Server 2016ImportantOut-of-band7%CISA KEVVulnCheckENISAKB5002863KB5002868
and 1 moreKB5002870
4 mentionsMicrosoft SharePoint Remote Code Execution Vulnerability
CVE-2026-45892 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandext4: drop extent cache after doing PARTIAL_VALID1 zeroout
CVE-2026-45912 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandext4: don't cache extent during splitting extent
CVE-2026-45942 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandext4: fix e4b bitmap inconsistency reports
CVE-2026-45956 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl()
CVE-2026-45958 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/exynos: vidi: fix to avoid directly dereferencing user pointer
CVE-2026-46150 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandfanotify: fix false positive on permission events
CVE-2026-46191 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandfbcon: Avoid OOB font access if console rotation fails
CVE-2026-46242 ↗2026-05-31azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandeventpoll: fix ep_remove struct eventpoll / struct file UAF
CVE-2026-46300 ↗2026-05-27azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-bandnet: skbuff: preserve shared-frag marker during coalescing
CVE-2026-46597 ↗2026-05-27azl3 cert-manager 1.12.15-6 on Azure Linux 3.0ImportantOut-of-bandInvoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh
CVE-2026-47294 ↗2026-05-29Microsoft SharePoint Enterprise Server 2016ImportantOut-of-band0%KB5002863KB5002868
and 1 moreKB5002870
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-47783 ↗2026-05-21azl3 memcached 1.6.27-4 on Azure Linux 3.0ImportantOut-of-bandIn memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.
CVE-2026-47784 ↗2026-05-21azl3 memcached 1.6.27-4 on Azure Linux 3.0ImportantOut-of-bandIn memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.
CVE-2026-48864 ↗2026-05-31azl3 libsolv 0.7.28-3 on Azure Linux 3.0ImportantOut-of-bandLibsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
CVE-2026-4892 ↗2026-05-15azl3 dnsmasq 2.90-1 on Azure Linux 3.0ImportantOut-of-bandCVE-2026-4892
CVE-2026-48959 ↗2026-06-02azl3 perl 5.38.2-509 on Azure Linux 3.0ImportantOut-of-bandIO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward
CVE-2026-48962 ↗2026-05-31azl3 perl 5.38.2-509 on Azure Linux 3.0ImportantOut-of-bandIO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob
CVE-2026-5260 ↗2026-05-31azl3 gnutls 3.8.3-8 on Azure Linux 3.0ImportantOut-of-bandGnutls: gnutls: information disclosure via heap overread in rsa key exchange
CVE-2026-5946 ↗2026-05-23azl3 bind 9.20.21-1 on Azure Linux 3.0ImportantOut-of-bandInvalid handling of CLASS != IN
CVE-2026-5947 ↗2026-05-23azl3 bind 9.20.21-1 on Azure Linux 3.0ImportantOut-of-bandSIG(0) validation during query flood may lead to undefined behavior
CVE-2026-6210 ↗2026-05-13azl3 qtsvg 6.6.1-3 on Azure Linux 3.0ImportantOut-of-bandType confusion and heap-buffer-overflow in Qt SVG marker handling causing application crash
CVE-2026-6473 ↗2026-05-16azl3 rust 1.75.0-28 on Azure Linux 3.0ImportantOut-of-bandPostgreSQL server undersizes allocations, via integer wraparound
CVE-2026-6475 ↗2026-05-16azl3 postgresql 16.12-1 on Azure Linux 3.0ImportantOut-of-bandPostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice
CVE-2026-6477 ↗2026-05-16azl3 rust 1.75.0-28 on Azure Linux 3.0ImportantOut-of-bandPostgreSQL libpq lo_* functions let server superuser overwrite client stack memory
CVE-2026-6479 ↗2026-05-16azl3 postgresql 16.12-1 on Azure Linux 3.0ImportantOut-of-bandPostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion
CVE-2026-6637 ↗2026-05-16azl3 postgresql 16.12-1 on Azure Linux 3.0ImportantOut-of-bandPostgreSQL refint allows stack buffer overflow and SQL injection
CVE-2026-6664 ↗2026-05-10azl3 pgbouncer 1.25.1-1 on Azure Linux 3.0ImportantOut-of-band1%VulnCheckPgBouncer integer overflow in PgBouncer network packet parsing
CVE-2026-6665 ↗2026-05-10azl3 pgbouncer 1.25.1-1 on Azure Linux 3.0ImportantOut-of-bandPgBouncer buffer overflow in SCRAM
CVE-2026-6735 ↗2026-05-11azl3 php 8.3.29-1 on Azure Linux 3.0ImportantOut-of-bandXSS within PHP-FPM status endpoint
CVE-2026-7598 ↗2026-05-03cbl2 libssh2 1.9.0-4 on CBL Mariner 2.0ImportantOut-of-bandlibssh2 userauth.c userauth_password integer overflow
CVE-2026-8466 ↗2026-05-27azl3 rabbitmq-server 3.13.7-3 on Azure Linux 3.0ImportantOut-of-bandUnbounded buffer accumulation in multipart header parsing causes denial of service in cowboy
CVE-2026-8711 ↗2026-05-23azl3 nginx 1.28.3-1 on Azure Linux 3.0ImportantOut-of-bandNGINX JavaScript vulnerability
CVE-2026-9256 ↗2026-05-27azl3 nginx 1.28.3-1 on Azure Linux 3.0ImportantOut-of-bandNGINX ngx_http_rewrite_module vulnerability
CVE-2026-9538 ↗2026-05-29azl3 perl 5.38.2-509 on Azure Linux 3.0ImportantOut-of-bandArchive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header
CVE-2026-9804 ↗2026-05-31azl3 kubevirt 1.7.1-2 on Azure Linux 3.0ImportantOut-of-bandKubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read
CVE-2025-15649 ↗2026-05-31azl3 perl 5.38.2-509 on Azure Linux 3.0ModerateOut-of-bandIO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date
CVE-2025-71272 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandmost: core: fix resource leak in most_register_interface error paths
CVE-2025-71273 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandwifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()
CVE-2025-71285 ↗2026-05-07azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: qrtr: Drop the MHI auto_queue feature for IPCR DL channels
CVE-2025-71289 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandfs/ntfs3: handle attr_set_size() errors when truncating files
CVE-2025-71290 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandmisc: ti_fpc202: fix a potential memory leak in probe function
CVE-2025-71293 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu/ras: Move ras data alloc before bad page check
CVE-2025-71294 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: fix NULL pointer issue buffer funcs
CVE-2025-71299 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandspi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing
CVE-2026-10028 ↗2026-06-02azl3 glib-networking 2.78.0-2 on Azure Linux 3.0ModerateOut-of-bandGlib-networking: infinite loop in glib-networking gnutls backend allows remote denial of service via circular certificate chain
CVE-2026-2291 ↗2026-05-15azl3 dnsmasq 2.92-1 on Azure Linux 3.0ModerateOut-of-bandCVE-2026-2291
CVE-2026-23631 ↗2026-05-08azl3 valkey 8.0.7-1 on Azure Linux 3.0ModerateOut-of-bandredis-server Lua use-after-free may allow remote code execution
CVE-2026-23679 ↗2026-05-28azl3 libgusb 0.3.5-3 on Azure Linux 3.0ModerateOut-of-bandlibusb < 1.0.30 NULL Pointer Dereference in parse_interface()
CVE-2026-25680 ↗2026-05-27azl3 application-gateway-kubernetes-ingress 1.7.7-3 on Azure Linux 3.0ModerateOut-of-bandInvoking denial of service when parsing arbitrary HTML in golang.org/x/net/html
CVE-2026-25681 ↗2026-05-27azl3 application-gateway-kubernetes-ingress 1.7.7-3 on Azure Linux 3.0ModerateOut-of-bandInvoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
CVE-2026-27136 ↗2026-05-27azl3 application-gateway-kubernetes-ingress 1.7.7-3 on Azure Linux 3.0ModerateOut-of-bandInvoking duplicate attributes can cause XSS in golang.org/x/net/html
CVE-2026-31696 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandrxrpc: Fix missing validation of ticket length in non-XDR key preparsing
CVE-2026-31715 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix UAF caused by decrementing sbi->nr_pages[] in f2fs_write_end_io()
CVE-2026-31767 ↗2026-05-13azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode
CVE-2026-32792 ↗2026-05-21azl3 unbound 1.19.1-5 on Azure Linux 3.0ModerateOut-of-bandPacket of death with DNSCrypt
CVE-2026-33006 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ModerateOut-of-bandApache HTTP Server: mod_auth_digest timing attack
CVE-2026-33007 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ModerateOut-of-bandApache HTTP Server: mod_authn_socache crash
CVE-2026-33523 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ModerateOut-of-bandApache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line
CVE-2026-33846 ↗2026-05-09azl3 gnutls 3.8.3-11 on Azure Linux 3.0ModerateOut-of-bandGnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly
CVE-2026-33857 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ModerateOut-of-bandApache HTTP Server: Off-by-one OOB reads in AJP getter functions
CVE-2026-34032 ↗2026-05-07azl3 httpd 2.4.66-1 on Azure Linux 3.0ModerateOut-of-bandApache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)
CVE-2026-34956 ↗2026-05-15azl3 openvswitch 3.3.0-3 on Azure Linux 3.0ModerateOut-of-bandOpenvswitch: open vswitch: denial of service via malformed ftp epasv command
CVE-2026-35429 ↗2026-05-11Microsoft Edge for AndroidModerateOut-of-band0%Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2026-3592 ↗2026-05-23azl3 bind 9.20.21-1 on Azure Linux 3.0ModerateOut-of-bandAmplification vulnerabilities via self-pointed glue records
CVE-2026-37458 ↗2026-05-09azl3 frr 10.5.0-3 on Azure Linux 3.0ModerateOut-of-bandMissing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.
CVE-2026-37459 ↗2026-05-09azl3 frr 10.5.0-3 on Azure Linux 3.0ModerateOut-of-bandAn integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
CVE-2026-39817 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ModerateOut-of-bandInvoking "go tool pack" does not sanitize output paths in cmd/go
CVE-2026-39819 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ModerateOut-of-bandInvoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
CVE-2026-39823 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ModerateOut-of-bandBypass of meta content URL escaping causes XSS in html/template
CVE-2026-39825 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ModerateOut-of-bandReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil
CVE-2026-39826 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ModerateOut-of-bandEscaper bypass leads to XSS in html/template
CVE-2026-39827 ↗2026-05-27azl3 cert-manager 1.12.15-6 on Azure Linux 3.0ModerateOut-of-bandInvoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh
CVE-2026-39828 ↗2026-05-27azl3 cert-manager 1.12.15-6 on Azure Linux 3.0ModerateOut-of-bandInvoking bypass of certificate restrictions in golang.org/x/crypto/ssh
CVE-2026-39835 ↗2026-05-27azl3 cert-manager 1.12.15-6 on Azure Linux 3.0ModerateOut-of-bandInvoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh
CVE-2026-40460 ↗2026-05-16azl3 nginx 1.28.3-1 on Azure Linux 3.0ModerateOut-of-bandNGINX ngx_quic_module vulnerability
CVE-2026-40612 ↗2026-05-13azl3 jq 1.7.1-5 on Azure Linux 3.0ModerateOut-of-bandjq: Stack overflow via unbounded recursion in jv_contains
CVE-2026-40622 ↗2026-05-21azl3 unbound 1.19.1-5 on Azure Linux 3.0ModerateOut-of-bandAnother 'ghost domain names' attack variant
CVE-2026-40701 ↗2026-05-16azl3 nginx 1.28.3-1 on Azure Linux 3.0ModerateOut-of-bandNGINX ngx_http_ssl_module vulnerability
CVE-2026-41107 ↗2026-05-11Microsoft Edge (Chromium-based)ModerateOut-of-band1%Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-41184 ↗2026-05-30azl3 cni-plugins 1.4.0-5 on Azure Linux 3.0ModerateOut-of-bandServiceAccount token disclosure via install-cni container logs
CVE-2026-41256 ↗2026-05-13azl3 jq 1.7.1-5 on Azure Linux 3.0ModerateOut-of-bandjq: Embedded NUL truncates top-level jq programs loaded with -f
CVE-2026-41257 ↗2026-05-13azl3 jq 1.7.1-5 on Azure Linux 3.0ModerateOut-of-bandjq: Signed-int overflow in `stack_reallocate` (jq VM stack)
CVE-2026-41292 ↗2026-05-21azl3 unbound 1.19.1-5 on Azure Linux 3.0ModerateOut-of-bandLong list of incoming EDNS options degrades performance
CVE-2026-42009 ↗2026-05-23azl3 gnutls 3.8.3-11 on Azure Linux 3.0ModerateOut-of-bandGnutls: gnutls: denial of service via dtls packet reordering vulnerability
CVE-2026-42010 ↗2026-05-15azl3 gnutls 3.8.3-8 on Azure Linux 3.0ModerateOut-of-bandGnutls: gnutls: authentication bypass via nul character in username
CVE-2026-42011 ↗2026-05-15azl3 gnutls 3.8.3-8 on Azure Linux 3.0ModerateOut-of-bandGnutls: gnutls: security bypass due to incorrect name constraint handling
CVE-2026-42015 ↗2026-05-31azl3 gnutls 3.8.3-8 on Azure Linux 3.0ModerateOut-of-bandGnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling
CVE-2026-42250 ↗2026-05-29azl3 bzip2 1.0.8-1 on Azure Linux 3.0ModerateOut-of-bandOff-by-One Leading to Out-of-Bounds Write in bzip2
CVE-2026-42256 ↗2026-05-11azl3 ruby 3.3.5-8 on Azure Linux 3.0ModerateOut-of-bandnet-imap: Denial of service via high iteration count for `SCRAM-*` authentication
CVE-2026-42257 ↗2026-05-11azl3 ruby 3.3.5-8 on Azure Linux 3.0ModerateOut-of-bandnet-imap: Command Injection via "raw" arguments to multiple commands
CVE-2026-42258 ↗2026-05-11azl3 ruby 3.3.5-8 on Azure Linux 3.0ModerateOut-of-bandnet-imap: Command Injection via unvalidated Symbol inputs
CVE-2026-42497 ↗2026-05-29azl3 perl 5.38.2-509 on Azure Linux 3.0ModerateOut-of-bandArchive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory
CVE-2026-42502 ↗2026-05-27azl3 application-gateway-kubernetes-ingress 1.7.7-3 on Azure Linux 3.0ModerateOut-of-bandInvoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html
CVE-2026-42506 ↗2026-05-27azl3 application-gateway-kubernetes-ingress 1.7.7-3 on Azure Linux 3.0ModerateOut-of-bandInvoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html
CVE-2026-42891 ↗2026-05-11Microsoft Edge for AndroidModerateOut-of-band0%Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2026-42923 ↗2026-05-21azl3 unbound 1.19.1-5 on Azure Linux 3.0ModerateOut-of-bandDegradation of service with unbounded NSEC3 hash calculations
CVE-2026-42934 ↗2026-05-16azl3 nginx 1.28.3-1 on Azure Linux 3.0ModerateOut-of-bandNGINX ngx_http_charset_module vulnerability
CVE-2026-42944 ↗2026-05-21azl3 unbound 1.19.1-5 on Azure Linux 3.0ModerateOut-of-bandHeap overflow with multiple NSID, COOKIE, PADDING EDNS options
CVE-2026-42959 ↗2026-05-21azl3 unbound 1.19.1-5 on Azure Linux 3.0ModerateOut-of-bandCrash during DNSSEC validation of malicious content
CVE-2026-42960 ↗2026-05-21azl3 unbound 1.19.1-5 on Azure Linux 3.0ModerateOut-of-bandPossible cache poisoning via promiscuous records for the authority section
CVE-2026-43010 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandbpf: Reject sleepable kprobe_multi programs at attach time
CVE-2026-43029 ↗2026-05-25azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmptcp: fix soft lockup in mptcp_recvmsg()
CVE-2026-43036 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: use skb_header_pointer() for TCPv4 GSO frag_off check
CVE-2026-43053 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandxfs: close crash window in attr dabtree inactivation
CVE-2026-43073 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandx86-64: rename misleadingly named '__copy_user_nocache()' function
CVE-2026-43083 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: ioam6: fix OOB and missing lock
CVE-2026-43088 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: af_key: zero aligned sockaddr tail in PF_KEY exports
CVE-2026-43101 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data()
CVE-2026-43107 ↗2026-05-07azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandxfrm: account XFRMA_IF_ID in aevent size calculation
CVE-2026-43109 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandx86: shadow stacks: proper error handling for mmap lock
CVE-2026-43115 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandsrcu: Use irq_work to start GP in tiny SRCU
CVE-2026-43116 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandnetfilter: ctnetlink: ensure safe access to master conntrack
CVE-2026-43118 ↗2026-05-07azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix zero size inode with non-zero size after log replay
CVE-2026-43119 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandBluetooth: hci_sync: annotate data-races around hdev->req_status
CVE-2026-43126 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandALSA: mixer: oss: Add card disconnect checkpoints
CVE-2026-43127 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandntfs3: fix circular locking dependency in run_unpack_ex
CVE-2026-43129 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandima: verify the previous kernel's IMA buffer lies in addressable RAM
CVE-2026-43131 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/amd/pm: Fix null pointer dereference issue
CVE-2026-43137 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandASoC: SOF: Intel: hda: Fix NULL pointer dereference
CVE-2026-43153 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandxfs: remove xfs_attr_leaf_hasname
CVE-2026-43161 ↗2026-05-07azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandiommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode
CVE-2026-43165 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandhwmon: (nct7363) Fix a resource leak in nct7363_present_pwm_fanin
CVE-2026-43172 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandwifi: iwlwifi: fix 22000 series SMEM parsing
CVE-2026-43185 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandksmbd: fix signededness bug in smb_direct_prepare_negotiation()
CVE-2026-43191 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Adjust PHY FSM transition to TX_EN-to-PLL_ON for TMDS on DCN35
CVE-2026-43195 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: validate user queue size constraints
CVE-2026-43197 ↗2026-05-07azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetconsole: avoid OOB reads, msg is not nul-terminated
CVE-2026-43198 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandtcp: fix potential race in tcp_v6_syn_recv_sock()
CVE-2026-43199 ↗2026-05-07azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query
CVE-2026-43201 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandAPEI/GHES: ARM processor Error: don't go past allocated memory
CVE-2026-43204 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandASoC: qcom: q6asm: drop DSP responses for closed data streams
CVE-2026-43216 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: Drop the lock in skb_may_tx_timestamp()
CVE-2026-43220 ↗2026-05-14azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-bandiommu/amd: serialize sequence allocation under concurrent TLB invalidations
CVE-2026-43234 ↗2026-05-07azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandteam: avoid NETDEV_CHANGEMTU event when unregistering slave
CVE-2026-43237 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4
CVE-2026-43243 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Add signal type check for dcn401 get_phyd32clk_src
CVE-2026-43244 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandkcm: fix zero-frag skb in frag_list on partial sendmsg error
CVE-2026-43245 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandntfs: ->d_compare() must not block
CVE-2026-43248 ↗2026-05-07azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-bandvhost: move vdpa group bound check to vhost_vdpa
CVE-2026-43250 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandusb: chipidea: udc: fix DMA and SG cleanup in _ep_nuke()
CVE-2026-43274 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandmailbox: mchp-ipc-sbi: fix out-of-bounds access in mchp_ipc_get_cluster_aggr_irq()
CVE-2026-43292 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandmm/vmalloc: prevent RCU stalls in kasan_release_vmalloc_node
CVE-2026-43294 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels
CVE-2026-43299 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandbtrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure()
CVE-2026-43300 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/panel: Fix a possible null-pointer dereference in jdi_panel_dsi_remove()
CVE-2026-43303 ↗2026-05-09azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-bandmm/page_alloc: clear page->private in free_pages_prepare()
CVE-2026-43305 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Fix mismatched unlock for DMUB HW lock in HWSS fast path
CVE-2026-43306 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandbpf: crypto: Use the correct destructor kfunc type
CVE-2026-43308 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandbtrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref()
CVE-2026-43309 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandmd raid: fix hang when stopping arrays with metadata through dm-raid
CVE-2026-43310 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandmedia: verisilicon: Avoid G2 bus error while decoding H.264 and HEVC
CVE-2026-43311 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandsoc/tegra: pmc: Fix unsafe generic_handle_irq() call
CVE-2026-43319 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandspi: spidev: fix lock inversion between spi_lock and buf_lock
CVE-2026-43331 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandx86/kexec: Disable KCOV instrumentation after load_segments()
CVE-2026-43338 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandbtrfs: reserve enough transaction items for qgroup ioctls
CVE-2026-43344 ↗2026-05-09azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandperf/x86/intel/uncore: Fix die ID init and look up bugs
CVE-2026-43352 ↗2026-05-09azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-bandi3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue
CVE-2026-43414 ↗2026-05-25azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: qla2xxx: Completely fix fcport double free
CVE-2026-43416 ↗2026-05-09azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandpowerpc, perf: Check that current->mm is alive before getting user callchain
CVE-2026-43456 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandbonding: fix type confusion in bond_setup_by_slave()
CVE-2026-43464 ↗2026-05-22azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/mlx5e: RX, Fix XDP multi-buf frag counting for legacy RQ
CVE-2026-43465 ↗2026-05-22azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ
CVE-2026-43491 ↗2026-05-20azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: qrtr: ns: Limit the maximum server registration per node
CVE-2026-43492 ↗2026-05-20azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandlib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl()
CVE-2026-43494 ↗2026-05-22azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/rds: reset op_nents when zerocopy page pin fails
CVE-2026-43495 ↗2026-05-22azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler
CVE-2026-43496 ↗2026-05-22azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked
CVE-2026-43501 ↗2026-05-22azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandipv6: rpl: reserve mac_len headroom when recompressed SRH grows
CVE-2026-43502 ↗2026-05-22azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/rds: handle zerocopy send cleanup before the message is queued
CVE-2026-43617 ↗2026-05-21azl3 rsync 3.4.1-2 on Azure Linux 3.0ModerateOut-of-bandRsync < 3.4.3 Authorization Bypass via Hostname Resolution
CVE-2026-43619 ↗2026-05-21azl3 rsync 3.4.1-2 on Azure Linux 3.0ModerateOut-of-bandRsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls
CVE-2026-43620 ↗2026-05-21azl3 rsync 3.4.1-2 on Azure Linux 3.0ModerateOut-of-bandRsync < 3.4.3 Out-of-Bounds Array Read via recv_files()
CVE-2026-43868 ↗2026-05-07cbl2 ceph 16.2.10-11 on CBL Mariner 2.0ModerateOut-of-bandApache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern
CVE-2026-43894 ↗2026-05-13azl3 jq 1.7.1-5 on Azure Linux 3.0ModerateOut-of-bandjq: Wild stack write via signed-integer overflow in decNumber D2U() macro
CVE-2026-43895 ↗2026-05-13azl3 jq 1.7.1-5 on Azure Linux 3.0ModerateOut-of-bandjq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts
CVE-2026-43896 ↗2026-05-13azl3 jq 1.7.1-5 on Azure Linux 3.0ModerateOut-of-bandjq: Stack Overflow in Recursive Object Merge
CVE-2026-43970 ↗2026-05-21azl3 rabbitmq-server 3.13.7-3 on Azure Linux 3.0ModerateOut-of-bandDecompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame
CVE-2026-44283 ↗2026-05-17azl3 etcd 3.5.28-1 on Azure Linux 3.0ModerateOut-of-bandetcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks
CVE-2026-44608 ↗2026-05-21azl3 unbound 1.19.1-5 on Azure Linux 3.0ModerateOut-of-bandUse after free and crash under special conditions in RPZ code
CVE-2026-44656 ↗2026-05-10azl3 vim 9.2.0392-1 on Azure Linux 3.0ModerateOut-of-bandVim: OS Command Injection via 'path' completion
CVE-2026-44662 ↗2026-05-16azl3 clamav 1.5.2-2 on Azure Linux 3.0ModerateOut-of-bandrust-openssl: Heap buffer overflow when encrypting with AES key-wrap-with-padding
CVE-2026-44708 ↗2026-05-28azl3 python-mistune 3.0.2-1 on Azure Linux 3.0ModerateOut-of-bandMistune Math Plugin XSS Escape Bypass
CVE-2026-44777 ↗2026-05-14azl3 jq 1.7.1-5 on Azure Linux 3.0ModerateOut-of-bandjq: stack overflow in module loading on mutual `include`
CVE-2026-44839 ↗2026-05-31azl3 rabbitmq-server 3.13.7-6 on Azure Linux 3.0ModerateOut-of-bandRabbitMQ: Unsanitized vhost names allow for XSS in management UI
CVE-2026-44844 ↗2026-05-28azl3 perl-XML-Parser 2.47-2 on Azure Linux 3.0ModerateOut-of-bandeml_parser: Recursion DoS via nested message/rfc822 attachments
CVE-2026-44897 ↗2026-05-28azl3 python-mistune 3.0.2-1 on Azure Linux 3.0ModerateOut-of-bandMistune Heading ID Attribute Injection XSS
CVE-2026-44898 ↗2026-05-28azl3 python-mistune 3.0.2-1 on Azure Linux 3.0ModerateOut-of-bandMistune TOC Anchor Injection XSS
CVE-2026-44899 ↗2026-05-28azl3 python-mistune 3.0.2-1 on Azure Linux 3.0ModerateOut-of-bandMistune Image Directive CSS Injection Vulnerability
CVE-2026-45130 ↗2026-05-10azl3 vim 9.2.0392-1 on Azure Linux 3.0ModerateOut-of-bandVim: Heap Buffer Overflow in spell file loading
CVE-2026-45492 ↗2026-05-15Microsoft Edge (Chromium-based)ModerateOut-of-band0%More likelyMicrosoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2026-45494 ↗2026-05-15Microsoft Edge (Chromium-based)ModerateOut-of-band0%More likelyMicrosoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-45571 ↗2026-05-28azl3 packer 1.9.5-13 on Azure Linux 3.0ModerateOut-of-bandgo-git: Crafted repositories may modify main and submodule .git directories
CVE-2026-45736 ↗2026-05-21azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandws: Uninitialized memory disclosure
CVE-2026-45834 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb()
CVE-2026-45835 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb()
CVE-2026-45836 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb()
CVE-2026-45838 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: fix end-of-list detection in cgroup_storage_get_next_key()
CVE-2026-45839 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: reject negative CO-RE accessor indices in bpf_core_parse_spec()
CVE-2026-45840 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandopenvswitch: cap upcall PID array size and pre-size vport replies
CVE-2026-45841 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO
CVE-2026-45842 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandslip: reject VJ receive packets on instances with no rstate array
CVE-2026-45843 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandslip: bound decode() reads against the compressed packet length
CVE-2026-45844 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: arp_tables: fix IEEE1394 ARP payload parsing
CVE-2026-45845 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/sched: taprio: fix NULL pointer dereference in class dump
CVE-2026-45846 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst()
CVE-2026-45850 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandipvs: skip ipv6 extension headers for csum checks
CVE-2026-45855 ↗2026-05-28azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandata: libata-scsi: avoid Non-NCQ command starvation
CVE-2026-45858 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandext4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1
CVE-2026-45859 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nfnetlink_queue: do shared-unconfirmed check before segmentation
CVE-2026-45861 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandgfs2: Fix slab-use-after-free in qd_put
CVE-2026-45877 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandHID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clients
CVE-2026-45894 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandiommu/vt-d: Clear Present bit before tearing down PASID entry
CVE-2026-45897 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nft_counter: serialize reset with spinlock
CVE-2026-45901 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nf_tables: revert commit_mutex usage in reset path
CVE-2026-45917 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandipvs: do not keep dest_dst if dev is going down
CVE-2026-45930 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: mctp: ensure our nlmsg responses are initialised
CVE-2026-45932 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Fix tcx/netkit detach permissions when prog fd isn't given
CVE-2026-45934 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix EEXIST abort due to non-consecutive gaps in chunk allocation
CVE-2026-45940 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: stmmac: fix oops when split header is enabled
CVE-2026-45943 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banderofs: fix inline data read failure for ztailpacking pclusters
CVE-2026-45944 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandiommu/vt-d: Clear Present bit before tearing down context entry
CVE-2026-45949 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandhwrng: core - use RCU and work_struct to fix race condition
CVE-2026-45961 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandgfs2: fix memory leaks in gfs2_fill_super error path
CVE-2026-45963 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandASoC: nau8821: Cancel delayed work on component remove
CVE-2026-45973 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/mlx5: Fix UMR hang in LAG error state unload
CVE-2026-45986 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: ccree - fix a memory leak in cc_mac_digest()
CVE-2026-45987 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2
CVE-2026-45988 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandrxrpc: Fix re-decryption of RESPONSE packets
CVE-2026-45989 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandof: unittest: fix use-after-free in testdrv_probe()
CVE-2026-45991 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandudf: fix partition descriptor append bookkeeping
CVE-2026-45993 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandLoongArch: Add spectre boundry for syscall dispatch table
CVE-2026-45994 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandibmasm: fix OOB reads in command_file_write due to missing size checks
CVE-2026-45996 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: imx: fix use-after-free on unbind
CVE-2026-45997 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: sd: fix missing put_disk() when device_add(&disk_dev) fails
CVE-2026-45998 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandrxrpc: Fix potential UAF after skb_unshare() failure
CVE-2026-45999 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banderofs: fix unsigned underflow in z_erofs_lz4_handle_overlap()
CVE-2026-46000 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandrxrpc: Fix conn-level packet handling to unshare RESPONSE packets
CVE-2026-46002 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandext2: reject inodes with zero i_nlink and valid mode in ext2_iget()
CVE-2026-46003 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: qrtr: ns: Limit the total number of nodes
CVE-2026-46005 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandxfs: fix a resource leak in xfs_alloc_buftarg()
CVE-2026-46006 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/nouveau: fix u32 overflow in pushbuf reloc bounds check
CVE-2026-46009 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandPCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown
CVE-2026-46011 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmedia: mtk-jpeg: fix use-after-free in release path due to uncancelled work
CVE-2026-46012 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandrxrpc: Fix memory leaks in rxkad_verify_response()
CVE-2026-46014 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: SVM: Add missing save/restore handling of LBR MSRs
CVE-2026-46015 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandtcp: call sk_data_ready() after listener migration
CVE-2026-46016 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandremoteproc: xlnx: Only access buffer information if IPI is buffered
CVE-2026-46017 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmm: fix deferred split queue races during migration
CVE-2026-46018 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES
CVE-2026-46019 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup
CVE-2026-46021 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandthermal: core: Fix thermal zone governor cleanup issues
CVE-2026-46022 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmisc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt()
CVE-2026-46024 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandlibceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply()
CVE-2026-46026 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: qrtr: ns: Limit the maximum number of lookups
CVE-2026-46027 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/smc: avoid early lgr access in smc_clc_wait_msg
CVE-2026-46031 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: ks8851: Reinstate disabling of BHs around IRQ handler
CVE-2026-46032 ↗2026-05-28azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: nSVM: Triple fault if restore host CR3 fails on nested #VMEXIT
CVE-2026-46033 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: authencesn - reject short ahash digests during instance creation
CVE-2026-46037 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandipv4: icmp: validate reply type before using icmp_pointers
CVE-2026-46038 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: qrtr: ns: Free the node during ctrl_cmd_bye()
CVE-2026-46040 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandinotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails
CVE-2026-46043 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv
CVE-2026-46046 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all()
CVE-2026-46047 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: qrtr: ns: Fix use-after-free in driver remove()
CVE-2026-46048 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: caiaq: fix usb_dev refcount leak on probe failure
CVE-2026-46049 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: ctxfi: Add fallback to default RSR for S/PDIF
CVE-2026-46050 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmd/raid10: fix deadlock with check operation and nowait requests
CVE-2026-46051 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmd/raid5: fix soft lockup in retry_aligned_read()
CVE-2026-46052 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandceph: only d_add() negative dentries when they are unhashed
CVE-2026-46053 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: rds: fix MR cleanup on copy error
CVE-2026-46054 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandselinux: fix overlayfs mmap() and mprotect() access checks
CVE-2026-46056 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: hci_event: fix potential UAF in SSP passkey handlers
CVE-2026-46058 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmedia: amphion: Fix race between m2m job_abort and device_run
CVE-2026-46059 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN
CVE-2026-46062 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandntfs3: fix integer overflow in run_unpack() volume boundary check
CVE-2026-46063 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandx86/shstk: Prevent deadlock during shstk sigreturn
CVE-2026-46064 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandibmasm: fix heap over-read in ibmasm_send_i2o_message()
CVE-2026-46065 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandfbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info
CVE-2026-46066 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandceph: fix num_ops off-by-one when crypto allocation fails
CVE-2026-46068 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx
CVE-2026-46069 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup()
CVE-2026-46070 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmd/raid5: validate payload size before accessing journal metadata
CVE-2026-46071 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: nSVM: Avoid clearing VMCB_LBR in vmcb12
CVE-2026-46072 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandntfs3: add buffer boundary checks to run_unpack()
CVE-2026-46075 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: atmel-sha204a - Fix potential UAF and memory leak in remove path
CVE-2026-46076 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1
CVE-2026-46077 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: atmel-tdes - fix DMA sync direction
CVE-2026-46078 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banderofs: fix the out-of-bounds nameoff handling for trailing dirents
CVE-2026-46079 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandrbd: fix null-ptr-deref when device_add_disk() fails
CVE-2026-46080 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandocfs2: split transactions in dio completion to avoid credit exhaustion
CVE-2026-46082 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0
CVE-2026-46083 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: fix resource leaks on device setup failure
CVE-2026-46084 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/mana_ib: Disable RX steering on RSS QP destroy
CVE-2026-46085 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandrxrpc: Fix rxkad crypto unalignment handling
CVE-2026-46086 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: bridge: use a stable FDB dst snapshot in RCU readers
CVE-2026-46088 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names()
CVE-2026-46089 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandzram: do not forget to endio for partial discard requests
CVE-2026-46090 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: aloop: Fix peer runtime UAF during format-change stop
CVE-2026-46091 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmedia: rc: igorplugusb: heed coherency rules
CVE-2026-46092 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: rtw88: check for PCI upstream bridge existence
CVE-2026-46094 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandext4: fix bounds check in check_xattrs() to prevent out-of-bounds access
CVE-2026-46098 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: caif: clear client service pointer on teardown
CVE-2026-46099 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels
CVE-2026-46101 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: reject zero shift in nft_bitwise
CVE-2026-46102 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: strparser: fix skb_head leak in strp_abort_strp()
CVE-2026-46103 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandcan: ucan: fix devres lifetime
CVE-2026-46106 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandeventfs: Hold eventfs_mutex and SRCU when remount walks events
CVE-2026-46107 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddm-thin: fix metadata refcount underflow
CVE-2026-46108 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandipmi:si: Return state to normal if message allocation fails
CVE-2026-46109 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: ulpi: fix memory leak on ulpi_register() error paths
CVE-2026-46110 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: stmmac: Prevent NULL deref when RX memory exhausted
CVE-2026-46111 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: hci_conn: fix potential UAF in create_big_sync
CVE-2026-46112 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/hns: Fix unlocked call to hns_roce_qp_remove()
CVE-2026-46113 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: x86: Fix shadow paging use-after-free due to unexpected GFN
CVE-2026-46114 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads
CVE-2026-46115 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandblock: add pgmap check to biovec_phys_mergeable
CVE-2026-46116 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandxfrm: defensively unhash xfrm_state lists in __xfrm_state_delete
CVE-2026-46119 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandlibceph: Fix slab-out-of-bounds access in auth message processing
CVE-2026-46120 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandip6_gre: Use cached t->net in ip6erspan_changelink().
CVE-2026-46121 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock
CVE-2026-46122 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: b43: enforce bounds check on firmware key index in b43_rx()
CVE-2026-46124 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandisofs: validate block number from NFS file handle in isofs_export_iget
CVE-2026-46125 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mac80211: remove station if connection prep fails
CVE-2026-46127 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp()
CVE-2026-46128 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandipmi: Check event message buffer response for bad data
CVE-2026-46129 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix double free in create_space_info() error path
CVE-2026-46130 ↗2026-05-29azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-banddm-verity-fec: fix reading parity bytes split across blocks (take 3)
CVE-2026-46131 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: x86: check for nEPT/nNPT in slow flush hypercalls
CVE-2026-46132 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo
CVE-2026-46133 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/rxe: Reject unknown opcodes before ICRC processing
CVE-2026-46135 ↗2026-05-29azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandnvmet-tcp: fix race between ICReq handling and queue teardown
CVE-2026-46136 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mt76: mt7921: fix a potential clc buffer length underflow
CVE-2026-46137 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmptcp: pm: ADD_ADDR rtx: fix potential data-race
CVE-2026-46138 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt
CVE-2026-46140 ↗2026-06-25azl3 kernel 6.6.142.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: btmtk: validate WMT event SKB length before struct access
CVE-2026-46142 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: libwx: fix VF illegal register access
CVE-2026-46144 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/mana: Fix error unwind in mana_ib_create_qp_rss()
CVE-2026-46145 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/mana: Validate rx_hash_key_len
CVE-2026-46146 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3()
CVE-2026-46147 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: arm64: Fix pin leak and publication ordering in __pkvm_init_vcpu()
CVE-2026-46148 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: microchip-core-qspi: control built-in cs manually
CVE-2026-46149 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show()
CVE-2026-46151 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: usblp: fix heap leak in IEEE 1284 device ID via short response
CVE-2026-46152 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mac80211: drop stray 'static' from fast-RX rx_result
CVE-2026-46153 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band8021q: delete cleared egress QoS mappings
CVE-2026-46155 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandsmb/client: fix out-of-bounds read in smb2_compound_op()
CVE-2026-46156 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandLoongArch: Fix potential ADE in loongson_gpu_fixup_dma_hang()
CVE-2026-46157 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger
CVE-2026-46158 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmptcp: pm: ADD_ADDR rtx: always decrease sk refcount
CVE-2026-46159 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak
CVE-2026-46160 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix missing last_unlink_trans update when removing a directory
CVE-2026-46161 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmd/raid10: fix divide-by-zero in setup_geo() with zero far_copies
CVE-2026-46163 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: b43legacy: enforce bounds check on firmware key index in RX path
CVE-2026-46164 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix double free in create_space_info_sub_group() error path
CVE-2026-46165 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandopenvswitch: vport: fix self-deadlock on release of tunnel ports
CVE-2026-46167 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl
CVE-2026-46168 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmptcp: fix scheduling with atomic in timestamp sockopt
CVE-2026-46170 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmptcp: pm: ADD_ADDR rtx: free sk if last
CVE-2026-46171 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandriscv: kvm: fix vector context allocation leak
CVE-2026-46172 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandipv6: xfrm6: release dst on error in xfrm6_rcv_encap()
CVE-2026-46173 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandexit: prevent preemption of oopsing TASK_DEAD task
CVE-2026-46174 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandx86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache
CVE-2026-46175 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix fsck inconsistency caused by FGGC of node block
CVE-2026-46176 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init()
CVE-2026-46177 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandipmi: Add limits to event and receive message requests
CVE-2026-46178 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq()
CVE-2026-46179 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandASoC: SOF: Don't allow pointer operations on unconfigured streams
CVE-2026-46180 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task
CVE-2026-46181 ↗2026-05-29azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event()
CVE-2026-46184 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandsound: ua101: fix division by zero at probe
CVE-2026-46185 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandsmb/client: fix out-of-bounds read in symlink_data()
CVE-2026-46186 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: virtio_bt: validate rx pkt_type header length
CVE-2026-46187 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: rsi: fix kthread lifetime race between self-exit and external-stop
CVE-2026-46189 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path
CVE-2026-46190 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show()
CVE-2026-46193 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandxfrm: ah: account for ESN high bits in async callbacks
CVE-2026-46194 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix node_cnt race between extent node destroy and writeback
CVE-2026-46195 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandsmb: client: validate dacloffset before building DACL pointers
CVE-2026-46196 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandtracepoint: balance regfunc() on func_add() failure in tracepoint_add_func()
CVE-2026-46197 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdkfd: validate SVM ioctl nattr against buffer size
CVE-2026-46198 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbatman-adv: fix integer overflow on buff_pos
CVE-2026-46199 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg
CVE-2026-46200 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: mpc52xx: fix controller deregistration
CVE-2026-46204 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu/vcn4: Prevent OOB reads when parsing IB
CVE-2026-46205 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandstaging: media: atomisp: Disallow all private IOCTLs
CVE-2026-46206 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbatman-adv: reject new tp_meter sessions during teardown
CVE-2026-46208 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbatman-adv: stop tp_meter sessions during mesh teardown
CVE-2026-46209 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs()
CVE-2026-46212 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbatman-adv: bla: prevent use-after-free when deleting claims
CVE-2026-46214 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandvsock/virtio: fix accept queue count leak on transport mismatch
CVE-2026-46218 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: Add bounds checking to ib_{get,set}_value
CVE-2026-46219 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: mpc52xx: fix use-after-free on unbind
CVE-2026-46220 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission
CVE-2026-46225 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: rspi: fix controller deregistration
CVE-2026-46226 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: fsl: fix controller deregistration
CVE-2026-46227 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandsctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL
CVE-2026-46229 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdkfd: Clear VRAM on allocation to prevent stale data exposure
CVE-2026-46230 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg
CVE-2026-46231 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbatman-adv: bla: put backbone reference on failed claim hash insert
CVE-2026-46232 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandHID: playstation: Clamp num_touch_reports
CVE-2026-46233 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbatman-adv: bla: only purge non-released claims
CVE-2026-46234 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandvsock: fix buffer size clamping order
CVE-2026-46235 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmedia: saa7164: add ioremap return checks and cleanups
CVE-2026-46236 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmedia: rc: xbox_remote: heed DMA restrictions
CVE-2026-46238 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbatman-adv: stop caching unowned originator pointers in BAT IV
CVE-2026-46241 ↗2026-05-29azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: mpc52xx: fix use-after-free on registration failure
CVE-2026-46333 ↗2026-05-16azl3 kernel-hwe 6.12.0.0-1 on Azure Linux 3.0ModerateOut-of-bandptrace: slightly saner 'get_dumpable()' logic
CVE-2026-46598 ↗2026-05-27azl3 docker-buildx 0.14.0-11 on Azure Linux 3.0ModerateOut-of-bandInvoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent
CVE-2026-4873 ↗2026-05-14azl3 curl 8.11.1-6 on Azure Linux 3.0ModerateOut-of-bandconnection reuse ignores TLS requirement
CVE-2026-4890 ↗2026-05-15azl3 dnsmasq 2.90-1 on Azure Linux 3.0ModerateOut-of-bandCVE-2026-4890
CVE-2026-4891 ↗2026-05-15azl3 dnsmasq 2.90-1 on Azure Linux 3.0ModerateOut-of-bandCVE-2026-4891
CVE-2026-4893 ↗2026-05-15azl3 dnsmasq 2.90-1 on Azure Linux 3.0ModerateOut-of-bandCVE-2026-4893
CVE-2026-5172 ↗2026-05-15azl3 dnsmasq 2.90-1 on Azure Linux 3.0ModerateOut-of-bandCVE-2026-5172
CVE-2026-5545 ↗2026-05-14azl3 curl 8.11.1-6 on Azure Linux 3.0ModerateOut-of-bandwrong reuse of HTTP Negotiate connection
CVE-2026-5773 ↗2026-05-14azl3 curl 8.11.1-6 on Azure Linux 3.0ModerateOut-of-bandwrong reuse of SMB connection
CVE-2026-5950 ↗2026-05-23azl3 bind 9.20.21-1 on Azure Linux 3.0ModerateOut-of-bandUnbounded resend loop in BIND 9 resolver
CVE-2026-6253 ↗2026-05-14azl3 curl 8.11.1-6 on Azure Linux 3.0ModerateOut-of-bandproxy credentials leak over redirect-to proxy
CVE-2026-6276 ↗2026-05-14azl3 curl 8.11.1-6 on Azure Linux 3.0ModerateOut-of-bandstale custom cookie host causes cookie leak
CVE-2026-6324 ↗2026-06-02azl3 libsoup 3.4.4-15 on Azure Linux 3.0ModerateOut-of-bandLibsoup: libsoup: http request smuggling via unsigned to signed conversion error
CVE-2026-6402 ↗2026-05-27azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandwebpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins
CVE-2026-6429 ↗2026-05-14azl3 curl 8.11.1-6 on Azure Linux 3.0ModerateOut-of-bandnetrc credential leak with reused proxy connection
CVE-2026-6472 ↗2026-05-16azl3 postgresql 16.12-1 on Azure Linux 3.0ModerateOut-of-bandPostgreSQL CREATE TYPE does not check multirange schema CREATE privilege
CVE-2026-6474 ↗2026-05-16azl3 postgresql 16.12-1 on Azure Linux 3.0ModerateOut-of-bandPostgreSQL timeofday() can disclose portions of server memory
CVE-2026-6478 ↗2026-05-16azl3 postgresql 16.12-1 on Azure Linux 3.0ModerateOut-of-bandPostgreSQL discloses MD5-hashed passwords via covert timing channel
CVE-2026-6666 ↗2026-05-10azl3 pgbouncer 1.25.1-1 on Azure Linux 3.0ModerateOut-of-bandPgBouncer crash in kill_pool_logins_server_error
CVE-2026-6667 ↗2026-05-10azl3 pgbouncer 1.25.1-1 on Azure Linux 3.0ModerateOut-of-bandPgBouncer missing authorization check in KILL_CLIENT admin command
CVE-2026-7168 ↗2026-05-14azl3 curl 8.11.1-6 on Azure Linux 3.0ModerateOut-of-bandcross-proxy Digest auth state leak
CVE-2026-7210 ↗2026-05-15azl3 python3 3.12.9-10 on Azure Linux 3.0ModerateOut-of-bandThe expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
CVE-2026-7258 ↗2026-05-11azl3 php 8.3.29-1 on Azure Linux 3.0ModerateOut-of-bandOut-of-bounds read in urldecode() on NetBSD
CVE-2026-7261 ↗2026-05-11azl3 php 8.3.29-1 on Azure Linux 3.0ModerateOut-of-bandSoapServer session-persisted object use-after-free via SOAP header fault
CVE-2026-7568 ↗2026-05-11azl3 php 8.3.29-1 on Azure Linux 3.0ModerateOut-of-bandSigned integer overflow in metaphone()
CVE-2026-7790 ↗2026-05-15azl3 rabbitmq-server 3.13.7-3 on Azure Linux 3.0ModerateOut-of-bandUnbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS
CVE-2026-8177 ↗2026-05-13azl3 perl-XML-LibXML 2.0209-2 on Azure Linux 3.0ModerateOut-of-bandXML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences
CVE-2026-8328 ↗2026-05-17azl3 python3 3.12.9-11 on Azure Linux 3.0ModerateOut-of-bandFTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
CVE-2026-8368 ↗2026-05-17azl3 perl-libwww-perl 6.72-1 on Azure Linux 3.0ModerateOut-of-bandLWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects
CVE-2026-8376 ↗2026-05-27azl3 perl 5.38.2-509 on Azure Linux 3.0ModerateOut-of-bandPerl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
CVE-2026-8723 ↗2026-05-23azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandqs.stringify crashes on null/undefined entries in comma-format arrays under encodeValuesOnly
CVE-2026-9149 ↗2026-05-27azl3 libsolv 0.7.28-3 on Azure Linux 3.0ModerateOut-of-bandLibsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file
CVE-2026-9150 ↗2026-05-27azl3 libsolv 0.7.28-3 on Azure Linux 3.0ModerateOut-of-bandLibsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums
CVE-2025-14575 ↗2026-05-23azl3 qtbase 6.6.3-4 on Azure Linux 3.0LowOut-of-bandUncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loading
CVE-2026-40416 ↗2026-05-11Microsoft Edge (Chromium-based)LowOut-of-band0%Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2026-40510 ↗2026-05-31azl3 opensc 0.27.1-1 on Azure Linux 3.0LowOut-of-bandOpenSC < 0.27.0-rc1 Stack Buffer Overflow via piv_process_history() in card-piv.c
CVE-2026-40528 ↗2026-05-31azl3 opensc 0.27.1-1 on Azure Linux 3.0LowOut-of-bandOpenSC < 0.27.0 Buffer Overrun in do_key_value() via profile.c
CVE-2026-41889 ↗2026-05-10azl3 keda 2.14.1-11 on Azure Linux 3.0LowOut-of-bandpgx: SQL Injection via placeholder confusion with dollar quoted string literals
CVE-2026-42534 ↗2026-05-21azl3 unbound 1.19.1-5 on Azure Linux 3.0LowOut-of-bandJostle logic bypass degrades resolution performance
CVE-2026-43964 ↗2026-05-06azl3 postfix 3.9.0-2 on Azure Linux 3.0LowOut-of-bandPostfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.
CVE-2026-43968 ↗2026-05-15azl3 rabbitmq-server 3.13.7-3 on Azure Linux 3.0LowOut-of-bandCR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1
CVE-2026-43969 ↗2026-05-15azl3 rabbitmq-server 3.13.7-3 on Azure Linux 3.0LowOut-of-bandCookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
CVE-2026-44390 ↗2026-05-21azl3 unbound 1.19.1-5 on Azure Linux 3.0LowOut-of-bandUnbounded name compression in certain cases causes degradation of service
CVE-2026-44896 ↗2026-05-28azl3 python-mistune 3.0.2-1 on Azure Linux 3.0LowOut-of-bandMistune: XSS via unescaped figclass/figwidth in Figure directive
CVE-2026-45186 ↗2026-05-11azl3 cmake 3.30.3-13 on Azure Linux 3.0LowOut-of-bandIn libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
CVE-2026-45232 ↗2026-05-21azl3 rsync 3.4.1-2 on Azure Linux 3.0LowOut-of-bandRsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy
CVE-2026-45570 ↗2026-05-28azl3 packer 1.9.5-13 on Azure Linux 3.0LowOut-of-bandgo-git: Improper single-quote escaping in go-git SSH transport
CVE-2026-45803 ↗2026-05-21azl3 gh 2.62.0-15 on Azure Linux 3.0LowOut-of-bandgh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection
CVE-2026-45893 ↗2026-05-28azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowOut-of-bandapparmor: Fix & Optimize table creation from possibly unaligned memory
CVE-2026-46004 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0LowOut-of-bandALSA: caiaq: Handle probe errors properly
CVE-2026-46023 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0LowOut-of-banddm mirror: fix integer overflow in create_dirty_log()
CVE-2026-46044 ↗2026-05-28azl3 kernel 6.6.139.1-1 on Azure Linux 3.0LowOut-of-bandipmi:ssif: Clean up kthread on errors
CVE-2026-46123 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0LowOut-of-bandBluetooth: virtio_bt: clamp rx length before skb_put
CVE-2026-46143 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0LowOut-of-bandASoC: qcom: q6apm-lpass-dai: Fix multiple graph opens
CVE-2026-46169 ↗2026-05-29azl3 kernel 6.6.139.1-1 on Azure Linux 3.0LowOut-of-bandhfsplus: fix uninit-value by validating catalog record size
CVE-2026-46483 ↗2026-05-17azl3 vim 9.2.0392-1 on Azure Linux 3.0LowOut-of-bandVim: Command injection in tar#Vimuntar via missing shellescape {special} flag
CVE-2026-47104 ↗2026-05-28azl3 libgusb 0.3.5-3 on Azure Linux 3.0LowOut-of-bandlibusb < 1.0.30 Out-of-Bounds Read in parse_iad_array()
CVE-2026-5222 ↗2026-05-27azl3 rust 1.75.0-28 on Azure Linux 3.0LowOut-of-bandCargo can be coerced to share credentials between registries
CVE-2026-5223 ↗2026-05-27azl3 rust 1.75.0-28 on Azure Linux 3.0LowOut-of-bandCrates in third party registries can override the cached source of other crates
CVE-2026-6638 ↗2026-05-16azl3 postgresql 16.12-1 on Azure Linux 3.0LowOut-of-bandPostgreSQL REFRESH PUBLICATION allows SQL injection via table name
CVE-2026-7259 ↗2026-05-11azl3 php 8.3.29-1 on Azure Linux 3.0LowOut-of-bandNull pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()
CVE-2026-7262 ↗2026-05-11azl3 php 8.3.29-1 on Azure Linux 3.0LowOut-of-bandNULL pointer dereference in SOAP apache:Map decoder with missing <value>
CVE-2026-8295 ↗2026-05-15azl3 simdjson 3.11.6-2 on Azure Linux 3.0LowOut-of-bandInteger overflow in simdjson
CVE-2025-71302 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-banddrm/panthor: fix for dma-fence safe access rules
CVE-2026-10000 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10000 Use after free in Passwords
CVE-2026-10001 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10001 Use after free in PerformanceManager
CVE-2026-10002 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10002 Use after free in PDFium
CVE-2026-10003 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10003 Use after free in Views
CVE-2026-10004 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10004 Insufficient validation of untrusted input in Passwords
CVE-2026-10005 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10005 Use after free in WebAppInstalls
CVE-2026-10006 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10006 Race in WebAudio
CVE-2026-10007 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10007 Use after free in SVG
CVE-2026-10009 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10009 Integer overflow in Skia
CVE-2026-10011 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10011 Inappropriate implementation in Skia
CVE-2026-10012 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10012 Use after free in Skia
CVE-2026-10013 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10013 Use after free in WebCodecs
CVE-2026-10015 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10015 Integer overflow in WTF
CVE-2026-10016 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10016 Use after free in DOM
CVE-2026-10017 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10017 Out of bounds read in Headless
CVE-2026-10018 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10018 Integer overflow in ANGLE
CVE-2026-10019 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10019 Integer overflow in ANGLE
CVE-2026-10020 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10020 Insufficient validation of untrusted input in Skia
CVE-2026-10021 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10021 Insufficient validation of untrusted input in USB
CVE-2026-10022 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-10022 Type Confusion in V8
CVE-2026-31769 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0N/AOut-of-bandgpib: fix use-after-free in IO ioctl handlers
CVE-2026-43021 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0N/AOut-of-bandBluetooth: hci_sync: fix leaks when hci_cmd_sync_queue_once fails
CVE-2026-43022 ↗2026-05-02azl3 kernel 6.6.141.1-1 on Azure Linux 3.0N/AOut-of-bandBluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists
CVE-2026-43045 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0N/AOut-of-bandmshv: Fix error handling in mshv_region_pin
CVE-2026-43317 ↗2026-05-09azl3 kernel 6.6.138.1-1 on Azure Linux 3.0N/AOut-of-bandmost: core: fix leak on early registration failure
CVE-2026-43320 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-banddrm/amd/display: Fix dsc eDP issue
CVE-2026-43398 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-banddrm/amdgpu: add upper bound check on user inputs in wait ioctl
CVE-2026-43400 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-banddrm/amdgpu: add upper bound check on user inputs in signal ioctl
CVE-2026-43421 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-bandusb: gadget: f_ncm: Fix net_device lifecycle with device_move
CVE-2026-43443 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-bandASoC: amd: acp-mach-common: Add missing error check for clock acquisition
CVE-2026-43474 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-bandfs: init flags_valid before calling vfs_fileattr_get
CVE-2026-7896 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7896 Integer overflow in Blink
CVE-2026-7897 ↗2026-05-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7897 Use after free in Mobile
CVE-2026-7898 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7898 Use after free in Chromoting
CVE-2026-7899 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7899 Out of bounds read and write in V8
CVE-2026-7900 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7900 Heap buffer overflow in ANGLE
CVE-2026-7901 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7901 Use after free in ANGLE
CVE-2026-7902 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7902 Out of bounds memory access in V8
CVE-2026-7903 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7903 Integer overflow in ANGLE
CVE-2026-7904 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7904 Out of bounds read in Fonts
CVE-2026-7905 ↗2026-05-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7905 Insufficient validation of untrusted input in Media
CVE-2026-7906 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7906 Use after free in SVG
CVE-2026-7907 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7907 Use after free in DOM
CVE-2026-7908 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7908 Use after free in Fullscreen
CVE-2026-7909 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7909 Inappropriate implementation in ServiceWorker
CVE-2026-7910 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7910 Use after free in Views
CVE-2026-7911 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7911 Use after free in Aura
CVE-2026-7912 ↗2026-05-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7912 Integer overflow in GPU
CVE-2026-7913 ↗2026-05-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7913 Insufficient policy enforcement in DevTools
CVE-2026-7914 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7914 Type Confusion in Accessibility
CVE-2026-7915 ↗2026-05-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7915 Insufficient data validation in DevTools
CVE-2026-7916 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7916 Insufficient data validation in InterestGroups
CVE-2026-7917 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7917 Use after free in Fullscreen
CVE-2026-7918 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7918 Use after free in GPU
CVE-2026-7919 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7919 Use after free in Aura
CVE-2026-7920 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7920 Use after free in Skia
CVE-2026-7921 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7921 Use after free in Passwords
CVE-2026-7922 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7922 Use after free in ServiceWorker
CVE-2026-7923 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7923 Out of bounds write in Skia
CVE-2026-7924 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7924 Uninitialized Use in Dawn
CVE-2026-7925 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7925 Use after free in Chromoting
CVE-2026-7926 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7926 Use after free in PresentationAPI
CVE-2026-7927 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7927 Type Confusion in Runtime
CVE-2026-7928 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7928 Use after free in WebRTC
CVE-2026-7929 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7929 Use after free in MediaRecording
CVE-2026-7930 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-bandChromium: CVE-2026-7930 Insufficient validation of untrusted input in Cookies
CVE-2026-7931 ↗2026-05-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7931 Insufficient validation of untrusted input in iOS
CVE-2026-7932 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7932 Insufficient policy enforcement in Downloads
CVE-2026-7933 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7933 Out of bounds read in WebCodecs
CVE-2026-7934 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7934 Insufficient validation of untrusted input in Popup Blocker
CVE-2026-7935 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7935 Inappropriate implementation in Speech
CVE-2026-7936 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-bandChromium: CVE-2026-7936 Object lifecycle issue in V8
CVE-2026-7937 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7937 Insufficient policy enforcement in DevTools
CVE-2026-7938 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7938 Use after free in CSS
CVE-2026-7939 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7939 Inappropriate implementation in SanitizerAPI
CVE-2026-7940 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7940 Use after free in V8
CVE-2026-7941 ↗2026-05-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7941 Insufficient validation of untrusted input in Mobile
CVE-2026-7942 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7942 Integer overflow in ANGLE
CVE-2026-7943 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7943 Insufficient validation of untrusted input in ANGLE
CVE-2026-7944 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7944 Insufficient validation of untrusted input in Persistent Cache
CVE-2026-7945 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7945 Insufficient validation of untrusted input in COOP
CVE-2026-7946 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7946 Insufficient policy enforcement in WebUI
CVE-2026-7947 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7947 Insufficient validation of untrusted input in Network
CVE-2026-7948 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7948 Race in Chromoting
CVE-2026-7949 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7949 Out of bounds read in Skia
CVE-2026-7950 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7950 Out of bounds read and write in GFX
CVE-2026-7951 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7951 Out of bounds write in WebRTC
CVE-2026-7952 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7952 Insufficient policy enforcement in Extensions
CVE-2026-7953 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7953 Insufficient validation of untrusted input in Omnibox
CVE-2026-7954 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7954 Race in Shared Storage
CVE-2026-7955 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7955 Uninitialized Use in GPU
CVE-2026-7956 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7956 Use after free in Navigation
CVE-2026-7957 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7957 Out of bounds write in Media
CVE-2026-7958 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7958 Inappropriate implementation in ServiceWorker
CVE-2026-7959 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7959 Inappropriate implementation in Navigation
CVE-2026-7960 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7960 Race in Speech
CVE-2026-7961 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7961 Insufficient validation of untrusted input in Permissions
CVE-2026-7962 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7962 Insufficient policy enforcement in DirectSockets
CVE-2026-7963 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7963 Inappropriate implementation in ServiceWorker
CVE-2026-7964 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7964 Insufficient validation of untrusted input in FileSystem
CVE-2026-7965 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7965 Insufficient validation of untrusted input in DevTools
CVE-2026-7966 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7966 Insufficient validation of untrusted input in SiteIsolation
CVE-2026-7967 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7967 Insufficient validation of untrusted input in Navigation
CVE-2026-7968 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7968 Insufficient validation of untrusted input in CORS
CVE-2026-7969 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7969 Integer overflow in Network
CVE-2026-7970 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7970 Use after free in TopChrome
CVE-2026-7971 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7971 Inappropriate implementation in ORB
CVE-2026-7972 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7972 Uninitialized Use in GPU
CVE-2026-7973 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7973 Integer overflow in Dawn
CVE-2026-7974 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7974 Use after free in Blink
CVE-2026-7975 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7975 Use after free in DevTools
CVE-2026-7976 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7976 Use after free in Views
CVE-2026-7977 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7977 Inappropriate implementation in Canvas
CVE-2026-7978 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7978 Inappropriate implementation in Companion
CVE-2026-7979 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7979 Inappropriate implementation in Media
CVE-2026-7980 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7980 Use after free in WebAudio
CVE-2026-7981 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7981 Out of bounds read in Codecs
CVE-2026-7982 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7982 Uninitialized Use in WebCodecs
CVE-2026-7983 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7983 Out of bounds read in Dawn
CVE-2026-7984 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7984 Use after free in ReadingMode
CVE-2026-7985 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7985 Use after free in GPU
CVE-2026-7986 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7986 Insufficient policy enforcement in Autofill
CVE-2026-7987 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7987 Use after free in WebRTC
CVE-2026-7988 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7988 Type Confusion in WebRTC
CVE-2026-7989 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7989 Insufficient data validation in DataTransfer
CVE-2026-7990 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7990 Insufficient validation of untrusted input in Updater
CVE-2026-7991 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7991 Use after free in UI
CVE-2026-7992 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7992 Insufficient validation of untrusted input in UI
CVE-2026-7993 ↗2026-05-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7993 Insufficient validation of untrusted input in Payments
CVE-2026-7994 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7994 Inappropriate implementation in Chromoting
CVE-2026-7995 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7995 Out of bounds read in AdFilter
CVE-2026-7996 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7996 Insufficient validation of untrusted input in SSL
CVE-2026-7997 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7997 Insufficient validation of untrusted input in Updater
CVE-2026-7998 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7998 Insufficient validation of untrusted input in Dialog
CVE-2026-7999 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7999 Inappropriate implementation in V8
CVE-2026-8000 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8000 Insufficient validation of untrusted input in ChromeDriver
CVE-2026-8001 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8001 Use after free in Printing
CVE-2026-8002 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8002 Use after free in Audio
CVE-2026-8003 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8003 Insufficient validation of untrusted input in TabGroups
CVE-2026-8004 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8004 Insufficient policy enforcement in DevTools
CVE-2026-8005 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8005 Insufficient validation of untrusted input in Cast
CVE-2026-8006 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8006 Insufficient policy enforcement in DevTools
CVE-2026-8007 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8007 Insufficient validation of untrusted input in Cast
CVE-2026-8008 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8008 Inappropriate implementation in DevTools
CVE-2026-8009 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8009 Inappropriate implementation in Cast
CVE-2026-8010 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8010 Insufficient validation of untrusted input in SiteIsolation
CVE-2026-8011 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8011 Insufficient policy enforcement in Search
CVE-2026-8012 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8012 Inappropriate implementation in MHTML
CVE-2026-8013 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8013 Insufficient validation of untrusted input in FedCM
CVE-2026-8014 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8014 Inappropriate implementation in Preload
CVE-2026-8015 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8015 Inappropriate implementation in Media
CVE-2026-8016 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8016 Use after free in WebRTC
CVE-2026-8017 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8017 Side-channel information leakage in Media
CVE-2026-8018 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8018 Insufficient policy enforcement in DevTools
CVE-2026-8019 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8019 Insufficient policy enforcement in WebApp
CVE-2026-8020 ↗2026-05-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8020 Uninitialized Use in GPU
CVE-2026-8021 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8021 Script injection in UI
CVE-2026-8022 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8022 Inappropriate implementation in MHTML
CVE-2026-8509 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8509 Heap buffer overflow in WebML
CVE-2026-8510 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8510 Integer overflow in Skia
CVE-2026-8511 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8511 Use after free in UI
CVE-2026-8512 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8512 Use after free in FileSystem
CVE-2026-8513 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8513 Use after free in Input
CVE-2026-8514 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8514 Use after free in Aura
CVE-2026-8515 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8515 Use after free in HID
CVE-2026-8516 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8516 Insufficient validation of untrusted input in DataTransfer
CVE-2026-8517 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8517 Object lifecycle issue in WebShare
CVE-2026-8518 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8518 Use after free in Blink
CVE-2026-8519 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8519 Integer overflow in ANGLE
CVE-2026-8520 ↗2026-05-21Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8520 Race in Payments
CVE-2026-8521 ↗2026-05-21Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8521 Use after free in Tab Groups
CVE-2026-8522 ↗2026-05-21Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8522 Use after free in Downloads
CVE-2026-8523 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8523 Use after free in Mojo
CVE-2026-8524 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8524 Out of bounds write in WebAudio
CVE-2026-8525 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8525 Heap buffer overflow in ANGLE
CVE-2026-8526 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8526 Out of bounds write in WebRTC
CVE-2026-8527 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8527 Insufficient validation of untrusted input in Downloads
CVE-2026-8528 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8528 Insufficient validation of untrusted input in SiteIsolation
CVE-2026-8529 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8529 Heap buffer overflow in Codecs
CVE-2026-8530 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8530 Use after free in Network
CVE-2026-8531 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8531 Heap buffer overflow in WebML
CVE-2026-8532 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8532 Integer overflow in XML
CVE-2026-8533 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8533 Use after free in Accessibility
CVE-2026-8534 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8534 Integer overflow in GPU
CVE-2026-8535 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8535 Out of bounds read in Media
CVE-2026-8536 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8536 Insufficient validation of untrusted input in ReadingMode
CVE-2026-8537 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8537 Insufficient policy enforcement in ViewTransitions
CVE-2026-8538 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8538 Insufficient validation of untrusted input in GPU
CVE-2026-8539 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8539 Script injection in SanitizerAPI
CVE-2026-8540 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8540 Type Confusion in V8
CVE-2026-8541 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8541 Out of bounds read in UI
CVE-2026-8542 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8542 Use after free in Core
CVE-2026-8543 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8543 Out of bounds read in FileSystem
CVE-2026-8544 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8544 Use after free in Media
CVE-2026-8545 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8545 Object corruption in Compositing
CVE-2026-8546 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8546 Out of bounds read in GPU
CVE-2026-8547 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8547 Insufficient policy enforcement in Passwords
CVE-2026-8548 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8548 Out of bounds write in Media
CVE-2026-8549 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8549 Use after free in Media
CVE-2026-8550 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8550 Use after free in Google Lens
CVE-2026-8551 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8551 Use after free in Downloads
CVE-2026-8552 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8552 Heap buffer overflow in GPU
CVE-2026-8553 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8553 Use after free in GPU
CVE-2026-8554 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8554 Type Confusion in ANGLE
CVE-2026-8555 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8555 Use after free in GTK
CVE-2026-8556 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8556 Inappropriate implementation in ANGLE
CVE-2026-8557 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8557 Use after free in Accessibility
CVE-2026-8558 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8558 Out of bounds write in Fonts
CVE-2026-8559 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8559 Integer overflow in Internationalization
CVE-2026-8560 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8560 Heap buffer overflow in SwiftShader
CVE-2026-8561 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8561 Incorrect security UI in Fullscreen
CVE-2026-8562 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8562 Side-channel information leakage in Navigation
CVE-2026-8563 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8563 Insufficient policy enforcement in IFrame Sandbox
CVE-2026-8564 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8564 Incorrect security UI in Downloads
CVE-2026-8565 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8565 Inappropriate implementation in Downloads
CVE-2026-8566 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8566 Insufficient policy enforcement in Payments
CVE-2026-8567 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8567 Integer overflow in ANGLE
CVE-2026-8568 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-bandChromium: CVE-2026-8568 Insufficient policy enforcement in AI
CVE-2026-8569 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8569 Out of bounds write in Codecs
CVE-2026-8570 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8570 Type Confusion in V8
CVE-2026-8571 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8571 Insufficient policy enforcement in GPU
CVE-2026-8572 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8572 Insufficient policy enforcement in Network
CVE-2026-8573 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8573 Integer overflow in Codecs
CVE-2026-8574 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8574 Use after free in Core
CVE-2026-8575 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8575 Use after free in UI
CVE-2026-8576 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8576 Inappropriate implementation in CORS
CVE-2026-8577 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8577 Integer overflow in Fonts
CVE-2026-8578 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8578 Out of bounds read in GPU
CVE-2026-8579 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8579 Insufficient validation of untrusted input in Skia
CVE-2026-8580 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8580 Use after free in Mojo
CVE-2026-8581 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8581 Use after free in GPU
CVE-2026-8582 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8582 Object lifecycle issue in Dawn
CVE-2026-8583 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8583 Insufficient policy enforcement in WebXR
CVE-2026-8584 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8584 Inappropriate implementation in Views
CVE-2026-8585 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8585 Inappropriate implementation in Media
CVE-2026-8586 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8586 Inappropriate implementation in Chromoting
CVE-2026-8587 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8587 Use after free in Extensions
CVE-2026-9110 ↗2026-05-21Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9110 Inappropriate implementation in UI
CVE-2026-9111 ↗2026-05-21Microsoft Edge (Chromium-based)N/AOut-of-band1%Chromium: CVE-2026-9111 Use after free in WebRTC
CVE-2026-9112 ↗2026-05-21Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9112 Use after free in GPU
CVE-2026-9113 ↗2026-05-21Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9113 Out of bounds read in GPU
CVE-2026-9114 ↗2026-05-21Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9114 Use after free in QUIC
CVE-2026-9115 ↗2026-05-21Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9115 Insufficient policy enforcement in Service Worker
CVE-2026-9116 ↗2026-05-21Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9116 Insufficient policy enforcement in ServiceWorker
CVE-2026-9117 ↗2026-05-21Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9117 Type Confusion in GFX
CVE-2026-9118 ↗2026-05-21Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9118 Use after free in XR
CVE-2026-9119 ↗2026-05-21Microsoft Edge (Chromium-based)N/AOut-of-band1%Chromium: CVE-2026-9119 Heap buffer overflow in WebRTC
CVE-2026-9120 ↗2026-05-21Microsoft Edge (Chromium-based)N/AOut-of-band1%Chromium: CVE-2026-9120 Use after free in WebRTC
CVE-2026-9121 ↗2026-05-21Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9126 Use after free in DOM
CVE-2026-9122 ↗2026-05-21Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9121 Out of bounds read in GPU
CVE-2026-9123 ↗2026-05-21Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9122 Out of bounds read in GPU
CVE-2026-9124 ↗2026-05-21Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9123 Heap buffer overflow in Chromecast
CVE-2026-9126 ↗2026-05-21Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9124 Insufficient validation of untrusted input in Input
CVE-2026-9873 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9873 Use after free in Network
CVE-2026-9874 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9874 Use after free in Dawn
CVE-2026-9875 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9875 Out of bounds read in WebGL
CVE-2026-9876 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9876 Use after free in WebGL
CVE-2026-9877 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9877 Use after free in ANGLE
CVE-2026-9878 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9878 Use after free in ANGLE
CVE-2026-9879 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9879 Out of bounds write in ANGLE
CVE-2026-9880 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9880 Insufficient validation of untrusted input in WebGL
CVE-2026-9881 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9881 Use after free in Bluetooth
CVE-2026-9882 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9882 Integer overflow in ANGLE
CVE-2026-9883 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9883 Use after free in Base
CVE-2026-9884 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9884 Use after free in Browser
CVE-2026-9885 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9885 Insufficient validation of untrusted input in UI
CVE-2026-9886 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9886 Use after free in Base
CVE-2026-9887 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9887 Use after free in Proxy
CVE-2026-9888 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9888 Use after free in WebView
CVE-2026-9889 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9889 Out of bounds read and write in Dawn
CVE-2026-9890 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9890 Use after free in XR
CVE-2026-9891 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9891 Use after free in Extensions
CVE-2026-9892 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9892 Inappropriate implementation in Skia
CVE-2026-9893 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9893 Use after free in Skia
CVE-2026-9894 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9894 Use after free in GPU
CVE-2026-9895 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9895 Out of bounds read in GPU
CVE-2026-9896 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9896 Out of bounds write in V8
CVE-2026-9897 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9897 Use after free in DOM
CVE-2026-9898 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9898 Insufficient validation of untrusted input in GPU
CVE-2026-9899 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9899 Use after free in ANGLE
CVE-2026-9900 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9900 Out of bounds write in ANGLE
CVE-2026-9901 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9901 Use after free in ANGLE
CVE-2026-9902 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9902 Use after free in Accessibility
CVE-2026-9903 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9903 Insufficient validation of untrusted input in Site Isolation
CVE-2026-9904 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9904 Use after free in ANGLE
CVE-2026-9905 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9905 Use after free in Accessibility
CVE-2026-9906 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9906 Out of bounds write in GPU
CVE-2026-9907 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9907 Out of bounds read in Dawn
CVE-2026-9908 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9908 Out of bounds read in ANGLE
CVE-2026-9909 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9909 Integer overflow in Skia
CVE-2026-9910 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9910 Out of bounds memory access in ANGLE
CVE-2026-9911 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9911 Integer overflow in ANGLE
CVE-2026-9912 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9912 Inappropriate implementation in GPU
CVE-2026-9913 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9913 Inappropriate implementation in ANGLE
CVE-2026-9914 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9914 Insufficient validation of untrusted input in ANGLE
CVE-2026-9915 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9915 Heap buffer overflow in ANGLE
CVE-2026-9916 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9916 Out of bounds write in ANGLE
CVE-2026-9917 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9917 Uninitialized Use in WebGL
CVE-2026-9918 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9918 Inappropriate implementation in Tint
CVE-2026-9919 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9919 Out of bounds read in WebGL
CVE-2026-9920 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9920 Uninitialized Use in GPU
CVE-2026-9921 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9921 Uninitialized Use in WebGL
CVE-2026-9922 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9922 Use after free in GPU
CVE-2026-9923 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9923 Use after free in Skia
CVE-2026-9924 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9924 Heap buffer overflow in ANGLE
CVE-2026-9925 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9925 Use after free in ANGLE
CVE-2026-9926 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9926 Heap buffer overflow in ANGLE
CVE-2026-9927 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9927 Use after free in ANGLE
CVE-2026-9928 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9928 Out of bounds read in ANGLE
CVE-2026-9929 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9929 Inappropriate implementation in WebGL
CVE-2026-9930 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9930 Out of bounds write in Dawn
CVE-2026-9931 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9931 Use after free in GPU
CVE-2026-9932 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9932 Use after free in ANGLE
CVE-2026-9933 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9933 Use after free in Input
CVE-2026-9934 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9934 Use after free in Aura
CVE-2026-9935 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9935 Uninitialized Use in ANGLE
CVE-2026-9936 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9936 Use after free in GFX
CVE-2026-9937 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9937 Use after free in UI
CVE-2026-9938 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9938 Inappropriate implementation in V8
CVE-2026-9939 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9939 Heap buffer overflow in WebCodecs
CVE-2026-9940 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9940 Heap buffer overflow in ANGLE
CVE-2026-9941 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9941 Use after free in ANGLE
CVE-2026-9942 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9942 Uninitialized Use in ANGLE
CVE-2026-9943 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9943 Out of bounds read in WebGL
CVE-2026-9944 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9944 Uninitialized Use in ANGLE
CVE-2026-9945 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9945 Use after free in Media
CVE-2026-9946 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9946 Use after free in ANGLE
CVE-2026-9947 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9947 Use after free in XML
CVE-2026-9948 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9948 Use after free in Views
CVE-2026-9949 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9949 Use after free in Core
CVE-2026-9950 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9950 Insufficient validation of untrusted input in iOS
CVE-2026-9951 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9951 Use after free in UI
CVE-2026-9952 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9952 Use after free in WebAudio
CVE-2026-9953 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9953 Out of bounds read in ANGLE
CVE-2026-9954 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9954 Use after free in TabStrip
CVE-2026-9955 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9955 Inappropriate implementation in iOS
CVE-2026-9956 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9956 Use after free in iOS
CVE-2026-9957 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9957 Use after free in PDF
CVE-2026-9958 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9958 Use after free in PDFium
CVE-2026-9959 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9959 Race in WebRTC
CVE-2026-9960 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9960 Integer overflow in PDFium
CVE-2026-9961 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9961 Use after free in SurfaceCapture
CVE-2026-9962 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9962 Use after free in WebRTC
CVE-2026-9963 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9963 Uninitialized Use in iOS
CVE-2026-9964 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9964 Use after free in Bluetooth
CVE-2026-9965 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9965 Out of bounds write in ANGLE
CVE-2026-9966 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9966 Integer overflow in XML
CVE-2026-9967 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9967 Out of bounds write in GPU
CVE-2026-9968 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9968 Integer overflow in V8
CVE-2026-9969 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9969 Insufficient validation of untrusted input in ANGLE
CVE-2026-9970 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9970 Use after free in WebGL
CVE-2026-9971 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9971 Inappropriate implementation in iOS
CVE-2026-9972 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9972 Uninitialized Use in Gamepad
CVE-2026-9973 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9973 Out of bounds write in V8
CVE-2026-9974 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9974 Out of bounds write in GPU
CVE-2026-9975 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9975 Out of bounds read and write in ANGLE
CVE-2026-9976 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9976 Inappropriate implementation in USB
CVE-2026-9977 ↗2026-05-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9977 Insufficient validation of untrusted input in WebShare
CVE-2026-9978 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9978 Use after free in Glic
CVE-2026-9979 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9979 Insufficient validation of untrusted input in Input
CVE-2026-9980 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9980 Insufficient validation of untrusted input in Printing
CVE-2026-9981 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9981 Inappropriate implementation in Skia
CVE-2026-9982 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9982 Insufficient validation of untrusted input in ANGLE
CVE-2026-9983 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9983 Type Confusion in Skia
CVE-2026-9984 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9984 Use after free in UI
CVE-2026-9985 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9985 Insufficient validation of untrusted input in Media
CVE-2026-9986 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9986 Insufficient validation of untrusted input in OptimizationGuide
CVE-2026-9988 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9988 Use after free in WebRTC
CVE-2026-9989 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9989 Inappropriate implementation in Media
CVE-2026-9990 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9990 Use after free in WebAppInstalls
CVE-2026-9991 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9991 Inappropriate implementation in Media
CVE-2026-9992 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9992 Use after free in Network
CVE-2026-9993 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9993 Use after free in Views
CVE-2026-9994 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9994 Use after free in Core
CVE-2026-9995 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9995 Use after free in WebXR
CVE-2026-9996 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9996 Out of bounds read in WebRTC
CVE-2026-9997 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9997 Use after free in Input
CVE-2026-9998 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9998 Integer overflow in Skia
CVE-2026-9999 ↗2026-05-29Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-9999 Inappropriate implementation in ANGLE
#

April 2026

Patch Tuesday April 14, 2026294 CVEs plus 443 Azure Linux package advisories · 23 critical · 2 exploitation detected · 4 in KEV737 CVEs · 41 critical · 2 exploitation detected · 5 in KEV · includes 443 Azure Linux package advisories
Risk matrix, April 2026
108 of these counts use a severity derived from CVSS because Microsoft assigned none.
108 of these counts use a severity derived from CVSS because Microsoft assigned none.
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-32201 ↗2026-04-14Microsoft SharePoint Enterprise Server 2016Important18%Exploitation detectedCISA KEVVulnCheckENISAKB5002853KB5002854
and 1 moreKB5002861
2 mentionsMicrosoft SharePoint Server Spoofing Vulnerability
CVE-2026-32202 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant64%Exploitation detectedCISA KEVVulnCheckENISAKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Shell Spoofing Vulnerability
CVE-2017-20230 ↗2026-05-03cbl2 perl 5.34.1-491 on CBL Mariner 2.0CriticalOut-of-bandStorable versions before 3.05 for Perl has a stack overflow
CVE-2025-62718 ↗2026-04-15azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0CriticalOut-of-bandAxios has a NO_PROXY Hostname Normalization Bypass Leads to SSRF
CVE-2026-21515 ↗2026-04-23Azure IOT CentralCriticalOut-of-band1%Azure IoT Central Elevation of Privilege Vulnerability
CVE-2026-23666 ↗2026-04-14Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit SystemsCritical1%KB5082398KB5082400
and 16 moreKB5082402KB5082403KB5082404KB5082406KB5082411KB5082413KB5082414KB5082417KB5082418KB5082419KB5082420KB5082421KB5082424KB5082425KB5082426KB5082427
.NET Framework Denial of Service Vulnerability
CVE-2026-24303 ↗2026-04-23Microsoft Partner CenterCriticalOut-of-band0%Microsoft Partner Center Elevation of Privilege Vulnerability
CVE-2026-26135 ↗2026-04-02Azure Custom Locations Resource ProviderCriticalOut-of-band1%Azure Custom Locations Resource Provider (RP) Elevation of Privilege Vulnerability
CVE-2026-26150 ↗2026-04-23Microsoft Purview eDiscoveryCriticalOut-of-band1%Microsoft Purview eDiscovery Elevation of Privilege Vulnerability
CVE-2026-27140 ↗2026-04-11azl3 golang 1.26.2-1 on Azure Linux 3.0CriticalOut-of-bandCode execution vulnerability in SWIG code generation in cmd/go
CVE-2026-27143 ↗2026-04-11azl3 golang 1.25.10-1 on Azure Linux 3.0CriticalOut-of-bandMissing bound checks can lead to memory corruption in safe Go in cmd/compile
CVE-2026-31478 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0CriticalOut-of-bandksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len()
CVE-2026-31607 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0CriticalOut-of-bandusbip: validate number_of_packets in usbip_pack_ret_submit()
CVE-2026-31608 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0CriticalOut-of-bandsmb: server: avoid double-free in smb_direct_free_sendmsg after smb_direct_flush_send_list()
CVE-2026-31657 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0CriticalOut-of-bandbatman-adv: hold claim backbone gateways by reference
CVE-2026-31659 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0CriticalOut-of-bandbatman-adv: reject oversized global TT response buffers
CVE-2026-31668 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0CriticalOut-of-bandseg6: separate dst_cache for input and output paths in seg6 lwtunnel
CVE-2026-31669 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0CriticalOut-of-bandmptcp: fix slab-use-after-free in __inet_lookup_established
CVE-2026-32157 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsCritical1%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-32172 ↗2026-04-23Microsoft Power AppsCriticalOut-of-band0%Microsoft Power Apps Remote Code Execution Vulnerability
CVE-2026-32173 ↗2026-04-02Azure SRE Agent Gateway - SignalR HubCriticalOut-of-band1%Azure SRE Agent Information Disclosure Vulnerability
CVE-2026-32186 ↗2026-04-02Microsoft BingCriticalOut-of-band1%Microsoft Bing Elevation of Privilege Vulnerability
CVE-2026-32190 ↗2026-04-14Microsoft Office 2019 for 32-bit editionsCritical0%KB5002859Microsoft Office Remote Code Execution Vulnerability
CVE-2026-32210 ↗2026-04-23Microsoft Dynamics 365 (online)CriticalOut-of-band1%Microsoft Dynamics 365 (online) Spoofing Vulnerability
CVE-2026-32211 ↗2026-04-02Azure Web AppsCriticalOut-of-band1%Azure MCP Server Information Disclosure Vulnerability
CVE-2026-32213 ↗2026-04-02Azure AI FoundryCriticalOut-of-band1%Azure AI Foundry Elevation of Privilege Vulnerability
CVE-2026-32282 ↗2026-04-11azl3 golang 1.25.9-1 on Azure Linux 3.0CriticalOut-of-bandTOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix
CVE-2026-33102 ↗2026-04-23Microsoft 365 CopilotCriticalOut-of-band0%Microsoft 365 Copilot Elevation of Privilege Vulnerability
CVE-2026-33105 ↗2026-04-02Azure Kubernetes ServiceCriticalOut-of-band1%Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
CVE-2026-33107 ↗2026-04-02Azure DatabricksCriticalOut-of-band1%Azure Databricks Elevation of Privilege Vulnerability
CVE-2026-33114 ↗2026-04-14Microsoft 365 Apps for Enterprise for 32-bit SystemsCritical0%Microsoft Word Remote Code Execution Vulnerability
CVE-2026-33115 ↗2026-04-14Microsoft 365 Apps for Enterprise for 32-bit SystemsCritical0%Microsoft Word Remote Code Execution Vulnerability
CVE-2026-33819 ↗2026-04-23Microsoft BingCriticalOut-of-band1%Microsoft Bing Remote Code Execution Vulnerability
CVE-2026-33824 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsCritical56%KB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
1 mentionsWindows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
CVE-2026-33826 ↗2026-04-14Windows Server 2019Critical1%More likelyKB5082060KB5082063
and 4 moreKB5082123KB5082126KB5082142KB5082198
Windows Active Directory Remote Code Execution Vulnerability
CVE-2026-33827 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows TCP/IP Remote Code Execution Vulnerability
CVE-2026-34872 ↗2026-05-07azl3 nodejs24 24.14.1-2 on Azure Linux 3.0CriticalOut-of-bandAn issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle).
CVE-2026-34873 ↗2026-05-07azl3 nodejs24 24.14.1-2 on Azure Linux 3.0CriticalOut-of-bandAn issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.
CVE-2026-34875 ↗2026-05-07azl3 nodejs24 24.14.1-2 on Azure Linux 3.0CriticalOut-of-bandAn issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.
CVE-2026-35431 ↗2026-04-23Microsoft Entra IDCriticalOut-of-band1%Microsoft Entra ID Entitlement Management Spoofing Vulnerability
CVE-2026-40175 ↗2026-04-15azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0CriticalOut-of-bandAxios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
CVE-2026-5194 ↗2026-04-15cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0CriticalOut-of-bandwolfSSL ECDSA Certificate Verification
CVE-2026-5450 ↗2026-04-22azl3 glibc 2.38-20 on Azure Linux 3.0CriticalOut-of-bandscanf %mc off-by-one heap buffer overflow
CVE-2023-20585 ↗2026-04-14Windows Server 2025 (Server Core installation)Important0%KB5082063KB5083769AMD: CVE-2023-20585 IOMMU Write Buffer Vulnerability
CVE-2025-14821 ↗2026-04-17cbl2 libssh 0.10.6-5 on CBL Mariner 2.0ImportantOut-of-bandLibssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows
CVE-2025-48431 ↗2026-04-30cbl2 ceph 16.2.10-11 on CBL Mariner 2.0ImportantOut-of-bandApache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error.
CVE-2026-0390 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5082123KB5082142
and 2 moreKB5082198KB5082200
UEFI Secure Boot Security Feature Bypass Vulnerability
CVE-2026-20806 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows COM Server Information Disclosure Vulnerability
CVE-2026-20928 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Recovery Environment Security Feature Bypass Vulnerability
CVE-2026-20930 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 5 moreKB5082063KB5082123KB5082142KB5082200KB5083769
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20945 ↗2026-04-14Microsoft SharePoint Enterprise Server 2016Important21%KB5002853KB5002854
and 3 moreKB5002856KB5002861KB5002862
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-23401 ↗2026-04-02azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandKVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE
CVE-2026-23406 ↗2026-04-10azl3 kernel 6.6.0.0-1 on Azure Linux 3.0ImportantOut-of-bandapparmor: fix side-effect bug in match_char() macro usage
CVE-2026-23407 ↗2026-04-10cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandapparmor: fix missing bounds check on DEFAULT table in verify_dfa()
CVE-2026-23408 ↗2026-04-10azl3 kernel 6.6.0.0-1 on Azure Linux 3.0ImportantOut-of-bandapparmor: Fix double free of ns_name in aa_replace_profiles()
CVE-2026-23410 ↗2026-04-10azl3 kernel 6.6.0.0-1 on Azure Linux 3.0ImportantOut-of-bandapparmor: fix race on rawdata dereference
CVE-2026-23411 ↗2026-04-10azl3 kernel 6.6.0.0-1 on Azure Linux 3.0ImportantOut-of-bandapparmor: fix race between freeing data and fs accessing it
CVE-2026-23422 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-banddpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler
CVE-2026-23428 ↗2026-04-25cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandksmbd: fix use-after-free of share_conf in compound request
CVE-2026-23447 ↗2026-04-25cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandnet: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check
CVE-2026-23653 ↗2026-04-14Microsoft Visual Studio Code CoPilot Chat ExtensionImportant1%GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
CVE-2026-23657 ↗2026-04-14Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft Word Remote Code Execution Vulnerability
CVE-2026-23670 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
CVE-2026-25184 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 3 moreKB5082063KB5083768KB5083769
Applocker Filter Driver (applockerfltr.sys) Elevation of Privilege Vulnerability
CVE-2026-25250 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportantKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
MITRE: CVE-2026-25250 Secure Boot disable Eazy Fix
CVE-2026-25833 ↗2026-05-07azl3 nodejs24 24.14.1-2 on Azure Linux 3.0ImportantOut-of-bandMbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function
CVE-2026-25835 ↗2026-05-07azl3 nodejs24 24.14.1-2 on Azure Linux 3.0ImportantOut-of-bandMbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).
CVE-2026-26143 ↗2026-04-14PowerShell 7.5Important1%Microsoft PowerShell Security Feature Bypass Vulnerability
CVE-2026-26149 ↗2026-04-14Microsoft Power Apps Desktop ClientImportant1%Microsoft Power Apps Desktop Client Spoofing Vulnerability
CVE-2026-26151 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant1%More likelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Remote Desktop Spoofing Vulnerability
CVE-2026-26152 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
CVE-2026-26153 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Encrypted File System (EFS) Elevation of Privilege Vulnerability
CVE-2026-26154 ↗2026-04-14Windows Server 2019Important1%KB5082060KB5082063
and 5 moreKB5082123KB5082126KB5082127KB5082142KB5082198
Windows Server Update Service (WSUS) Tampering Vulnerability
CVE-2026-26155 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant1%KB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
CVE-2026-26156 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-26159 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Remote Desktop Licensing Service Elevation of Privilege Vulnerability
CVE-2026-26160 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Remote Desktop Licensing Service Elevation of Privilege Vulnerability
CVE-2026-26161 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Sensor Data Service Elevation of Privilege Vulnerability
CVE-2026-26162 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows OLE Elevation of Privilege Vulnerability
CVE-2026-26163 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 8 moreKB5082063KB5082123KB5082126KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-26165 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 4 moreKB5082063KB5082142KB5083768KB5083769
Windows Shell Elevation of Privilege Vulnerability
CVE-2026-26166 ↗2026-04-14Windows Server 2022Important0%KB5082052KB5082060
and 4 moreKB5082063KB5082142KB5083768KB5083769
Windows Shell Elevation of Privilege Vulnerability
CVE-2026-26167 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-26168 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-26169 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant2%More likelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Kernel Memory Information Disclosure Vulnerability
CVE-2026-26170 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
PowerShell Elevation of Privilege Vulnerability
CVE-2026-26171 ↗2026-04-14PowerShell 7.5Important2%KB5086095KB5086096
and 1 moreKB5086097
.NET Denial of Service Vulnerability
CVE-2026-26172 ↗2026-04-14Windows Server 2022Important0%KB5082052KB5082060
and 5 moreKB5082063KB5082142KB5082200KB5083768KB5083769
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-26173 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-26174 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
CVE-2026-26175 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Boot Manager Security Feature Bypass Vulnerability
CVE-2026-26176 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Client Side Caching driver (csc.sys) Elevation of Privilege Vulnerability
CVE-2026-26177 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-26178 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083769
Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability
CVE-2026-26179 ↗2026-04-14Windows Server 2025 (Server Core installation)Important0%KB5082052KB5082060
and 3 moreKB5082063KB5083768KB5083769
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-26180 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-26181 ↗2026-04-14Windows Server 2025 (Server Core installation)Important0%KB5082052KB5082060
and 3 moreKB5082063KB5083768KB5083769
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2026-26182 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-26183 ↗2026-04-14Windows Server 2019Important0%KB5082060KB5082063
and 5 moreKB5082123KB5082126KB5082127KB5082142KB5082198
Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability
CVE-2026-26184 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-27144 ↗2026-04-11azl3 golang 1.25.10-1 on Azure Linux 3.0ImportantOut-of-bandMiscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile
CVE-2026-27906 ↗2026-04-14Windows 10 Version 21H2 for 32-bit SystemsImportant0%More likelyKB5082052KB5082200
and 2 moreKB5083768KB5083769
Windows Hello Security Feature Bypass Vulnerability
CVE-2026-27907 ↗2026-04-14Windows Server 2025 (Server Core installation)Important0%KB5082052KB5082060
and 3 moreKB5082063KB5083768KB5083769
Windows Storage Spaces Controller Elevation of Privilege Vulnerability
CVE-2026-27908 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant2%More likelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability
CVE-2026-27909 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Search Service Elevation of Privilege Vulnerability
CVE-2026-27910 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Installer Elevation of Privilege Vulnerability
CVE-2026-27911 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows User Interface Core Elevation of Privilege Vulnerability
CVE-2026-27912 ↗2026-04-14Windows Server 2019Important0%KB5082060KB5082063
and 5 moreKB5082123KB5082126KB5082127KB5082142KB5082198
Windows Kerberos Elevation of Privilege Vulnerability
CVE-2026-27913 ↗2026-04-14Windows Server 2019Important0%More likelyKB5082060KB5082123
and 4 moreKB5082126KB5082127KB5082142KB5082198
Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-27914 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant3%More likelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Microsoft Management Console Elevation of Privilege Vulnerability
CVE-2026-27915 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2026-27916 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2026-27917 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 8 moreKB5082063KB5082123KB5082126KB5082142KB5082198KB5082200KB5083768KB5083769
Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) Elevation of Privilege Vulnerability
CVE-2026-27918 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Shell Elevation of Privilege Vulnerability
CVE-2026-27919 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2026-27920 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2026-27921 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant1%More likelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability
CVE-2026-27922 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-27923 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-27924 ↗2026-04-14Windows Server 2022Important0%KB5082052KB5082060
and 2 moreKB5082142KB5082200
Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-27925 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows UPnP Device Host Information Disclosure Vulnerability
CVE-2026-27926 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-27927 ↗2026-04-14Windows Server 2022 (Server Core installation)Important0%KB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-27928 ↗2026-04-14Windows Server 2019Important0%KB5082060KB5082063
and 3 moreKB5082123KB5082142KB5082198
Windows Hello Security Feature Bypass Vulnerability
CVE-2026-27929 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability
CVE-2026-27930 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows GDI Information Disclosure Vulnerability
CVE-2026-27931 ↗2026-04-14Windows Server 2022Important0%KB5082052KB5082060
and 5 moreKB5082063KB5082142KB5082200KB5083768KB5083769
Windows GDI Information Disclosure Vulnerability
CVE-2026-28387 ↗2026-04-09azl3 openssl 3.3.5-5 on Azure Linux 3.0ImportantOut-of-bandPotential Use-after-free in DANE Client Code
CVE-2026-28388 ↗2026-04-09azl3 openssl 3.3.5-4 on Azure Linux 3.0ImportantOut-of-bandNULL Pointer Dereference When Processing a Delta CRL
CVE-2026-28389 ↗2026-04-11azl3 qemu 9.1.0-5 on Azure Linux 3.0ImportantOut-of-bandPossible NULL Dereference When Processing CMS KeyAgreeRecipientInfo
CVE-2026-28390 ↗2026-04-11azl3 edk2 20240524git3e722403cd16-16 on Azure Linux 3.0ImportantOut-of-bandPossible NULL Dereference When Processing CMS KeyTransportRecipientInfo
CVE-2026-28808 ↗2026-04-23azl3 erlang 26.2.5.20-1 on Azure Linux 3.0ImportantOut-of-bandScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)
CVE-2026-30656 ↗2026-05-03azl3 fio 3.37-3 on Azure Linux 3.0ImportantOut-of-bandA NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the fdp_pli option. The callback function str_fdp_pli_cb() does not validate the input pointer and calls strdup() on a NULL value when the option is specified without an argument. This results in a segmentation fault and process crash.
CVE-2026-31407 ↗2026-04-07azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandnetfilter: conntrack: add missing netlink policy validations
CVE-2026-31408 ↗2026-04-07azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandBluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold
CVE-2026-31414 ↗2026-04-14azl3 kernel 6.6.130.1-3 on Azure Linux 3.0Importantnetfilter: nf_conntrack_expect: use expect->helper
CVE-2026-31416 ↗2026-04-14azl3 kernel 6.6.130.1-3 on Azure Linux 3.0Importantnetfilter: nfnetlink_log: account for netlink header size
CVE-2026-31417 ↗2026-04-14azl3 kernel 6.6.130.1-3 on Azure Linux 3.0Importantnet/x25: Fix overflow when accumulating packets
CVE-2026-31418 ↗2026-04-14azl3 kernel 6.6.130.1-3 on Azure Linux 3.0Importantnetfilter: ipset: drop logically empty buckets in mtype_del
CVE-2026-31419 ↗2026-04-14azl3 kernel 6.6.134.1-2 on Azure Linux 3.0Importantnet: bonding: fix use-after-free in bond_xmit_broadcast()
CVE-2026-31427 ↗2026-04-14azl3 kernel 6.6.130.1-3 on Azure Linux 3.0Importantnetfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp
CVE-2026-31430 ↗2026-04-22azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandX.509: Fix out-of-bounds access when parsing extensions
CVE-2026-31431 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-band95%CISA KEVVulnCheckENISA5 mentionscrypto: algif_aead - Revert to operating out-of-place
CVE-2026-31432 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandksmbd: fix OOB write in QUERY_INFO for compound requests
CVE-2026-31433 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandksmbd: fix potencial OOB in get_file_all_info() for compound requests
CVE-2026-31446 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandext4: fix use-after-free in update_super_work when racing with umount
CVE-2026-31448 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandext4: avoid infinite loops caused by residual data
CVE-2026-31449 ↗2026-04-23azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandext4: validate p_idx bounds in ext4_ext_correct_indexes
CVE-2026-31450 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandext4: publish jinode after initialization
CVE-2026-31453 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandxfs: avoid dereferencing log items after push callbacks
CVE-2026-31454 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandxfs: save ailp before dropping the AIL lock in push callbacks
CVE-2026-31455 ↗2026-04-23cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandxfs: stop reclaim before pushing AIL during unmount
CVE-2026-31464 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandscsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done()
CVE-2026-31469 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandvirtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false
CVE-2026-31473 ↗2026-04-23cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandmedia: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex
CVE-2026-31476 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandksmbd: do not expire session on binding failure
CVE-2026-31477 ↗2026-04-23cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandksmbd: fix memory leaks and NULL deref in smb2_lock()
CVE-2026-31480 ↗2026-04-23cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandtracing: Fix potential deadlock in cpu hotplug with osnoise
CVE-2026-31482 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bands390/entry: Scrub r12 register on kernel entry
CVE-2026-31483 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bands390/syscalls: Add spectre boundary for syscall dispatch table
CVE-2026-31485 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandspi: spi-fsl-lpspi: fix teardown order issue (UAF)
CVE-2026-31487 ↗2026-04-23azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandspi: use generic driver_override infrastructure
CVE-2026-31492 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandRDMA/irdma: Initialize free_qp completion before using it
CVE-2026-31493 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandRDMA/efa: Fix use of completion ctx after free
CVE-2026-31494 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandnet: macb: use the current queue number for stats
CVE-2026-31498 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandBluetooth: L2CAP: Fix ERTM re-init and zero pdu_len infinite loop
CVE-2026-31500 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandBluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock
CVE-2026-31502 ↗2026-04-23azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandteam: fix header_ops type confusion with non-Ethernet ports
CVE-2026-31504 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandnet: fix fanout UAF in packet_release() via NETDEV_UP race
CVE-2026-31505 ↗2026-04-23azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandiavf: fix out-of-bounds writes in iavf_get_ethtool_stats()
CVE-2026-31506 ↗2026-04-23azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandnet: bcmasp: fix double free of WoL irq
CVE-2026-31507 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandnet/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer
CVE-2026-31508 ↗2026-04-30cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandnet: openvswitch: Avoid releasing netdev before teardown completes
CVE-2026-31512 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandBluetooth: L2CAP: Validate PDU length before reading SDU length in l2cap_ecred_data_rcv()
CVE-2026-31515 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandaf_key: validate families in pfkey_send_migrate()
CVE-2026-31516 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandxfrm: prevent policy_hthresh.work from racing with netns teardown
CVE-2026-31518 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandesp: fix skb leak with espintcp and async crypto
CVE-2026-31519 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandbtrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create
CVE-2026-31521 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandmodule: Fix kernel panic when a symbol st_shndx is out of bounds
CVE-2026-31523 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandnvme-pci: ensure we're polling a polled queue
CVE-2026-31525 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandbpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN
CVE-2026-31527 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-banddriver core: platform: use generic driver_override infrastructure
CVE-2026-31528 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandperf: Make sure to use pmu_ctx->pmu for groups
CVE-2026-31530 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandcxl/port: Fix use after free of parent_port in cxl_detach_ep()
CVE-2026-31532 ↗2026-04-24azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandcan: raw: fix ro->uniq use-after-free in raw_rcv()
CVE-2026-31533 ↗2026-05-01azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandnet/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
CVE-2026-31537 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandsmb: server: make use of smbdirect_socket.send_io.bcredits
CVE-2026-31548 ↗2026-04-29cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandwifi: cfg80211: cancel pmsr_free_wk in cfg80211_pmsr_wdev_down
CVE-2026-31552 ↗2026-04-29cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandwifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom
CVE-2026-31563 ↗2026-04-29azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandnet: macb: Use dev_consume_skb_any() to free TX SKBs
CVE-2026-31568 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bands390/mm: Add missing secure storage access fixups for donated memory
CVE-2026-31570 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandcan: gw: fix OOB heap access in cgw_csum_crc8_rel()
CVE-2026-31576 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandmedia: hackrf: fix to not free memory after the device is registered in hackrf_probe()
CVE-2026-31578 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandmedia: as102: fix to not free memory after the device is registered in as102_usb_probe()
CVE-2026-31580 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandbcache: fix cached_dev.sb_bio use-after-free and crash
CVE-2026-31581 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandALSA: 6fire: fix use-after-free on disconnect
CVE-2026-31582 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandhwmon: (powerz) Fix use-after-free on USB disconnect
CVE-2026-31583 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandmedia: em28xx: fix use-after-free in em28xx_v4l2_open()
CVE-2026-31584 ↗2026-04-29cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandmedia: mediatek: vcodec: fix use-after-free in encoder release path
CVE-2026-31586 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandmm: blk-cgroup: fix use-after-free in cgwb_release_workfn()
CVE-2026-31588 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandKVM: x86: Use scratch field in MMIO fragment to hold small write values
CVE-2026-31589 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandmm: call ->free_folio() directly in folio_unmap_invalidate()
CVE-2026-31591 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandKVM: SEV: Lock all vCPUs when synchronzing VMSAs for SNP launch finish
CVE-2026-31593 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandKVM: SEV: Reject attempts to sync VMSA of an already-launched/encrypted vCPU
CVE-2026-31598 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandocfs2: fix possible deadlock between unlink and dio_end_io_write
CVE-2026-31602 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandALSA: ctxfi: Limit PTP to a single page
CVE-2026-31609 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandsmb: client: avoid double-free in smbd_free_send_io() after smbd_send_batch_flush()
CVE-2026-31613 ↗2026-04-26azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ImportantOut-of-bandsmb: client: fix OOB reads parsing symlink error response
CVE-2026-31616 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandusb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete()
CVE-2026-31617 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandusb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb()
CVE-2026-31622 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandNFC: digital: Bounds check NFC-A cascade depth in SDD response handler
CVE-2026-31626 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandstaging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify()
CVE-2026-31629 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandnfc: llcp: add missing return after LLCP_CLOSED checks
CVE-2026-31630 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandrxrpc: proc: size address buffers for %pISpc output
CVE-2026-31648 ↗2026-04-29azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandmm: filemap: fix nr_pages calculation overflow in filemap_map_pages()
CVE-2026-31656 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-banddrm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat
CVE-2026-31662 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandtipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG
CVE-2026-31663 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandxfrm: hold dev ref until after transport_finish NF_HOOK
CVE-2026-31667 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandInput: uinput - fix circular locking dependency with ff-core
CVE-2026-31674 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandnetfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check()
CVE-2026-31675 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandnet/sched: sch_netem: fix out-of-bounds access in packet corruption
CVE-2026-31686 ↗2026-04-29azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandmm/kasan: fix double free for kasan pXds
CVE-2026-31688 ↗2026-04-29azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-banddriver core: enforce device_lock for driver_match_device()
CVE-2026-31789 ↗2026-04-09azl3 openssl 3.3.5-4 on Azure Linux 3.0ImportantOut-of-bandHeap Buffer Overflow in Hexadecimal Conversion
CVE-2026-32068 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
CVE-2026-32069 ↗2026-04-14Windows Server 2022 (Server Core installation)Important0%KB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-32070 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%More likelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2026-32071 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant1%KB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2026-32072 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Active Directory Spoofing Vulnerability
CVE-2026-32073 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-32074 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-32075 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2026-32076 ↗2026-04-14Windows Server 2025 (Server Core installation)Important0%KB5082052KB5082060
and 3 moreKB5082063KB5083768KB5083769
Windows Storage Spaces Controller Elevation of Privilege Vulnerability
CVE-2026-32077 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 10 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5082806KB5083768KB5083769
Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2026-32078 ↗2026-04-14Windows Server 2022 (Server Core installation)Important0%KB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-32079 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Web Account Manager Information Disclosure Vulnerability
CVE-2026-32080 ↗2026-04-14Windows Server 2019Important0%KB5082060KB5082063
and 3 moreKB5082123KB5082142KB5082198
Windows WalletService Elevation of Privilege Vulnerability
CVE-2026-32081 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Package Catalog Information Disclosure Vulnerability
CVE-2026-32082 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
CVE-2026-32083 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
CVE-2026-32084 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Print Spooler Information Disclosure Vulnerability
CVE-2026-32085 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Remote Procedure Call Information Disclosure Vulnerability
CVE-2026-32086 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
CVE-2026-32087 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
CVE-2026-32088 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Biometric Service Security Feature Bypass Vulnerability
CVE-2026-32089 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Speech Brokered Api Elevation of Privilege Vulnerability
CVE-2026-32090 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Speech Brokered Api Elevation of Privilege Vulnerability
CVE-2026-32091 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2026-32093 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant1%More likelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
CVE-2026-32148 ↗2026-05-03cbl2 rabbitmq-server 3.11.24-3 on CBL Mariner 2.0ImportantOut-of-bandLockfile checksums not verified in Hex allows dependency integrity bypass
CVE-2026-32149 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-32150 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
CVE-2026-32151 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Shell Information Disclosure Vulnerability
CVE-2026-32152 ↗2026-04-14Windows Server 2022Important0%More likelyKB5082052KB5082060
and 4 moreKB5082063KB5082142KB5083768KB5083769
Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-32153 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082123
and 3 moreKB5082200KB5083768KB5083769
Windows Speech Runtime Elevation of Privilege Vulnerability
CVE-2026-32154 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-32155 ↗2026-04-14Windows Server 2022Important0%KB5082052KB5082060
and 4 moreKB5082063KB5082142KB5082200KB5083769
Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-32156 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows UPnP Device Host Remote Code Execution Vulnerability
CVE-2026-32158 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-32159 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-32160 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-32162 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows COM Elevation of Privilege Vulnerability
CVE-2026-32163 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows User Interface Core Elevation of Privilege Vulnerability
CVE-2026-32164 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows User Interface Core Elevation of Privilege Vulnerability
CVE-2026-32165 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows User Interface Core Elevation of Privilege Vulnerability
CVE-2026-32167 ↗2026-04-14Microsoft SQL Server 2025 for x64-based Systems (CU3)Important0%KB5083245KB5083252
and 8 moreKB5084814KB5084815KB5084816KB5084817KB5084818KB5084819KB5084820KB5084821
SQL Server Elevation of Privilege Vulnerability
CVE-2026-32168 ↗2026-04-14Azure Monitor AgentImportant0%Azure Monitor Agent Elevation of Privilege Vulnerability
CVE-2026-32171 ↗2026-04-14Azure Logic AppsImportant0%Azure Logic Apps Elevation of Privilege Vulnerability
CVE-2026-32176 ↗2026-04-14Microsoft SQL Server 2025 for x64-based Systems (CU3)Important0%KB5083245KB5083252
and 8 moreKB5084814KB5084815KB5084816KB5084817KB5084818KB5084819KB5084820KB5084821
SQL Server Elevation of Privilege Vulnerability
CVE-2026-32178 ↗2026-04-14Microsoft Visual Studio 2022 version 17.12Important2%KB5086095KB5086096
and 1 moreKB5086097
.NET Spoofing Vulnerability
CVE-2026-32181 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 5 moreKB5082063KB5082142KB5082200KB5083768KB5083769
Connected User Experiences and Telemetry Service Denial of Service Vulnerability
CVE-2026-32183 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant1%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Snipping Tool Remote Code Execution Vulnerability
CVE-2026-32184 ↗2026-04-14Microsoft HPC Pack 2019Important2%Microsoft High Performance Compute (HPC) Pack Elevation of Privilege Vulnerability
CVE-2026-32188 ↗2026-04-14Office Online ServerImportant0%KB5002855KB5002860Microsoft Excel Information Disclosure Vulnerability
CVE-2026-32189 ↗2026-04-14Office Online ServerImportant0%KB5002855KB5002860Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-32192 ↗2026-04-14Azure Monitor AgentImportant2%Azure Monitor Agent Elevation of Privilege Vulnerability
CVE-2026-32195 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5083768Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-32196 ↗2026-04-14Windows Admin CenterImportant0%Windows Admin Center Spoofing Vulnerability
CVE-2026-32197 ↗2026-04-14Office Online ServerImportant0%KB5002855KB5002860Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-32198 ↗2026-04-14Office Online ServerImportant0%KB5002855KB5002860Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-32199 ↗2026-04-14Office Online ServerImportant0%KB5002855KB5002860Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-32200 ↗2026-04-14Microsoft Office 2019 for 32-bit editionsImportant0%KB5002808Microsoft PowerPoint Remote Code Execution Vulnerability
CVE-2026-32203 ↗2026-04-14Microsoft Visual Studio 2026 version 18.4Important2%KB5086095KB5086096
and 1 moreKB5086097
.NET and Visual Studio Denial of Service Vulnerability
CVE-2026-32212 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
CVE-2026-32214 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
CVE-2026-32215 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Kernel Information Disclosure Vulnerability
CVE-2026-32216 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5083768Windows Redirected Drive Buffering System Denial of Service Vulnerability
CVE-2026-32217 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Kernel Information Disclosure Vulnerability
CVE-2026-32218 ↗2026-04-14Windows Server 2022Important0%KB5082052KB5082060
and 5 moreKB5082063KB5082142KB5082200KB5083768KB5083769
Windows Kernel Information Disclosure Vulnerability
CVE-2026-32219 ↗2026-04-14Windows Server 2025 (Server Core installation)Important0%KB5082063KB5083768
and 1 moreKB5083769
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2026-32220 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082063KB5083768
and 1 moreKB5083769
UEFI Secure Boot Security Feature Bypass Vulnerability
CVE-2026-32221 ↗2026-04-14Windows Server 2025 (Server Core installation)Important0%KB5082063KB5083768
and 1 moreKB5083769
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-32222 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082063KB5083768
and 1 moreKB5083769
Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-32223 ↗2026-04-14Windows Server 2025 (Server Core installation)Important1%KB5082063KB5083768
and 1 moreKB5083769
Windows USB Printing Stack (usbprint.sys) Elevation of Privilege Vulnerability
CVE-2026-32224 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5083768Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
CVE-2026-32225 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant1%More likelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Shell Security Feature Bypass Vulnerability
CVE-2026-32226 ↗2026-04-14Microsoft .NET Framework 4.8 on Windows 10 Version 22H2 for x64-based SystemsImportant1%KB5082398KB5082400
and 16 moreKB5082402KB5082403KB5082404KB5082406KB5082411KB5082413KB5082414KB5082417KB5082418KB5082419KB5082420KB5082421KB5082424KB5082425KB5082426KB5082427
.NET Framework Denial of Service Vulnerability
CVE-2026-32280 ↗2026-04-11azl3 golang 1.26.3-1 on Azure Linux 3.0ImportantOut-of-bandUnexpected work during chain building in crypto/x509
CVE-2026-32281 ↗2026-04-11cbl2 gcc 11.2.0-9 on CBL Mariner 2.0ImportantOut-of-bandInefficient policy validation in crypto/x509
CVE-2026-32283 ↗2026-04-11azl3 golang 1.26.3-1 on Azure Linux 3.0ImportantOut-of-bandUnauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
CVE-2026-32288 ↗2026-04-11azl3 containerized-data-importer 1.62.0-3 on Azure Linux 3.0ImportantOut-of-bandUnbounded allocation for old GNU sparse in archive/tar
CVE-2026-32316 ↗2026-04-17cbl2 jq 1.6-5 on CBL Mariner 2.0ImportantOut-of-bandjq: Integer overflow in jvp_string_append() allows Heap-based Buffer Overflow
CVE-2026-32631 ↗2026-04-14Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3)Important0%GitHub: CVE-2026-32631 'git clone' from manipulated repositories can leak NTLM hashes
CVE-2026-3298 ↗2026-04-27azl3 python3 3.12.9-10 on Azure Linux 3.0ImportantOut-of-bandOut-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes
CVE-2026-33095 ↗2026-04-14Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft Word Remote Code Execution Vulnerability
CVE-2026-33096 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant1%KB5082052KB5082060
and 4 moreKB5082063KB5082142KB5083768KB5083769
HTTP.sys Denial of Service Vulnerability
CVE-2026-33098 ↗2026-04-14Windows Server 2019 (Server Core installation)Important0%KB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability
CVE-2026-33099 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 7 moreKB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083769
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-33100 ↗2026-04-14Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-33101 ↗2026-04-14Windows Server 2025 (Server Core installation)Important0%KB5082060KB5082063
and 2 moreKB5083768KB5083769
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2026-33103 ↗2026-04-14Microsoft Dynamics 365 (on-premises) version 9.0Important0%KB5078943Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2026-33104 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Win32k Elevation of Privilege Vulnerability
CVE-2026-33116 ↗2026-04-14.NET 10.0 installed on Mac OSImportant2%KB5082398KB5082400
and 17 moreKB5082402KB5082403KB5082411KB5082413KB5082414KB5082417KB5082418KB5082419KB5082420KB5082421KB5082424KB5082425KB5082426KB5082427KB5086095KB5086096KB5086097
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVE-2026-33120 ↗2026-04-14Microsoft SQL Server 2022 for x64-based Systems (GDR)Important1%KB5084815Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-33822 ↗2026-04-14Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft Word Information Disclosure Vulnerability
CVE-2026-33825 ↗2026-04-14Microsoft Defender Antimalware PlatformImportant7%More likelyCISA KEVVulnCheckENISAMicrosoft Defender Elevation of Privilege Vulnerability
CVE-2026-33845 ↗2026-05-07cbl2 gnutls 3.7.11-6 on CBL Mariner 2.0ImportantOut-of-bandGnutls: gnutls: denial of service via dtls zero-length fragment
CVE-2026-34001 ↗2026-04-29cbl2 xorg-x11-server 1.20.10-16 on CBL Mariner 2.0ImportantOut-of-bandXorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption
CVE-2026-34445 ↗2026-04-09azl3 pytorch 2.2.2-12 on Azure Linux 3.0ImportantOut-of-bandONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.
CVE-2026-34591 ↗2026-04-07azl3 poetry 1.8.3-1 on Azure Linux 3.0ImportantOut-of-bandPoetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write
CVE-2026-34601 ↗2026-04-04azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandxmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion
CVE-2026-34874 ↗2026-05-07azl3 nodejs24 24.14.1-2 on Azure Linux 3.0ImportantOut-of-bandAn issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.
CVE-2026-34876 ↗2026-05-07azl3 nodejs24 24.14.1-2 on Azure Linux 3.0ImportantOut-of-bandAn issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len parameter. This is caused by missing validation of the tag_len parameter against the size of the internal 16-byte authentication buffer. The issue affects the public multipart CCM API in Mbed TLS 3.x, where mbedtls_ccm_finish() can be invoked directly by applications. In Mbed TLS 4.x versions prior to the fix, the same missing validation exists in the internal implementation; however, the function is not exposed as part of the public API. Exploitation requires application-level invocation of the multipart CCM API.
CVE-2026-34982 ↗2026-04-08cbl2 vim 9.2.0240-1 on CBL Mariner 2.0ImportantOut-of-bandVim modeline bypass via various options affects Vim < 9.2.0276
CVE-2026-35093 ↗2026-04-09cbl2 libinput 1.21.0-2 on CBL Mariner 2.0ImportantOut-of-bandLibinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins
CVE-2026-35385 ↗2026-04-04cbl2 openssh 8.9p1-9 on CBL Mariner 2.0ImportantOut-of-bandIn OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).
CVE-2026-35469 ↗2026-04-17azl3 containerd2 0.0.0-1 on Azure Linux 3.0ImportantOut-of-bandSpdyStream: DOS on CRI
CVE-2026-35535 ↗2026-04-05cbl2 sudo 1.9.17-1 on CBL Mariner 2.0ImportantOut-of-bandIn Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
CVE-2026-35611 ↗2026-04-11azl3 rubygem-addressable 2.8.5-2 on Azure Linux 3.0ImportantOut-of-bandAddressable has a Regular Expression Denial of Service in Addressable templates
CVE-2026-37555 ↗2026-05-03cbl2 libsndfile 1.0.31-4 on CBL Mariner 2.0ImportantOut-of-bandAn issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 167) were not. When samplesperblock (int) * blocks (int) exceeds INT_MAX, the 32-bit multiplication overflows before being assigned to sf.frames (sf_count_t/int64). With samplesperblock=50000 and blocks=50000, the product 2500000000 overflows to -1794967296. This causes incorrect frame count leading to heap buffer overflow or denial of service. Both values come from the WAV file header and are attacker-controlled. This issue was discovered after an incomplete fix for CVE-2022-33065.
CVE-2026-39853 ↗2026-04-12cbl2 osslsigncode 2.7-1 on CBL Mariner 2.0ImportantOut-of-bandosslsigncode has a Stack Buffer Overflow via Unbounded Digest Copy During Signature Verification
CVE-2026-40024 ↗2026-04-10azl3 sleuthkit 4.12.1-1 on Azure Linux 3.0ImportantOut-of-bandSleuth Kit tsk_recover Path Traversal
CVE-2026-40164 ↗2026-04-17azl3 jq 1.7.1-4 on Azure Linux 3.0ImportantOut-of-bandjq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed
CVE-2026-40170 ↗2026-05-05cbl2 nodejs18 18.20.3-12 on CBL Mariner 2.0ImportantOut-of-bandngtcp2 has a qlog transport parameter serialization stack buffer overflow
CVE-2026-40372 ↗2026-04-21ASP.NET Core 10.0ImportantOut-of-band11%KB5091596ASP.NET Core Elevation of Privilege Vulnerability
CVE-2026-40393 ↗2026-04-14azl3 mesa 24.0.1-6 on Azure Linux 3.0ImportantIn Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.
CVE-2026-40706 ↗2026-04-23azl3 ntfs-3g 2022.10.3-2 on Azure Linux 3.0ImportantOut-of-bandIn NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered on the READ path (stat, readdir, open) when processing a security descriptor with multiple ACCESS_DENIED ACEs containing WRITE_OWNER from distinct group SIDs.
CVE-2026-40890 ↗2026-04-23cbl2 cri-o 1.22.3-20 on CBL Mariner 2.0ImportantOut-of-bandgithub.com/gomarkdown/markdown: Out-of-bounds Read in SmartypantsRenderer
CVE-2026-41035 ↗2026-04-17azl3 rsync 3.4.1-2 on Azure Linux 3.0ImportantOut-of-bandIn rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.
CVE-2026-41066 ↗2026-04-26azl3 python-lxml 4.9.3-1 on Azure Linux 3.0ImportantOut-of-bandlxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
CVE-2026-41082 ↗2026-05-07azl3 ocaml-dune 3.15.2-1 on Azure Linux 3.0ImportantOut-of-bandIn OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
CVE-2026-41205 ↗2026-04-25azl3 python-mako 1.2.4-3 on Azure Linux 3.0ImportantOut-of-bandMako: Path traversal via double-slash URI prefix in TemplateLookup
CVE-2026-41445 ↗2026-04-23cbl2 tensorflow 2.11.1-2 on CBL Mariner 2.0ImportantOut-of-bandKissFFT Integer Overflow Heap Buffer Overflow via kiss_fftndr_alloc()
CVE-2026-41602 ↗2026-04-30azl3 influxdb 2.7.5-15 on Azure Linux 3.0ImportantOut-of-bandApache Thrift: Go TFramedTransport uint32 overflow
CVE-2026-41603 ↗2026-04-30azl3 thrift 0.15.0-5 on Azure Linux 3.0ImportantOut-of-bandApache Thrift: Java TSSLTransportFactory hostname verification
CVE-2026-41604 ↗2026-04-30azl3 thrift 0.15.0-5 on Azure Linux 3.0ImportantOut-of-bandApache Thrift: Swift Range crash in skip()
CVE-2026-41605 ↗2026-04-30azl3 thrift 0.15.0-5 on Azure Linux 3.0ImportantOut-of-bandApache Thrift: Swift Compact Protocol integer overflow
CVE-2026-41636 ↗2026-04-30cbl2 ceph 16.2.10-11 on CBL Mariner 2.0ImportantOut-of-bandApache Thrift: Node.js skip() recursion
CVE-2026-41676 ↗2026-04-26cbl2 rpm-ostree 2022.1-8 on CBL Mariner 2.0ImportantOut-of-bandrust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
CVE-2026-41678 ↗2026-04-26azl3 clamav 1.5.2-1 on Azure Linux 3.0ImportantOut-of-bandrust-openssl: Incorrect bounds assertion in aes key wrap
CVE-2026-41681 ↗2026-04-26azl3 python-cryptography 42.0.5-4 on Azure Linux 3.0ImportantOut-of-bandrust-openssl: MdCtxRef::digest_final() writes past caller buffer with no length check
CVE-2026-41898 ↗2026-04-29cbl2 rpm-ostree 2022.1-8 on CBL Mariner 2.0ImportantOut-of-bandrust-openssl: Unchecked callback-returned length in PSK and cookie generate trampolines can cause OpenSSL to leak adjacent memory to the network peer
CVE-2026-41907 ↗2026-04-26azl3 uuid 1.6.2-51 on Azure Linux 3.0ImportantOut-of-banduuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is provided
CVE-2026-4786 ↗2026-04-19azl3 python3 3.12.9-10 on Azure Linux 3.0ImportantOut-of-bandIncomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
CVE-2026-5263 ↗2026-04-15cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0ImportantOut-of-bandURI nameConstraints not enforced in ConfirmNameConstraints()
CVE-2026-5264 ↗2026-04-15cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0ImportantOut-of-bandDTLS 1.3 ACK heap buffer overflow
CVE-2026-5435 ↗2026-04-29azl3 glibc 2.38-19 on Azure Linux 3.0ImportantOut-of-bandPotential buffer overflow in ns_sprintrrf TSIG handling path
CVE-2026-5466 ↗2026-04-15cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0ImportantOut-of-bandwc_VerifyEccsiHash missing sanity check
CVE-2026-5477 ↗2026-04-15cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0ImportantOut-of-bandPrefix-substitution forgery via integer overflow in wolfCrypt CMAC
CVE-2026-5479 ↗2026-04-15cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0ImportantOut-of-bandwolfSSL EVP ChaCha20-Poly1305 AEAD authentication tag
CVE-2026-5500 ↗2026-04-15cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0ImportantOut-of-bandImproper Validation of AES-GCM Authentication Tag Length in PKCS#7 Envelope Allows Authentication Bypass
CVE-2026-5501 ↗2026-04-15cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0ImportantOut-of-bandImproper Certificate Signature Verification in X.509 Chain Validation Allows Forged Leaf Certificates
CVE-2026-5928 ↗2026-04-22cbl2 glibc 2.35-10 on CBL Mariner 2.0ImportantOut-of-bandStatic buffer overflow in deprecated nis_local_principal
CVE-2026-6100 ↗2026-04-19azl3 python3 3.12.9-10 on Azure Linux 3.0ImportantOut-of-bandUse-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
CVE-2026-6409 ↗2026-04-23azl3 grpc 1.62.3-1 on Azure Linux 3.0ImportantOut-of-bandDenial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input
CVE-2026-6507 ↗2026-04-23azl3 dnsmasq 2.90-1 on Azure Linux 3.0ImportantOut-of-bandDnsmasq: dnsmasq: denial of service due to out-of-bounds write in dhcp bootreply processing
CVE-2026-6846 ↗2026-05-03azl3 gdb 13.2-7 on Azure Linux 3.0ImportantOut-of-bandBinutils: binutils: arbitrary code execution via malformed xcoff object file processing
CVE-2026-7246 ↗2026-05-17azl3 python-click 8.1.7-2 on Azure Linux 3.0ImportantOut-of-bandPallets Click contains a command injection via Unsanitized Filename "click.edit()"
CVE-2025-13763 ↗2026-04-25azl3 opensc 0.26.1-1 on Azure Linux 3.0ModerateOut-of-bandLibopensc: opensc: multiple uses of uninitialized variable
CVE-2025-66442 ↗2026-05-07azl3 nodejs24 24.14.1-2 on Azure Linux 3.0ModerateOut-of-bandIn Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.
CVE-2026-1502 ↗2026-04-15cbl2 python3 3.9.19-19 on CBL Mariner 2.0ModerateOut-of-bandHTTP client proxy tunnel headers not validated for CR/LF
CVE-2026-21637 ↗2026-04-14Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)Moderate1%HackerOne: CVE-2026-21637 TLS PSK/ALPN Callback Exceptions Bypass Error Handlers
CVE-2026-21998 ↗2026-04-23cbl2 mysql 8.0.45-3 on CBL Mariner 2.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-22002 ↗2026-04-23cbl2 mysql 8.0.45-3 on CBL Mariner 2.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-22004 ↗2026-04-23cbl2 mysql 8.0.45-3 on CBL Mariner 2.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-22005 ↗2026-04-23azl3 mysql 8.0.45-2 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-22009 ↗2026-04-23cbl2 mysql 8.0.45-3 on CBL Mariner 2.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-22015 ↗2026-04-23azl3 mysql 8.0.45-2 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
CVE-2026-22017 ↗2026-04-23azl3 mysql 8.0.45-2 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-23403 ↗2026-04-10cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandapparmor: fix memory leak in verify_header
CVE-2026-23404 ↗2026-04-10azl3 kernel 6.6.0.0-1 on Azure Linux 3.0ModerateOut-of-bandapparmor: replace recursive profile removal with iterative approach
CVE-2026-23405 ↗2026-04-10azl3 kernel 6.6.0.0-1 on Azure Linux 3.0ModerateOut-of-bandapparmor: fix: limit the number of levels of policy namespaces
CVE-2026-23409 ↗2026-04-10azl3 kernel 6.6.0.0-1 on Azure Linux 3.0ModerateOut-of-bandapparmor: fix differential encoding verification
CVE-2026-23414 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandtls: Purge async_hold in tls_decrypt_async_wait()
CVE-2026-23420 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandwifi: wlcore: Fix a locking bug
CVE-2026-23434 ↗2026-04-25cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandmtd: rawnand: serialize lock/unlock against other NAND operations
CVE-2026-23438 ↗2026-04-25cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: mvpp2: guard flow control update with global_tx_fc in buffer switching
CVE-2026-23439 ↗2026-04-25cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandudp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG_IPV6=n
CVE-2026-23442 ↗2026-04-05azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandipv6: add NULL checks for idev in SRv6 paths
CVE-2026-23444 ↗2026-04-05azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandwifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure
CVE-2026-23446 ↗2026-04-25cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: usb: aqc111: Do not perform PM inside suspend callback
CVE-2026-23468 ↗2026-04-05azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: Limit BO list entry count to prevent resource exhaustion
CVE-2026-23472 ↗2026-04-05azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandserial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN
CVE-2026-23473 ↗2026-04-05azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandio_uring/poll: fix multishot recv missing EOF on wakeup race
CVE-2026-25834 ↗2026-05-07azl3 nodejs24 24.14.1-2 on Azure Linux 3.0ModerateOut-of-bandMbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.
CVE-2026-27447 ↗2026-04-05azl3 cups 2.4.16-1 on Azure Linux 3.0ModerateOut-of-bandOpenPrinting CUPS: Authorization bypass via case-insensitive group-member lookup
CVE-2026-27456 ↗2026-04-05azl3 util-linux 2.40.2-3 on Azure Linux 3.0ModerateOut-of-bandutil-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup
CVE-2026-28532 ↗2026-05-02azl3 frr 10.5.0-2 on Azure Linux 3.0ModerateOut-of-bandFRRouting < 10.5.3 Integer Overflow in OSPF TLV Parser Functions
CVE-2026-28810 ↗2026-04-11cbl2 erlang 25.3.2.21-5 on CBL Mariner 2.0ModerateOut-of-bandPredictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver
CVE-2026-29181 ↗2026-04-11azl3 containerd2 2.1.6-1 on Azure Linux 3.0ModerateOut-of-bandOpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
CVE-2026-3087 ↗2026-05-01azl3 python3 3.12.9-13 on Azure Linux 3.0ModerateOut-of-bandshutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
CVE-2026-31394 ↗2026-04-05azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandmac80211: fix crash in ieee80211_chan_bw_change for AP_VLAN stations
CVE-2026-31410 ↗2026-04-07azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandksmbd: use volume UUID in FS_OBJECT_ID_INFORMATION
CVE-2026-31420 ↗2026-04-14azl3 kernel 6.6.130.1-3 on Azure Linux 3.0Moderatebridge: mrp: reject zero test interval to avoid OOM panic
CVE-2026-31421 ↗2026-04-14azl3 kernel 6.6.130.1-3 on Azure Linux 3.0Moderatenet/sched: cls_fw: fix NULL pointer dereference on shared blocks
CVE-2026-31422 ↗2026-04-14azl3 kernel 6.6.130.1-3 on Azure Linux 3.0Moderatenet/sched: cls_flow: fix NULL pointer dereference on shared blocks
CVE-2026-31423 ↗2026-04-14azl3 kernel 6.6.130.1-3 on Azure Linux 3.0Moderatenet/sched: sch_hfsc: fix divide-by-zero in rtsc_min()
CVE-2026-31424 ↗2026-04-14azl3 kernel 6.6.130.1-3 on Azure Linux 3.0Moderatenetfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP
CVE-2026-31426 ↗2026-04-14azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateACPI: EC: clean up handlers on probe failure in acpi_ec_setup()
CVE-2026-31428 ↗2026-04-14azl3 kernel 6.6.130.1-3 on Azure Linux 3.0Moderatenetfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD
CVE-2026-31429 ↗2026-04-22azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnet: skb: fix cross-cache free of KFENCE-allocated skb head
CVE-2026-31439 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-banddmaengine: xilinx: xdma: Fix regmap init error handling
CVE-2026-31440 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-banddmaengine: idxd: Fix leaking event log memory
CVE-2026-31441 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-banddmaengine: idxd: Fix memory leak when a wq is reset
CVE-2026-31444 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandksmbd: fix use-after-free and NULL deref in smb_grant_oplock()
CVE-2026-31447 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandext4: reject mount if bigalloc with s_first_data_block != 0
CVE-2026-31451 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandext4: replace BUG_ON with proper error handling in ext4_read_inline_folio
CVE-2026-31452 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandext4: convert inline data to extents when truncate exceeds inline size
CVE-2026-31458 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandmm/damon/sysfs: check contexts->nr before accessing contexts_arr[0]
CVE-2026-31461 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Fix drm_edid leak in amdgpu_dm
CVE-2026-31462 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: prevent immediate PASID reuse case
CVE-2026-31467 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-banderofs: add GFP_NOIO in the bio completion if needed
CVE-2026-31474 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandcan: isotp: fix tx.buf use-after-free in isotp_sendmsg()
CVE-2026-31486 ↗2026-04-23azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandhwmon: (pmbus/core) Protect regulator operations with mutex
CVE-2026-31488 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Do not skip unrelated mode changes in DSC validation
CVE-2026-31489 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandspi: meson-spicc: Fix double-put in remove path
CVE-2026-31495 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnetfilter: ctnetlink: use netlink policy range checks
CVE-2026-31496 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nf_conntrack_expect: skip expectations in other netns via proc
CVE-2026-31497 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandBluetooth: btusb: clamp SCO altsetting table indices
CVE-2026-31499 ↗2026-04-30azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandBluetooth: L2CAP: Fix deadlock in l2cap_conn_del()
CVE-2026-31503 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandudp: Fix wildcard bind conflict check when using hash2
CVE-2026-31509 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnfc: nci: fix circular locking dependency in nci_close_device
CVE-2026-31510 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandBluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb
CVE-2026-31520 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandHID: apple: avoid memory leak in apple_report_fixup()
CVE-2026-31522 ↗2026-04-23azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandHID: magicmouse: avoid memory leak in magicmouse_report_fixup()
CVE-2026-31524 ↗2026-04-23cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandHID: asus: avoid memory leak in asus_report_fixup()
CVE-2026-31531 ↗2026-04-24azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandipv4: nexthop: allocate skb dynamically in rtm_get_nexthop()
CVE-2026-31536 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandsmb: server: let send_done handle a completion without IB_SEND_SIGNALED
CVE-2026-31540 ↗2026-04-30cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-banddrm/i915/gt: Check set_default_submission() before deferencing
CVE-2026-31545 ↗2026-04-30cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandNFC: nxp-nci: allow GPIOs to sleep
CVE-2026-31546 ↗2026-04-30cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: bonding: fix NULL deref in bond_debug_rlb_hash_show
CVE-2026-31549 ↗2026-04-29cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandi2c: cp2615: fix serial string NULL-deref at probe
CVE-2026-31550 ↗2026-04-29cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandpmdomain: bcm: bcm2835-power: Increase ASB control timeout
CVE-2026-31551 ↗2026-04-29cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandwifi: mac80211: Fix static_branch_dec() underflow for aql_disable.
CVE-2026-31555 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandfutex: Clear stale exiting pointer in futex_lock_pi() retry path
CVE-2026-31557 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnvmet: move async event work off nvmet-wq
CVE-2026-31560 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandspi: spi-dw-dma: fix print error log when wait finish transaction
CVE-2026-31565 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandRDMA/irdma: Fix deadlock during netdev reset with active connections
CVE-2026-31566 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib
CVE-2026-31574 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandclockevents: Add missing resets of the next_event_forced flag
CVE-2026-31575 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandmm/userfaultfd: fix hugetlb fault mutex hash calculation
CVE-2026-31577 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandnilfs2: fix NULL i_assoc_inode dereference in nilfs_mdt_save_to_shadow_map
CVE-2026-31579 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandwireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit
CVE-2026-31585 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandmedia: vidtv: fix nfeeds state corruption on start_streaming failure
CVE-2026-31587 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandASoC: qcom: q6apm: move component registration to unmanaged version
CVE-2026-31590 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandKVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION
CVE-2026-31592 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandKVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock
CVE-2026-31594 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandPCI: endpoint: pci-epf-vntb: Remove duplicate resource teardown
CVE-2026-31595 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandPCI: endpoint: pci-epf-vntb: Stop cmd_handler work in epf_ntb_epc_cleanup
CVE-2026-31596 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandocfs2: handle invalid dinode in ocfs2_group_extend
CVE-2026-31597 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY
CVE-2026-31599 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandmedia: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections
CVE-2026-31600 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandarm64: mm: Handle invalid large leaf mappings correctly
CVE-2026-31601 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandvfio/xe: Reorganize the init to decouple migration from reset
CVE-2026-31603 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandstaging: sm750fb: fix division by zero in ps_to_hz()
CVE-2026-31604 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandwifi: rtw88: fix device leak on probe failure
CVE-2026-31605 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandfbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO
CVE-2026-31606 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandusb: gadget: f_hid: don't call cdev_init while cdev in use
CVE-2026-31610 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandksmbd: fix mechToken leak when SPNEGO decode fails after token alloc
CVE-2026-31611 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandksmbd: require 3 sub-authorities before reading sub_auth[2]
CVE-2026-31612 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandksmbd: validate EaNameLength in smb2_get_ea()
CVE-2026-31615 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandusb: gadget: renesas_usb3: validate endpoint index in standard request handlers
CVE-2026-31618 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandfbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO
CVE-2026-31619 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandALSA: fireworks: bound device-supplied status before string array lookup
CVE-2026-31620 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandALSA: usx2y: us144mkii: fix NULL deref on missing interface 0
CVE-2026-31621 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandbnge: return after auxiliary_device_uninit() in error path
CVE-2026-31623 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnet: usb: cdc-phonet: fix skb frags[] overflow in rx_complete()
CVE-2026-31624 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandHID: core: clamp report_size in s32ton() to avoid undefined shift
CVE-2026-31625 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandHID: alps: fix NULL pointer dereference in alps_raw_event()
CVE-2026-31627 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandi2c: s3c24xx: check the size of the SMBUS message before using it
CVE-2026-31628 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandx86/CPU: Fix FPDSS on Zen1
CVE-2026-31634 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandrxrpc: fix reference count leak in rxrpc_server_keyring()
CVE-2026-31637 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandrxrpc: reject undecryptable rxkad response tickets
CVE-2026-31638 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandrxrpc: Only put the call ref if one was acquired
CVE-2026-31639 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandrxrpc: Fix key reference count leak from call->key
CVE-2026-31642 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandrxrpc: Fix call removal to use RCU safe deletion
CVE-2026-31645 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: lan966x: fix page pool leak in error paths
CVE-2026-31646 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: lan966x: fix page_pool error handling in lan966x_fdma_rx_alloc_page_pool()
CVE-2026-31649 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: stmmac: fix integer underflow in chain mode
CVE-2026-31651 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandmmc: vub300: fix NULL-deref on disconnect
CVE-2026-31655 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandpmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled
CVE-2026-31658 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnet: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit()
CVE-2026-31660 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnfc: pn533: allocate rx skb before consuming bytes
CVE-2026-31661 ↗2026-04-29cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandwifi: brcmsmac: Fix dma_free_coherent() size
CVE-2026-31664 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandxfrm: clear trailing padding in build_polexpire()
CVE-2026-31665 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nft_ct: fix use-after-free in timeout object destroy
CVE-2026-31670 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnet: rfkill: prevent unlimited numbers of rfkill events from being created
CVE-2026-31671 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandxfrm_user: fix info leak in build_report()
CVE-2026-31672 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandwifi: rt2x00usb: fix devres lifetime
CVE-2026-31673 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandaf_unix: read UNIX_DIAG_VFS data under unix_state_lock
CVE-2026-31676 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandrxrpc: only handle RESPONSE during service challenge
CVE-2026-31677 ↗2026-04-26azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: af_alg - limit RX SG extraction by receive buffer budget
CVE-2026-31678 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandopenvswitch: defer tunnel netdev_put to RCU release
CVE-2026-31679 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandopenvswitch: validate MPLS set/set_masked payload length
CVE-2026-31680 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnet: ipv6: flowlabel: defer exclusive option free until RCU teardown
CVE-2026-31681 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnetfilter: xt_multiport: validate range encoding in checkentry
CVE-2026-31682 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandbridge: br_nd_send: linearize skb before parsing ND options
CVE-2026-31684 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnet: sched: act_csum: validate nested VLAN headers
CVE-2026-31685 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandnetfilter: ip6t_eui64: reject invalid MAC header for all packets
CVE-2026-31689 ↗2026-04-29azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandEDAC/mc: Fix error path ordering in edac_mc_alloc()
CVE-2026-31692 ↗2026-05-01azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandrtnetlink: add missing netlink_ns_capable() check for peer netns
CVE-2026-31790 ↗2026-04-09azl3 openssl 3.3.5-4 on Azure Linux 3.0ModerateOut-of-bandIncorrect Failure Handling in RSA KEM RSASVE Encapsulation
CVE-2026-32147 ↗2026-04-26azl3 erlang 26.2.5.18-1 on Azure Linux 3.0ModerateOut-of-bandSFTP chroot bypass via path traversal in SSH_FXP_FSETSTAT
CVE-2026-3219 ↗2026-04-23azl3 python-pip 24.2-6 on Azure Linux 3.0ModerateOut-of-bandpip doesn't reject concatenated ZIP and tar archives
CVE-2026-32289 ↗2026-04-11azl3 golang 1.25.10-1 on Azure Linux 3.0ModerateOut-of-bandJsBraceDepth Context Tracking Bugs (XSS) in html/template
CVE-2026-33119 ↗2026-04-10Microsoft Edge for AndroidModerateOut-of-band0%Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2026-33555 ↗2026-04-15azl3 haproxy 2.9.11-4 on Azure Linux 3.0ModerateOut-of-bandAn issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
CVE-2026-33810 ↗2026-04-11azl3 golang 1.25.8-1 on Azure Linux 3.0ModerateOut-of-bandCase-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509
CVE-2026-33829 ↗2026-04-14Windows 10 Version 1809 for 32-bit SystemsModerate3%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Snipping Tool Spoofing Vulnerability
CVE-2026-33947 ↗2026-04-17cbl2 jq 1.6-5 on CBL Mariner 2.0ModerateOut-of-bandjq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted()
CVE-2026-33999 ↗2026-04-29cbl2 xorg-x11-server 1.20.10-16 on CBL Mariner 2.0ModerateOut-of-bandXorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling
CVE-2026-34003 ↗2026-04-29cbl2 xorg-x11-server 1.20.10-16 on CBL Mariner 2.0ModerateOut-of-bandXorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access
CVE-2026-34267 ↗2026-04-23azl3 mysql 8.0.45-2 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-34270 ↗2026-04-23azl3 mysql 8.0.45-2 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-34271 ↗2026-04-23azl3 mysql 8.0.45-2 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-34276 ↗2026-04-23azl3 mysql 8.0.45-2 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-34278 ↗2026-04-23cbl2 mysql 8.0.45-3 on CBL Mariner 2.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-34293 ↗2026-04-23cbl2 mysql 8.0.45-3 on CBL Mariner 2.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-34303 ↗2026-04-23azl3 mysql 8.0.45-2 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-34304 ↗2026-04-23azl3 mysql 8.0.45-2 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-34308 ↗2026-04-23cbl2 mysql 8.0.45-3 on CBL Mariner 2.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-34317 ↗2026-05-07cbl2 mysql 8.0.45-3 on CBL Mariner 2.0ModerateOut-of-bandVulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Shell executes to compromise MySQL Shell. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Shell. CVSS 3.1 Base Score 5.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H).
CVE-2026-34318 ↗2026-05-07cbl2 mysql 8.0.45-3 on CBL Mariner 2.0ModerateOut-of-bandVulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Shell. While the vulnerability is in MySQL Shell, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Shell accessible data. CVSS 3.1 Base Score 5.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N).
CVE-2026-34319 ↗2026-05-07cbl2 mysql 8.0.45-3 on CBL Mariner 2.0ModerateOut-of-bandVulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Shell executes to compromise MySQL Shell. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Shell. CVSS 3.1 Base Score 5.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H).
CVE-2026-34446 ↗2026-04-09azl3 pytorch 2.2.2-12 on Azure Linux 3.0ModerateOut-of-bandONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load
CVE-2026-34477 ↗2026-04-13azl3 javapackages-bootstrap 1.14.0-4 on Azure Linux 3.0ModerateOut-of-bandApache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass
CVE-2026-34480 ↗2026-04-15azl3 javapackages-bootstrap 1.14.0-4 on Azure Linux 3.0ModerateOut-of-bandApache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
CVE-2026-34757 ↗2026-04-12azl3 qtbase 6.6.3-4 on Azure Linux 3.0ModerateOut-of-bandLIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure
CVE-2026-34871 ↗2026-05-07azl3 nodejs24 24.14.1-2 on Azure Linux 3.0ModerateOut-of-bandAn issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG).
CVE-2026-34933 ↗2026-04-09cbl2 avahi 0.8-5 on CBL Mariner 2.0ModerateOut-of-bandAvahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flags crashes avahi-daemon
CVE-2026-34978 ↗2026-04-05azl3 cups 2.4.16-1 on Azure Linux 3.0ModerateOut-of-bandOpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache)
CVE-2026-34979 ↗2026-04-05azl3 cups 2.4.16-1 on Azure Linux 3.0ModerateOut-of-bandOpenPrinting CUPS: Heap overflow in `get_options()`
CVE-2026-34980 ↗2026-04-05azl3 cups 2.4.16-1 on Azure Linux 3.0ModerateOut-of-bandOpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network
CVE-2026-34990 ↗2026-04-05azl3 cups 2.4.16-1 on Azure Linux 3.0ModerateOut-of-bandOpenPrinting CUPS: Local print admin token disclosure using temporary printers
CVE-2026-35177 ↗2026-04-08azl3 vim 9.2.0240-1 on Azure Linux 3.0ModerateOut-of-bandPath traversal issue with zip.vim in Vim
CVE-2026-35199 ↗2026-04-17azl3 SymCrypt 103.8.0-1 on Azure Linux 3.0ModerateOut-of-bandSymCrypt SymCryptXmssSign function - Heap overflow via 64->32-bit leaf-count truncation
CVE-2026-35201 ↗2026-04-15cbl2 rubygem-rdiscount 2.2.0.2-3 on CBL Mariner 2.0ModerateOut-of-bandDiscount has an Out-of-bounds Read in rdiscount
CVE-2026-35206 ↗2026-04-12cbl2 helm 3.14.2-10 on CBL Mariner 2.0ModerateOut-of-bandHelm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
CVE-2026-35236 ↗2026-04-23azl3 mysql 8.0.45-2 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-35237 ↗2026-04-23cbl2 mysql 8.0.45-3 on CBL Mariner 2.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-35238 ↗2026-04-23azl3 mysql 8.0.45-2 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-35239 ↗2026-04-23azl3 mysql 8.0.45-2 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-35240 ↗2026-04-23azl3 mysql 8.0.45-2 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-35414 ↗2026-04-04azl3 openssh 9.8p1-5 on Azure Linux 3.0ModerateOut-of-bandOpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
CVE-2026-35549 ↗2026-04-04azl3 mariadb 10.11.16-1 on Azure Linux 3.0ModerateOut-of-bandAn issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha256_crypt_r uses alloca.
CVE-2026-3833 ↗2026-05-07cbl2 gnutls 3.7.11-6 on CBL Mariner 2.0ModerateOut-of-bandGnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison
CVE-2026-39314 ↗2026-04-09azl3 cups 2.4.16-1 on Azure Linux 3.0ModerateOut-of-bandCUPS has an integer underflow in `_ppdCreateFromIPP` causes root cupsd crash via negative `job-password-supported`
CVE-2026-39316 ↗2026-04-09azl3 cups 2.4.16-1 on Azure Linux 3.0ModerateOut-of-bandCUPS has a use-after-free in `cupsdDeleteTemporaryPrinters` via dangling subscription pointer
CVE-2026-39855 ↗2026-04-12cbl2 osslsigncode 2.7-1 on CBL Mariner 2.0ModerateOut-of-bandosslsigncode has an Integer Underflow in PE Page Hash Calculation Can Cause Out-of-Bounds Read
CVE-2026-39856 ↗2026-04-12cbl2 osslsigncode 2.7-1 on CBL Mariner 2.0ModerateOut-of-bandosslsigncode has an Out-of-Bounds Read via Unvalidated Section Bounds in PE Page Hash Calculation
CVE-2026-39881 ↗2026-04-10azl3 vim 9.2.0240-1 on Azure Linux 3.0ModerateOut-of-bandVim Ex command injection in Vims NetBeans integration
CVE-2026-39882 ↗2026-04-11azl3 containerd2 2.1.6-1 on Azure Linux 3.0ModerateOut-of-bandOpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies
CVE-2026-39956 ↗2026-04-17cbl2 jq 1.6-5 on CBL Mariner 2.0ModerateOut-of-bandjq: Missing runtime type checks for _strindices lead to crash and limited memory disclosure
CVE-2026-39979 ↗2026-04-17cbl2 jq 1.6-5 on CBL Mariner 2.0ModerateOut-of-bandjq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers
CVE-2026-40025 ↗2026-04-10azl3 sleuthkit 4.12.1-1 on Azure Linux 3.0ModerateOut-of-bandSleuth Kit APFS Keybag Parser Out-of-Bounds Read
CVE-2026-40026 ↗2026-04-10azl3 sleuthkit 4.12.1-1 on Azure Linux 3.0ModerateOut-of-bandSleuth Kit ISO9660 SUSP Extension Reference Out-of-Bounds Read
CVE-2026-40179 ↗2026-04-17cbl2 prometheus 2.37.9-7 on CBL Mariner 2.0ModerateOut-of-bandPrometheus: Stored XSS via metric names and label values in web UI tooltips and metrics explorer
CVE-2026-40225 ↗2026-04-29cbl2 systemd 250.3-24 on CBL Mariner 2.0ModerateOut-of-bandIn udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.
CVE-2026-40226 ↗2026-04-12azl3 systemd 255-26 on Azure Linux 3.0ModerateOut-of-bandIn nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.
CVE-2026-40255 ↗2026-04-18azl3 httpd 2.4.66-1 on Azure Linux 3.0ModerateOut-of-band@adonisjs/http-server has an Open Redirect vulnerability
CVE-2026-40355 ↗2026-05-01azl3 krb5 1.21.3-3 on Azure Linux 3.0ModerateOut-of-bandIn MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.
CVE-2026-40356 ↗2026-05-01azl3 krb5 1.21.3-3 on Azure Linux 3.0ModerateOut-of-bandIn MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.
CVE-2026-40385 ↗2026-04-14azl3 libexif 0.6.24-2 on Azure Linux 3.0ModerateIn libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.
CVE-2026-40386 ↗2026-04-14azl3 libexif 0.6.24-2 on Azure Linux 3.0ModerateIn libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.
CVE-2026-41079 ↗2026-04-26cbl2 cups 2.3.3op2-11 on CBL Mariner 2.0ModerateOut-of-bandOpenPrinting CUPS: Heap out-of-bounds read in SNMP supply-level polling leaks stack memory to authenticated users
CVE-2026-41254 ↗2026-04-21azl3 lcms2 2.15-2 on Azure Linux 3.0ModerateOut-of-bandLittle CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
CVE-2026-41305 ↗2026-04-27azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandPostCSS has XSS via Unescaped </style> in its CSS Stringify Output
CVE-2026-41411 ↗2026-04-26azl3 vim 9.2.0240-1 on Azure Linux 3.0ModerateOut-of-bandVim: Command injection via backtick expansion in tag filenames
CVE-2026-41526 ↗2026-05-01azl3 kf-kcoreaddons 5.249.0-1 on Azure Linux 3.0ModerateOut-of-bandIn KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applications relying on this method in a security-critical path to handle user input are affected and could be exploited. In particular, because sendInput() sends a string to a terminal, a control character such as \x01 can be used during injection.
CVE-2026-41606 ↗2026-04-30azl3 thrift 0.15.0-6 on Azure Linux 3.0ModerateOut-of-bandApache Thrift: c_glib dispatch stack overflow
CVE-2026-41607 ↗2026-04-30cbl2 ceph 16.2.10-11 on CBL Mariner 2.0ModerateOut-of-bandApache Thrift: C++ JSON OOB read
CVE-2026-41989 ↗2026-04-24azl3 libgcrypt 1.10.3-1 on Azure Linux 3.0ModerateOut-of-bandLibgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.
CVE-2026-42798 ↗2026-05-05cbl2 lcms2 2.13.1-2 on CBL Mariner 2.0ModerateOut-of-bandLittle CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.
CVE-2026-4878 ↗2026-04-11cbl2 libcap 2.60-7 on CBL Mariner 2.0ModerateOut-of-bandLibcap: libcap: privilege escalation via toctou race condition in cap_set_file()
CVE-2026-5160 ↗2026-04-19cbl2 gh 2.13.0-26 on CBL Mariner 2.0ModerateOut-of-bandVersions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS) due to improper ordering of URL validation and normalization. The renderer validates link destinations using a prefix-based check (IsDangerousURL) before resolving HTML entities. This allows an attacker to bypass protocol filtering by encoding dangerous schemes using HTML5 named character references. For example, a payload such as javascript&colon;alert(1) is not recognized as dangerous during validation, leading to arbitrary script execution in the context of applications that render the URL.
CVE-2026-5295 ↗2026-04-15cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0ModerateOut-of-bandStack Buffer Overflow in wolfSSL PKCS7 wc_PKCS7_DecryptOri() via Oversized OID
CVE-2026-5358 ↗2026-04-22azl3 glibc 2.38-20 on Azure Linux 3.0ModerateOut-of-bandStatic buffer overflow in deprecated nis_local_principal
CVE-2026-5393 ↗2026-04-15cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0ModerateOut-of-bandOOB Read in DoTls13CertificateVerify with WOLFSSL_DUAL_ALG_CERTS
CVE-2026-5446 ↗2026-04-15cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0ModerateOut-of-bandwolfSSL ARIA-GCM TLS 1.2/DTLS 1.2 GCM nonce reuse
CVE-2026-5447 ↗2026-04-15azl3 mariadb 10.11.16-1 on Azure Linux 3.0ModerateOut-of-bandHeap buffer overflow in CertFromX509() via AuthorityKeyIdentifier
CVE-2026-5460 ↗2026-04-15cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0ModerateOut-of-bandHeap Use-After-Free in PQC Hybrid KeyShare Error Cleanup in wolfSSL TLS 1.3
CVE-2026-5503 ↗2026-04-15azl3 mariadb 10.11.16-1 on Azure Linux 3.0ModerateOut-of-bandout-of-bounds write in TLSX_EchChangeSNI via attacker-controlled publicName
CVE-2026-5504 ↗2026-04-15cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0ModerateOut-of-bandPKCS7 CBC Padding Oracle — Plaintext Recovery
CVE-2026-5507 ↗2026-04-15cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0ModerateOut-of-bandSession Cache Restore — Arbitrary Free via Deserialized Pointer
CVE-2026-6238 ↗2026-04-30azl3 glibc 2.38-19 on Azure Linux 3.0ModerateOut-of-bandBuffer overread in ns_printrrf with corrupted RDATA field
CVE-2026-6357 ↗2026-04-30azl3 python3 3.12.9-10 on Azure Linux 3.0ModerateOut-of-bandpip self-update functionality can import newly installed modules after wheel installation
CVE-2026-6383 ↗2026-05-07cbl2 kubevirt 0.59.0-38 on CBL Mariner 2.0ModerateOut-of-bandKubevirt: kubevirt: unauthorized subresource access due to improper rbac evaluation
CVE-2026-6732 ↗2026-04-29cbl2 libxml2 2.10.4-11 on CBL Mariner 2.0ModerateOut-of-bandLibxml2: libxml2: denial of service via crafted xsd-validated document
CVE-2026-6843 ↗2026-05-03cbl2 nano 6.0-3 on CBL Mariner 2.0ModerateOut-of-bandNano: nano: format string vulnerability leads to denial of service
CVE-2026-6845 ↗2026-05-03cbl2 binutils 2.37-20 on CBL Mariner 2.0ModerateOut-of-bandBinutils: binutils: denial of service via crafted elf file
CVE-2026-6861 ↗2026-04-29azl3 emacs 29.4-3 on Azure Linux 3.0ModerateOut-of-bandEmacs: emacs: memory corruption vulnerability when processing svg css
CVE-2026-22001 ↗2026-04-23azl3 mysql 8.0.45-2 on Azure Linux 3.0LowOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).
CVE-2026-2708 ↗2026-04-29cbl2 libsoup 3.0.4-13 on CBL Mariner 2.0LowOut-of-bandLibsoup: libsoup: http request smuggling via duplicate content-length headers
CVE-2026-27820 ↗2026-04-18azl3 ruby 3.3.5-8 on Azure Linux 3.0LowOut-of-bandzlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption
CVE-2026-3184 ↗2026-04-07cbl2 util-linux 2.37.4-10 on CBL Mariner 2.0LowOut-of-bandUtil-linux: util-linux: access control bypass due to improper hostname canonicalization
CVE-2026-33118 ↗2026-04-10Microsoft Edge (Chromium-based)LowOut-of-band1%Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-33948 ↗2026-04-17cbl2 jq 1.6-5 on CBL Mariner 2.0LowOut-of-bandjq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed Input
CVE-2026-34479 ↗2026-04-15azl3 javapackages-bootstrap 1.14.0-4 on Azure Linux 3.0LowOut-of-bandApache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
CVE-2026-34481 ↗2026-04-15azl3 javapackages-bootstrap 1.14.0-4 on Azure Linux 3.0LowOut-of-bandApache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
CVE-2026-34743 ↗2026-04-04azl3 xz 5.4.4-2 on Azure Linux 3.0LowOut-of-bandXZ Utils: Buffer overflow in lzma_index_append()
CVE-2026-35386 ↗2026-04-04azl3 openssh 9.8p1-5 on Azure Linux 3.0LowOut-of-bandIn OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.
CVE-2026-35387 ↗2026-04-04azl3 openssh 9.8p1-6 on Azure Linux 3.0LowOut-of-bandOpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.
CVE-2026-35388 ↗2026-04-04cbl2 openssh 8.9p1-9 on CBL Mariner 2.0LowOut-of-bandOpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
CVE-2026-3832 ↗2026-05-07cbl2 gnutls 3.7.11-6 on CBL Mariner 2.0LowOut-of-bandGnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response
CVE-2026-41080 ↗2026-04-18cbl2 expat 2.6.4-4 on CBL Mariner 2.0LowOut-of-bandlibexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
CVE-2026-41140 ↗2026-04-26azl3 poetry 1.8.3-1 on Azure Linux 3.0LowOut-of-bandPoetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4
CVE-2026-41677 ↗2026-04-26cbl2 rust 1.72.0-15 on CBL Mariner 2.0LowOut-of-bandrust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized length
CVE-2026-41988 ↗2026-04-24azl3 uuid 1.6.2-51 on Azure Linux 3.0LowOut-of-banduuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by this issue.
CVE-2026-5187 ↗2026-04-23cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0LowOut-of-bandHeap Out-of-Bounds Write in DecodeObjectId() in wolfSSL
CVE-2026-5188 ↗2026-04-15azl3 mariadb 10.11.16-1 on Azure Linux 3.0LowOut-of-bandInteger underflow in X.509 SAN parsing in wolfSSL
CVE-2026-5392 ↗2026-04-15cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0LowOut-of-bandwolfSSL heap OOB read in PKCS7 SignedData streaming
CVE-2026-5448 ↗2026-04-15cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0LowOut-of-band1-2 Byte Buffer Overflow in wolfSSL_X509_notAfter/notBefore
CVE-2026-5772 ↗2026-04-15azl3 mariadb 10.11.16-1 on Azure Linux 3.0LowOut-of-bandMatchDomainName 1-Byte Stack Buffer Over-Read in Hostname Validation
CVE-2026-5778 ↗2026-04-15azl3 mariadb 10.11.16-1 on Azure Linux 3.0LowOut-of-bandInteger underflow leads to out-of-bounds access in sniffer ChaCha decrypt path.
CVE-2026-5958 ↗2026-04-22cbl2 sed 4.8-3 on CBL Mariner 2.0LowOut-of-bandRace Condition in GNU Sed
CVE-2026-6019 ↗2026-04-29cbl2 python3 3.9.19-19 on CBL Mariner 2.0LowOut-of-bandBaseCookie.js_output() does not neutralize embedded characters
CVE-2026-6842 ↗2026-05-03azl3 nano 6.4-2 on Azure Linux 3.0LowOut-of-bandNano: nano: local attacker can inject malicious .desktop launcher due to insecure directory permissions
CVE-2026-40556 ↗2026-04-29azl3 nano 6.4-2 on Azure Linux 3.0N/AOut-of-bandInsecure Directory Permissions in GNU nano Leading to Privilege Abuse
CVE-2026-5272 ↗2026-04-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5272 Heap buffer overflow in GPU
CVE-2026-5273 ↗2026-04-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5273 Use after free in CSS
CVE-2026-5274 ↗2026-04-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5274 Integer overflow in Codecs
CVE-2026-5275 ↗2026-04-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5275 Heap buffer overflow in ANGLE
CVE-2026-5276 ↗2026-04-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5276 Insufficient policy enforcement in WebUSB
CVE-2026-5277 ↗2026-04-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5277 Integer overflow in ANGLE
CVE-2026-5279 ↗2026-04-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5279 Object corruption in V8
CVE-2026-5280 ↗2026-04-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5280 Use after free in WebCodecs
CVE-2026-5281 ↗2026-04-02Microsoft Edge (Chromium-based)N/AOut-of-band5%CISA KEVVulnCheckENISAChromium: CVE-2026-5281 Use after free in Dawn
CVE-2026-5283 ↗2026-04-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5283 Inappropriate implementation in ANGLE
CVE-2026-5284 ↗2026-04-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5284 Use after free in Dawn
CVE-2026-5285 ↗2026-04-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5285 Use after free in WebGL
CVE-2026-5286 ↗2026-04-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5286 Use after free in Dawn
CVE-2026-5287 ↗2026-04-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5287 Use after free in PDF
CVE-2026-5289 ↗2026-04-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5289 Use after free in Navigation
CVE-2026-5290 ↗2026-04-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5290 Use after free in Compositing
CVE-2026-5291 ↗2026-04-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5291 Inappropriate implementation in WebGL
CVE-2026-5292 ↗2026-04-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5292 Out of bounds read in WebCodecs
CVE-2026-5858 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band1%Chromium: CVE-2026-5858 Heap buffer overflow in WebML
CVE-2026-5859 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5859 Integer overflow in WebML
CVE-2026-5860 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5860 Use after free in WebRTC
CVE-2026-5861 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5861 Use after free in V8
CVE-2026-5862 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5862 Inappropriate implementation in V8
CVE-2026-5863 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5863 Inappropriate implementation in V8
CVE-2026-5864 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5864 Heap buffer overflow in WebAudio
CVE-2026-5865 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band1%Chromium: CVE-2026-5865 Type Confusion in V8
CVE-2026-5866 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5866 Use after free in Media
CVE-2026-5867 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5867 Heap buffer overflow in WebML
CVE-2026-5868 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5868 Heap buffer overflow in ANGLE
CVE-2026-5869 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5869 Heap buffer overflow in WebML
CVE-2026-5870 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5870 Integer overflow in Skia
CVE-2026-5871 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5871 Type Confusion in V8
CVE-2026-5872 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5872 Use after free in Blink
CVE-2026-5873 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5873 Out of bounds read and write in V8
CVE-2026-5874 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5874 Use after free in PrivateAI
CVE-2026-5875 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5875 Policy bypass in Blink
CVE-2026-5876 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5876 Side-channel information leakage in Navigation
CVE-2026-5877 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5877 Use after free in Navigation
CVE-2026-5878 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5878 Incorrect security UI in Blink
CVE-2026-5879 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5879 Insufficient validation of untrusted input in ANGLE
CVE-2026-5880 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5880 Incorrect security UI in browser UI
CVE-2026-5881 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5881 Policy bypass in LocalNetworkAccess
CVE-2026-5882 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5882 Incorrect security UI in Fullscreen
CVE-2026-5883 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5883 Use after free in Media
CVE-2026-5884 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5884 Insufficient validation of untrusted input in Media
CVE-2026-5885 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5885 Insufficient validation of untrusted input in WebML
CVE-2026-5886 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5886 Out of bounds read in WebAudio
CVE-2026-5887 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5887 Insufficient validation of untrusted input in Downloads
CVE-2026-5888 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5888 Uninitialized Use in WebCodecs
CVE-2026-5889 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5889 Cryptographic Flaw in PDFium
CVE-2026-5890 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5890 Race in WebCodecs
CVE-2026-5891 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5891 Insufficient policy enforcement in browser UI
CVE-2026-5892 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5892 Insufficient policy enforcement in PWAs
CVE-2026-5893 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5893 Race in V8
CVE-2026-5894 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5894 Inappropriate implementation in PDF
CVE-2026-5895 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5895 Incorrect security UI in Omnibox
CVE-2026-5896 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5896 Policy bypass in Audio
CVE-2026-5897 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5897 Incorrect security UI in Downloads
CVE-2026-5898 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5898 Incorrect security UI in Omnibox
CVE-2026-5899 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5899 Incorrect security UI in History Navigation
CVE-2026-5900 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5900 Policy bypass in Downloads
CVE-2026-5901 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5901 Policy bypass in DevTools
CVE-2026-5902 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5902 Race in Media
CVE-2026-5903 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5903 Policy bypass in IFrameSandbox
CVE-2026-5904 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-bandChromium: CVE-2026-5904 Use after free in V8
CVE-2026-5905 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5905 Incorrect security UI in Permissions
CVE-2026-5906 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5906 Incorrect security UI in Omnibox
CVE-2026-5907 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5907 Insufficient data validation in Media
CVE-2026-5908 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5908 Integer overflow in Media
CVE-2026-5909 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5909 Integer overflow in Media
CVE-2026-5910 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5910 Integer overflow in Media
CVE-2026-5911 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5911 Policy bypass in ServiceWorkers
CVE-2026-5912 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5912 Integer overflow in WebRTC
CVE-2026-5913 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5913 Out of bounds read in Blink
CVE-2026-5914 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5914 Type Confusion in CSS
CVE-2026-5915 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5915 Insufficient validation of untrusted input in WebML
CVE-2026-5918 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5918 Inappropriate implementation in Navigation
CVE-2026-5919 ↗2026-04-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-5919 Insufficient validation of untrusted input in WebSockets
CVE-2026-6296 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6296 Heap buffer overflow in ANGLE
CVE-2026-6297 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6297 Use after free in Proxy
CVE-2026-6298 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6298 Heap buffer overflow in Skia
CVE-2026-6299 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6299 Use after free in Prerender
CVE-2026-6300 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6300 Use after free in CSS
CVE-2026-6301 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6301 Type Confusion in Turbofan
CVE-2026-6302 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6302 Use after free in Video
CVE-2026-6303 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6303 Use after free in Codecs
CVE-2026-6304 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6304 Use after free in Graphite
CVE-2026-6305 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6305 Heap buffer overflow in PDFium
CVE-2026-6306 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6306 Heap buffer overflow in PDFium
CVE-2026-6307 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6307 Type Confusion in Turbofan
CVE-2026-6308 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6308 Out of bounds read in Media
CVE-2026-6309 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6309 Use after free in Viz
CVE-2026-6310 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6310 Use after free in Dawn
CVE-2026-6311 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6311 Uninitialized Use in Accessibility
CVE-2026-6312 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6312 Insufficient policy enforcement in Passwords
CVE-2026-6313 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6313 Insufficient policy enforcement in CORS
CVE-2026-6314 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6314 Out of bounds write in GPU
CVE-2026-6316 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6316 Use after free in Forms
CVE-2026-6317 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6317 Use after free in Cast
CVE-2026-6318 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6318 Use after free in Codecs
CVE-2026-6359 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6359 Use after free in Video
CVE-2026-6360 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6360 Use after free in FileSystem
CVE-2026-6361 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6361 Heap buffer overflow in PDFium
CVE-2026-6362 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6362 Use after free in Codecs
CVE-2026-6363 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6363 Type Confusion in V8
CVE-2026-6364 ↗2026-04-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6364 Out of bounds read in Skia
CVE-2026-6919 ↗2026-04-24Microsoft Edge for AndroidN/AOut-of-band0%Chromium: CVE-2026-6919 Use after free in DevTools
CVE-2026-6920 ↗2026-04-28Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6920 Out of bounds read in GPU
CVE-2026-6921 ↗2026-04-24Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6921 Race in GPU
#

March 2026

Patch Tuesday March 10, 2026171 CVEs plus 289 Azure Linux package advisories · 19 critical · 0 exploitation detected · 2 in KEV460 CVEs · 26 critical · 0 exploitation detected · 2 in KEV · includes 289 Azure Linux package advisories
Risk matrix, March 2026
73 of these counts use a severity derived from CVSS because Microsoft assigned none.
73 of these counts use a severity derived from CVSS because Microsoft assigned none.
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2025-69720 ↗2026-03-25azl3 ncurses 6.4-2 on Azure Linux 3.0CriticalOut-of-bandThe infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
CVE-2026-21536 ↗2026-03-05Microsoft Devices Pricing ProgramCriticalOut-of-band2%Microsoft Devices Pricing Program Remote Code Execution Vulnerability
CVE-2026-23395 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0CriticalOut-of-bandBluetooth: L2CAP: Fix accepting multiple L2CAP_ECRED_CONN_REQ
CVE-2026-23651 ↗2026-03-05Microsoft ACI Confidential ContainersCriticalOut-of-band1%Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability
CVE-2026-23658 ↗2026-03-19Azure DevOps: msazureCriticalOut-of-band1%Azure DevOps: msazure Elevation of Privilege Vulnerability
CVE-2026-23659 ↗2026-03-19Azure Data FactoryCriticalOut-of-band1%Azure Data Factory Information Disclosure Vulnerability
CVE-2026-24299 ↗2026-03-19Microsoft 365 CopilotCriticalOut-of-band1%M365 Copilot Information Disclosure Vulnerability
CVE-2026-26110 ↗2026-03-10Microsoft Office 2019 for 32-bit editionsCritical0%KB50028381 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-26113 ↗2026-03-10Microsoft SharePoint Enterprise Server 2016Critical0%KB5002843KB5002845
and 4 moreKB5002847KB5002848KB5002850KB5002851
1 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-26120 ↗2026-03-19Microsoft BingCriticalOut-of-band1%Microsoft Bing Tampering Vulnerability
CVE-2026-26122 ↗2026-03-05Microsoft ACI Confidential ContainersCriticalOut-of-band1%Microsoft ACI Confidential Containers Information Disclosure Vulnerability
CVE-2026-26124 ↗2026-03-05Microsoft ACI Confidential ContainersCriticalOut-of-band0%Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability
CVE-2026-26125 ↗2026-03-05Payment Orchestrator ServiceCriticalOut-of-band1%Payment Orchestrator Service Elevation of Privilege Vulnerability
CVE-2026-26136 ↗2026-03-19Microsoft CopilotCriticalOut-of-band1%Microsoft Copilot Information Disclosure Vulnerability
CVE-2026-26137 ↗2026-03-19Microsoft Exchange OnlineCriticalOut-of-band1%Microsoft Exchange Elevation of Privilege Vulnerability
CVE-2026-26138 ↗2026-03-19Microsoft PurviewCriticalOut-of-band1%Microsoft Purview Elevation of Privilege Vulnerability
CVE-2026-26139 ↗2026-03-19Microsoft PurviewCriticalOut-of-band1%Microsoft Purview Elevation of Privilege Vulnerability
CVE-2026-26144 ↗2026-03-10Microsoft 365 Apps for Enterprise for 64-bit SystemsCritical1%1 mentionsMicrosoft Excel Information Disclosure Vulnerability
CVE-2026-32169 ↗2026-03-19Azure Cloud ShellCriticalOut-of-band1%Azure Cloud Shell Elevation of Privilege Vulnerability
CVE-2026-32191 ↗2026-03-19Microsoft Bing ImagesCriticalOut-of-band1%Microsoft Bing Images Remote Code Execution Vulnerability
CVE-2026-32194 ↗2026-03-19Microsoft Bing ImagesCriticalOut-of-band1%1 mentionsMicrosoft Bing Images Remote Code Execution Vulnerability
CVE-2026-3381 ↗2026-03-07cbl2 boost 1.76.0-4 on CBL Mariner 2.0CriticalOut-of-bandCompress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib
CVE-2026-33937 ↗2026-03-31cbl2 reaper 3.1.1-22 on CBL Mariner 2.0CriticalOut-of-bandHandlebars.js has JavaScript Injection via AST Type Confusion
CVE-2026-4176 ↗2026-04-01cbl2 binutils 2.37-20 on CBL Mariner 2.0CriticalOut-of-bandPerl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib
CVE-2026-4739 ↗2026-04-02cbl2 cmake 3.21.4-23 on CBL Mariner 2.0CriticalOut-of-bandInteger overflow vulnerabilities in InsightSoftwareConsortium/ITK
CVE-2026-4746 ↗2026-03-27cbl2 binutils 2.37-20 on CBL Mariner 2.0CriticalOut-of-bandHeap Buffer Over-Write Vulenrabilty in timeplus-io/proton
CVE-2006-10003 ↗2026-03-20azl3 perl-XML-Parser 2.47-1 on Azure Linux 3.0ImportantOut-of-bandXML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack
CVE-2025-66413 ↗2026-03-15azl3 git 2.45.4-3 on Azure Linux 3.0ImportantOut-of-bandGit for Windows leaks NTLM hash when cloning from an attacker-controlled server
CVE-2025-67030 ↗2026-03-29cbl2 javapackages-bootstrap 1.5.0-7 on CBL Mariner 2.0ImportantOut-of-bandDirectory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
CVE-2025-69648 ↗2026-03-15cbl2 binutils 2.37-20 on CBL Mariner 2.0ImportantOut-of-bandGNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.
CVE-2025-69650 ↗2026-03-11azl3 binutils 2.41-10 on Azure Linux 3.0ImportantOut-of-bandGNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service.
CVE-2025-69651 ↗2026-03-11azl3 binutils 2.41-10 on Azure Linux 3.0ImportantOut-of-bandGNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service.
CVE-2025-70873 ↗2026-04-18azl3 sqlite 3.44.0-2 on Azure Linux 3.0ImportantOut-of-bandAn information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.
CVE-2025-71238 ↗2026-03-05azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandscsi: qla2xxx: Fix bsg_done() causing double free
CVE-2026-0031 ↗2026-03-07cbl2 hyperv-daemons 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandIn multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0032 ↗2026-03-07cbl2 hyperv-daemons 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandIn multiple functions of mem_protect.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0038 ↗2026-03-05azl3 hyperv-daemons 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandIn multiple functions of mem_protect.c, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-1519 ↗2026-03-29cbl2 bind 9.16.50-3 on CBL Mariner 2.0ImportantOut-of-bandExcessive NSEC3 iterations cause high CPU load during insecure delegation validation
CVE-2026-20967 ↗2026-03-10System Center Operations Manager 2019Important1%System Center Operations Manager (SCOM) Elevation of Privilege Vulnerability
CVE-2026-21262 ↗2026-03-10Microsoft SQL Server 2017 for x64-based Systems (GDR)Important2%VulnCheckKB5077464KB5077465
and 8 moreKB5077466KB5077468KB5077469KB5077470KB5077471KB5077472KB5077473KB5077474
1 mentionsSQL Server Elevation of Privilege Vulnerability
CVE-2026-21710 ↗2026-04-01cbl2 nodejs18 18.20.3-12 on CBL Mariner 2.0ImportantOut-of-bandA flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` to be called on a non-array. This exception is thrown synchronously inside a property getter and cannot be intercepted by `error` event listeners, meaning it cannot be handled without wrapping every `req.headersDistinct` access in a `try/catch`. * This vulnerability affects all Node.js HTTP servers on **20.x, 22.x, 24.x, and v25.x**
CVE-2026-23231 ↗2026-03-05cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandnetfilter: nf_tables: fix use-after-free in nf_tables_addchain()
CVE-2026-23233 ↗2026-03-19azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandf2fs: fix to avoid mapping wrong physical block for swapfile
CVE-2026-23234 ↗2026-03-05cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandf2fs: fix to avoid UAF in f2fs_write_end_io()
CVE-2026-23235 ↗2026-03-05azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandf2fs: fix out-of-bounds access in sysfs attribute read/write
CVE-2026-23239 ↗2026-03-12azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandespintcp: Fix race condition in espintcp_close()
CVE-2026-23240 ↗2026-03-12azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandtls: Fix race condition in tls_sw_cancel_work_tx()
CVE-2026-23243 ↗2026-03-19azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandRDMA/umad: Reject negative data_len in ib_umad_write
CVE-2026-23265 ↗2026-03-20azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandf2fs: fix to do sanity check on node footer in {read,write}_end_io
CVE-2026-23267 ↗2026-03-20azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandf2fs: fix IS_CHECKPOINTED flag inconsistency issue caused by concurrent atomic commit and checkpoint writes
CVE-2026-23268 ↗2026-03-20azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandapparmor: fix unprivileged local user can do privileged policy management
CVE-2026-23281 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: libertas: fix use-after-free in lbs_free_adapter()
CVE-2026-23287 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandirqchip/sifive-plic: Fix frozen interrupt due to affinity setting
CVE-2026-23289 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandIB/mthca: Add missed mthca_unmap_user_db() for mthca_create_srq()
CVE-2026-23293 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandnet: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled
CVE-2026-23296 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandscsi: core: Fix refcount leak for tagset_refcnt
CVE-2026-23300 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandnet: ipv6: fix panic when IPv4 route references loopback IPv6 nexthop
CVE-2026-23306 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandscsi: pm8001: Fix use-after-free in pm8001_queue_command()
CVE-2026-23308 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandpinctrl: equilibrium: fix warning trace on load
CVE-2026-23310 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandbpf/bonding: reject vlan+srcmac xmit_hash_policy change when XDP is loaded
CVE-2026-23313 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandi40e: Fix preempt count leak in napi poll tracepoint
CVE-2026-23315 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211()
CVE-2026-23318 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandALSA: usb-audio: Use correct version for UAC3 header validation
CVE-2026-23325 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: mt76: mt7996: Fix possible oob access in mt7996_mac_write_txwi_80211()
CVE-2026-23327 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandcxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed()
CVE-2026-23330 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandnfc: nci: complete pending data exchange on device close
CVE-2026-23335 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandRDMA/irdma: Fix kernel stack leak in irdma_create_user_ah()
CVE-2026-23336 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: cfg80211: cancel rfkill_block work in wiphy_unregister()
CVE-2026-23339 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandnfc: nci: free skb on nci_transceive early error paths
CVE-2026-23340 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandnet: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs
CVE-2026-23343 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandxdp: produce a warning when calculated tailroom is negative
CVE-2026-23351 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandnetfilter: nft_set_pipapo: split gc into unlink and reclaim phase
CVE-2026-23352 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandx86/efi: defer freeing of boot services memory
CVE-2026-23359 ↗2026-03-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandbpf: Fix stack-out-of-bounds write in devmap
CVE-2026-23361 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandPCI: dwc: ep: Flush MSI-X write before unmapping its ATU entry
CVE-2026-23364 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandksmbd: Compare MACs in constant time
CVE-2026-23367 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: radiotap: reject radiotap with unknown bits
CVE-2026-23372 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandnfc: rawsock: cancel tx_work before socket teardown
CVE-2026-23374 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandblktrace: fix __this_cpu_read/write in preemptible context
CVE-2026-23377 ↗2026-03-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandice: change XDP RxQ frag_size from DMA write length to xdp.frame_sz
CVE-2026-23378 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandnet/sched: act_ife: Fix metalist update behavior
CVE-2026-23386 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandgve: fix incorrect buffer cleanup in gve_tx_clean_pending_packets for QPL
CVE-2026-23388 ↗2026-03-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandSquashfs: check metadata block offset is within range
CVE-2026-23391 ↗2026-03-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandnetfilter: xt_CT: drop pending enqueued packets on template removal
CVE-2026-23392 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandnetfilter: nf_tables: release flowtable after rcu grace period on error
CVE-2026-23393 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandbridge: cfm: Fix race condition in peer_mep deletion
CVE-2026-23397 ↗2026-03-27azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandnfnetlink_osf: validate individual option lengths in fingerprints
CVE-2026-23654 ↗2026-03-10GitHub Repo: Zero Shot scFoundationImportant1%GitHub: Zero Shot SCFoundation Remote Code Execution Vulnerability
CVE-2026-23656 ↗2026-03-10Windows App Client for Windows DesktopImportant0%Windows App Installer Spoofing Vulnerability
CVE-2026-23660 ↗2026-03-10Windows Admin Center in Azure PortalImportant0%Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability
CVE-2026-23661 ↗2026-03-10Azure IoT ExplorerImportant1%Azure IoT Explorer Information Disclosure Vulnerability
CVE-2026-23662 ↗2026-03-10Azure IoT ExplorerImportant1%Azure IoT Explorer Information Disclosure Vulnerability
CVE-2026-23664 ↗2026-03-10Azure IoT ExplorerImportant1%Azure IoT Explorer Information Disclosure Vulnerability
CVE-2026-23665 ↗2026-03-10Azure Linux Virtual Machines with Azure Diagnostics extensionImportantLinux Azure Diagnostic extension (LAD) Elevation of Privilege Vulnerability
CVE-2026-23667 ↗2026-03-10Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5078752KB5078883
and 4 moreKB5078885KB5079420KB5079466KB5079473
Broadcast DVR Elevation of Privilege Vulnerability
CVE-2026-23668 ↗2026-03-10Windows 10 Version 1809 for 32-bit SystemsImportant4%More likelyKB5078734KB5078737
and 7 moreKB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2026-23669 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant1%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
RPC Runtime Library Remote Code Execution Vulnerability
CVE-2026-23671 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5078734KB5078736
and 10 moreKB5078737KB5078740KB5078752KB5078766KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Bluetooth RFCOM Protocol Driver Elevation of Privilege Vulnerability
CVE-2026-23672 ↗2026-03-10Windows Server 2022 (Server Core installation)Important0%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-23673 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVE-2026-23674 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant1%KB5078734KB5078736
and 13 moreKB5078737KB5078738KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
MapUrlToZone Security Feature Bypass Vulnerability
CVE-2026-23868 ↗2026-03-12azl3 giflib 5.2.1-10 on Azure Linux 3.0ImportantOut-of-bandGiflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible.
CVE-2026-23941 ↗2026-03-17cbl2 erlang 25.3.2.21-4 on CBL Mariner 2.0ImportantOut-of-bandRequest smuggling via first-wins Content-Length parsing in inets httpd
CVE-2026-24282 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5078752KB5078883
and 5 moreKB5078885KB5078938KB5079420KB5079466KB5079473
Push message Routing Service Elevation of Privilege Vulnerability
CVE-2026-24283 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5078734KB5078736
and 4 moreKB5078740KB5079420KB5079466KB5079473
Multiple UNC Provider Kernel Driver Elevation of Privilege Vulnerability
CVE-2026-24285 ↗2026-03-10Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5078734KB5078736
and 11 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079473
Win32k Elevation of Privilege Vulnerability
CVE-2026-24287 ↗2026-03-10Windows Server 2022Important0%KB5078734KB5078736
and 9 moreKB5078737KB5078740KB5078752KB5078766KB5078883KB5078885KB5079420KB5079466KB5079473
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-24288 ↗2026-03-10Windows 10 Version 21H2 for 32-bit SystemsImportant0%KB5078885Windows Mobile Broadband Driver Remote Code Execution Vulnerability
CVE-2026-24289 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant4%More likelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-24290 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5078734KB5078736
and 9 moreKB5078737KB5078740KB5078752KB5078766KB5078883KB5078885KB5079420KB5079466KB5079473
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-24291 ↗2026-03-10Windows 10 Version 1809 for 32-bit SystemsImportant3%More likelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability
CVE-2026-24292 ↗2026-03-10Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5078734KB5078736
and 9 moreKB5078737KB5078740KB5078752KB5078766KB5078883KB5078885KB5079420KB5079466KB5079473
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
CVE-2026-24293 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant1%KB5078734KB5078736
and 8 moreKB5078737KB5078740KB5078766KB5078883KB5078885KB5079420KB5079466KB5079473
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-24294 ↗2026-03-10Windows 10 Version 1809 for 32-bit SystemsImportant5%More likelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-24295 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5078734KB5078736
and 10 moreKB5078737KB5078740KB5078752KB5078766KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-24296 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5078734KB5078736
and 11 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-24297 ↗2026-03-10Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5078752KB5078774
and 3 moreKB5078775KB5078885KB5078938
Windows Kerberos Security Feature Bypass Vulnerability
CVE-2026-25075 ↗2026-03-25azl3 strongswan 5.9.14-8 on Azure Linux 3.0ImportantOut-of-bandstrongSwan 4.5.0 < 6.0.5 EAP-TTLS AVP Parsing Integer Underflow
CVE-2026-25165 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Performance Counters for Windows Elevation of Privilege Vulnerability
CVE-2026-25166 ↗2026-03-10Windows ADK for Windows 11, version 24H2Important2%Windows System Image Manager Assessment and Deployment Kit (ADK) Remote Code Execution Vulnerability
CVE-2026-25167 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5078736KB5078740
and 3 moreKB5079420KB5079466KB5079473
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2026-25168 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Graphics Component Denial of Service Vulnerability
CVE-2026-25169 ↗2026-03-10Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Graphics Component Denial of Service Vulnerability
CVE-2026-25170 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5078734KB5078736
and 7 moreKB5078737KB5078740KB5078766KB5078883KB5079420KB5079466KB5079473
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2026-25171 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Authentication Elevation of Privilege Vulnerability
CVE-2026-25172 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant1%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079466KB5079473KB5084597
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2026-25173 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant1%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079466KB5079473KB5084597
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2026-25174 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Extensible File Allocation Table Elevation of Privilege Vulnerability
CVE-2026-25175 ↗2026-03-10Windows Server 2022 (Server Core installation)Important0%KB5078734KB5078737
and 7 moreKB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938
Windows NTFS Elevation of Privilege Vulnerability
CVE-2026-25176 ↗2026-03-10Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-25177 ↗2026-03-10Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2026-25178 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-25179 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-25180 ↗2026-03-10Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Graphics Component Information Disclosure Vulnerability
CVE-2026-25181 ↗2026-03-10Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
GDI+ Information Disclosure Vulnerability
CVE-2026-25185 ↗2026-03-10Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Shell Link Processing Spoofing Vulnerability
CVE-2026-25186 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant1%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Accessibility Infrastructure (ATBroker.exe) Information Disclosure Vulnerability
CVE-2026-25187 ↗2026-03-10Windows 10 Version 1809 for 32-bit SystemsImportant3%More likelyVulnCheckKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
1 mentionsWinlogon Elevation of Privilege Vulnerability
CVE-2026-25188 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant1%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-25189 ↗2026-03-10Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5078737KB5078752
and 2 moreKB5078766KB5078885
Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-25190 ↗2026-03-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows GDI Remote Code Execution Vulnerability
CVE-2026-25679 ↗2026-03-12cbl2 golang 1.18.8-10 on CBL Mariner 2.0ImportantOut-of-bandIncorrect parsing of IPv6 host literals in net/url
CVE-2026-26017 ↗2026-03-08azl3 coredns 1.11.4-14 on Azure Linux 3.0ImportantOut-of-bandCoreDNS ACL Bypass
CVE-2026-26018 ↗2026-03-08azl3 coredns 1.11.4-14 on Azure Linux 3.0ImportantOut-of-bandCoreDNS Loop Detection Denial of Service Vulnerability
CVE-2026-26030 ↗2026-03-10Microsoft Semantic Kernel Python SDKImportant4%GitHub: CVE-2026-26030 Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable
CVE-2026-26105 ↗2026-03-10Microsoft SharePoint Enterprise Server 2016Important1%KB5002843KB5002845
and 1 moreKB5002850
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-26106 ↗2026-03-10Microsoft SharePoint Enterprise Server 2016Important1%KB5002843KB5002845
and 1 moreKB5002850
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-26107 ↗2026-03-10Office Online ServerImportant0%KB5002846KB5002849Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-26108 ↗2026-03-10Office Online ServerImportant0%KB5002718KB5002846
and 1 moreKB5002849
Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-26109 ↗2026-03-10Office Online ServerImportant0%KB5002846KB5002849Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-26111 ↗2026-03-10Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079466KB5079473KB5084597
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2026-26112 ↗2026-03-10Office Online ServerImportant0%KB5002846KB5002849Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-26114 ↗2026-03-10Microsoft SharePoint Enterprise Server 2016Important2%KB5002845KB5002850Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-26115 ↗2026-03-10Microsoft SQL Server 2025 for x64-based Systems (GDR)Important1%KB5077464KB5077465
and 8 moreKB5077466KB5077468KB5077469KB5077470KB5077471KB5077472KB5077473KB5077474
SQL Server Elevation of Privilege Vulnerability
CVE-2026-26116 ↗2026-03-10Microsoft SQL Server 2025 for x64-based Systems (GDR)Important1%KB5077466KB5077468SQL Server Elevation of Privilege Vulnerability
CVE-2026-26117 ↗2026-03-10Arc Enabled Servers - Azure Connected Machine AgentImportant0%Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2026-26118 ↗2026-03-10Azure MCP Server Tools 2.0.0 (NuGet)Important1%Azure MCP Server Tools Elevation of Privilege Vulnerability
CVE-2026-26121 ↗2026-03-10Azure IoT ExplorerImportant1%Azure IOT Explorer Spoofing Vulnerability
CVE-2026-26123 ↗2026-03-10Microsoft Authenticator for AndroidImportant1%Microsoft Authenticator Information Disclosure Vulnerability
CVE-2026-26127 ↗2026-03-10Microsoft.Bcl.Memory 10.0Important2%VulnCheckKB5081276KB50812781 mentions.NET Denial of Service Vulnerability
CVE-2026-26128 ↗2026-03-10Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-26130 ↗2026-03-10ASP.NET Core 8.0Important3%KB5081276KB5081277
and 1 moreKB5081278
ASP.NET Core Denial of Service Vulnerability
CVE-2026-26131 ↗2026-03-10.NET 10.0 installed on LinuxImportant0%KB5081276.NET Elevation of Privilege Vulnerability
CVE-2026-26132 ↗2026-03-10Windows Server 2022Important2%More likelyKB5078734KB5078736
and 8 moreKB5078737KB5078740KB5078766KB5078883KB5078885KB5079420KB5079466KB5079473
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-26133 ↗2026-03-12Microsoft OneNote for iOSImportantOut-of-band0%M365 Copilot Information Disclosure Vulnerability
CVE-2026-26134 ↗2026-03-10Microsoft Office for AndroidImportant0%Microsoft Office Elevation of Privilege Vulnerability
CVE-2026-26141 ↗2026-03-10Azure Automation Hybrid Worker Windows ExtensionImportant0%Hybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege Vulnerability
CVE-2026-26148 ↗2026-03-10Microsoft Azure AD SSH Login extension for LinuxImportant0%Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability
CVE-2026-2673 ↗2026-03-17azl3 nodejs24 24.13.0-3 on Azure Linux 3.0ImportantOut-of-bandOpenSSL TLS 1.3 server may choose unexpected key agreement group
CVE-2026-27135 ↗2026-03-20azl3 nghttp2 1.61.0-2 on Azure Linux 3.0ImportantOut-of-bandnghttp2 Denial of service: Assertion failure due to the missing state validation
CVE-2026-27142 ↗2026-03-11azl3 golang 1.25.8-1 on Azure Linux 3.0ImportantOut-of-bandURLs in meta content attribute actions are not escaped in html/template
CVE-2026-27459 ↗2026-03-19azl3 pyOpenSSL 24.2.1-1 on Azure Linux 3.0ImportantOut-of-bandpyOpenSSL DTLS cookie callback buffer overflow
CVE-2026-27601 ↗2026-03-07azl3 boost 1.83.0-2 on Azure Linux 3.0ImportantOut-of-bandUnderscore.js has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack
CVE-2026-27651 ↗2026-03-27azl3 nginx 1.28.2-1 on Azure Linux 3.0ImportantOut-of-bandNGINX ngx_mail_auth_http_module vulnerability
CVE-2026-27654 ↗2026-03-27azl3 nginx 1.28.2-1 on Azure Linux 3.0ImportantOut-of-bandNGINX ngx_http_dav_module vulnerability
CVE-2026-27784 ↗2026-03-27azl3 nginx 1.28.2-1 on Azure Linux 3.0ImportantOut-of-bandNGINX ngx_http_mp4_module vulnerability
CVE-2026-29785 ↗2026-04-02cbl2 telegraf 1.29.4-22 on CBL Mariner 2.0ImportantOut-of-bandNATS Server panic via malicious compression on leafnode port
CVE-2026-29786 ↗2026-03-11azl3 tar 1.35-2 on Azure Linux 3.0ImportantOut-of-bandnode-tar: Hardlink Path Traversal via Drive-Relative Linkpath
CVE-2026-30922 ↗2026-03-21azl3 python-pyasn1 0.4.8-1 on Azure Linux 3.0ImportantOut-of-bandpyasn1 Vulnerable to Denial of Service via Unbounded Recursion
CVE-2026-3104 ↗2026-03-29azl3 bind 9.20.18-1 on Azure Linux 3.0ImportantOut-of-bandMemory leak in code preparing DNSSEC proofs of non-existence
CVE-2026-31788 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandxen/privcmd: restrict usage in unprivileged domU
CVE-2026-31802 ↗2026-03-14cbl2 tar 1.34-3 on CBL Mariner 2.0ImportantOut-of-bandnode-tar Symlink Path Traversal via Drive-Relative Linkpath
CVE-2026-32141 ↗2026-03-25cbl2 python-tensorboard 2.11.0-3 on CBL Mariner 2.0ImportantOut-of-bandflatted: Unbounded recursion DoS in parse() revive phase
CVE-2026-32241 ↗2026-03-29azl3 flannel 0.24.2-26 on Azure Linux 3.0ImportantOut-of-bandFlannel vulnerable to cross-node remote code execution via extension backend BackendData injection
CVE-2026-32287 ↗2026-04-02cbl2 telegraf 1.29.4-22 on CBL Mariner 2.0ImportantOut-of-bandInfinite loop in github.com/antchfx/xpath
CVE-2026-32647 ↗2026-03-27azl3 nginx 1.28.2-1 on Azure Linux 3.0ImportantOut-of-bandNGINX ngx_http_mp4_module vulnerability
CVE-2026-32748 ↗2026-03-27azl3 squid 6.13-3 on Azure Linux 3.0ImportantOut-of-bandSquid has Denial of Service in ICP Response handling
CVE-2026-32775 ↗2026-03-17azl3 libexif 0.6.24-1 on Azure Linux 3.0ImportantOut-of-bandlibexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.
CVE-2026-33186 ↗2026-03-26cbl2 grpc 1.42.0-11 on CBL Mariner 2.0ImportantOut-of-bandgRPC-Go has an authorization bypass via missing leading slash in :path
CVE-2026-33216 ↗2026-04-02cbl2 telegraf 1.29.4-22 on CBL Mariner 2.0ImportantOut-of-bandNATS has MQTT plaintext password disclosure
CVE-2026-33228 ↗2026-03-25cbl2 python-tensorboard 2.11.0-3 on CBL Mariner 2.0ImportantOut-of-bandflatted: Prototype Pollution via parse()
CVE-2026-3336 ↗2026-03-05azl3 grpc 1.62.3-1 on Azure Linux 3.0ImportantOut-of-bandPKCS7_verify Certificate Chain Validation Bypass in AWS-LC
CVE-2026-3338 ↗2026-03-05cbl2 tensorflow 2.11.1-2 on CBL Mariner 2.0ImportantOut-of-bandPKCS7_verify Signature Validation Bypass in AWS-LC
CVE-2026-33413 ↗2026-03-28cbl2 etcd 3.5.21-4 on CBL Mariner 2.0ImportantOut-of-bandetcd: Authorization bypasses in multiple APIs
CVE-2026-33416 ↗2026-03-29cbl2 qt5-qtbase 5.12.11-19 on CBL Mariner 2.0ImportantOut-of-bandLIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE`
CVE-2026-33526 ↗2026-03-27azl3 squid 6.13-3 on Azure Linux 3.0ImportantOut-of-bandSquid vulnerable to Denial of Service in ICP Request handling
CVE-2026-33554 ↗2026-04-02cbl2 freeipmi 1.6.6-3 on CBL Mariner 2.0ImportantOut-of-bandipmi-oem in FreeIPMI before 1.16.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Three subcommands were found to have exploitable buffer overflows on response messages. They are: "ipmi-oem dell get-last-post-code - get the last POST code and string describing the error on some Dell servers," "ipmi-oem supermicro extra-firmware-info - get extra firmware info on Supermic
CVE-2026-33636 ↗2026-03-29cbl2 tensorflow 2.11.1-2 on CBL Mariner 2.0ImportantOut-of-bandLIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64
CVE-2026-33671 ↗2026-03-29azl3 nodejs24 24.13.0-3 on Azure Linux 3.0ImportantOut-of-bandPicomatch has a ReDoS vulnerability via extglob quantifiers
CVE-2026-33891 ↗2026-03-31cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ImportantOut-of-bandForge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
CVE-2026-33895 ↗2026-03-31azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandForge has signature forgery in Ed25519 due to missing S > L check
CVE-2026-33896 ↗2026-03-31azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandForge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)
CVE-2026-33938 ↗2026-03-31cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ImportantOut-of-bandHandlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
CVE-2026-33939 ↗2026-03-31cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ImportantOut-of-bandHandlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
CVE-2026-33940 ↗2026-03-31cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ImportantOut-of-bandHandlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
CVE-2026-33941 ↗2026-03-31cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ImportantOut-of-bandHandlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
CVE-2026-34714 ↗2026-04-01cbl2 vim 9.2.0240-1 on CBL Mariner 2.0ImportantOut-of-bandVim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.
CVE-2026-3547 ↗2026-03-25cbl2 mariadb 10.6.24-1 on CBL Mariner 2.0ImportantOut-of-bandwolfSSL: out-of-bounds read (DoS) in ALPN parsing due to incomplete validation
CVE-2026-3548 ↗2026-03-25cbl2 mariadb 10.6.24-1 on CBL Mariner 2.0ImportantOut-of-bandBuffer overflow in CRL number parsing in wolfSSL
CVE-2026-3549 ↗2026-03-25azl3 mariadb 10.11.16-1 on Azure Linux 3.0ImportantOut-of-bandECH parsing heap buffer overflow
CVE-2026-3805 ↗2026-03-13azl3 mysql 8.0.45-1 on Azure Linux 3.0ImportantOut-of-banduse after free in SMB connection reuse
CVE-2026-4046 ↗2026-04-02cbl2 glibc 2.35-10 on CBL Mariner 2.0ImportantOut-of-bandiconv crash due to assertion failure with untrusted input
CVE-2026-4111 ↗2026-03-17cbl2 libarchive 3.6.1-8 on CBL Mariner 2.0ImportantOut-of-bandLibarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive
CVE-2026-4424 ↗2026-03-25cbl2 libarchive 3.6.1-8 on CBL Mariner 2.0ImportantOut-of-bandLibarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing
CVE-2026-4519 ↗2026-03-25azl3 python3 3.12.9-10 on Azure Linux 3.0ImportantOut-of-bandwebbrowser.open() allows leading dashes in URLs
CVE-2026-4645 ↗2026-03-27cbl2 telegraf 1.29.4-21 on CBL Mariner 2.0ImportantOut-of-bandGithub.com/antchfx/xpath: xpath: denial of service via crafted boolean xpath expressions
CVE-2026-4732 ↗2026-04-02azl3 libsndfile 1.2.2-4 on Azure Linux 3.0ImportantOut-of-bandOut-of-bounds Read Overflow in tildearrow/furnace
CVE-2026-4775 ↗2026-03-27cbl2 libtiff 4.6.0-12 on CBL Mariner 2.0ImportantOut-of-bandLibtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing
CVE-2026-5121 ↗2026-04-02cbl2 libarchive 3.6.1-9 on CBL Mariner 2.0ImportantOut-of-bandLibarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing
CVE-2026-5201 ↗2026-04-02cbl2 gdk-pixbuf2 2.40.0-8 on CBL Mariner 2.0ImportantOut-of-bandGdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image
CVE-2006-10002 ↗2026-03-20azl3 perl-XML-Parser 2.47-1 on Azure Linux 3.0ModerateOut-of-bandXML::Parser versions through 2.47 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes
CVE-2024-14027 ↗2026-03-11azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandxattr: switch to CLASS(fd)
CVE-2025-69644 ↗2026-03-11azl3 binutils 2.41-10 on Azure Linux 3.0ModerateOut-of-bandAn issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.
CVE-2025-69645 ↗2026-03-11azl3 binutils 2.41-11 on Azure Linux 3.0ModerateOut-of-bandBinutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.
CVE-2025-69646 ↗2026-03-11azl3 binutils 2.41-10 on Azure Linux 3.0ModerateOut-of-bandBinutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.
CVE-2025-69647 ↗2026-03-15cbl2 binutils 2.37-20 on CBL Mariner 2.0ModerateOut-of-bandGNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.
CVE-2025-69649 ↗2026-03-11azl3 binutils 2.41-10 on Azure Linux 3.0ModerateOut-of-bandGNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.
CVE-2025-69652 ↗2026-03-11azl3 binutils 2.41-10 on Azure Linux 3.0ModerateOut-of-bandGNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.
CVE-2025-71239 ↗2026-03-18azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandaudit: add fchmodat2() to change attributes class
CVE-2025-71265 ↗2026-03-19azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandfs: ntfs3: fix infinite loop in attr_load_runs_range on inconsistent metadata
CVE-2025-71266 ↗2026-03-19azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandfs: ntfs3: check return value of indx_find to avoid infinite loop
CVE-2025-71267 ↗2026-03-19azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandfs: ntfs3: fix infinite loop triggered by zero-sized ATTR_LIST
CVE-2025-71269 ↗2026-03-20azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: do not free data reservation in fallback from inline due to -ENOSPC
CVE-2026-0964 ↗2026-03-31azl3 libssh 0.10.6-5 on Azure Linux 3.0ModerateOut-of-bandLibssh: improper sanitation of paths received from scp servers
CVE-2026-0966 ↗2026-03-31azl3 libssh 0.10.6-5 on Azure Linux 3.0ModerateOut-of-bandLibssh: buffer underflow in ssh_get_hexa() on invalid input
CVE-2026-1965 ↗2026-03-12azl3 curl 8.11.1-5 on Azure Linux 3.0ModerateOut-of-bandbad reuse of HTTP Negotiate connection
CVE-2026-2100 ↗2026-04-02cbl2 p11-kit 0.24.1-1 on CBL Mariner 2.0ModerateOut-of-bandP11-kit: p11-kit: null dereference via c_derivekey with specific null parameters
CVE-2026-21711 ↗2026-04-01azl3 nodejs24 24.14.1-2 on Azure Linux 3.0ModerateOut-of-bandA flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running under `--permission` without `--allow-net` can create and expose local IPC endpoints, allowing communication with other processes on the same host outside of the intended network restriction boundary. This vulnerability affects Node.js **25.x** processes using the Permission Model where `--allow-net` is intentionally omitted to restrict network access. Note that `--allow-net` is currently an experimental feature.
CVE-2026-21712 ↗2026-03-31azl3 nodejs24 24.13.0-3 on Azure Linux 3.0ModerateOut-of-bandA flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.
CVE-2026-21713 ↗2026-04-01azl3 nodejs 20.14.0-14 on Azure Linux 3.0ModerateOut-of-bandA flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.
CVE-2026-21714 ↗2026-04-01azl3 nodejs24 24.13.0-3 on Azure Linux 3.0ModerateOut-of-bandA memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnerability affects HTTP2 users on Node.js 20, 22, 24 and 25.
CVE-2026-21717 ↗2026-04-01azl3 nodejs 20.14.0-15 on Azure Linux 3.0ModerateOut-of-bandA flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade performance of the Node.js process. The most common trigger is any endpoint that calls `JSON.parse()` on attacker-controlled input, as JSON parsing automatically internalizes short strings into the affected hash table. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.
CVE-2026-2297 ↗2026-03-07cbl2 python3 3.9.19-19 on CBL Mariner 2.0ModerateOut-of-bandSourcelessFileLoader does not use io.open_code()
CVE-2026-23236 ↗2026-03-05cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandfbdev: smscufx: properly copy ioctl memory to kernelspace
CVE-2026-23237 ↗2026-03-05cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandplatform/x86: classmate-laptop: Add missing NULL pointer checks
CVE-2026-23238 ↗2026-03-05cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandromfs: check sb_set_blocksize() return value
CVE-2026-23241 ↗2026-03-18azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandaudit: add missing syscalls to read class
CVE-2026-23242 ↗2026-03-19azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/siw: Fix potential NULL pointer dereference in header processing
CVE-2026-23244 ↗2026-03-19azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnvme: fix memory allocation in nvme_pr_read_keys()
CVE-2026-23245 ↗2026-03-19azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/sched: act_gate: snapshot parameters with RCU on replace
CVE-2026-23246 ↗2026-03-19azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
CVE-2026-23247 ↗2026-03-19azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandtcp: secure_seq: add back ports to TS offset
CVE-2026-23248 ↗2026-03-19azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandperf/core: Fix refcount bug and potential UAF in perf_mmap
CVE-2026-23253 ↗2026-03-20azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandmedia: dvb-core: fix wrong reinitialization of ringbuffer on reopen
CVE-2026-23255 ↗2026-03-20azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: add proper RCU protection to /proc/net/ptype
CVE-2026-23259 ↗2026-03-20azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandio_uring/rw: free potentially allocated iovec on cache put failure
CVE-2026-23266 ↗2026-03-20azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandfbdev: rivafb: fix divide error in nv3_arb()
CVE-2026-23269 ↗2026-03-20azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandapparmor: validate DFA start states are in bounds in unpack_pdb
CVE-2026-23271 ↗2026-03-21azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandperf: Fix __perf_event_overflow() vs perf_remove_from_context() race
CVE-2026-23272 ↗2026-03-21azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nf_tables: unconditionally bump set->nelems before insertion
CVE-2026-23274 ↗2026-03-21azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels
CVE-2026-23276 ↗2026-03-21azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: add xmit recursion limit to tunnel xmit functions
CVE-2026-23277 ↗2026-03-21azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit
CVE-2026-23278 ↗2026-03-21azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nf_tables: always walk all pending catchall elements
CVE-2026-23279 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mac80211: fix NULL pointer dereference in mesh_rx_csa_frame()
CVE-2026-23284 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: ethernet: mtk_eth_soc: Reset prog ptr to old_prog in case of error in mtk_xdp_setup()
CVE-2026-23285 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-banddrbd: fix null-pointer dereference on local read error
CVE-2026-23286 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandatm: lec: fix null-ptr-deref in lec_arp_clear_vccs
CVE-2026-23290 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: usb: pegasus: validate USB endpoints
CVE-2026-23291 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnfc: pn533: properly drop the usb interface reference on disconnect
CVE-2026-23292 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: target: Fix recursive locking in __configfs_open_file()
CVE-2026-23298 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandcan: ucan: Fix infinite loop from zero-length messages
CVE-2026-23302 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: annotate data-races around sk->sk_{data_ready,write_space}
CVE-2026-23303 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandsmb: client: Don't log plaintext credentials in cifs_set_cifscreds
CVE-2026-23304 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu()
CVE-2026-23307 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandcan: ems_usb: ems_usb_read_bulk_callback(): check the proper length of a message
CVE-2026-23312 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: usb: kaweth: validate USB endpoints
CVE-2026-23317 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/vmwgfx: Return the correct value in vmw_translate_ptr functions
CVE-2026-23319 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Fix a UAF issue in bpf_trampoline_link_cgroup_shim
CVE-2026-23320 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: gadget: f_ncm: align net_device lifecycle with bind/unbind
CVE-2026-23324 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandcan: usb: etas_es58x: correctly anchor the urb in the read bulk callback
CVE-2026-23333 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nft_set_rbtree: validate open interval overlap
CVE-2026-23334 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandcan: usb: f81604: handle short interrupt urb messages properly
CVE-2026-23346 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandarm64: io: Extract user memory type in ioremap_prot()
CVE-2026-23347 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandcan: usb: f81604: correctly anchor the urb in the read bulk callback
CVE-2026-23348 ↗2026-03-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandcxl: Fix race of nvdimm_bus object when creating nvdimm objects
CVE-2026-23356 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-banddrbd: fix "LOGIC BUG" in drbd_al_begin_io_nonblock()
CVE-2026-23357 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandcan: mcp251x: fix deadlock in error path of mcp251x_open
CVE-2026-23360 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnvme: fix admin queue leak on controller reset
CVE-2026-23362 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandcan: bcm: fix locking for bcm_op runtime updates
CVE-2026-23365 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: usb: kalmia: validate USB endpoints
CVE-2026-23368 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: phy: register phy led_triggers during probe to avoid AB-BA deadlock
CVE-2026-23370 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandplatform/x86: dell-wmi-sysman: Don't hex dump plaintext password data
CVE-2026-23371 ↗2026-03-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandsched/deadline: Fix missing ENQUEUE_REPLENISH during PI de-boosting
CVE-2026-23379 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/sched: ets: fix divide by zero in the offload path
CVE-2026-23381 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: bridge: fix nd_tbl NULL dereference when IPv6 is disabled
CVE-2026-23382 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandHID: Add HID_CLAIMED_INPUT guards in raw_event callbacks missing them
CVE-2026-23383 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf, arm64: Force 8-byte alignment for JIT buffer to prevent atomic tearing
CVE-2026-23389 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandice: Fix memory leak in ice_set_ringparam()
CVE-2026-23390 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandtracing/dma: Cap dma_map_sg tracepoint arrays to prevent buffer overflow
CVE-2026-23394 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandaf_unix: Give up GC if MSG_PEEK intervened.
CVE-2026-23396 ↗2026-03-27azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mac80211: fix NULL deref in mesh_matches_local()
CVE-2026-23398 ↗2026-03-27azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandicmp: fix NULL pointer dereference in icmp_tag_validation()
CVE-2026-23399 ↗2026-03-29azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnf_tables: nft_dynset: fix possible stateful expression memleak in error path
CVE-2026-2369 ↗2026-03-25cbl2 libsoup 3.0.4-12 on CBL Mariner 2.0ModerateOut-of-bandLibsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources
CVE-2026-23865 ↗2026-03-04azl3 freetype 2.13.2-1 on Azure Linux 3.0ModerateOut-of-bandAn integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.
CVE-2026-23942 ↗2026-03-17cbl2 erlang 25.3.2.21-4 on CBL Mariner 2.0ModerateOut-of-bandSFTP root escape via component-agnostic prefix check in ssh_sftpd
CVE-2026-23943 ↗2026-03-17azl3 erlang 26.2.5.17-1 on Azure Linux 3.0ModerateOut-of-bandPre-auth SSH DoS via unbounded zlib inflate
CVE-2026-2436 ↗2026-04-02azl3 libsoup 3.4.4-14 on Azure Linux 3.0ModerateOut-of-bandLibsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake
CVE-2026-25645 ↗2026-03-29azl3 python-requests 2.31.0-3 on Azure Linux 3.0ModerateOut-of-bandRequests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
CVE-2026-2645 ↗2026-03-25cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0ModerateOut-of-bandAcceptance of CertificateVerify Message before ClientKeyExchange in TLS 1.2
CVE-2026-2646 ↗2026-03-25cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0ModerateOut-of-bandHeap buffer overflow in session parsing with wolfSSL_d2i_SSL_SESSION() function
CVE-2026-27137 ↗2026-03-11azl3 golang 1.25.7-1 on Azure Linux 3.0ModerateOut-of-bandIncorrect enforcement of email constraints in crypto/x509
CVE-2026-27138 ↗2026-03-11azl3 golang 1.25.7-1 on Azure Linux 3.0ModerateOut-of-bandPanic in name constraint checking for malformed certificates in crypto/x509
CVE-2026-28753 ↗2026-03-27azl3 nginx 1.28.2-1 on Azure Linux 3.0ModerateOut-of-bandNGINX ngx_mail_proxy_module vulnerability
CVE-2026-28755 ↗2026-03-27azl3 nginx 1.28.2-1 on Azure Linux 3.0ModerateOut-of-bandNGINX ngx_stream_ssl_module vulnerability
CVE-2026-29111 ↗2026-03-26cbl2 systemd-bootstrap 250.3-13 on CBL Mariner 2.0ModerateOut-of-bandsystemd: Local unprivileged user can trigger an assert
CVE-2026-3099 ↗2026-03-25azl3 libsoup 3.4.4-12 on Azure Linux 3.0ModerateOut-of-bandLibsoup: libsoup: authentication bypass via digest authentication replay attack
CVE-2026-3119 ↗2026-03-29azl3 bind 9.20.18-1 on Azure Linux 3.0ModerateOut-of-bandAuthenticated query containing a TKEY record may cause named to terminate unexpectedly
CVE-2026-32249 ↗2026-03-15cbl2 vim 9.2.0088-1 on CBL Mariner 2.0ModerateOut-of-bandNFA regex engine NULL pointer dereference affects Vim < 9.2.0137
CVE-2026-32776 ↗2026-03-17azl3 expat 2.6.4-4 on Azure Linux 3.0ModerateOut-of-bandlibexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
CVE-2026-32777 ↗2026-03-17azl3 expat 2.6.4-4 on Azure Linux 3.0ModerateOut-of-bandlibexpat before 2.7.5 allows an infinite loop while parsing DTD content.
CVE-2026-33055 ↗2026-03-25cbl2 kata-containers 3.2.0.azl2-7 on CBL Mariner 2.0ModerateOut-of-bandtar-rs incorrectly ignores PAX size headers if header size is nonzero
CVE-2026-33056 ↗2026-03-25azl3 kata-containers-cc 3.15.0.aks0-7 on Azure Linux 3.0ModerateOut-of-bandtar-rs: unpack_in can chmod arbitrary directories by following symlinks
CVE-2026-33343 ↗2026-03-28cbl2 etcd 3.5.21-4 on CBL Mariner 2.0ModerateOut-of-bandetcd: Nested etcd transactions bypass RBAC authorization checks
CVE-2026-33412 ↗2026-03-26azl3 vim 9.2.0088-1 on Azure Linux 3.0ModerateOut-of-bandVim affected by Command injection via newline in glob()
CVE-2026-33515 ↗2026-03-27azl3 squid 6.13-3 on Azure Linux 3.0ModerateOut-of-bandSquid has issues in ICP message handling
CVE-2026-33542 ↗2026-03-31azl3 telegraf 1.31.0-19 on Azure Linux 3.0ModerateOut-of-bandIncus does not verify combined fingerprint when downloading images from simplestreams servers
CVE-2026-33672 ↗2026-03-29azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandPicomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
CVE-2026-33750 ↗2026-03-31azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandbrace-expansion: Zero-step sequence causes process hang and memory exhaustion
CVE-2026-33916 ↗2026-03-31cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ModerateOut-of-bandHandlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection
CVE-2026-33936 ↗2026-03-29azl3 python-ecdsa 0.18.0-2 on Azure Linux 3.0ModerateOut-of-bandpython-ecdsa: Denial of Service via improper DER length validation in crafted private keys
CVE-2026-34043 ↗2026-04-01cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ModerateOut-of-bandSerialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
CVE-2026-34085 ↗2026-03-27azl3 fontconfig 2.14.2-1 on Azure Linux 3.0ModerateOut-of-bandfontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
CVE-2026-34353 ↗2026-03-31azl3 ocaml 5.1.1-1 on Azure Linux 3.0ModerateOut-of-bandIn OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.
CVE-2026-3494 ↗2026-03-07cbl2 mariadb 10.6.24-1 on CBL Mariner 2.0ModerateOut-of-bandMariaDB Server Audit Plugin Comment Handling Bypass
CVE-2026-3503 ↗2026-03-25cbl2 mariadb 10.6.24-1 on CBL Mariner 2.0ModerateOut-of-bandFault injection attack with ML-DSA and ML-KEM on ARM
CVE-2026-3591 ↗2026-03-29azl3 bind 9.20.18-1 on Azure Linux 3.0ModerateOut-of-bandA stack use-after-return flaw in SIG(0) handling code may enable ACL bypass
CVE-2026-3644 ↗2026-03-19azl3 python3 3.12.9-9 on Azure Linux 3.0ModerateOut-of-bandIncomplete control character validation in http.cookies
CVE-2026-3713 ↗2026-03-09azl3 libpng 1.6.55-1 on Azure Linux 3.0ModerateOut-of-bandpnggroup libpng pnm2png pnm2png.c do_pnm2png heap-based overflow
CVE-2026-3731 ↗2026-03-11azl3 libssh 0.10.6-6 on Azure Linux 3.0ModerateOut-of-bandlibssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds
CVE-2026-3783 ↗2026-03-12azl3 cmake 3.30.3-12 on Azure Linux 3.0ModerateOut-of-bandtoken leak with redirect and netrc
CVE-2026-3784 ↗2026-03-12azl3 curl 8.11.1-5 on Azure Linux 3.0ModerateOut-of-bandwrong proxy connection reuse with credentials
CVE-2026-3849 ↗2026-03-25cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0ModerateOut-of-bandBuffer Overflow in HPKE via Oversized ECH Config
CVE-2026-3904 ↗2026-03-13cbl2 glibc 2.35-10 on CBL Mariner 2.0ModerateOut-of-bandCalling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library version 2.36 under high load on x86_64 systems, the client may call memcmp on inputs that are concurrently modified by other processes or threads and crash. The nscd client in the GNU C Library uses the memcmp function with inputs that may be concurrently modified by another thread, potentially resulting in spurious cache misses, which in itself is not a security issue.  However in the GNU C Library version 2.36 an optimized implementation of memcmp was introduced for x86_64 which could crash when invoked with such undefined behaviour, turning this into a potential crash of the nscd client and the application that uses it. This implementation was backported to the 2.35 branch, making the nscd client in that branch vulnerable as well.  Subsequently, the fix for this issue was backported to all vulnerable branches in the GNU C Library repository. It is
CVE-2026-4105 ↗2026-03-17cbl2 systemd 250.3-23 on CBL Mariner 2.0ModerateOut-of-bandSystemd: systemd: privilege escalation via improper access control in registermachine d-bus method
CVE-2026-4224 ↗2026-03-19azl3 python3 3.12.9-9 on Azure Linux 3.0ModerateOut-of-bandStack overflow parsing XML with deeply nested DTD content models
CVE-2026-4426 ↗2026-03-25azl3 libarchive 3.7.7-4 on Azure Linux 3.0ModerateOut-of-bandLibarchive: libarchive: denial of service via malformed iso file processing
CVE-2026-4437 ↗2026-03-22azl3 glibc 2.38-19 on Azure Linux 3.0ModerateOut-of-bandgethostbyaddr and gethostbyaddr_r may incorrectly handle DNS response
CVE-2026-4438 ↗2026-03-22azl3 glibc 2.38-19 on Azure Linux 3.0ModerateOut-of-bandgethostbyaddr and gethostbyaddr_r return invalid DNS hostnames
CVE-2026-4647 ↗2026-03-27cbl2 binutils 2.37-20 on CBL Mariner 2.0ModerateOut-of-bandBinutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library
CVE-2026-4833 ↗2026-03-29azl3 rubygem-rdiscount 2.2.7.1-1 on Azure Linux 3.0ModerateOut-of-bandOrc discount Markdown markdown.c compile recursion
CVE-2026-4897 ↗2026-04-02cbl2 polkit 0.119-4 on CBL Mariner 2.0ModerateOut-of-bandPolkit: polkit: denial of service via unbounded input processing through standard input
CVE-2026-4948 ↗2026-05-02cbl2 firewalld 1.0.3-2 on CBL Mariner 2.0ModerateOut-of-bandFirewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization
CVE-2026-5119 ↗2026-04-02cbl2 libsoup 3.0.4-13 on CBL Mariner 2.0ModerateOut-of-bandLibsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment
CVE-2025-13462 ↗2026-03-25azl3 tensorflow 2.16.1-11 on Azure Linux 3.0LowOut-of-bandtarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling
CVE-2025-49010 ↗2026-04-01cbl2 opensc 0.23.0-5 on CBL Mariner 2.0LowOut-of-bandOpenSC: Stack-buffer-overflow WRITE in GET RESPONSE
CVE-2025-66037 ↗2026-04-01cbl2 opensc 0.23.0-5 on CBL Mariner 2.0LowOut-of-bandOpenSC: Out of Bounds vulnerability
CVE-2025-66038 ↗2026-04-01cbl2 opensc 0.23.0-5 on CBL Mariner 2.0LowOut-of-bandOpenSC: `sc_compacttlv_find_tag` can return out-of-bounds pointers
CVE-2025-66215 ↗2026-04-01cbl2 opensc 0.23.0-5 on CBL Mariner 2.0LowOut-of-bandOpenSC: Stack-buffer-overflow WRITE in card-oberthur
CVE-2025-70888 ↗2026-03-29cbl2 osslsigncode 2.7-1 on CBL Mariner 2.0LowOut-of-bandAn issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the osslsigncode.c component
CVE-2026-0385 ↗2026-03-13Microsoft Edge for AndroidLowOut-of-band0%Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2026-0819 ↗2026-03-25cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0LowOut-of-bandStack buffer overflow in PKCS7 SignedData encoding with custom signed attributes
CVE-2026-0965 ↗2026-03-31cbl2 libssh 0.10.6-5 on CBL Mariner 2.0LowOut-of-bandLibssh: libssh: denial of service via improper configuration file handling
CVE-2026-0967 ↗2026-03-31azl3 libssh 0.10.6-5 on Azure Linux 3.0LowOut-of-bandLibssh: libssh: denial of service via inefficient regular expression processing
CVE-2026-0968 ↗2026-04-05azl3 libssh 0.10.6-6 on Azure Linux 3.0LowOut-of-bandLibssh: libssh: denial of service due to malformed sftp message
CVE-2026-1005 ↗2026-03-25cbl2 mariadb 10.6.24-1 on CBL Mariner 2.0LowOut-of-bandInteger underflow leads to out-of-bounds access in sniffer AES-GCM/CCM/ARIA-GCM decrypt path
CVE-2026-21715 ↗2026-04-01azl3 nodejs 20.14.0-14 on Azure Linux 3.0LowOut-of-bandA flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs-read` can still use `fs.realpathSync.native()` to check file existence, resolve symlink targets, and enumerate filesystem paths outside of permitted directories. This vulnerability affects **20.x, 22.x, 24.x, and 25.x** processes using the Permission Model where `--allow-fs-read` is intentionally restricted.
CVE-2026-21716 ↗2026-04-01azl3 nodejs24 24.13.0-3 on Azure Linux 3.0LowOut-of-bandAn incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their callback-based equivalents (`fs.fchmod()`, `fs.fchown()`) were correctly patched. As a result, code running under `--permission` with restricted `--allow-fs-write` can still use promise-based `FileHandle` methods to modify file permissions and ownership on already-open file descriptors, bypassing the intended write restrictions. This vulnerability affects **20.x, 22.x, 24.x, and 25.x** processes using the Permission Model where `--allow-fs-write` is intentionally restricted.
CVE-2026-27139 ↗2026-03-11azl3 golang 1.24.13-1 on Azure Linux 3.0LowOut-of-bandFileInfo can escape from a Root in os
CVE-2026-27448 ↗2026-03-19azl3 pyOpenSSL 24.2.1-1 on Azure Linux 3.0LowOut-of-bandpyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback
CVE-2026-32187 ↗2026-03-27Microsoft Edge (Chromium-based)LowOut-of-bandMicrosoft Edge (Chromium-based) Defense in Depth Vulnerability - Rejected
CVE-2026-3229 ↗2026-03-25azl3 mariadb 10.11.16-1 on Azure Linux 3.0LowOut-of-bandInteger Overflow in Certificate Chain Allocation
CVE-2026-3230 ↗2026-03-25cbl2 mariadb 10.6.24-1 on CBL Mariner 2.0LowOut-of-bandImproper key_share validation in TLS 1.3 HelloRetryRequest
CVE-2026-32766 ↗2026-03-21azl3 kata-containers-cc 3.15.0.aks0-7 on Azure Linux 3.0LowOut-of-bandastral-tokio-tar insufficiently validates PAX extensions during extraction
CVE-2026-32778 ↗2026-03-17azl3 expat 2.6.4-4 on Azure Linux 3.0LowOut-of-bandlibexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
CVE-2026-34073 ↗2026-04-03azl3 python-cryptography 42.0.5-4 on Azure Linux 3.0LowOut-of-bandcryptography has incomplete DNS name constraint enforcement on peer names
CVE-2026-3479 ↗2026-03-21azl3 python3 3.12.9-9 on Azure Linux 3.0LowOut-of-bandpkgutil.get_data() does not enforce documented restrictions
CVE-2026-3579 ↗2026-03-25cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0LowOut-of-bandNon-constant time multiplication subroutine __muldi3 on RISC-V RV32I
CVE-2026-3580 ↗2026-03-25cbl2 mariadb 10.6.24-1 on CBL Mariner 2.0LowOut-of-bandCompiler-induced timing leak in sp_256_get_entry_256_9 on RISC-V
CVE-2026-3632 ↗2026-03-21azl3 libsoup 3.4.4-12 on Azure Linux 3.0LowOut-of-bandLibsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames
CVE-2026-3633 ↗2026-03-21azl3 libsoup 3.4.4-12 on Azure Linux 3.0LowOut-of-bandLibsoup: libsoup: header and http request injection via crlf injection
CVE-2026-3634 ↗2026-03-21cbl2 libsoup 3.0.4-12 on CBL Mariner 2.0LowOut-of-bandLibsoup: libsoup: http header injection and response splitting via crlf injection in content-type header
CVE-2026-4159 ↗2026-03-25azl3 mariadb 10.11.16-1 on Azure Linux 3.0LowOut-of-bandwc_PKCS7_DecodeEnvelopedData 1 byte out-of-bounds read
CVE-2026-4395 ↗2026-03-25cbl2 mariadb 10.6.25-1 on CBL Mariner 2.0LowOut-of-bandHeap-based buffer overflow in wc_ecc_import_x963_ex KCAPI path
CVE-2026-5107 ↗2026-03-31azl3 frr 10.5.0-1 on Azure Linux 3.0LowOut-of-bandFRRouting FRR EVPN Type-2 Route bgp_evpn.c process_type2_route access control
CVE-2026-3536 ↗2026-03-06Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3536 Integer overflow in ANGLE
CVE-2026-3537 ↗2026-03-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3537 Object lifecycle issue in PowerVR
CVE-2026-3538 ↗2026-03-06Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3538 Integer overflow in Skia
CVE-2026-3539 ↗2026-03-06Microsoft Edge (Chromium-based)N/AOut-of-bandChromium: CVE-2026-3539 Object lifecycle issue in DevTools
CVE-2026-3540 ↗2026-03-06Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3540 Inappropriate implementation in WebAudio
CVE-2026-3541 ↗2026-03-06Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3541 Inappropriate implementation in CSS
CVE-2026-3542 ↗2026-03-06Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3542 Inappropriate implementation in WebAssembly
CVE-2026-3543 ↗2026-03-06Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3543 Inappropriate implementation in V8
CVE-2026-3544 ↗2026-03-06Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3544 Heap buffer overflow in WebCodecs
CVE-2026-3545 ↗2026-03-06Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3545 Insufficient data validation in Navigation
CVE-2026-3909 ↗2026-03-16Microsoft Edge (Chromium-based)N/AOut-of-band2%CISA KEVVulnCheckENISA1 mentionsChromium: CVE-2026-3909 Out of bounds write in Skia
CVE-2026-3910 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band2%CISA KEVVulnCheckENISA1 mentionsChromium: CVE-2026-3910 Inappropriate implementation in V8
CVE-2026-3913 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3913 Heap buffer overflow in WebML
CVE-2026-3914 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3914 Integer overflow in WebML
CVE-2026-3915 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3915 Heap buffer overflow in WebML
CVE-2026-3916 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3916 Out of bounds read in Web Speech
CVE-2026-3917 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3917 Use after free in Agents
CVE-2026-3918 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3918 Use after free in WebMCP
CVE-2026-3919 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3919 Use after free in Extensions
CVE-2026-3920 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3920 Out of bounds memory access in WebML
CVE-2026-3921 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3921 Use after free in TextEncoding
CVE-2026-3922 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3922 Use after free in MediaStream
CVE-2026-3923 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3923 Use after free in WebMIDI
CVE-2026-3924 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3924 Use after free in WindowDialog
CVE-2026-3925 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3925 Incorrect security UI in LookalikeChecks
CVE-2026-3926 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3926 Out of bounds read in V8
CVE-2026-3927 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3927 Incorrect security UI in PictureInPicture
CVE-2026-3928 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3928 Insufficient policy enforcement in Extensions
CVE-2026-3929 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3929 Side-channel information leakage in ResourceTiming
CVE-2026-3930 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3930 Unsafe navigation in Navigation
CVE-2026-3931 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3931 Heap buffer overflow in Skia
CVE-2026-3932 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3932 Insufficient policy enforcement in PDF
CVE-2026-3934 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3934 Insufficient policy enforcement in ChromeDriver
CVE-2026-3935 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3935 Incorrect security UI in WebAppInstalls
CVE-2026-3936 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3936 Use after free in WebView
CVE-2026-3937 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3937 Incorrect security UI in Downloads
CVE-2026-3938 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3938 Insufficient policy enforcement in Clipboard
CVE-2026-3939 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3939 Use after free in WebView
CVE-2026-3940 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3940 Insufficient policy enforcement in DevTools
CVE-2026-3941 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3941 Insufficient policy enforcement in DevTools
CVE-2026-3942 ↗2026-03-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3942 Incorrect security UI in PictureInPicture
CVE-2026-4440 ↗2026-03-22Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4440 Out of bounds read and write in WebGL
CVE-2026-4441 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4441 Use after free in Base
CVE-2026-4442 ↗2026-03-27Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4442 Heap buffer overflow in CSS
CVE-2026-4443 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4443 Heap buffer overflow in WebAudio
CVE-2026-4444 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4444 Stack buffer overflow in WebRTC
CVE-2026-4445 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4445 Use after free in WebRTC
CVE-2026-4446 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4446 Use after free in WebRTC
CVE-2026-4447 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4447 Inappropriate implementation in V8
CVE-2026-4448 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4448 Heap buffer overflow in ANGLE
CVE-2026-4449 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4449 Use after free in Blink
CVE-2026-4450 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4450 Out of bounds write in V8
CVE-2026-4451 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4451 Insufficient validation of untrusted input in Navigation
CVE-2026-4452 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4452 Integer overflow in ANGLE
CVE-2026-4453 ↗2026-03-20Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4453 Integer overflow in Dawn
CVE-2026-4454 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4454 Use after free in Network
CVE-2026-4455 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4455 Heap buffer overflow in PDFium
CVE-2026-4456 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4456 Use after free in Digital Credentials API
CVE-2026-4457 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4457 Type Confusion in V8
CVE-2026-4458 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4458 Use after free in Extensions
CVE-2026-4459 ↗2026-03-20Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4459 Out of bounds read and write in WebAudio
CVE-2026-4460 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4460 Out of bounds read in Skia
CVE-2026-4461 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4461 Inappropriate implementation in V8
CVE-2026-4462 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4462 Out of bounds read in Blink
CVE-2026-4463 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4463 Heap buffer overflow in WebRTC
CVE-2026-4464 ↗2026-03-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4464 Integer overflow in ANGLE
CVE-2026-4673 ↗2026-03-27Microsoft Edge (Chromium-based)N/AOut-of-band1%Chromium: CVE-2026-4673 Heap buffer overflow in WebAudio
CVE-2026-4674 ↗2026-03-27Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4674 Out of bounds read in CSS
CVE-2026-4675 ↗2026-03-27Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4675 Heap buffer overflow in WebGL
CVE-2026-4676 ↗2026-03-27Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4676 Use after free in Dawn
CVE-2026-4677 ↗2026-03-27Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4677 Out of bounds read in WebAudio
CVE-2026-4678 ↗2026-03-27Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4678 Use after free in WebGPU
CVE-2026-4679 ↗2026-03-27Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4679 Integer overflow in Fonts
CVE-2026-4680 ↗2026-03-27Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4680 Use after free in FedCM
#

February 2026

Patch Tuesday February 10, 202680 CVEs plus 89 Azure Linux package advisories · 7 critical · 6 exploitation detected · 7 in KEV169 CVEs · 12 critical · 6 exploitation detected · 7 in KEV · includes 89 Azure Linux package advisories
Risk matrix, February 2026
18 of these counts use a severity derived from CVSS because Microsoft assigned none.
18 of these counts use a severity derived from CVSS because Microsoft assigned none.
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-21510 ↗2026-02-10Windows 10 Version 1809 for 32-bit SystemsImportant26%Exploitation detectedCISA KEVVulnCheckENISAKB5075897KB5075899
and 12 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077179KB5077181KB5077212
Windows Shell Security Feature Bypass Vulnerability
CVE-2026-21513 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant15%Exploitation detectedCISA KEVVulnCheckENISAKB5075897KB5075899
and 12 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077179KB5077181KB5077212
MSHTML Framework Security Feature Bypass Vulnerability
CVE-2026-21514 ↗2026-02-10Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant2%Exploitation detectedCISA KEVVulnCheckENISAMicrosoft Word Security Feature Bypass Vulnerability
CVE-2026-21519 ↗2026-02-10Windows 10 Version 1809 for 32-bit SystemsImportant2%Exploitation detectedCISA KEVVulnCheckENISAKB5075897KB5075899
and 10 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075999KB5077179KB5077181KB5077212
Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-21533 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant4%Exploitation detectedCISA KEVVulnCheckENISAKB5075897KB5075899
and 12 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077179KB5077181KB5077212
Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVE-2026-21525 ↗2026-02-10Windows 10 Version 1809 for 32-bit SystemsModerate5%Exploitation detectedCISA KEVVulnCheckENISAKB5075897KB5075899
and 12 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077179KB5077181KB5077212
Windows Remote Access Connection Manager Denial of Service Vulnerability
CVE-2025-61144 ↗2026-02-26azl3 libtiff 4.6.0-11 on Azure Linux 3.0CriticalOut-of-bandlibtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.
CVE-2025-62878 ↗2026-02-26cbl2 local-path-provisioner 0.0.21-20 on CBL Mariner 2.0CriticalOut-of-bandLocal Path Provisioner vulnerable to Path Traversal via parameters.pathPattern
CVE-2026-21522 ↗2026-02-10Microsoft ACI Confidential ContainersCritical0%Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability
CVE-2026-21532 ↗2026-02-05Azure FunctionsCriticalOut-of-band1%Azure Function Information Disclosure Vulnerability
CVE-2026-21535 ↗2026-02-19Microsoft TeamsCriticalOut-of-band1%Microsoft Teams Information Disclosure Vulnerability
CVE-2026-23655 ↗2026-02-10Microsoft ACI Confidential ContainersCritical1%Microsoft ACI Confidential Containers Information Disclosure Vulnerability
CVE-2026-24300 ↗2026-02-05Azure Front DoorCriticalOut-of-band1%Azure Front Door Elevation of Privilege Vulnerability
CVE-2026-24302 ↗2026-02-05Azure ARCCriticalOut-of-band2%Azure Arc Elevation of Privilege Vulnerability
CVE-2026-24834 ↗2026-02-23cbl2 kata-containers 3.2.0.azl2-7 on CBL Mariner 2.0CriticalOut-of-bandKata Container to Guest micro VM privilege escalation
CVE-2026-26119 ↗2026-02-17Windows Admin CenterCriticalOut-of-band1%More likelyWindows Admin Center Elevation of Privilege Vulnerability
CVE-2026-27211 ↗2026-02-25azl3 cloud-hypervisor 48.0.246-1 on Azure Linux 3.0CriticalOut-of-bandCloud Hypervisor: Host File Exfiltration via QCOW Backing File Abuse
CVE-2026-27969 ↗2026-02-27cbl2 vitess 17.0.7-12 on CBL Mariner 2.0CriticalOut-of-bandVitess users with backup storage access can write to arbitrary file paths on restore
CVE-2023-2804 ↗2026-02-10Windows Server 2022, 23H2 Edition (Server Core installation)Important1%KB5075897Red Hat, Inc. CVE-2023-2804: Heap Based Overflow libjpeg-turbo
CVE-2025-67733 ↗2026-02-26azl3 valkey 8.0.6-1 on Azure Linux 3.0ImportantOut-of-bandValkey Affected by RESP Protocol Injection via Lua error_reply
CVE-2025-68121 ↗2026-03-05azl3 golang 1.26.0-1 on Azure Linux 3.0ImportantOut-of-bandUnexpected session resumption in crypto/tls
CVE-2025-69299 ↗2026-02-22azl3 doxygen 1.9.8-2 on Azure Linux 3.0ImportantOut-of-bandWordPress Oxygen theme <= 6.0.8 - Server Side Request Forgery (SSRF) vulnerability
CVE-2025-71221 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-banddmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue()
CVE-2025-71225 ↗2026-02-21cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandmd: suspend array while updating raid_disks via sysfs
CVE-2025-71226 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: iwlwifi: Implement settime64 as stub for MVM/MLD PTP
CVE-2025-71228 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandLoongArch: Set correct protection_map[] for VM_NONE/VM_SHARED
CVE-2025-71229 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: rtw88: Fix alignment fault in rtw_core_enable_beacon()
CVE-2025-71231 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandcrypto: iaa - Fix out-of-bounds index in find_empty_iaa_compression_mode
CVE-2025-71233 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandPCI: endpoint: Avoid creating sub-groups asynchronously
CVE-2025-71234 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: rtl8xxxu: fix slab-out-of-bounds in rtl8xxxu_sta_add
CVE-2025-71236 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandscsi: qla2xxx: Validate sp before freeing associated memory
CVE-2026-20841 ↗2026-02-10Windows NotepadImportant12%1 mentionsWindows Notepad App Remote Code Execution Vulnerability
CVE-2026-20846 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant1%KB5075897KB5075899
and 12 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077179KB5077181KB5077212
GDI+ Denial of Service Vulnerability
CVE-2026-21218 ↗2026-02-10.NET 10.0 installed on Mac OSImportant1%KB5077862KB5077863
and 1 moreKB5077864
.NET Spoofing Vulnerability
CVE-2026-21222 ↗2026-02-10Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5075897KB5075899
and 10 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075999KB5077181KB5077212
Windows Kernel Information Disclosure Vulnerability
CVE-2026-21228 ↗2026-02-10Azure LocalImportant1%Azure Local Remote Code Execution Vulnerability
CVE-2026-21229 ↗2026-02-10Power BI Report ServerImportant1%Power BI Remote Code Execution Vulnerability
CVE-2026-21231 ↗2026-02-10Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5075897KB5075899
and 12 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077179KB5077181KB5077212
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-21232 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5075897KB5075899
and 5 moreKB5075941KB5075942KB5077179KB5077181KB5077212
Windows HTTP.sys Elevation of Privilege Vulnerability
CVE-2026-21234 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5075897KB5075899
and 9 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5077179KB5077181KB5077212
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
CVE-2026-21235 ↗2026-02-10Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5075904KB5075906
and 7 moreKB5075912KB5075941KB5075943KB5075970KB5075971KB5075999KB5077179
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2026-21236 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5075897KB5075899
and 12 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077179KB5077181KB5077212
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-21237 ↗2026-02-10Windows Server 2022Important0%KB5075897KB5075899
and 8 moreKB5075906KB5075912KB5075941KB5075942KB5075943KB5077179KB5077181KB5077212
Windows Subsystem for Linux Elevation of Privilege Vulnerability
CVE-2026-21238 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant3%More likelyKB5075897KB5075899
and 12 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077179KB5077181KB5077212
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-21239 ↗2026-02-10Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5075897KB5075899
and 11 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077181KB5077212
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-21240 ↗2026-02-10Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5075897KB5075899
and 9 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5077179KB5077181KB5077212
Windows HTTP.sys Elevation of Privilege Vulnerability
CVE-2026-21241 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant2%More likelyKB5075897KB5075899
and 7 moreKB5075906KB5075941KB5075942KB5075943KB5077179KB5077181KB5077212
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-21242 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5075897KB5075899
and 8 moreKB5075906KB5075912KB5075941KB5075942KB5075943KB5077179KB5077181KB5077212
Windows Subsystem for Linux Elevation of Privilege Vulnerability
CVE-2026-21243 ↗2026-02-10Windows Server 2019Important1%KB5075897KB5075899
and 4 moreKB5075904KB5075906KB5075942KB5075943
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
CVE-2026-21244 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant1%KB5075897KB5075899
and 10 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075999KB5077179KB5077181KB5077212
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-21245 ↗2026-02-10Windows Server 2025 (Server Core installation)Important0%KB5075899KB5075942
and 3 moreKB5077179KB5077181KB5077212
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-21246 ↗2026-02-10Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5075897KB5075899
and 11 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077181KB5077212
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2026-21247 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant1%KB5075897KB5075899
and 10 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075999KB5077179KB5077181KB5077212
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-21248 ↗2026-02-10Windows 10 Version 1809 for x64-based SystemsImportant1%KB5075897KB5075899
and 10 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075999KB5077179KB5077181KB5077212
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-21249 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant11%KB5075897KB5075899
and 11 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075999KB5077179KB5077181KB5077212
Windows NTLM Spoofing Vulnerability
CVE-2026-21250 ↗2026-02-10Windows Server 2025 (Server Core installation)Important1%KB5075897KB5075899
and 4 moreKB5075942KB5077179KB5077181KB5077212
Windows HTTP.sys Elevation of Privilege Vulnerability
CVE-2026-21251 ↗2026-02-10Windows Server 2019Important0%KB5075897KB5075899
and 5 moreKB5075904KB5075906KB5075942KB5075943KB5075999
Cluster Client Failover (CCF) Elevation of Privilege Vulnerability
CVE-2026-21253 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant1%More likelyKB5075897KB5075899
and 12 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077179KB5077181KB5077212
Mailslot File System Elevation of Privilege Vulnerability
CVE-2026-21255 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5075897KB5075899
and 10 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075999KB5077179KB5077181KB5077212
Windows Hyper-V Security Feature Bypass Vulnerability
CVE-2026-21256 ↗2026-02-10Microsoft Visual Studio 2022 version 17.14Important1%GitHub Copilot and Visual Studio Remote Code Execution Vulnerability
CVE-2026-21257 ↗2026-02-10Microsoft Visual Studio 2022 version 17.14Important1%GitHub Copilot and Visual Studio Elevation of Privilege Vulnerability
CVE-2026-21258 ↗2026-02-10Office Online ServerImportant1%KB5002835KB5002837Microsoft Excel Information Disclosure Vulnerability
CVE-2026-21259 ↗2026-02-10Office Online ServerImportant1%KB5002835KB5002837Microsoft Excel Elevation of Privilege Vulnerability
CVE-2026-21260 ↗2026-02-10Microsoft SharePoint Enterprise Server 2016Important1%KB5002833KB5002834
and 4 moreKB5002836KB5002839KB5002840KB5002841
Microsoft Outlook Spoofing Vulnerability
CVE-2026-21261 ↗2026-02-10Office Online ServerImportant1%KB5002835KB5002837Microsoft Excel Information Disclosure Vulnerability
CVE-2026-21508 ↗2026-02-10Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5075897KB5075899
and 12 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077179KB5077181KB5077212
Windows Storage Elevation of Privilege Vulnerability
CVE-2026-21511 ↗2026-02-10Microsoft SharePoint Enterprise Server 2016Important3%More likelyKB5002833KB5002834
and 4 moreKB5002836KB5002839KB5002840KB5002841
Microsoft Outlook Spoofing Vulnerability
CVE-2026-21512 ↗2026-02-10Azure DevOps Server 2022Important1%Azure DevOps Server Cross-Site Scripting Vulnerability
CVE-2026-21516 ↗2026-02-10GitHub Copilot Plugin for JetBrains IDEsImportant1%GitHub Copilot for Jetbrains Remote Code Execution Vulnerability
CVE-2026-21517 ↗2026-02-10Windows App for MacImportant0%Windows App for Mac Installer Elevation of Privilege Vulnerability
CVE-2026-21518 ↗2026-02-10Visual Studio CodeImportant1%GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-21523 ↗2026-02-10Microsoft Visual Studio Code CoPilot Chat ExtensionImportant1%GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability
CVE-2026-21527 ↗2026-02-10Microsoft Exchange Server Subscription Edition RTMImportant8%KB5074992KB5074993
and 2 moreKB5074994KB5074995
Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-21528 ↗2026-02-10Azure IoT ExplorerImportant1%Azure IoT Explorer Information Disclosure Vulnerability
CVE-2026-21529 ↗2026-02-10Azure HDInsightImportant1%Azure HDInsight Spoofing Vulnerability
CVE-2026-21531 ↗2026-02-10Azure AI Language AuthoringImportant2%Azure SDK for Python Remote Code Execution Vulnerability
CVE-2026-21537 ↗2026-02-10Microsoft Defender for Endpoint for LinuxImportant1%Microsoft Defender for Endpoint Linux Extension Remote Code Execution Vulnerability
CVE-2026-21863 ↗2026-02-26azl3 valkey 8.0.6-1 on Azure Linux 3.0ImportantOut-of-bandMalformed Valkey Cluster bus message can lead to Remote DoS
CVE-2026-23066 ↗2026-03-15cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandrxrpc: Fix recvmsg() unconditional requeue
CVE-2026-23068 ↗2026-03-15cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandspi: spi-sprd-adi: Fix double free in probe error path
CVE-2026-23191 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandALSA: aloop: Fix racy access at PCM trigger
CVE-2026-23204 ↗2026-03-21cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandnet/sched: cls_u32: use skb_header_pointer_careful()
CVE-2026-23208 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandALSA: usb-audio: Prevent excessive number of frames
CVE-2026-23213 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/amd/pm: Disable MMIO access during SMU Mode 1 reset
CVE-2026-23214 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandbtrfs: reject new transactions if the fs is fully read-only
CVE-2026-23215 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandx86/vmware: Fix hypercall clobbers
CVE-2026-23216 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandscsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count()
CVE-2026-23221 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandbus: fsl-mc: fix use-after-free in driver_override_show()
CVE-2026-23226 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandksmbd: add chann_lock to protect ksmbd_chann_list xarray
CVE-2026-23227 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/exynos: vidi: use ctx->lock to protect struct vidi_context member variables related to memory alloc/free
CVE-2026-23230 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandsmb: client: split cached_fid bitfields to avoid shared-byte RMW races
CVE-2026-2492 ↗2026-02-23azl3 tensorflow 2.16.1-10 on Azure Linux 3.0ImportantOut-of-bandTensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
CVE-2026-26960 ↗2026-02-22azl3 tar 1.35-2 on Azure Linux 3.0ImportantOut-of-bandnode-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction
CVE-2026-27141 ↗2026-03-05cbl2 azcopy 10.25.1-6 on CBL Mariner 2.0ImportantOut-of-bandSending certain HTTP/2 frames can cause a server to panic in golang.org/x/net
CVE-2026-27623 ↗2026-03-25azl3 valkey 8.0.7-1 on Azure Linux 3.0ImportantOut-of-bandValkey has Pre-Authentication DOS from malformed RESP request
CVE-2026-27965 ↗2026-02-27cbl2 vitess 17.0.7-14 on CBL Mariner 2.0ImportantOut-of-bandVitess users with backup storage access can gain unauthorized access to production deployment environments
CVE-2026-28364 ↗2026-02-28azl3 ocaml 5.1.1-1 on Azure Linux 3.0ImportantOut-of-bandIn OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.
CVE-2025-61143 ↗2026-02-26azl3 libtiff 4.6.0-11 on Azure Linux 3.0ModerateOut-of-bandlibtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.
CVE-2025-71202 ↗2026-03-19cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandiommu/sva: invalidate stale IOTLB entries for kernel address space
CVE-2025-71227 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mac80211: don't WARN for connections on invalid channels
CVE-2025-71230 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandhfs: ensure sb->s_fs_info is always cleaned up
CVE-2025-71232 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: qla2xxx: Free sp in error path to fix system crash
CVE-2025-71235 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: qla2xxx: Delay module unload while fabric scan in progress
CVE-2025-71237 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandnilfs2: Fix potential block overflow that cause system hang
CVE-2026-0391 ↗2026-02-05Microsoft Edge (Chromium-based)ModerateOut-of-band1%Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2026-1979 ↗2026-02-21azl3 nghttp2 1.61.0-2 on Azure Linux 3.0ModerateOut-of-bandmruby JMPNOT-to-JMPIF Optimization vm.c mrb_vm_exec use after free
CVE-2026-2243 ↗2026-02-23azl3 qemu 8.2.0-27 on Azure Linux 3.0ModerateOut-of-bandQemu-kvm: heap buffer out-of-bounds read in vmdk compressed grain parsing
CVE-2026-23069 ↗2026-03-15cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandvsock/virtio: fix potential underflow in virtio_transport_get_credit()
CVE-2026-23086 ↗2026-03-19cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandvsock/virtio: cap TX credit to local buffer size
CVE-2026-23088 ↗2026-03-19cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandtracing: Fix crash on synthetic stacktrace field usage
CVE-2026-23100 ↗2026-03-22cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandmm/hugetlb: fix hugetlb_pmd_shared()
CVE-2026-23110 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandscsi: core: Wake up the error handler when final completions race against each other
CVE-2026-23113 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandio_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop
CVE-2026-23118 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandrxrpc: Fix data-race warning and potential load/store tearing
CVE-2026-23126 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandnetdevsim: fix a race issue related to the operation on bpf_bound_progs list
CVE-2026-23137 ↗2026-03-19cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandof: unittest: Fix memory leak in unittest_data_add()
CVE-2026-23138 ↗2026-03-19cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandtracing: Add recursion protection in kernel stack trace recording
CVE-2026-23141 ↗2026-03-19cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandbtrfs: send: check for inline extents in range_is_hole_in_parent()
CVE-2026-23154 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: fix segmentation of forwarding fraglist GRO
CVE-2026-23157 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandbtrfs: do not strictly require dirty metadata threshold for metadata writepages
CVE-2026-23169 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandmptcp: fix race in mptcp_pm_nl_flush_addrs_doit()
CVE-2026-23171 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandbonding: fix use-after-free due to enslave fail after slave array update
CVE-2026-23207 ↗2026-03-20azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: tegra210-quad: Protect curr_xfer check in IRQ handler
CVE-2026-23212 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandbonding: annotate data-races around slave->last_rx
CVE-2026-23217 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandriscv: trace: fix snapshot deadlock with sbi ecall
CVE-2026-23220 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error paths
CVE-2026-23222 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly
CVE-2026-23223 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandxfs: fix UAF in xchk_btree_check_block_owner
CVE-2026-23224 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-banderofs: fix UAF issue for file-backed mounts w/ directio option
CVE-2026-23225 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandsched/mmcid: Don't assume CID is CPU owned on mode switch
CVE-2026-23228 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandsmb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection()
CVE-2026-23229 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: virtio - Add spinlock protection with virtqueue notification
CVE-2026-24051 ↗2026-04-29azl3 ignition-flatcar 2.22.0-1 on Azure Linux 3.0ModerateOut-of-bandOpenTelemetry-Go Affected by Arbitrary Code Execution via PATH Hijacking
CVE-2026-2443 ↗2026-02-21azl3 libsoup 3.4.4-11 on Azure Linux 3.0ModerateOut-of-bandLibsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure
CVE-2026-25541 ↗2026-03-04azl3 trident 0.21.0-1 on Azure Linux 3.0ModerateOut-of-bandBytes is vulnerable to integer overflow in BytesMut::reserve
CVE-2026-27199 ↗2026-02-25azl3 python-werkzeug 3.0.3-2 on Azure Linux 3.0ModerateOut-of-bandWerkzeug safe_join() allows Windows special device names
CVE-2026-2739 ↗2026-02-25cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ModerateOut-of-bandThis affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely.
CVE-2026-27571 ↗2026-02-27cbl2 telegraf 1.29.4-18 on CBL Mariner 2.0ModerateOut-of-bandnats-server websockets are vulnerable to pre-auth memory DoS
CVE-2026-28417 ↗2026-03-01azl3 vim 9.1.1616-1 on Azure Linux 3.0ModerateOut-of-bandVim has OS Command Injection in netrw
CVE-2026-28418 ↗2026-03-01azl3 vim 9.1.1616-1 on Azure Linux 3.0ModerateOut-of-bandVim has Heap-based Buffer Overflow in Emacs tags parsing
CVE-2026-28419 ↗2026-03-01azl3 vim 9.1.1616-1 on Azure Linux 3.0ModerateOut-of-bandVim has Heap-based Buffer Underflow in Emacs tags parsing
CVE-2026-28420 ↗2026-03-01azl3 vim 9.1.1616-1 on Azure Linux 3.0ModerateOut-of-bandVim has Heap-based Buffer Overflow and OOB Read in :terminal
CVE-2026-28421 ↗2026-03-01azl3 vim 9.1.1616-1 on Azure Linux 3.0ModerateOut-of-bandVim has a heap-buffer-overflow and a segmentation fault
CVE-2025-69873 ↗2026-02-27cbl2 python-tensorboard 2.11.0-3 on CBL Mariner 2.0LowOut-of-bandajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., "^(a|a)*$") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with $data: true for dynamic schema validation.
CVE-2026-0102 ↗2026-02-17Microsoft Edge (Chromium-based)LowOut-of-band0%Microsoft Edge (Chromium-based) Defense in Depth Vulnerability
CVE-2026-1703 ↗2026-02-21azl3 python-virtualenv 20.36.1-1 on Azure Linux 3.0LowOut-of-bandLimited path traversal when installing wheel archives
CVE-2026-21620 ↗2026-02-25azl3 erlang 26.2.5.15-1 on Azure Linux 3.0LowOut-of-bandTFTP Path Traversal
CVE-2026-27171 ↗2026-02-21azl3 zlib 1.3.1-1 on Azure Linux 3.0LowOut-of-bandzlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
CVE-2026-28422 ↗2026-03-01azl3 vim 9.1.1616-1 on Azure Linux 3.0LowOut-of-bandVim has stack-buffer-overflow in build_stl_str_hl()
CVE-2025-11563 ↗2026-02-26azl3 mysql 8.0.45-1 on Azure Linux 3.0N/AOut-of-bandwcurl path traversal with percent-encoded slashes
CVE-2025-61145 ↗2026-02-26azl3 libtiff 4.6.0-11 on Azure Linux 3.0N/AOut-of-bandlibtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.
CVE-2026-1861 ↗2026-02-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-1861 Heap buffer overflow in libvpx
CVE-2026-1862 ↗2026-02-06Microsoft Edge (Chromium-based)N/AOut-of-band1%Chromium: CVE-2026-1862 Type Confusion in V8
CVE-2026-2313 ↗2026-02-17Microsoft Edge (Chromium-based)N/AOut-of-band4%Chromium: CVE-2026-2313 Use after free in CSS
CVE-2026-2314 ↗2026-02-18Microsoft Edge (Chromium-based)N/AOut-of-band4%Chromium: CVE-2026-2314 Heap buffer overflow in Codecs
CVE-2026-2316 ↗2026-02-18Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-2316 Insufficient policy enforcement in Frames
CVE-2026-2317 ↗2026-02-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-2317 Inappropriate implementation in Animation
CVE-2026-2318 ↗2026-02-17Microsoft Edge (Chromium-based)N/AOut-of-band0%CVE-2026-2318
CVE-2026-2319 ↗2026-02-18Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-2319 Race in DevTools
CVE-2026-2320 ↗2026-02-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-2320 Inappropriate implementation in File input
CVE-2026-2322 ↗2026-02-18Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-2322 Heap buffer overflow in Codecs
CVE-2026-2323 ↗2026-02-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-2323 Inappropriate implementation in Downloads
CVE-2026-2441 ↗2026-02-17Microsoft Edge (Chromium-based)N/AOut-of-band22%CISA KEVVulnCheckENISAChromium: CVE-2026-2441 Use after free in CSS
CVE-2026-2648 ↗2026-02-20Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-2648 Heap buffer overflow in PDFium
CVE-2026-2649 ↗2026-02-20Microsoft Edge (Chromium-based)N/AOut-of-band1%Chromium: CVE-2026-2649 Integer overflow in V8
CVE-2026-2650 ↗2026-02-20Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-2650 Heap buffer overflow in Media
CVE-2026-3061 ↗2026-02-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3061 Out of bounds read in Media
CVE-2026-3062 ↗2026-02-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3062 Out of bounds read and write in Tint
CVE-2026-3063 ↗2026-02-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3063 Inappropriate implementation in DevTools
#

January 2026

Patch Tuesday January 13, 2026139 CVEs plus 171 Azure Linux package advisories · 17 critical · 2 exploitation detected · 3 in KEV310 CVEs · 30 critical · 2 exploitation detected · 3 in KEV · includes 171 Azure Linux package advisories
Risk matrix, January 2026
14 of these counts use a severity derived from CVSS because Microsoft assigned none.
14 of these counts use a severity derived from CVSS because Microsoft assigned none.
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-20805 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant5%Exploitation detectedCISA KEVVulnCheckENISAKB5073379KB5073450
and 8 moreKB5073455KB5073457KB5073696KB5073698KB5073722KB5073723KB5073724KB5074109
Desktop Window Manager Information Disclosure Vulnerability
CVE-2026-21509 ↗2026-01-26Microsoft Office 2019 for 32-bit editionsImportantOut-of-band72%Exploitation detectedCISA KEVVulnCheckENISAKB5002713Microsoft Office Security Feature Bypass Vulnerability
CVE-2025-68789 ↗2026-01-15azl3 kernel 6.6.119.3-1 on Azure Linux 3.0CriticalOut-of-bandhwmon: (ibmpex) fix use-after-free in high/low store
CVE-2025-68814 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0CriticalOut-of-bandio_uring: fix filename leak in __io_openat_prep()
CVE-2025-68819 ↗2026-01-15azl3 kernel 6.6.119.3-1 on Azure Linux 3.0CriticalOut-of-bandmedia: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg()
CVE-2025-68822 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0CriticalOut-of-bandInput: alps - fix use-after-free bugs caused by dev3_register_work
CVE-2025-68823 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0CriticalOut-of-bandublk: fix deadlock when reading partition table
CVE-2025-71064 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0CriticalOut-of-bandnet: hns3: using the num_tqps in the vf driver to apply for resources
CVE-2025-71066 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0CriticalOut-of-bandnet/sched: ets: Always remove class from active list before deleting in ets_qdisc_change
CVE-2025-71072 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0CriticalOut-of-bandshmem: fix recovery on rename failures
CVE-2025-71073 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0CriticalOut-of-bandInput: lkkbd - disable pending work before freeing device
CVE-2025-71074 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0CriticalOut-of-bandfunctionfs: fix the open/removal races
CVE-2025-71098 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0CriticalOut-of-bandip6_gre: make ip6gre_header() robust
CVE-2026-20822 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2026-20854 ↗2026-01-13Windows Server 2025 (Server Core installation)Critical1%KB5073379KB5074109Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
CVE-2026-20876 ↗2026-01-13Windows Server 2025 (Server Core installation)Critical1%KB5073379KB5073450
and 2 moreKB5073455KB5074109
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
CVE-2026-20944 ↗2026-01-13Microsoft 365 Apps for Enterprise for 32-bit SystemsCritical0%Microsoft Word Remote Code Execution Vulnerability
CVE-2026-20952 ↗2026-01-13Microsoft Office 2019 for 64-bit editionsCritical0%KB5002826Microsoft Office Remote Code Execution Vulnerability
CVE-2026-20953 ↗2026-01-13Microsoft Office 2019 for 64-bit editionsCritical1%KB5002826Microsoft Office Remote Code Execution Vulnerability
CVE-2026-20955 ↗2026-01-13Office Online ServerCritical1%KB5002824Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-20957 ↗2026-01-13Office Online ServerCritical0%KB5002824KB5002831Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-21227 ↗2026-01-22Azure Logic AppsCriticalOut-of-band0%Azure Logic Apps Elevation of Privilege Vulnerability
CVE-2026-21264 ↗2026-01-22Microsoft AccountCriticalOut-of-band0%Microsoft Account Spoofing Vulnerability
CVE-2026-21520 ↗2026-01-22Microsoft Copilot StudioCriticalOut-of-band1%Copilot Studio Information Disclosure Vulnerability
CVE-2026-21521 ↗2026-01-22Microsoft 365 Word CopilotCriticalOut-of-band1%Word Copilot Information Disclosure Vulnerability
CVE-2026-21524 ↗2026-01-22Azure Data ExplorerCriticalOut-of-band1%Azure Data Explorer Information Disclosure Vulnerability
CVE-2026-22184 ↗2026-01-09azl3 ceph 18.2.2-12 on Azure Linux 3.0CriticalOut-of-bandzlib <= 1.3.1.2 untgz Global Buffer Overflow in TGZfname()
CVE-2026-24304 ↗2026-01-22Azure Resource ManagerCriticalOut-of-band1%Azure Resource Manager Elevation of Privilege Vulnerability
CVE-2026-24305 ↗2026-01-22Microsoft Entra IDCriticalOut-of-band0%Azure Entra ID Elevation of Privilege Vulnerability
CVE-2026-24306 ↗2026-01-22Azure Front DoorCriticalOut-of-band1%Azure Front Door Elevation of Privilege Vulnerability
CVE-2026-24307 ↗2026-01-22Microsoft 365 CopilotCriticalOut-of-band1%M365 Copilot Information Disclosure Vulnerability
CVE-2026-24821 ↗2026-03-05cbl2 ceph 16.2.10-11 on CBL Mariner 2.0CriticalOut-of-bandA heap-based buffer over-read that might affect a system that compiles untrusted Lua code in turanszkij/WickedEngine.
CVE-2023-31096 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
MITRE: CVE-2023-31096 Windows Agere Soft Modem Driver Elevation of Privilege Vulnerability
CVE-2024-55414 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Motorola Soft Modem Driver Elevation of Privilege Vulnerability
CVE-2025-15444 ↗2026-01-09azl3 libsodium 1.0.19-1 on Azure Linux 3.0ImportantOut-of-bandCrypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium
CVE-2025-62291 ↗2026-01-18azl3 strongswan 5.9.14-7 on Azure Linux 3.0ImportantOut-of-bandIn the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.
CVE-2025-68753 ↗2026-01-06azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandALSA: firewire-motu: add bounds check in put_user loop for DSP events
CVE-2025-68756 ↗2026-01-06azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandblock: Use RCU in blk_mq_[un]quiesce_tagset() instead of set->tag_list_lock
CVE-2025-68759 ↗2026-01-06azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: rtl818x: Fix potential memory leaks in rtl8180_init_rx_ring()
CVE-2025-68766 ↗2026-01-06azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandirqchip/mchp-eic: Fix error code in mchp_eic_domain_alloc()
CVE-2025-68771 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandocfs2: fix kernel BUG in ocfs2_find_victim_chain
CVE-2025-68781 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandusb: phy: fsl-usb: Fix use-after-free in delayed work during device removal
CVE-2025-68782 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandscsi: target: Reset t_task_cdb pointer in error case
CVE-2025-68785 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandnet: openvswitch: fix middle attribute validation in push_nsh() action
CVE-2025-68786 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandksmbd: skip lock-range check on equal size to avoid size==0 underflow
CVE-2025-68795 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandethtool: Avoid overflowing userspace buffer on stats query
CVE-2025-68801 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandmlxsw: spectrum_router: Fix neighbour use-after-free
CVE-2025-68808 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandmedia: vidtv: initialize local pointers upon transfer of memory ownership
CVE-2025-68817 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandksmbd: fix use-after-free in ksmbd_tree_connect_put under concurrency
CVE-2025-69194 ↗2026-01-10azl3 wget 2.1.0-6 on Azure Linux 3.0ImportantOut-of-bandWget2: arbitrary file write via metalink path traversal in gnu wget2
CVE-2025-69195 ↗2026-01-10azl3 wget 2.1.0-6 on Azure Linux 3.0ImportantOut-of-bandWget2: gnu wget2: memory corruption and crash via filename sanitization logic with attacker-controlled urls
CVE-2025-71067 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandntfs: set dummy blocksize to read boot_block when mounting
CVE-2025-71068 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandsvcrdma: bound check rq_pages index in inline path
CVE-2025-71075 ↗2026-01-15azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandscsi: aic94xx: fix use-after-free in device removal path
CVE-2025-71081 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandASoC: stm32: sai: fix OF node leak on probe
CVE-2025-71082 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandBluetooth: btusb: revert use of devm_kzalloc in btusb
CVE-2025-71087 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandiavf: fix off-by-one issues in iavf_config_rss_reg()
CVE-2025-71089 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandiommu: disable SVA when CONFIG_X86 is set
CVE-2025-71101 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandplatform/x86: hp-bioscfg: Fix out-of-bounds array access in ACPI package parsing
CVE-2025-71105 ↗2026-01-16azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandf2fs: use global inline_xattr_slab instead of per-sb slab cache
CVE-2025-71109 ↗2026-01-16azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandMIPS: ftrace: Fix memory corruption when kernel is located beyond 32 bits
CVE-2025-71114 ↗2026-01-16azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandvia_wdt: fix critical boot hang due to unnamed resource allocation
CVE-2025-71122 ↗2026-01-16azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandiommufd/selftest: Check for overflow in IOMMU_TEST_OP_ADD_RESERVED
CVE-2025-71130 ↗2026-01-16azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-banddrm/i915/gem: Zero-initialize the eb.vma array in i915_gem_do_execbuffer
CVE-2025-71133 ↗2026-01-16azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandRDMA/irdma: avoid invalid read in irdma_net_event
CVE-2025-71143 ↗2026-01-16azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandclk: samsung: exynos-clkout: Assign .num before accessing .hws
CVE-2025-71152 ↗2026-02-28cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandnet: dsa: properly keep track of conduit reference
CVE-2025-71162 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-banddmaengine: tegra-adma: Fix use-after-free
CVE-2026-0386 ↗2026-01-13Windows Server 2019Important1%KB5073379KB5073450
and 9 moreKB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723
Windows Deployment Services Remote Code Execution Vulnerability
CVE-2026-0719 ↗2026-01-11azl3 libsoup 3.4.4-11 on Azure Linux 3.0ImportantOut-of-bandLibsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authentication
CVE-2026-0897 ↗2026-01-16azl3 keras 3.3.3-5 on Azure Linux 3.0ImportantOut-of-bandDenial of Service in Keras via Excessive Memory Allocation in HDF5 Metadata
CVE-2026-20803 ↗2026-01-13Microsoft SQL Server 2022 for x64-based Systems (GDR)Important1%KB5072936KB5073031
and 1 moreKB5073177
Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-20804 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Windows Hello Tampering Vulnerability
CVE-2026-20808 ↗2026-01-13Windows Server 2025 (Server Core installation)Important0%KB5073379KB5073450
and 1 moreKB5074109
Windows File Explorer Elevation of Privilege Vulnerability
CVE-2026-20809 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 7 moreKB5073455KB5073457KB5073696KB5073722KB5073723KB5073724KB5074109
Windows Kernel Memory Elevation of Privilege Vulnerability
CVE-2026-20810 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073723KB5073724Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-20811 ↗2026-01-13Windows Server 2022Important0%KB5073379KB5073450
and 3 moreKB5073455KB5073457KB5074109
Win32k Elevation of Privilege Vulnerability
CVE-2026-20812 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
LDAP Tampering Vulnerability
CVE-2026-20814 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2026-20815 ↗2026-01-13Windows Server 2025 (Server Core installation)Important0%KB5073379KB5074109Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
CVE-2026-20816 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Installer Elevation of Privilege Vulnerability
CVE-2026-20817 ↗2026-01-13Windows Server 2022Important5%More likelyKB5073379KB5073450
and 4 moreKB5073455KB5073457KB5073724KB5074109
Windows Error Reporting Service Elevation of Privilege Vulnerability
CVE-2026-20818 ↗2026-01-13Windows Server 2019Important1%KB5073379KB5073450
and 3 moreKB5073457KB5073722KB5073723
Windows Kernel Information Disclosure Vulnerability
CVE-2026-20819 ↗2026-01-13Windows 11 Version 25H2 for x64-based SystemsImportant1%KB5073455KB5074109Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability
CVE-2026-20820 ↗2026-01-13Windows Server 2022 (Server Core installation)Important3%More likelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2026-20821 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Remote Procedure Call Information Disclosure Vulnerability
CVE-2026-20823 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Windows File Explorer Information Disclosure Vulnerability
CVE-2026-20824 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 8 moreKB5073455KB5073457KB5073696KB5073698KB5073722KB5073723KB5073724KB5074109
Windows Remote Assistance Security Feature Bypass Vulnerability
CVE-2026-20825 ↗2026-01-13Windows 10 Version 1809 for x64-based SystemsImportant1%KB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Hyper-V Information Disclosure Vulnerability
CVE-2026-20826 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure Vulnerability
CVE-2026-20827 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure Vulnerability
CVE-2026-20828 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows rndismp6.sys Information Disclosure Vulnerability
CVE-2026-20829 ↗2026-01-13Windows 10 Version 1809 for x64-based SystemsImportant1%KB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
TPM Trustlet Information Disclosure Vulnerability
CVE-2026-20830 ↗2026-01-13Windows Server 2025 (Server Core installation)Important0%KB5073379Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
CVE-2026-20831 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-20832 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability
CVE-2026-20833 ↗2026-01-13Windows Server 2019Important0%KB5073379KB5073450
and 9 moreKB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723
Windows Kerberos Information Disclosure Vulnerability
CVE-2026-20834 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Spoofing Vulnerability
CVE-2026-20835 ↗2026-01-13Windows Server 2025 (Server Core installation)Important1%KB5073379KB5073450
and 1 moreKB5074109
Capability Access Management Service (camsvc) Information Disclosure Vulnerability
CVE-2026-20836 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2026-20837 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Media Remote Code Execution Vulnerability
CVE-2026-20838 ↗2026-01-13Windows Server 2022Important1%KB5073379KB5073450
and 3 moreKB5073455KB5073457KB5074109
Windows Kernel Information Disclosure Vulnerability
CVE-2026-20839 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 10 moreKB5073455KB5073457KB5073695KB5073696KB5073698KB5073699KB5073722KB5073723KB5073724KB5074109
Windows Client-Side Caching (CSC) Service Information Disclosure Vulnerability
CVE-2026-20840 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant4%More likelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-20842 ↗2026-01-13Windows Server 2022Important0%KB5073379KB5073450
and 4 moreKB5073455KB5073457KB5073724KB5074109
Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-20843 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant3%More likelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
CVE-2026-20844 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Windows Clipboard Server Elevation of Privilege Vulnerability
CVE-2026-20847 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 10 moreKB5073455KB5073457KB5073695KB5073696KB5073698KB5073699KB5073722KB5073723KB5073724KB5074109
Microsoft Windows File Explorer Spoofing Vulnerability
CVE-2026-20848 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 8 moreKB5073455KB5073457KB5073696KB5073698KB5073722KB5073723KB5073724KB5074109
Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-20849 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Kerberos Elevation of Privilege Vulnerability
CVE-2026-20851 ↗2026-01-13Windows Server 2025 (Server Core installation)Important1%KB5073379KB5074109Capability Access Management Service (camsvc) Information Disclosure Vulnerability
CVE-2026-20852 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Windows Hello Tampering Vulnerability
CVE-2026-20853 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073455KB5073722
and 3 moreKB5073723KB5073724KB5074109
Windows WalletService Elevation of Privilege Vulnerability
CVE-2026-20856 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 8 moreKB5073455KB5073457KB5073696KB5073698KB5073722KB5073723KB5073724KB5074109
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
CVE-2026-20857 ↗2026-01-13Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-20858 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20859 ↗2026-01-13Windows Server 2025 (Server Core installation)Important0%KB5073379KB5074109Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2026-20860 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant8%More likelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-20861 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20862 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Information Disclosure Vulnerability
CVE-2026-20863 ↗2026-01-13Windows Server 2022Important0%KB5073379KB5073450
and 3 moreKB5073455KB5073457KB5074109
Win32k Elevation of Privilege Vulnerability
CVE-2026-20864 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
CVE-2026-20865 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20866 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20867 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20868 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2026-20869 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability
CVE-2026-20870 ↗2026-01-13Windows Server 2025 (Server Core installation)Important0%KB5073379KB5074109Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
CVE-2026-20871 ↗2026-01-13Windows Server 2022Important4%More likelyKB5073379KB5073450
and 4 moreKB5073455KB5073457KB5073724KB5074109
Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-20872 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant19%KB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
NTLM Hash Disclosure Spoofing Vulnerability
CVE-2026-20873 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20874 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20875 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant2%KB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2026-20877 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20918 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20919 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 8 moreKB5073455KB5073457KB5073696KB5073698KB5073722KB5073723KB5073724KB5074109
Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-20920 ↗2026-01-13Windows Server 2022Important0%KB5073450KB5073455
and 1 moreKB5073457
Win32k Elevation of Privilege Vulnerability
CVE-2026-20921 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-20922 ↗2026-01-13Windows Server 2022 (Server Core installation)Important1%More likelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-20923 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20924 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20925 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant17%KB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
NTLM Hash Disclosure Spoofing Vulnerability
CVE-2026-20926 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 8 moreKB5073455KB5073457KB5073696KB5073698KB5073722KB5073723KB5073724KB5074109
Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-20927 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows SMB Server Denial of Service Vulnerability
CVE-2026-20929 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073450KB5073455
and 10 moreKB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724
Windows HTTP.sys Elevation of Privilege Vulnerability
CVE-2026-20931 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%VulnCheckKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-20932 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Windows File Explorer Information Disclosure Vulnerability
CVE-2026-20934 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 8 moreKB5073455KB5073457KB5073696KB5073698KB5073722KB5073723KB5073724KB5074109
Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-20935 ↗2026-01-13Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5073455KB5074109Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability
CVE-2026-20936 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows NDIS Information Disclosure Vulnerability
CVE-2026-20937 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Windows File Explorer Information Disclosure Vulnerability
CVE-2026-20938 ↗2026-01-13Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5073455KB5074109Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
CVE-2026-20939 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Windows File Explorer Information Disclosure Vulnerability
CVE-2026-20940 ↗2026-01-13Windows 10 Version 22H2 for 32-bit SystemsImportant0%KB5073455KB5073457
and 9 moreKB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-20941 ↗2026-01-13Windows Server 2025 (Server Core installation)Important0%KB5073379KB5074109Host Process for Windows Tasks Elevation of Privilege Vulnerability
CVE-2026-20943 ↗2026-01-13Microsoft SharePoint Server 2019Important1%KB5002822KB5002825
and 2 moreKB5002826KB5002828
Microsoft Office Click-To-Run Remote Code Execution Vulnerability
CVE-2026-20946 ↗2026-01-13Microsoft Office 2019 for 32-bit editionsImportant1%KB5002831Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-20947 ↗2026-01-13Microsoft SharePoint Enterprise Server 2016Important13%KB5002822KB5002823
and 3 moreKB5002825KB5002827KB5002828
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-20948 ↗2026-01-13Microsoft SharePoint Enterprise Server 2016Important0%KB5002823KB5002825
and 3 moreKB5002827KB5002828KB5002829
Microsoft Word Remote Code Execution Vulnerability
CVE-2026-20949 ↗2026-01-13Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft Excel Security Feature Bypass Vulnerability
CVE-2026-20950 ↗2026-01-13Office Online ServerImportant0%KB5002824KB5002831Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-20951 ↗2026-01-13Microsoft SharePoint Enterprise Server 2016Important1%KB5002822KB5002825
and 1 moreKB5002828
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-20956 ↗2026-01-13Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-20958 ↗2026-01-13Microsoft SharePoint Enterprise Server 2016Important0%KB5002822KB5002825
and 1 moreKB5002828
Microsoft SharePoint Information Disclosure Vulnerability
CVE-2026-20959 ↗2026-01-13Microsoft SharePoint Enterprise Server 2016Important6%KB5002822KB5002825
and 1 moreKB5002828
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-20960 ↗2026-01-16Microsoft Power Apps Desktop ClientImportantOut-of-band0%PowerApps Desktop Client Remote Code Execution Vulnerability
CVE-2026-20962 ↗2026-01-13Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Dynamic Root of Trust for Measurement (DRTM) Information Disclosure Vulnerability
CVE-2026-20963 ↗2026-01-13Microsoft SharePoint Enterprise Server 2016Important23%CISA KEVVulnCheckENISAKB5002822KB5002825
and 1 moreKB5002828
1 mentionsMicrosoft SharePoint Remote Code Execution Vulnerability
CVE-2026-20965 ↗2026-01-13Windows Admin Center in Azure PortalImportant0%Windows Admin Center Elevation of Privilege Vulnerability
CVE-2026-21219 ↗2026-01-13Windows SDKImportant0%Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
CVE-2026-21221 ↗2026-01-13Windows Server 2025 (Server Core installation)Important0%KB5073379KB5074109Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
CVE-2026-21224 ↗2026-01-13Azure Connected Machine AgentImportant0%Azure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2026-21226 ↗2026-01-13Azure Core shared client library for PythonImportant1%Azure Core shared client library for Python Remote Code Execution Vulnerability
CVE-2026-21265 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450
and 8 moreKB5073455KB5073457KB5073696KB5073698KB5073722KB5073723KB5073724KB5074109
Secure Boot Certificate Expiration Security Feature Bypass Vulnerability
CVE-2026-21441 ↗2026-01-09azl3 tensorflow 2.16.1-9 on Azure Linux 3.0ImportantOut-of-bandurllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
CVE-2026-22185 ↗2026-01-09azl3 openldap 2.6.7-2 on Azure Linux 3.0ImportantOut-of-bandOpenLDAP <= 2.6.10 LMDB mdb_load Heap Buffer Underflow in readline()
CVE-2026-22980 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandnfsd: provide locking for v4_end_grace
CVE-2026-22984 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandlibceph: prevent potential out-of-bounds reads in handle_auth_done()
CVE-2026-23490 ↗2026-01-21azl3 python-pyasn1 0.4.8-1 on Azure Linux 3.0ImportantOut-of-bandpyasn1 has a DoS vulnerability in decoder
CVE-2025-13034 ↗2026-01-09cbl2 curl 8.8.0-7 on CBL Mariner 2.0ModerateOut-of-bandNo QUIC certificate pinning with GnuTLS
CVE-2025-14017 ↗2026-01-09azl3 curl 8.11.1-4 on Azure Linux 3.0ModerateOut-of-bandbroken TLS options for threaded LDAPS
CVE-2025-14524 ↗2026-01-09azl3 cmake 3.30.3-10 on Azure Linux 3.0ModerateOut-of-bandbearer token leak on cross-protocol redirect
CVE-2025-14819 ↗2026-01-09azl3 curl 8.11.1-4 on Azure Linux 3.0ModerateOut-of-bandOpenSSL partial chain store policy bypass
CVE-2025-15079 ↗2026-01-09cbl2 curl 8.8.0-7 on CBL Mariner 2.0ModerateOut-of-bandlibssh global known_hosts override
CVE-2025-15281 ↗2026-01-21azl3 glibc 2.38-16 on Azure Linux 3.0ModerateOut-of-bandwordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory
CVE-2025-15504 ↗2026-04-11azl3 nodejs24 24.14.1-2 on Azure Linux 3.0ModerateOut-of-bandlief-project LIEF ELF Binary Parser.tcc parse_binary null pointer dereference
CVE-2025-24528 ↗2026-01-21azl3 krb5 1.21.3-2 on Azure Linux 3.0ModerateOut-of-bandIn MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update size to resize() in kdb_log.c. An authenticated attacker can cause an out-of-bounds write and kadmind daemon crash.
CVE-2025-56226 ↗2026-01-21azl3 libsndfile 1.2.2-3 on Azure Linux 3.0ModerateOut-of-bandLibsndfile <=1.2.2 contains a memory leak vulnerability in the mpeg_l3_encoder_init() function within the mpeg_l3_encode.c file.
CVE-2025-68151 ↗2026-01-10azl3 coredns 1.11.4-12 on Azure Linux 3.0ModerateOut-of-bandCoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages
CVE-2025-68276 ↗2026-01-14cbl2 avahi 0.8-4 on CBL Mariner 2.0ModerateOut-of-bandAvahi has a reachable assertion in avahi_wide_area_scan_cache
CVE-2025-68468 ↗2026-01-14cbl2 avahi 0.8-4 on CBL Mariner 2.0ModerateOut-of-bandAvahi has a reachable assertion in lookup_multicast_callback
CVE-2025-68471 ↗2026-01-14cbl2 avahi 0.8-4 on CBL Mariner 2.0ModerateOut-of-bandAvahi has a reachable assertion in lookup_start
CVE-2025-68755 ↗2026-01-06azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandstaging: most: remove broken i2c driver
CVE-2025-68757 ↗2026-01-06azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/vgem-fence: Fix potential deadlock on release
CVE-2025-68758 ↗2026-01-06azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandbacklight: led-bl: Add devlink to supplier LEDs
CVE-2025-68763 ↗2026-01-06azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: starfive - Correctly handle return of sg_nents_for_len
CVE-2025-68764 ↗2026-01-06azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags
CVE-2025-68765 ↗2026-01-06azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandmt76: mt7615: Fix memory leak in mt7615_mcu_wtbl_sta_add()
CVE-2025-68767 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandhfsplus: Verify inode mode when loading from disk
CVE-2025-68768 ↗2026-01-15azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandinet: frags: flush pending skbs in fqdir_pre_exit()
CVE-2025-68769 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix return value of f2fs_recover_fsync_data()
CVE-2025-68772 ↗2026-01-15azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix to avoid updating compression context during writeback
CVE-2025-68773 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandspi: fsl-cpm: Check length parity before switching to 16 bit mode
CVE-2025-68774 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandhfsplus: fix missing hfs_bnode_get() in __hfs_bnode_create
CVE-2025-68775 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandnet/handshake: duplicate handshake cancellations leak socket
CVE-2025-68776 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandnet/hsr: fix NULL pointer dereference in prp_get_untagged_frame()
CVE-2025-68777 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandInput: ti_am335x_tsc - fix off-by-one error in wire_order validation
CVE-2025-68778 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandbtrfs: don't log conflicting inode if it's a dir moved in the current transaction
CVE-2025-68780 ↗2026-01-15azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandsched/deadline: only set free_cpus for online runqueues
CVE-2025-68783 ↗2026-01-15azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandALSA: usb-mixer: us16x08: validate meter packet indices
CVE-2025-68787 ↗2026-01-15azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandnetrom: Fix memory leak in nr_sendmsg()
CVE-2025-68788 ↗2026-01-15azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandfsnotify: do not generate ACCESS/MODIFY events on child for special files
CVE-2025-68794 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandiomap: adjust read range correctly for non-block-aligned positions
CVE-2025-68796 ↗2026-01-15azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix to avoid updating zero-sized extent in extent cache
CVE-2025-68797 ↗2026-01-15azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandchar: applicom: fix NULL pointer dereference in ac_ioctl
CVE-2025-68798 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandperf/x86/amd: Check event before enable to avoid GPF
CVE-2025-68799 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandcaif: fix integer underflow in cffrml_receive()
CVE-2025-68800 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandmlxsw: spectrum_mr: Fix use-after-free when updating multicast route stats
CVE-2025-68803 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNFSD: NFSv4 file creation neglects setting ACL
CVE-2025-68806 ↗2026-01-15azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: fix buffer validation by including null terminator size in EA length
CVE-2025-68809 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandksmbd: vfs: fix race on m_flags in vfs_cache
CVE-2025-68815 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandnet/sched: ets: Remove drr class from the active list if it changes to strict
CVE-2025-68816 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandnet/mlx5: fw_tracer, Validate format string parameters
CVE-2025-68818 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandscsi: Revert "scsi: qla2xxx: Perform lockless command completion in abort path"
CVE-2025-71065 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix to avoid potential deadlock
CVE-2025-71069 ↗2026-01-15azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandf2fs: invalidate dentry cache on failed whiteout creation
CVE-2025-71077 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandtpm: Cap the number of PCR banks
CVE-2025-71078 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandpowerpc/64s/slb: Fix SLB multihit issue during SLB preload
CVE-2025-71079 ↗2026-01-15azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandnet: nfc: fix deadlock between nfc_unregister_device and rfkill_fop_write
CVE-2025-71083 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-banddrm/ttm: Avoid NULL pointer deref for evicted BOs
CVE-2025-71084 ↗2026-01-15azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/cm: Fix leaking the multicast GID table reference
CVE-2025-71088 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandmptcp: fallback earlier on simult connection
CVE-2025-71091 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandteam: fix check for port enabled in team_queue_override_port_prio_changed()
CVE-2025-71093 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bande1000: fix OOB in e1000_tbi_should_accept()
CVE-2025-71095 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandnet: stmmac: fix the crash issue for zero copy XDP_TX action
CVE-2025-71096 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandRDMA/core: Check for the presence of LS_NLA_TYPE_DGID correctly
CVE-2025-71097 ↗2026-01-15azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandipv4: Fix reference count leak when using error routes with nexthop objects
CVE-2025-71102 ↗2026-01-16azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandscs: fix a wrong parameter in __scs_magic
CVE-2025-71107 ↗2026-01-16azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandf2fs: ensure node page reads complete before f2fs_put_super() finishes
CVE-2025-71108 ↗2026-01-16azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandusb: typec: ucsi: Handle incorrect num_connectors capability
CVE-2025-71111 ↗2026-01-16azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandhwmon: (w83791d) Convert macros to functions to avoid TOCTOU
CVE-2025-71112 ↗2026-01-16azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandnet: hns3: add VLAN id validation before using
CVE-2025-71113 ↗2026-01-16azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandcrypto: af_alg - zero initialize memory allocated via sock_kmalloc
CVE-2025-71115 ↗2026-01-16azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandum: init cpu_tasks[] earlier
CVE-2025-71116 ↗2026-01-16azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandlibceph: make decode_pool() more resilient against corrupted osdmaps
CVE-2025-71118 ↗2026-01-16azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandACPICA: Avoid walking the Namespace if start_node is NULL
CVE-2025-71119 ↗2026-01-16azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandpowerpc/kexec: Enable SMT before waking offline CPUs
CVE-2025-71120 ↗2026-01-16azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandSUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf
CVE-2025-71121 ↗2026-01-16azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandparisc: Do not reprogram affinitiy on ASP chip
CVE-2025-71125 ↗2026-01-16azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandtracing: Do not register unsupported perf events
CVE-2025-71127 ↗2026-01-16azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandwifi: mac80211: Discard Beacon frames to non-broadcast address
CVE-2025-71129 ↗2026-01-16azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandLoongArch: BPF: Sign extend kfunc call arguments
CVE-2025-71131 ↗2026-01-16azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandcrypto: seqiv - Do not use req->iv after crypto_aead_encrypt
CVE-2025-71132 ↗2026-01-16azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandsmc91x: fix broken irq-context in PREEMPT_RT
CVE-2025-71136 ↗2026-01-16azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandmedia: adv7842: Avoid possible out-of-bounds array accesses in adv7842_cp_log_status()
CVE-2025-71137 ↗2026-01-16azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandocteontx2-pf: fix "UBSAN: shift-out-of-bounds error"
CVE-2025-71138 ↗2026-01-16azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-banddrm/msm/dpu: Add missing NULL pointer check for pingpong interface
CVE-2025-71147 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandKEYS: trusted: Fix a memory leak in tpm2_load_cmd
CVE-2025-71150 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandksmbd: Fix refcount leak when invalid session is found on session lookup
CVE-2025-71154 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: usb: rtl8150: fix memory leak on usb_submit_urb() failure
CVE-2025-71160 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnetfilter: nf_tables: avoid chain re-validation if possible
CVE-2025-71161 ↗2026-02-28cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-banddm-verity: disable recursive forward error correction
CVE-2025-71163 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-banddmaengine: idxd: fix device leaks on compat bind and unbind
CVE-2025-71183 ↗2026-03-27cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandbtrfs: always detect conflicting inodes when logging inode refs
CVE-2025-71184 ↗2026-03-27cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandbtrfs: fix NULL dereference on root when tracing inode eviction
CVE-2026-0716 ↗2026-01-17azl3 libsoup 3.4.4-14 on Azure Linux 3.0ModerateOut-of-bandLibsoup: out-of-bounds read in libsoup websocket frame processing
CVE-2026-0861 ↗2026-01-16cbl2 glibc 2.35-7 on CBL Mariner 2.0ModerateOut-of-bandInteger overflow in memalign leads to heap corruption
CVE-2026-0915 ↗2026-01-17azl3 glibc 2.38-16 on Azure Linux 3.0ModerateOut-of-bandgetnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler
CVE-2026-0990 ↗2026-01-19cbl2 libxml2 2.10.4-9 on CBL Mariner 2.0ModerateOut-of-bandLibxml2: libxml2: denial of service via uncontrolled recursion in xml catalog processing
CVE-2026-21444 ↗2026-01-07azl3 libtpms 0.9.6-8 on Azure Linux 3.0ModerateOut-of-bandlibtpms returns wrong initialization vector when certain symmetric ciphers are used
CVE-2026-21860 ↗2026-01-11cbl2 python-tensorboard 2.11.0-3 on CBL Mariner 2.0ModerateOut-of-bandWerkzeug safe_join() allows Windows special device names with compound extensions
CVE-2026-22693 ↗2026-01-11azl3 harfbuzz 8.3.0-4 on Azure Linux 3.0ModerateOut-of-bandNull Pointer Dereference in SubtableUnicodesCache::create leading to DoS
CVE-2026-22695 ↗2026-01-14cbl2 libpng 1.6.52-1 on CBL Mariner 2.0ModerateOut-of-bandLIBPNG has a heap buffer over-read in png_image_read_direct_scaled (regression from CVE-2025-65018 fix)
CVE-2026-22701 ↗2026-01-13cbl2 python-filelock 3.0.12-13 on CBL Mariner 2.0Moderatefilelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock
CVE-2026-22702 ↗2026-01-13cbl2 python-virtualenv 20.26.6-3 on CBL Mariner 2.0Moderatevirtualenv Has TOCTOU Vulnerabilities in Directory Creation
CVE-2026-22801 ↗2026-01-14azl3 libpng 1.6.52-1 on Azure Linux 3.0ModerateOut-of-bandLIBPNG has an integer truncation causing heap buffer over-read in png_image_write_*
CVE-2026-22976 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet/sched: sch_qfq: Fix NULL deref when deactivating inactive aggregate in qfq_reset
CVE-2026-22977 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: sock: fix hardened usercopy panic in sock_recv_errqueue
CVE-2026-22979 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: fix memory leak in skb_segment_list for GRO packets
CVE-2026-22982 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: mscc: ocelot: Fix crash when adding interface under a lag
CVE-2026-22990 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandlibceph: replace overzealous BUG_ON in osdmap_apply_incremental()
CVE-2026-22991 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandlibceph: make free_choose_arg_map() resilient to partial allocation
CVE-2026-22992 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandlibceph: return the handler error from mon_handle_auth_done()
CVE-2026-22996 ↗2026-02-28cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet/mlx5e: Don't store mlx5e_priv in mlx5e_dev devlink priv
CVE-2026-22997 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: can: j1939: j1939_xtp_rx_rts_session_active(): deactivate session upon receiving the second rts
CVE-2026-22998 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec
CVE-2026-22999 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet/sched: sch_qfq: do not free existing class in qfq_change_class()
CVE-2026-23000 ↗2026-02-26cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet/mlx5e: Fix crash on profile change rollback failure
CVE-2026-23004 ↗2026-03-27cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-banddst: fix races in rt6_uncached_list_del() and rt_del_uncached_list()
CVE-2025-13151 ↗2026-01-09azl3 gnutls 3.8.3-6 on Azure Linux 3.0LowOut-of-bandCVE-2025-13151
CVE-2025-15224 ↗2026-01-09cbl2 curl 8.8.0-7 on CBL Mariner 2.0LowOut-of-bandlibssh key passphrase bypass without agent set
CVE-2025-71094 ↗2026-01-15azl3 kernel 6.6.119.3-3 on Azure Linux 3.0LowOut-of-bandnet: usb: asix: validate PHY address before use
CVE-2026-0989 ↗2026-01-19cbl2 libxml2 2.10.4-9 on CBL Mariner 2.0LowOut-of-bandLibxml2: unbounded relaxng include recursion leading to stack overflow
CVE-2026-0992 ↗2026-01-19azl3 libxml2 2.11.5-7 on Azure Linux 3.0LowOut-of-bandLibxml2: libxml2: denial of service via crafted xml catalogs
CVE-2026-21895 ↗2026-01-11azl3 kata-containers-cc 3.15.0.aks0-5 on Azure Linux 3.0LowOut-of-bandrsa crate has potential panic on a prime being equal to 1
CVE-2026-22978 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0LowOut-of-bandwifi: avoid kernel-infoleak from struct iw_point
CVE-2026-0628 ↗2026-01-09Microsoft Edge (Chromium-based)N/AOut-of-band7%Chromium: CVE-2026-0628 Insufficient policy enforcement in WebView tag
CVE-2026-0899 ↗2026-01-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-0899 Out of bounds memory access in V8
CVE-2026-0900 ↗2026-01-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-0900 Inappropriate implementation in V8
CVE-2026-0901 ↗2026-01-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-0901 Inappropriate implementation in Blink
CVE-2026-0902 ↗2026-01-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-0902 Inappropriate implementation in V8
CVE-2026-0903 ↗2026-01-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-0903 Insufficient validation of untrusted input in Downloads
CVE-2026-0904 ↗2026-01-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-0904 Incorrect security UI in Digital Credentials
CVE-2026-0905 ↗2026-01-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-0905 Insufficient policy enforcement in Network
CVE-2026-0906 ↗2026-01-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-0906 Incorrect security UI
CVE-2026-0907 ↗2026-01-16Microsoft Edge (Chromium-based)N/AOut-of-band8%Chromium: CVE-2026-0907 Incorrect security UI in Split View
CVE-2026-0908 ↗2026-01-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-0908 Use after free in ANGLE
CVE-2026-1220 ↗2026-01-23Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-1220 Race in V8
CVE-2026-1504 ↗2026-01-30Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-1504 Inappropriate implementation in Background Fetch API
CVE-2026-21223 ↗2026-01-16Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
#

December 2025

Patch Tuesday December 9, 202583 CVEs plus 266 Azure Linux package advisories · 8 critical · 1 exploitation detected · 2 in KEV349 CVEs · 15 critical · 1 exploitation detected · 2 in KEV · includes 266 Azure Linux package advisories
Risk matrix, December 2025
18 of these counts use a severity derived from CVSS because Microsoft assigned none.
18 of these counts use a severity derived from CVSS because Microsoft assigned none.
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2025-62221 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant2%Exploitation detectedCISA KEVVulnCheckENISAKB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2025-40242 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0CriticalOut-of-bandgfs2: Fix unlikely race in gdlm_put_lock
CVE-2025-40244 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0CriticalOut-of-bandhfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent()
CVE-2025-40251 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0CriticalOut-of-banddevlink: rate: Unset parent pointer in devl_rate_nodes_destroy
CVE-2025-40262 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0CriticalOut-of-bandInput: imx_sc_key - fix memory corruption on unload
CVE-2025-62554 ↗2025-12-09Microsoft Office LTSC 2024 for 64-bit editionsCritical0%KB5002819Microsoft Office Remote Code Execution Vulnerability
CVE-2025-62557 ↗2025-12-09Microsoft Office LTSC 2024 for 32-bit editionsCritical0%KB5002819Microsoft Office Remote Code Execution Vulnerability
CVE-2025-64663 ↗2025-12-18Azure Cognitive Service for LanguageCriticalOut-of-band1%Custom Question Answering Elevation of Privilege Vulnerability
CVE-2025-64675 ↗2025-12-18Azure Cosmos DBCriticalOut-of-band1%Azure Cosmos DB Spoofing Vulnerability
CVE-2025-64676 ↗2025-12-18Microsoft PurviewCriticalOut-of-band1%Microsoft Purview eDiscovery Remote Code Execution Vulnerability
CVE-2025-64677 ↗2025-12-18Office Out-of-Box ExperienceCriticalOut-of-band0%Office Out-of-Box Experience Spoofing Vulnerability
CVE-2025-65037 ↗2025-12-18Azure Container AppsCriticalOut-of-band1%Azure Container Apps Remote Code Execution Vulnerability
CVE-2025-65041 ↗2025-12-18Microsoft Partner CenterCriticalOut-of-band1%Microsoft Partner Center Elevation of Privilege Vulnerability
CVE-2025-68193 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0CriticalOut-of-banddrm/xe/guc: Add devm release action to safely tear down CT
CVE-2025-68206 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0CriticalOut-of-bandnetfilter: nft_ct: add seqadj extension for natted connections
CVE-2025-68615 ↗2025-12-24cbl2 net-snmp 5.9.4-1 on CBL Mariner 2.0CriticalOut-of-bandNet-SNMP snmptrapd crash
CVE-2023-54207 ↗2026-02-28cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandHID: uclogic: Correct devm device reference for hidinput input_dev name
CVE-2025-12385 ↗2025-12-06cbl2 qt5-qtbase 5.12.11-18 on CBL Mariner 2.0ImportantOut-of-bandImproper validation of <img> tag size in Text component parser
CVE-2025-12819 ↗2025-12-05cbl2 pgbouncer 1.24.1-1 on CBL Mariner 2.0ImportantOut-of-bandUntrusted search path in auth_query connection in PgBouncer
CVE-2025-13699 ↗2025-12-27azl3 mariadb 10.11.11-1 on Azure Linux 3.0ImportantOut-of-bandMariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability
CVE-2025-14180 ↗2025-12-29cbl2 php 8.1.33-1 on CBL Mariner 2.0ImportantOut-of-bandNULL Pointer Dereference in PDO quoting
CVE-2025-14523 ↗2025-12-13azl3 libsoup 3.4.4-10 on Azure Linux 3.0ImportantOut-of-bandLibsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)
CVE-2025-15284 ↗2026-01-03azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandarrayLimit bypass in bracket notation allows DoS via memory exhaustion
CVE-2025-2296 ↗2025-12-17azl3 edk2 20240524git3e722403cd16-10 on Azure Linux 3.0ImportantOut-of-bandUn-verified kernel bypass Secure Boot mechanism in direct boot mode
CVE-2025-34297 ↗2025-12-05cbl2 tensorflow 2.11.1-2 on CBL Mariner 2.0ImportantOut-of-bandKissFFT Integer Overflow Heap Buffer Overflow via kiss_fft_alloc
CVE-2025-34468 ↗2026-01-03azl3 libcap 2.69-10 on Azure Linux 3.0ImportantOut-of-bandlibcoap Stack-Based Buffer Overflow in Address Resolution DoS or Potential RCE
CVE-2025-40223 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandmost: usb: Fix use-after-free in hdm_disconnect
CVE-2025-40233 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandocfs2: clear extent cache after moving/defragmenting extents
CVE-2025-40240 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandsctp: avoid NULL dereference when chunk data buffer is missing
CVE-2025-40258 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandmptcp: fix race condition in mptcp_schedule_work()
CVE-2025-40272 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandmm/secretmem: fix use-after-free race in fault handler
CVE-2025-40312 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Importantjfs: Verify inode mode when loading from disk
CVE-2025-40314 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Importantusb: cdns3: gadget: Use-after-free during failed initialization and exit of cdnsp gadget
CVE-2025-40319 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Importantbpf: Sync pending IRQ work before freeing ring buffer
CVE-2025-40362 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandceph: fix multifs mds auth caps issue
CVE-2025-48637 ↗2026-01-09azl3 hyperv-daemons 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandIn multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-54100 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant2%KB5071417KB5071501
and 13 moreKB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072033KB5074204KB5074353
PowerShell Remote Code Execution Vulnerability
CVE-2025-55233 ↗2025-12-09Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2025-58098 ↗2025-12-11azl3 httpd 2.4.65-1 on Azure Linux 3.0ImportantOut-of-bandApache HTTP Server: Server Side Includes adds query string to #exec cmd=...
CVE-2025-59516 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Storage VSP Driver Elevation of Privilege Vulnerability
CVE-2025-59517 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5071413KB5071417
and 7 moreKB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Storage VSP Driver Elevation of Privilege Vulnerability
CVE-2025-59775 ↗2025-12-07cbl2 httpd 2.4.65-1 on CBL Mariner 2.0ImportantOut-of-bandApache HTTP Server: NTLM Leakage on Windows through UNC SSRF
CVE-2025-61729 ↗2025-12-05cbl2 python-tensorboard 2.11.0-3 on CBL Mariner 2.0ImportantOut-of-bandExcessive resource consumption when printing error string for host certificate validation in crypto/x509
CVE-2025-62454 ↗2025-12-09Windows 11 Version 25H2 for ARM64-based SystemsImportant2%More likelyKB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2025-62455 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5071501KB5071503
and 7 moreKB5071504KB5071505KB5071506KB5071507KB5071543KB5071544KB5071546
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
CVE-2025-62456 ↗2025-12-09Windows 11 Version 25H2 for ARM64-based SystemsImportant1%KB5071413KB5071417
and 4 moreKB5071542KB5071547KB5072014KB5072033
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
CVE-2025-62457 ↗2025-12-09Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2025-62458 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant1%More likelyKB5071413KB5071417
and 8 moreKB5071501KB5071503KB5071505KB5071506KB5071543KB5071544KB5071546KB5071547
Win32k Elevation of Privilege Vulnerability
CVE-2025-62461 ↗2025-12-09Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2025-62462 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2025-62463 ↗2025-12-09Windows Server 2022Important0%KB5071413KB5071417
and 5 moreKB5071542KB5071546KB5071547KB5072014KB5072033
DirectX Graphics Kernel Denial of Service Vulnerability
CVE-2025-62464 ↗2025-12-09Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2025-62465 ↗2025-12-09Windows Server 2022Important0%KB5071413KB5071417
and 4 moreKB5071542KB5071547KB5072014KB5072033
DirectX Graphics Kernel Denial of Service Vulnerability
CVE-2025-62466 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5071413KB5071417
and 13 moreKB5071501KB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Client-Side Caching Elevation of Privilege Vulnerability
CVE-2025-62467 ↗2025-12-09Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2025-62468 ↗2025-12-09Windows Server 2025 (Server Core installation)Important0%More likelyKB5071417KB5071542
and 2 moreKB5072014KB5072033
Windows Defender Firewall Service Information Disclosure Vulnerability
CVE-2025-62469 ↗2025-12-09Windows Server 2025 (Server Core installation)Important0%KB5072014KB5072033Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2025-62470 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5071413KB5071417
and 13 moreKB5071501KB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2025-62472 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5071413KB5071417
and 13 moreKB5071501KB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVE-2025-62473 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5071413KB5071417
and 13 moreKB5071501KB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-62474 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5071413KB5071417
and 11 moreKB5071501KB5071503KB5071505KB5071506KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVE-2025-62549 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5071413KB5071417
and 13 moreKB5071501KB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-62550 ↗2025-12-09Azure Monitor AgentImportant1%Azure Monitor Agent Remote Code Execution Vulnerability
CVE-2025-62552 ↗2025-12-09Microsoft Office 2019 for 32-bit editionsImportant1%KB5002812Microsoft Access Remote Code Execution Vulnerability
CVE-2025-62553 ↗2025-12-09Microsoft Office 2019 for 32-bit editionsImportant1%KB5002818KB5002820Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62555 ↗2025-12-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002802KB5002804
and 3 moreKB5002806KB5002816KB5002821
Microsoft Word Remote Code Execution Vulnerability
CVE-2025-62556 ↗2025-12-09Office Online ServerImportant1%KB5002817KB5002820Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62558 ↗2025-12-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002802KB5002804
and 3 moreKB5002806KB5002816KB5002821
Microsoft Word Remote Code Execution Vulnerability
CVE-2025-62559 ↗2025-12-09Microsoft SharePoint Enterprise Server 2016Important0%KB5002802KB5002804
and 3 moreKB5002806KB5002816KB5002821
Microsoft Word Remote Code Execution Vulnerability
CVE-2025-62560 ↗2025-12-09Office Online ServerImportant0%KB5002817KB5002820Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62561 ↗2025-12-09Office Online ServerImportant0%KB5002817KB5002818
and 1 moreKB5002820
Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62562 ↗2025-12-09Microsoft SharePoint Enterprise Server 2016Important1%KB5002802KB5002804
and 3 moreKB5002806KB5002816KB5002821
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2025-62563 ↗2025-12-09Office Online ServerImportant1%KB5002817KB5002818
and 1 moreKB5002820
Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62564 ↗2025-12-09Office Online ServerImportant0%KB5002817KB5002820Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62565 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5071413KB5071417
and 7 moreKB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows File Explorer Elevation of Privilege Vulnerability
CVE-2025-62567 ↗2025-12-09Windows 10 Version 1809 for x64-based SystemsImportant1%KB5071413KB5071417
and 8 moreKB5071503KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Hyper-V Denial of Service Vulnerability
CVE-2025-62569 ↗2025-12-09Windows Server 2025 (Server Core installation)Important0%KB5071542KB5072014
and 1 moreKB5072033
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2025-62570 ↗2025-12-09Windows Server 2025 (Server Core installation)Important0%KB5072014KB5072033Windows Camera Frame Server Monitor Information Disclosure Vulnerability
CVE-2025-62571 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5071413KB5071417
and 13 moreKB5071501KB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Installer Elevation of Privilege Vulnerability
CVE-2025-62572 ↗2025-12-09Windows Server 2025 (Server Core installation)Important0%KB5072014KB5072033Application Information Service Elevation of Privilege Vulnerability
CVE-2025-62573 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5071413KB5071417
and 7 moreKB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2025-64658 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows File Explorer Elevation of Privilege Vulnerability
CVE-2025-64661 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5071413KB5071417
and 7 moreKB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Shell Elevation of Privilege Vulnerability
CVE-2025-64666 ↗2025-12-09Microsoft Exchange Server 2019 Cumulative Update 15Important1%KB5071873KB5071874
and 2 moreKB5071875KB5071876
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2025-64667 ↗2025-12-09Microsoft Exchange Server Subscription Edition RTMImportant1%KB5071873KB5071874
and 2 moreKB5071875KB5071876
Microsoft Exchange Server Spoofing Vulnerability
CVE-2025-64669 ↗2025-12-09Windows Admin CenterImportant0%Windows Admin Center Elevation of Privilege Vulnerability
CVE-2025-64670 ↗2025-12-09Windows Server 2022Important1%KB5071413KB5071417
and 5 moreKB5071542KB5071546KB5071547KB5072014KB5072033
Windows DirectX Information Disclosure Vulnerability
CVE-2025-64671 ↗2025-12-09GitHub Copilot Plugin for JetBrains IDEsImportant0%GitHub Copilot for Jetbrains Remote Code Execution Vulnerability
CVE-2025-64672 ↗2025-12-09Microsoft SharePoint Server Subscription EditionImportant1%KB5002815Microsoft SharePoint Server Spoofing Vulnerability
CVE-2025-64673 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Storage VSP Driver Elevation of Privilege Vulnerability
CVE-2025-64678 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-64679 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-64680 ↗2025-12-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-66293 ↗2025-12-05cbl2 libpng 1.6.51-1 on CBL Mariner 2.0ImportantOut-of-bandLIBPNG has an out-of-bounds read in png_image_read_composite
CVE-2025-66418 ↗2025-12-10cbl2 python-urllib3 1.26.19-2 on CBL Mariner 2.0ImportantOut-of-bandurllib3 allows an unbounded number of links in the decompression chain
CVE-2025-66471 ↗2025-12-10cbl2 python-urllib3 1.26.19-2 on CBL Mariner 2.0ImportantOut-of-bandurllib3 Streaming API improperly handles highly compressed data
CVE-2025-66476 ↗2025-12-05azl3 vim 9.1.1616-1 on Azure Linux 3.0ImportantOut-of-bandVim for Windows Uncontrolled Search Path Element Remote Code Execution Vulnerability
CVE-2025-68156 ↗2025-12-19cbl2 coredns 1.11.1-24 on CBL Mariner 2.0ImportantOut-of-bandExpr has Denial of Service via Unbounded Recursion in Builtin Functions
CVE-2025-68174 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandamd/amdkfd: enhance kfd process check in switch partition
CVE-2025-68188 ↗2025-12-17azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandtcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check()
CVE-2025-68190 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/amdgpu/atom: Check kcalloc() for WS buffer in amdgpu_atom_execute_table_locked()
CVE-2025-68196 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/amd/display: Cache streams targeting link when performing LT automation
CVE-2025-68224 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandscsi: core: Fix a regression triggered by scsi_host_busy()
CVE-2025-68227 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandmptcp: Fix proto fallback detection with BPF
CVE-2025-68231 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandmm/mempool: fix poisoning order>0 pages with HIGHMEM
CVE-2025-68235 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandnouveau/firmware: Add missing kfree() of nvkm_falcon_fw::boot
CVE-2025-68237 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandmtdchar: fix integer overflow in read/write ioctls
CVE-2025-68254 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandstaging: rtl8723bs: fix out-of-bounds read in OnBeacon ESR IE parsing
CVE-2025-68255 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandstaging: rtl8723bs: fix stack buffer overflow in OnAssocReq IE parsing
CVE-2025-68256 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandstaging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser
CVE-2025-68261 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandext4: add i_data_sem protection in ext4_destroy_inline_data_nolock()
CVE-2025-68265 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandnvme: fix admin request_queue lifetime
CVE-2025-68266 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandbfs: Reconstruct file type when loading from disk
CVE-2025-68283 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandlibceph: replace BUG_ON with bounds check for map->max_osd
CVE-2025-68284 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandlibceph: prevent potential out-of-bounds writes in handle_auth_session_key()
CVE-2025-68285 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandlibceph: fix potential use-after-free in have_mon_and_osd_map()
CVE-2025-68287 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandusb: dwc3: Fix race condition between concurrent dwc3_remove_requests() call paths
CVE-2025-68290 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandmost: usb: fix double free on late probe failure
CVE-2025-68297 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandceph: fix crash in process_v2_sparse_read() for encrypted directories
CVE-2025-68301 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandnet: atlantic: fix fragment overflow handling in RX path
CVE-2025-68303 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandplatform/x86: intel: punit_ipc: fix memory corruption
CVE-2025-68304 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandBluetooth: hci_core: lookup hci_conn on RX path on protocol side
CVE-2025-68307 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandcan: gs_usb: gs_usb_xmit_callback(): fix handling of failed transmitted URBs
CVE-2025-68311 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandtty: serial: ip22zilog: Use platform device for probing
CVE-2025-68315 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandf2fs: fix to detect potential corrupted nid in free_nid_list
CVE-2025-68324 ↗2025-12-20azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandscsi: imm: Fix use-after-free bug caused by unfinished delayed work
CVE-2025-68331 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandusb: uas: fix urb unmapping issue when the uas device is remove during ongoing data transfer
CVE-2025-68346 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandALSA: dice: fix buffer overflow in detect_stream_formats()
CVE-2025-68356 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandgfs2: Prevent recursive memory reclaim
CVE-2025-68367 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandmacintosh/mac_hid: fix race condition in mac_hid_toggle_emumouse
CVE-2025-68380 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: ath11k: fix peer HE MCS assignment
CVE-2025-68476 ↗2025-12-24cbl2 keda 2.4.0-30 on CBL Mariner 2.0ImportantOut-of-bandKEDA has Arbitrary File Read via Insufficient Path Validation in HashiCorp Vault Service Account Credential
CVE-2025-68729 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: ath12k: Fix MSDU buffer types handling in RX error path
CVE-2025-68973 ↗2025-12-30azl3 gnupg2 2.4.7-1 on Azure Linux 3.0ImportantOut-of-bandIn GnuPG through 2.4.8, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)
CVE-2023-53749 ↗2025-12-09azl3 kernel 6.6.117.1-1 on Azure Linux 3.0Moderatex86: fix clear_user_rep_good() exception handling annotation
CVE-2023-54061 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandx86: fix clear_user_rep_good() exception handling annotation
CVE-2023-54082 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandaf_unix: Fix null-ptr-deref in unix_stream_sendpage().
CVE-2023-54161 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandaf_unix: Fix null-ptr-deref in unix_stream_sendpage().
CVE-2025-10543 ↗2025-12-05cbl2 influxdb 2.6.1-24 on CBL Mariner 2.0ModerateOut-of-bandIn Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library, may be incorrectly encoded if their length exceeds 65535 bytes. This may lead to unexpected content in packets sent to the server (for example, part of an MQTT topic may leak into the message body in a PUBLISH packet). The issue arises because the length of the data passed in was converted from an int64/int32 (depending upon CPU) to an int16 without checks for overflows. The int16 length was then written, followed by the data (e.g. topic). This meant that when the data (e.g. topic) was over 65535 bytes then the amount of data written exceeds what the length field indicates. This could lead to a corrupt packet, or mean that the excess data leaks into another field (e.g. topic leaks into message body).
CVE-2025-12084 ↗2025-12-06cbl2 python3 3.9.19-17 on CBL Mariner 2.0ModerateOut-of-bandQuadratic complexity in node ID cache clearing
CVE-2025-13281 ↗2025-12-16azl3 kubernetes 1.30.10-18 on Azure Linux 3.0ModerateOut-of-bandPortworx Half-Blind SSRF in kube-controller-manager
CVE-2025-13836 ↗2025-12-05cbl2 python3 3.9.19-16 on CBL Mariner 2.0ModerateOut-of-bandExcessive read buffering DoS in http.client
CVE-2025-14087 ↗2025-12-13azl3 glib 2.78.6-5 on Azure Linux 3.0ModerateOut-of-bandGlib: glib: buffer underflow in gvariant parser leads to heap corruption
CVE-2025-14104 ↗2025-12-13cbl2 util-linux 2.37.4-9 on CBL Mariner 2.0ModerateOut-of-bandUtil-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames
CVE-2025-14177 ↗2025-12-29azl3 php 8.3.23-1 on Azure Linux 3.0ModerateOut-of-bandInformation Leak of Memory in getimagesize
CVE-2025-14178 ↗2025-12-29azl3 php 8.3.23-1 on Azure Linux 3.0ModerateOut-of-bandHeap buffer overflow in array_merge()
CVE-2025-14512 ↗2025-12-13cbl2 glib 2.71.0-8 on CBL Mariner 2.0ModerateOut-of-bandGlib: integer overflow in glib gio attribute escaping causes heap buffer overflow
CVE-2025-37731 ↗2025-12-16azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandElasticsearch Improper Authentication
CVE-2025-40215 ↗2025-12-05azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandxfrm: delete x->tunnel as we delete x
CVE-2025-40217 ↗2025-12-05azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandpidfs: validate extensible ioctls
CVE-2025-40218 ↗2025-12-05azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandmm/damon/vaddr: do not repeat pte_offset_map_lock() until success
CVE-2025-40219 ↗2025-12-05azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandPCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV
CVE-2025-40220 ↗2025-12-05azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandfuse: fix livelock in synchronous file put from fuseblk workers
CVE-2025-40243 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandhfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits()
CVE-2025-40245 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnios2: ensure that memblock.current_limit is set when setting pfn limits
CVE-2025-40247 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/msm: Fix pgtable prealloc error path
CVE-2025-40248 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandvsock: Ignore signal/timeout on connect() if already established
CVE-2025-40250 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnet/mlx5: Clean up only new IRQ glue on request_irq() failure
CVE-2025-40252 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end()
CVE-2025-40253 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bands390/ctcm: Fix double-kfree
CVE-2025-40254 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: openvswitch: remove never-working support for setting nsh fields
CVE-2025-40257 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandmptcp: fix a race in mptcp_pm_del_add_timer()
CVE-2025-40259 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandscsi: sg: Do not sleep in atomic context
CVE-2025-40261 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl()
CVE-2025-40263 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandInput: cros_ec_keyb - fix an invalid memory access
CVE-2025-40264 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandbe2net: pass wrb_params in case of OS2BMC
CVE-2025-40266 ↗2025-12-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandKVM: arm64: Check the untrusted offset in FF-A memory share
CVE-2025-40268 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandcifs: client: fix memory leak in smb3_fs_context_parse_param
CVE-2025-40269 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandALSA: usb-audio: Fix potential overflow of PCM transfer buffer
CVE-2025-40273 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandNFSD: free copynotify stateid in nfs4_free_ol_stateid()
CVE-2025-40275 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandALSA: usb-audio: Fix NULL pointer dereference in snd_usb_mixer_controls_badd
CVE-2025-40277 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE
CVE-2025-40278 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: sched: act_ife: initialize struct tc_ife to fix KMSAN kernel-infoleak
CVE-2025-40279 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: sched: act_connmark: initialize struct tc_ife to fix kernel leak
CVE-2025-40280 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandtipc: Fix use-after-free in tipc_mon_reinit_self().
CVE-2025-40281 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandsctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto
CVE-2025-40282 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandBluetooth: 6lowpan: reset link-local header on ipv6 recv path
CVE-2025-40283 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandBluetooth: btusb: reorder cleanup in btusb_disconnect to avoid UAF
CVE-2025-40284 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandBluetooth: MGMT: cancel mesh send timer when hdev removed
CVE-2025-40285 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandsmb/server: fix possible refcount leak in smb2_sess_setup()
CVE-2025-40286 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandsmb/server: fix possible memory leak in smb2_read()
CVE-2025-40287 ↗2025-12-08azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandexfat: fix improper check of dentry.stream.valid_size
CVE-2025-40288 ↗2025-12-08azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: Fix NULL pointer dereference in VRAM logic for APU devices
CVE-2025-40289 ↗2025-12-08azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: hide VRAM sysfs attributes on GPUs without VRAM
CVE-2025-40292 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderatevirtio-net: fix received length check in big packets
CVE-2025-40293 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderateiommufd: Don't overflow during division for dirty tracking
CVE-2025-40294 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateBluetooth: MGMT: Fix OOB access in parse_adv_monitor_pattern()
CVE-2025-40297 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderatenet: bridge: fix use-after-free due to MST port state bypass
CVE-2025-40301 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateBluetooth: hci_event: validate skb length for unknown CC opcode
CVE-2025-40303 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderatebtrfs: ensure no dirty metadata is written back for an fs with errors
CVE-2025-40304 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderatefbdev: Add bounds checking in bit_putcs to fix vmalloc-out-of-bounds
CVE-2025-40305 ↗2025-12-09azl3 kernel 6.6.117.1-1 on Azure Linux 3.0Moderate9p/trans_fd: p9_fd_request: kick rx thread if EPOLLIN
CVE-2025-40306 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderateorangefs: fix xattr related buffer overflow...
CVE-2025-40307 ↗2025-12-09azl3 kernel 6.6.117.1-1 on Azure Linux 3.0Moderateexfat: validate cluster allocation bits of the allocation bitmap
CVE-2025-40308 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateBluetooth: bcsp: receive data only if registered
CVE-2025-40309 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateBluetooth: SCO: Fix UAF on sco_conn_free
CVE-2025-40310 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderateamd/amdkfd: resolve a race in amdgpu_amdkfd_device_fini_sw
CVE-2025-40311 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderateaccel/habanalabs: support mapping cb with vmalloc-backed coherent memory
CVE-2025-40313 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderatentfs3: pretend $Extend records as regular files
CVE-2025-40315 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderateusb: gadget: f_fs: Fix epfile null pointer access after ep enable.
CVE-2025-40317 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderateregmap: slimbus: fix bus_context pointer in regmap init calls
CVE-2025-40321 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderatewifi: brcmfmac: fix crash while sending Action Frames in standalone AP Mode
CVE-2025-40322 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderatefbdev: bitblit: bound-check glyph index in bit_putcs*
CVE-2025-40323 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0Moderatefbcon: Set fb_display[i]->mode to NULL when the mode is released
CVE-2025-40324 ↗2025-12-09azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateNFSD: Fix crash in nfsd4_read_release()
CVE-2025-40328 ↗2025-12-10azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandsmb: client: fix potential UAF in smb2_close_cached_fid()
CVE-2025-40329 ↗2025-12-10azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/sched: Fix deadlock in drm_sched_entity_kill_jobs_cb
CVE-2025-40331 ↗2025-12-10azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandsctp: Prevent TOCTOU out-of-bounds write
CVE-2025-40332 ↗2025-12-10azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdkfd: Fix mmap write lock not release
CVE-2025-40333 ↗2025-12-10azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix infinite loop in __insert_extent_tree()
CVE-2025-40334 ↗2025-12-10azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: validate userq buffer virtual address and size
CVE-2025-40335 ↗2025-12-10azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: validate userq input args
CVE-2025-40336 ↗2025-12-10azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/gpusvm: fix hmm_pfn_to_map_order() usage
CVE-2025-40337 ↗2025-12-10azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: stmmac: Correctly handle Rx checksum offload errors
CVE-2025-40338 ↗2025-12-10azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandASoC: Intel: avs: Do not share the name pointer between components
CVE-2025-40339 ↗2025-12-10azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: fix nullptr err of vm_handle_moved
CVE-2025-40340 ↗2025-12-10azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/xe: Fix oops in xe_gem_fault when running core_hotunplug test.
CVE-2025-40341 ↗2025-12-10azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandfutex: Don't leak robust_list pointer on exec race
CVE-2025-40342 ↗2025-12-10azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnvme-fc: use lock accessing port_state and rport state
CVE-2025-40343 ↗2025-12-10azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnvmet-fc: avoid scheduling association deletion twice
CVE-2025-40345 ↗2025-12-14azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: storage: sddr55: Reject out-of-bound new_pba
CVE-2025-40354 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: increase max link count and fix link->enc NULL pointer access
CVE-2025-40355 ↗2025-12-17azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandsysfs: check visibility before changing group attribute ownership
CVE-2025-55753 ↗2025-12-11cbl2 httpd 2.4.65-1 on CBL Mariner 2.0ModerateOut-of-bandApache HTTP Server: mod_md (ACME), unintended retry intervals
CVE-2025-59529 ↗2025-12-21cbl2 avahi 0.8-4 on CBL Mariner 2.0ModerateOut-of-bandsimple protocol server ignores accepts unlimited connections and logs failures without limit
CVE-2025-61727 ↗2025-12-06cbl2 golang 1.18.8-10 on CBL Mariner 2.0ModerateOut-of-bandImproper application of excluded DNS name constraints when verifying wildcard names in crypto/x509
CVE-2025-62408 ↗2025-12-11azl3 fluent-bit 3.1.10-2 on Azure Linux 3.0ModerateOut-of-bandc-ares has a Use After Free vulnerability when connection is cleaned up after error
CVE-2025-65082 ↗2025-12-07azl3 httpd 2.4.65-1 on Azure Linux 3.0ModerateOut-of-bandApache HTTP Server: CGI environment variable override
CVE-2025-65637 ↗2025-12-07cbl2 influxdb 2.6.1-27 on CBL Mariner 2.0ModerateOut-of-bandA denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters.
CVE-2025-66200 ↗2025-12-07azl3 httpd 2.4.65-1 on Azure Linux 3.0ModerateOut-of-bandApache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo
CVE-2025-67873 ↗2026-01-21azl3 rust 1.75.0-22 on Azure Linux 3.0ModerateOut-of-bandCapstone doesn't check Skipdata length, leading to cs_insn.bytes heap buffer overflow
CVE-2025-67897 ↗2025-12-17azl3 kata-containers-cc 3.15.0.aks0-6 on Azure Linux 3.0ModerateOut-of-bandIn Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.
CVE-2025-68114 ↗2025-12-21cbl2 qemu 6.2.0-26 on CBL Mariner 2.0ModerateOut-of-bandCapstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow and overflow
CVE-2025-68146 ↗2025-12-19azl3 python-filelock 3.14.0-1 on Azure Linux 3.0ModerateOut-of-bandfilelock has TOCTOU race condition that allows symlink attacks during lock file creation
CVE-2025-68161 ↗2025-12-21azl3 javapackages-bootstrap 1.14.0-3 on Azure Linux 3.0ModerateOut-of-bandApache Log4j Core: Missing TLS hostname verification in Socket appender
CVE-2025-68175 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandmedia: nxp: imx8-isi: Fix streaming cleanup on release
CVE-2025-68198 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandcrash: fix crashkernel resource shrink
CVE-2025-68201 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: remove two invalid BUG_ON()s
CVE-2025-68203 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: fix lock warning in amdgpu_userq_fence_driver_process
CVE-2025-68204 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandpmdomain: arm: scmi: Fix genpd leak on provider registration failure
CVE-2025-68209 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandmlx5: Fix default values in create CQ
CVE-2025-68211 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandksm: use range-walk function to jump over holes in scan_get_next_rmap_item
CVE-2025-68214 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandtimers: Fix NULL function pointer race in timer_shutdown_sync()
CVE-2025-68217 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandInput: pegasus-notetaker - fix potential out-of-bounds access
CVE-2025-68219 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandcifs: fix memory leak in smb3_fs_context_parse_param error path
CVE-2025-68220 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: ethernet: ti: netcp: Standardize knav_dma_open_channel to return NULL on error
CVE-2025-68222 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandpinctrl: s32cc: fix uninitialized memory in s32_pinctrl_desc
CVE-2025-68223 ↗2025-12-17azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-banddrm/radeon: delete radeon_fence_process in is_signaled, no deadlock
CVE-2025-68229 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: target: tcm_loop: Fix segfault in tcm_loop_tpg_address_show()
CVE-2025-68230 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: fix gpu page fault after hibernation on PF passthrough
CVE-2025-68233 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/tegra: Add call to put_pid()
CVE-2025-68236 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: ufs: ufs-qcom: Fix UFS OCP issue during UFS power down (PC=3)
CVE-2025-68239 ↗2025-12-17azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandbinfmt_misc: restore write access before closing files opened by open_exec()
CVE-2025-68251 ↗2026-05-25azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-banderofs: avoid infinite loops due to corrupted subpage compact indexes
CVE-2025-68257 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandcomedi: check device's attached status in compat ioctls
CVE-2025-68258 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandcomedi: multiq3: sanitize config options in multiq3_attach()
CVE-2025-68259 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: SVM: Don't skip unrelated instruction if INT3/INTO is replaced
CVE-2025-68263 ↗2025-12-17azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: ipc: fix use-after-free in ipc_msg_send_request
CVE-2025-68264 ↗2025-12-17azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandext4: refresh inline data size before write operations
CVE-2025-68281 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandASoC: SDCA: bug fix while parsing mipi-sdca-control-cn-list
CVE-2025-68282 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: gadget: udc: fix use-after-free in usb_gadget_state_work
CVE-2025-68286 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Check NULL before accessing
CVE-2025-68288 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: storage: Fix memory leak in USB bulk transport
CVE-2025-68289 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: gadget: f_eem: Fix memory leak in eem_unwrap
CVE-2025-68291 ↗2026-01-13azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandmptcp: Initialise rcv_mss before calling tcp_send_active_reset() in mptcp_do_fastclose().
CVE-2025-68295 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandsmb: client: fix memory leak in cifs_construct_tcon()
CVE-2025-68296 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-banddrm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup
CVE-2025-68302 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: sxgbe: fix potential NULL dereference in sxgbe_rx()
CVE-2025-68308 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandcan: kvaser_usb: leaf: Fix potential infinite loop in command parsers
CVE-2025-68309 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandPCI/AER: Fix NULL pointer access by aer_info
CVE-2025-68313 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandx86/CPU/AMD: Add RDSEED fix for Zen5
CVE-2025-68317 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandio_uring/zctx: check chained notif contexts
CVE-2025-68318 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandclk: thead: th1520-ap: set all AXI clocks to CLK_IS_CRITICAL
CVE-2025-68322 ↗2025-12-18azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandparisc: Avoid crash due to unaligned access in unwinder
CVE-2025-68327 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: renesas_usbhs: Fix synchronous external abort on unbind
CVE-2025-68328 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandfirmware: stratix10-svc: fix bug in saving controller data
CVE-2025-68330 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandiio: accel: bmc150: Fix irq assumption regression
CVE-2025-68332 ↗2025-12-24azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandcomedi: c6xdigio: Fix invalid PNP driver unregistration
CVE-2025-68333 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandsched_ext: Fix possible deadlock in the deferred_irq_workfn()
CVE-2025-68334 ↗2025-12-24azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandplatform/x86/amd/pmc: Add support for Van Gogh SoC
CVE-2025-68335 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandcomedi: pcl818: fix null-ptr-deref in pcl818_ai_cancel()
CVE-2025-68336 ↗2025-12-24azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandlocking/spinlock/debug: Fix data-race in do_raw_write_lock
CVE-2025-68337 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandjbd2: avoid bug_on in jbd2_journal_get_create_access() when file system corrupted
CVE-2025-68338 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: dsa: microchip: Don't free uninitialized ksz_irq
CVE-2025-68339 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandatm/fore200e: Fix possible data race in fore200e_open()
CVE-2025-68340 ↗2025-12-24cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandteam: Move team device type change at the end of team_port_add
CVE-2025-68342 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandcan: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before accessing data
CVE-2025-68343 ↗2025-12-24azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandcan: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before accessing header
CVE-2025-68344 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: wavefront: Fix integer overflow in sample size validation
CVE-2025-68345 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_hda_read_acpi()
CVE-2025-68347 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events
CVE-2025-68349 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid
CVE-2025-68354 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandregulator: core: Protect regulator_supply_alias_list with regulator_list_mutex
CVE-2025-68357 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandiomap: allocate s_dio_done_wq for async reads as well
CVE-2025-68358 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix racy bitfield write in btrfs_clear_space_info_full()
CVE-2025-68362 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: rtl818x: rtl8187: Fix potential buffer underflow in rtl8187_rx_cb()
CVE-2025-68363 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Check skb->transport_header is set in bpf_skb_check_mtu
CVE-2025-68364 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandocfs2: relax BUG() to ocfs2_error() in __ocfs2_move_extent()
CVE-2025-68365 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandfs/ntfs3: Initialize allocated memory before use
CVE-2025-68366 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandnbd: defer config unlock in nbd_genl_connect
CVE-2025-68371 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: smartpqi: Fix device resources accessed after device removal
CVE-2025-68372 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandnbd: defer config put in recv_work
CVE-2025-68374 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandmd: fix rcu protection in md_wakeup_thread
CVE-2025-68376 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandcoresight: ETR: Fix ETR buffer use-after-free issue
CVE-2025-68378 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Fix stackmap overflow check in __bpf_get_stackid()
CVE-2025-68379 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/rxe: Fix null deref on srq->rq.queue after resize failure
CVE-2025-68384 ↗2025-12-20azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandElasticsearch Allocation of Resources Without Limits or Throttling
CVE-2025-68390 ↗2025-12-20azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandElasticsearch Allocation of Resources Without Limits or Throttling
CVE-2025-68724 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id
CVE-2025-68725 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Do not let BPF test infra emit invalid GSO types to stack
CVE-2025-68728 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandntfs3: fix uninit memory after failed mi_read in mi_format_new
CVE-2025-68732 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandgpu: host1x: Fix race in syncpt alloc/free
CVE-2025-68733 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandsmack: fix bug: unprivileged task can create labels
CVE-2025-68736 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandlandlock: Fix handling of disconnected directories
CVE-2025-68740 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandima: Handle error code returned by ima_filter_rule_match()
CVE-2025-68741 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: qla2xxx: Fix improper freeing of purex item
CVE-2025-68742 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Fix invalid prog->stats access when update_effective_progs fails
CVE-2025-68744 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Free special fields when update [lru_,]percpu_hash maps
CVE-2025-68745 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: qla2xxx: Clear cmds after chip reset
CVE-2025-68746 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: tegra210-quad: Fix timeout handling
CVE-2025-68972 ↗2025-12-29cbl2 gnupg2 2.4.0-3 on CBL Mariner 2.0ModerateOut-of-bandIn GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor" message is printed during verification). This is related to use of \f as a marker to denote truncation of a long plaintext line.
CVE-2025-69277 ↗2026-01-03azl3 libsodium 1.0.19-1 on Azure Linux 3.0ModerateOut-of-bandlibsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.
CVE-2025-11961 ↗2026-01-03cbl2 nmap 7.93-3 on CBL Mariner 2.0LowOut-of-bandOOBR and OOBW in pcap_ether_aton() in libpcap
CVE-2025-11964 ↗2026-01-03azl3 libpcap 1.10.5-1 on Azure Linux 3.0LowOut-of-bandOOBW in utf_16le_to_utf_8_truncated() in libpcap
CVE-2025-13837 ↗2025-12-05cbl2 python3 3.9.19-16 on CBL Mariner 2.0LowOut-of-bandOut-of-memory when loading Plist
CVE-2025-13912 ↗2025-12-17cbl2 mariadb 10.6.24-1 on CBL Mariner 2.0LowOut-of-bandPotential non-constant time compiled code with Clang LLVM
CVE-2025-40353 ↗2025-12-17azl3 kernel 6.6.117.1-1 on Azure Linux 3.0LowOut-of-bandarm64: mte: Do not warn if the page is already tagged in copy_highpage()
CVE-2025-61594 ↗2026-01-03azl3 ruby 3.3.5-6 on Azure Linux 3.0LowOut-of-bandURI Credential Leakage Bypass over CVE-2025-27221
CVE-2025-62223 ↗2025-12-04Microsoft Edge (Chromium-based)LowOut-of-band0%Microsoft Edge (Chromium-based) for Mac Spoofing Vulnerability
CVE-2025-65046 ↗2025-12-18Microsoft Edge for AndroidLowOut-of-band0%Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2025-68727 ↗2025-12-25azl3 kernel 6.6.117.1-1 on Azure Linux 3.0LowOut-of-bandntfs3: Fix uninit buffer allocated by __getname()
CVE-2025-13630 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13630 Type Confusion in V8
CVE-2025-13631 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13631 Inappropriate implementation in Google Updater
CVE-2025-13632 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13632 Inappropriate implementation in DevTools
CVE-2025-13633 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13633 Use after free in Digital Credentials
CVE-2025-13634 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13634 Inappropriate implementation in Downloads
CVE-2025-13635 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13635 Inappropriate implementation in Downloads
CVE-2025-13636 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13636 Inappropriate implementation in Split View
CVE-2025-13637 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13637 Inappropriate implementation in Downloads
CVE-2025-13638 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13638 Use after free in Media Stream
CVE-2025-13639 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13639 Inappropriate implementation in WebRTC
CVE-2025-13640 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13640 Inappropriate implementation in Passwords
CVE-2025-13720 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13720 Bad cast in Loader
CVE-2025-13721 ↗2025-12-04Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13721 Race in v8
CVE-2025-14174 ↗2025-12-15Microsoft Edge (Chromium-based)N/AOut-of-band23%CISA KEVVulnCheckENISAChromium: CVE-2025-14174 Out of bounds memory access in ANGLE
CVE-2025-14372 ↗2025-12-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-14372 Use after free in Password Manager
CVE-2025-14373 ↗2025-12-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-14373 Inappropriate implementation in Toolbar
CVE-2025-14765 ↗2025-12-18Microsoft Edge (Chromium-based)N/AOut-of-band3%Chromium: CVE-2025-14765 Out of bounds read and write in V8
CVE-2025-14766 ↗2025-12-18Microsoft Edge (Chromium-based)N/AOut-of-band3%Chromium: CVE-2025-14766 Use after free in WebGPU
#

November 2025

Patch Tuesday November 11, 202581 CVEs plus 103 Azure Linux package advisories · 12 critical · 1 exploitation detected · 3 in KEV184 CVEs · 14 critical · 1 exploitation detected · 3 in KEV · includes 103 Azure Linux package advisories
Risk matrix, November 2025
8 of these counts use a severity derived from CVSS because Microsoft assigned none.
8 of these counts use a severity derived from CVSS because Microsoft assigned none.
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2025-62215 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant6%Exploitation detectedCISA KEVVulnCheckENISAKB5068779KB5068781
and 6 moreKB5068787KB5068791KB5068840KB5068861KB5068865KB5068966
Windows Kernel Elevation of Privilege Vulnerability
CVE-2025-30398 ↗2025-11-11Nuance PowerScribe 360 version 4.0.5Critical1%Nuance PowerScribe 360 Information Disclosure Vulnerability
CVE-2025-40165 ↗2025-11-13azl3 kernel 6.6.112.1-2 on Azure Linux 3.0CriticalOut-of-bandmedia: nxp: imx8-isi: m2m: Fix streaming cleanup on release
CVE-2025-40172 ↗2025-11-13azl3 kernel 6.6.112.1-2 on Azure Linux 3.0CriticalOut-of-bandaccel/qaic: Treat remaining == 0 as error in find_and_map_user_pages()
CVE-2025-49752 ↗2025-11-20Azure Bastion DeveloperCriticalOut-of-band1%Azure Bastion Elevation of Privilege Vulnerability
CVE-2025-59245 ↗2025-11-20Microsoft SharePoint OnlineCriticalOut-of-band1%Microsoft SharePoint Online Elevation of Privilege Vulnerability
CVE-2025-60716 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5068779KB5068781
and 6 moreKB5068787KB5068791KB5068840KB5068861KB5068865KB5068966
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2025-60724 ↗2025-11-11Microsoft Office LTSC for Mac 2021Critical6%KB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
GDI+ Remote Code Execution Vulnerability
CVE-2025-62199 ↗2025-11-11Microsoft Office 2016 (32-bit edition)Critical1%KB5002809Microsoft Office Remote Code Execution Vulnerability
CVE-2025-62207 ↗2025-11-20Azure Monitor Control ServiceCriticalOut-of-band1%Azure Monitor Elevation of Privilege Vulnerability
CVE-2025-62214 ↗2025-11-11Microsoft Visual Studio 2022 version 17.14Critical1%Visual Studio Remote Code Execution Vulnerability
CVE-2025-62459 ↗2025-11-20Microsoft 365 Defender PortalCriticalOut-of-band0%Microsoft Defender Portal Spoofing Vulnerability
CVE-2025-64655 ↗2025-11-20Dynamics OmniChannel SDK Storage ContainersCriticalOut-of-band0%More likelyDynamics OmniChannel SDK Storage Containers Elevation of Privilege Vulnerability
CVE-2025-64656 ↗2025-11-20Azure App GatewayCriticalOut-of-band1%Azure Application Gateway Elevation of Privilege Vulnerability
CVE-2025-64657 ↗2025-11-20Azure App GatewayCriticalOut-of-band1%Azure Application Gateway Elevation of Privilege Vulnerability
CVE-2024-25621 ↗2025-11-08cbl2 moby-containerd 1.6.26-12 on CBL Mariner 2.0ImportantOut-of-bandcontainerd affected by a local privilege escalation via wide permissions on CRI directory
CVE-2024-47866 ↗2025-11-14azl3 ceph 18.2.2-11 on Azure Linux 3.0ImportantOut-of-bandRGW DoS attack with empty HTTP header in S3 object copy
CVE-2025-12638 ↗2025-12-03azl3 keras 3.3.3-5 on Azure Linux 3.0ImportantOut-of-bandPath Traversal Vulnerability in keras-team/keras via Tar Archive Extraction in keras.utils.get_file()
CVE-2025-12816 ↗2025-11-29cbl2 reaper 3.1.1-19 on CBL Mariner 2.0ImportantOut-of-bandCVE-2025-12816
CVE-2025-12863 ↗2025-11-11cbl2 libxml2 2.10.4-9 on CBL Mariner 2.0ImportantLibxml2: namespace use-after-free in xmlsettreedoc() function of libxml2
CVE-2025-12970 ↗2025-11-29azl3 fluent-bit 3.1.10-2 on Azure Linux 3.0ImportantOut-of-bandCVE-2025-12970
CVE-2025-12977 ↗2025-11-29azl3 fluent-bit 3.1.9-6 on Azure Linux 3.0ImportantOut-of-bandCVE-2025-12977
CVE-2025-13226 ↗2025-11-21cbl2 nodejs18 18.20.3-9 on CBL Mariner 2.0ImportantOut-of-bandType Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-13227 ↗2025-11-21azl3 nodejs 20.14.0-9 on Azure Linux 3.0ImportantOut-of-bandType Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-13230 ↗2025-11-21cbl2 nodejs18 18.20.3-9 on CBL Mariner 2.0ImportantOut-of-bandType Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-13601 ↗2025-11-29cbl2 glib 2.71.0-7 on CBL Mariner 2.0ImportantOut-of-bandGlib: integer overflow in in g_escape_uri_string()
CVE-2025-31133 ↗2025-11-09cbl2 moby-runc 1.1.9-9 on CBL Mariner 2.0ImportantOut-of-bandrunc container escape via "masked path" abuse due to mount race conditions
CVE-2025-40135 ↗2025-11-13azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandipv6: use RCU in ip6_xmit()
CVE-2025-40139 ↗2025-11-13azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandsmc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set().
CVE-2025-40149 ↗2025-11-13azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandtls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().
CVE-2025-40170 ↗2025-11-13azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandnet: use dst_dev_rcu() in sk_setup_caps()
CVE-2025-40176 ↗2025-11-13azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandtls: wait for pending async decryptions if tls_strp_msg_hold fails
CVE-2025-40190 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandext4: guard against EA inode refcount underflow in xattr update
CVE-2025-40198 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandext4: avoid potential buffer over-read in parse_apply_sb_mount_options()
CVE-2025-40201 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandkernel/sys.c: fix the racy usage of task_lock(tsk->group_leader) in sys_prlimit64() paths
CVE-2025-40204 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandsctp: Fix MAC comparison to be constant-time
CVE-2025-40205 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandbtrfs: avoid potential out-of-bounds in btrfs_encode_fh()
CVE-2025-40211 ↗2025-11-22azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandACPI: video: Fix use-after-free in acpi_video_switch_brightness()
CVE-2025-47179 ↗2025-11-11Microsoft Configuration Manager 2403Important0%Configuration Manager Elevation of Privilege Vulnerability
CVE-2025-47913 ↗2025-11-17cbl2 moby-compose 2.17.3-11 on CBL Mariner 2.0ImportantOut-of-bandPotential denial of service in golang.org/x/crypto/ssh/agent
CVE-2025-52565 ↗2025-11-09cbl2 kubernetes 1.28.4-19 on CBL Mariner 2.0ImportantOut-of-bandcontainer escape due to /dev/console mount and related races
CVE-2025-52881 ↗2025-11-09cbl2 moby-runc 1.1.9-9 on CBL Mariner 2.0ImportantOut-of-bandrunc: LSM labels can be bypassed with malicious config using dummy procfs files
CVE-2025-59240 ↗2025-11-11Microsoft Office LTSC 2021 for 32-bit editionsImportant1%KB5002811Microsoft Excel Information Disclosure Vulnerability
CVE-2025-59499 ↗2025-11-11Microsoft SQL Server 2017 for x64-based Systems (GDR)Important1%KB5068400KB5068401
and 6 moreKB5068402KB5068403KB5068404KB5068405KB5068406KB5068407
Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-59504 ↗2025-11-11Azure MonitorImportant0%Azure Monitor Agent Remote Code Execution Vulnerability
CVE-2025-59505 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 9 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068905KB5068907KB5068966
Windows Smart Card Reader Elevation of Privilege Vulnerability
CVE-2025-59506 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 9 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068905KB5068907KB5068966
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2025-59507 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 7 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068966
Windows Speech Runtime Elevation of Privilege Vulnerability
CVE-2025-59508 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 7 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068966
Windows Speech Recognition Elevation of Privilege Vulnerability
CVE-2025-59509 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5068779KB5068781
and 6 moreKB5068787KB5068791KB5068840KB5068861KB5068865KB5068966
Windows Speech Recognition Information Disclosure Vulnerability
CVE-2025-59510 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 8 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068905KB5068966
Windows Routing and Remote Access Service (RRAS) Denial of Service Vulnerability
CVE-2025-59511 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 6 moreKB5068787KB5068791KB5068840KB5068861KB5068865KB5068966
Windows WLAN Service Elevation of Privilege Vulnerability
CVE-2025-59512 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant3%More likelyKB5068779KB5068781
and 9 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068905KB5068907KB5068966
Customer Experience Improvement Program (CEIP) Elevation of Privilege Vulnerability
CVE-2025-59513 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 11 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068906KB5068908KB5068909KB5068966
Windows Bluetooth RFCOM Protocol Driver Information Disclosure Vulnerability
CVE-2025-59514 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
CVE-2025-59515 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 4 moreKB5068791KB5068861KB5068865KB5068966
Windows Broadcast DVR User Service Elevation of Privilege Vulnerability
CVE-2025-59777 ↗2025-11-13azl3 libmicrohttpd 0.9.77-3 on Azure Linux 3.0ImportantOut-of-bandNULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.
CVE-2025-60703 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVE-2025-60704 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Kerberos Elevation of Privilege Vulnerability
CVE-2025-60705 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Client-Side Caching Elevation of Privilege Vulnerability
CVE-2025-60706 ↗2025-11-11Windows 10 Version 1809 for x64-based SystemsImportant0%KB5068779KB5068781
and 7 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068966
Windows Hyper-V Information Disclosure Vulnerability
CVE-2025-60707 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 6 moreKB5068787KB5068791KB5068840KB5068861KB5068865KB5068966
Multimedia Class Scheduler Service (MMCSS) Driver Elevation of Privilege Vulnerability
CVE-2025-60708 ↗2025-11-11Windows 10 Version 1809 for x64-based SystemsImportant0%KB5068779KB5068781
and 7 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068966
Storvsp.sys Driver Denial of Service Vulnerability
CVE-2025-60709 ↗2025-11-11Windows 11 Version 25H2 for ARM64-based SystemsImportant1%KB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2025-60710 ↗2025-11-11Windows Server 2025 (Server Core installation)Important5%CISA KEVVulnCheckENISAKB5072014KB5072033Host Process for Windows Tasks Elevation of Privilege Vulnerability
CVE-2025-60713 ↗2025-11-11Windows Server 2019Important0%KB5068779KB5068787
and 5 moreKB5068791KB5068840KB5068861KB5068864KB5068966
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
CVE-2025-60714 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5068779KB5068781
and 11 moreKB5068787KB5068791KB5068840KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909
Windows OLE Remote Code Execution Vulnerability
CVE-2025-60715 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-60717 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 4 moreKB5068791KB5068861KB5068865KB5068966
Windows Broadcast DVR User Service Elevation of Privilege Vulnerability
CVE-2025-60718 ↗2025-11-11Windows 11 Version 24H2 for ARM64-based SystemsImportant0%KB5068861KB5068966Windows Administrator Protection Elevation of Privilege Vulnerability
CVE-2025-60719 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-60720 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege Vulnerability
CVE-2025-60721 ↗2025-11-11Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5068861KB5068966Windows Administrator Protection Elevation of Privilege Vulnerability
CVE-2025-60722 ↗2025-11-11OneDrive for AndroidImportant1%Microsoft OneDrive for Android Elevation of Privilege Vulnerability
CVE-2025-60723 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5068779KB5068781
and 6 moreKB5068787KB5068791KB5068840KB5068861KB5068865KB5068966
DirectX Graphics Kernel Denial of Service Vulnerability
CVE-2025-60726 ↗2025-11-11Office Online ServerImportant1%KB5002801KB5002810
and 1 moreKB5002811
Microsoft Excel Information Disclosure Vulnerability
CVE-2025-60727 ↗2025-11-11Office Online ServerImportant1%KB5002801KB5002810
and 1 moreKB5002811
Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-60728 ↗2025-11-11Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant1%Microsoft Excel Information Disclosure Vulnerability
CVE-2025-60876 ↗2025-11-13azl3 busybox 1.36.1-19 on Azure Linux 3.0ImportantOut-of-bandBusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).
CVE-2025-62200 ↗2025-11-11Office Online ServerImportant0%KB5002801KB5002811Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62201 ↗2025-11-11Office Online ServerImportant0%KB5002801KB5002811Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62202 ↗2025-11-11Office Online ServerImportant1%KB5002801KB5002810
and 1 moreKB5002811
Microsoft Excel Information Disclosure Vulnerability
CVE-2025-62203 ↗2025-11-11Office Online ServerImportant0%KB5002801KB5002811Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62204 ↗2025-11-11Microsoft SharePoint Enterprise Server 2016Important1%KB5002800KB5002803
and 1 moreKB5002805
Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2025-62205 ↗2025-11-11Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft Office Remote Code Execution Vulnerability
CVE-2025-62206 ↗2025-11-11Microsoft Dynamics 365 (on-premises) version 9.1Important1%KB5067331Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2025-62208 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows License Manager Information Disclosure Vulnerability
CVE-2025-62209 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows License Manager Information Disclosure Vulnerability
CVE-2025-62210 ↗2025-11-11Dynamics 365 Field Service (online)Important1%Dynamics 365 Field Service (online) Spoofing Vulnerability
CVE-2025-62211 ↗2025-11-11Dynamics 365 Field Service (online)Important1%Dynamics 365 Field Service (online) Spoofing Vulnerability
CVE-2025-62213 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-62216 ↗2025-11-11Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft Office Remote Code Execution Vulnerability
CVE-2025-62217 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-62218 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068781KB5068791
and 4 moreKB5068861KB5068864KB5068865KB5068966
Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability
CVE-2025-62219 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068781KB5068791
and 4 moreKB5068861KB5068864KB5068865KB5068966
Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability
CVE-2025-62220 ↗2025-11-11Windows Subsystem for Linux GUIImportant1%Windows Subsystem for Linux GUI Remote Code Execution Vulnerability
CVE-2025-62222 ↗2025-11-11Microsoft Visual Studio Code CoPilot Chat ExtensionImportant1%Agentic AI and Visual Studio Code Remote Code Execution Vulnerability
CVE-2025-62449 ↗2025-11-11Microsoft Visual Studio Code CoPilot Chat ExtensionImportant0%Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability
CVE-2025-62452 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-62453 ↗2025-11-11Visual Studio CodeImportant0%GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability
CVE-2025-62689 ↗2025-11-13azl3 libmicrohttpd 0.9.77-3 on Azure Linux 3.0ImportantOut-of-bandNULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.
CVE-2025-64324 ↗2025-11-20azl3 kubevirt 1.5.3-2 on Azure Linux 3.0ImportantOut-of-bandKubeVirt Vulnerable to Arbitrary Host File Read and Write
CVE-2025-64660 ↗2025-11-20Visual Studio CodeImportantOut-of-band1%GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability
CVE-2025-64720 ↗2025-11-27Windows 10 Version 1809 for 32-bit SystemsImportantOut-of-band0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
LIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premultiplication
CVE-2025-65018 ↗2025-11-27Windows 10 Version 1809 for 32-bit SystemsImportantOut-of-band0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
LIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read`
CVE-2025-66031 ↗2025-11-29azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandnode-forge ASN.1 Unbounded Recursion
CVE-2011-10034 ↗2025-11-14azl3 autogen 5.18.16-9 on Azure Linux 3.0ModerateOut-of-bandIRAI AUTOMGEN <= 8.0.0.7 Use-After-Free Remote DoS
CVE-2025-10158 ↗2025-11-19azl3 rsync 3.4.1-1 on Azure Linux 3.0ModerateOut-of-bandRsync: Out of bounds array access via negative index
CVE-2025-10966 ↗2025-11-08azl3 cmake 3.30.3-10 on Azure Linux 3.0ModerateOut-of-bandmissing SFTP host verification with wolfSSH
CVE-2025-11230 ↗2025-11-21cbl2 haproxy 2.4.24-1 on CBL Mariner 2.0ModerateOut-of-bandDenial of service vulnerability in HAProxy mjson library
CVE-2025-11935 ↗2025-11-25azl3 mariadb 10.11.11-1 on Azure Linux 3.0ModerateOut-of-bandForward Secrecy Violation in WolfSSL TLS 1.3
CVE-2025-11936 ↗2025-11-25azl3 mariadb 10.11.11-1 on Azure Linux 3.0ModerateOut-of-bandPotential DoS Vulnerability through Multiple KeyShareEntry with Same Group in TLS 1.3 ClientHello
CVE-2025-12748 ↗2025-11-15azl3 libvirt 10.0.0-6 on Azure Linux 3.0ModerateOut-of-bandLibvirt: denial of service in xml parsing
CVE-2025-12818 ↗2025-11-14azl3 rust 1.90.0-3 on Azure Linux 3.0ModerateOut-of-bandPostgreSQL libpq undersizes allocations, via integer wraparound
CVE-2025-12875 ↗2025-11-11azl3 nghttp2 1.61.0-2 on Azure Linux 3.0Moderatemruby array.c ary_fill_exec out-of-bounds write
CVE-2025-12969 ↗2025-11-29cbl2 fluent-bit 3.0.6-4 on CBL Mariner 2.0ModerateOut-of-bandCVE-2025-12969
CVE-2025-13120 ↗2025-11-19cbl2 rust 1.72.0-11 on CBL Mariner 2.0ModerateOut-of-bandmruby array.c sort_cmp use after free
CVE-2025-13193 ↗2025-11-21azl3 libvirt 10.0.0-5 on Azure Linux 3.0ModerateOut-of-bandLibvirt: information disclosure via world-readable vm snapshots
CVE-2025-40107 ↗2025-11-04azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandcan: hi311x: fix null pointer dereference when resuming from sleep before interface was enabled
CVE-2025-40109 ↗2025-11-10azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandcrypto: rng - Ensure set_ent is always present
CVE-2025-40110 ↗2025-11-13azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/vmwgfx: Fix a null-ptr access in the cursor snooper
CVE-2025-40111 ↗2025-11-13azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/vmwgfx: Fix Use-after-free in validation
CVE-2025-40136 ↗2025-11-13azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandcrypto: hisilicon/qm - request reserved interrupt for virtual function
CVE-2025-40146 ↗2025-11-13azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandblk-mq: fix potential deadlock while nr_requests grown
CVE-2025-40158 ↗2025-11-13azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandipv6: use RCU in ip6_output()
CVE-2025-40164 ↗2025-11-13azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandusbnet: Fix using smp_processor_id() in preemptible code warnings
CVE-2025-40167 ↗2025-11-13azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandext4: detect invalid INLINE_DATA + EXTENTS flag combination
CVE-2025-40168 ↗2025-11-13azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandsmc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().
CVE-2025-40173 ↗2025-11-13azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnet/ip6_tunnel: Prevent perpetual tunnel growth
CVE-2025-40178 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandpid: Add a judgment for ns null in pid_nr_ns
CVE-2025-40179 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandext4: verify orphan file size is not too big
CVE-2025-40180 ↗2025-11-14azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandmailbox: zynqmp-ipi: Fix out-of-bounds access in mailbox cleanup loop
CVE-2025-40187 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnet/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce()
CVE-2025-40188 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandpwm: berlin: Fix wrong register in suspend/resume
CVE-2025-40192 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandRevert "ipmi: fix msg stack when IPMI is disconnected"
CVE-2025-40193 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandxtensa: simdisk: add input size check in proc_write_simdisk
CVE-2025-40194 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandcpufreq: intel_pstate: Fix object lifecycle issue in update_qos_request()
CVE-2025-40195 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandmount: handle NULL values in mnt_ns_release()
CVE-2025-40197 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandmedia: mc: Clear minor number before put device
CVE-2025-40200 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandSquashfs: reject negative file sizes in squashfs_read_inode()
CVE-2025-40202 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandipmi: Rework user message limit handling
CVE-2025-40206 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nft_objref: validate objref and objrefmap expressions
CVE-2025-40207 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandmedia: v4l2-subdev: Fix alloc failure check in v4l2_subdev_call_state_try()
CVE-2025-40210 ↗2025-11-22azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandRevert "NFSD: Remove the cap on number of operations per NFSv4 COMPOUND"
CVE-2025-40213 ↗2026-06-10azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete
CVE-2025-54770 ↗2025-11-21cbl2 grub2 2.06-15 on CBL Mariner 2.0ModerateOut-of-bandGrub2: use-after-free in net_set_vlan
CVE-2025-54771 ↗2025-11-21cbl2 grub2 2.06-15 on CBL Mariner 2.0ModerateOut-of-bandGrub2: use-after-free in grub_file_close()
CVE-2025-58436 ↗2025-11-30azl3 cups 2.4.13-1 on Azure Linux 3.0ModerateOut-of-bandOpenPrinting CUPS slow client can halt cupsd, leading to a possible DoS attack
CVE-2025-60753 ↗2025-11-11azl3 libarchive 3.7.7-3 on Azure Linux 3.0ModerateAn issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).
CVE-2025-61661 ↗2025-11-21cbl2 grub2 2.06-15 on CBL Mariner 2.0ModerateOut-of-bandGrub2: grub2: out-of-bounds write via malicious usb device
CVE-2025-61662 ↗2025-11-21cbl2 grub2 2.06-15 on CBL Mariner 2.0ModerateOut-of-bandGrub2: missing unregister call for gettext command may lead to use-after-free
CVE-2025-61663 ↗2025-11-21cbl2 grub2 2.06-15 on CBL Mariner 2.0ModerateOut-of-bandGrub2: missing unregister call for normal commands may lead to use-after-free
CVE-2025-61664 ↗2025-11-21cbl2 grub2 2.06-15 on CBL Mariner 2.0ModerateOut-of-bandGrub2: missing unregister call for normal_exit command may lead to use-after-free
CVE-2025-61915 ↗2025-11-30azl3 cups 2.4.13-1 on Azure Linux 3.0ModerateOut-of-bandOpenPrinting CUPS vulnerable to stack based out-of-bound write
CVE-2025-64329 ↗2025-11-08azl3 containerd2 2.0.0-14 on Azure Linux 3.0ModerateOut-of-bandcontainerd CRI server: Host memory exhaustion through Attach goroutine leak
CVE-2025-64432 ↗2025-11-09cbl2 kubevirt 0.59.0-30 on CBL Mariner 2.0ModerateOut-of-bandKubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer
CVE-2025-64433 ↗2025-11-09cbl2 kubevirt 0.59.0-30 on CBL Mariner 2.0ModerateOut-of-bandKubeVirt Arbitrary Container File Read
CVE-2025-64434 ↗2025-11-09cbl2 kubevirt 0.59.0-30 on CBL Mariner 2.0ModerateOut-of-bandKubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing
CVE-2025-64435 ↗2025-11-09azl3 kubevirt 1.5.0-5 on Azure Linux 3.0ModerateOut-of-bandKubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation
CVE-2025-64436 ↗2025-11-09cbl2 kubevirt 0.59.0-30 on CBL Mariner 2.0ModerateOut-of-bandKubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
CVE-2025-64437 ↗2025-11-09cbl2 kubevirt 0.59.0-30 on CBL Mariner 2.0ModerateOut-of-bandKubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes
CVE-2025-64505 ↗2025-11-26cbl2 qt5-qtbase 5.12.11-18 on CBL Mariner 2.0ModerateOut-of-bandLIBPNG is vulnerable to a heap buffer overflow in `png_do_quantize` via malformed palette index
CVE-2025-64506 ↗2025-11-27azl3 libpng 1.6.40-1 on Azure Linux 3.0ModerateOut-of-bandLIBPNG is vulnerable to a heap buffer over-read in `png_write_image_8bit` with grayscale+alpha or RGB/RGBA images
CVE-2025-64704 ↗2025-11-29azl3 fluent-bit 3.1.9-6 on Azure Linux 3.0ModerateOut-of-bandWebAssembly Micro Runtime vulnerable to a segmentation fault in v128.store instruction
CVE-2025-64713 ↗2025-11-29cbl2 fluent-bit 3.0.6-4 on CBL Mariner 2.0ModerateOut-of-bandWebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcode
CVE-2025-66030 ↗2025-11-29cbl2 reaper 3.1.1-19 on CBL Mariner 2.0ModerateOut-of-bandnode-forge ASN.1 OID Integer Truncation
CVE-2025-66221 ↗2025-12-03azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandWerkzeug safe_join() allows Windows special device names
CVE-2025-11931 ↗2025-11-25cbl2 mariadb 10.6.21-1 on CBL Mariner 2.0LowOut-of-bandInteger Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt
CVE-2025-11932 ↗2025-11-25cbl2 mariadb 10.6.21-1 on CBL Mariner 2.0LowOut-of-bandTiming Side-Channel in PSK Binder Verification
CVE-2025-11933 ↗2025-11-25azl3 mariadb 10.11.11-1 on Azure Linux 3.0LowOut-of-bandDoS Vulnerability in wolfSSL TLS 1.3 CKS Extension
CVE-2025-11934 ↗2025-11-25azl3 mariadb 10.11.11-1 on Azure Linux 3.0LowOut-of-bandImproper Validation of Signature Algorithm Used in TLS 1.3 CertificateVerify
CVE-2025-12817 ↗2025-11-14cbl2 postgresql 14.19-1 on CBL Mariner 2.0LowOut-of-bandPostgreSQL CREATE STATISTICS does not check for schema CREATE privilege
CVE-2025-12888 ↗2025-11-25cbl2 mariadb 10.6.21-1 on CBL Mariner 2.0LowOut-of-bandConstant Time Issue with Xtensa-based ESP32 and X22519
CVE-2025-12889 ↗2025-11-25azl3 mariadb 10.11.11-1 on Azure Linux 3.0LowOut-of-bandTLS 1.2 Client Can Downgrade Digest Used
CVE-2025-2486 ↗2025-11-29cbl2 edk2 20230301gitf80f052277c8-43 on CBL Mariner 2.0LowOut-of-bandUEFI Shell accessible in AAVMF with Secure Boot enabled on Ubuntu
CVE-2025-66382 ↗2025-11-29azl3 expat 2.6.4-2 on Azure Linux 3.0LowOut-of-bandIn libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.
CVE-2025-12725 ↗2025-11-06Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12725 Out of bounds write in WebGPU
CVE-2025-12726 ↗2025-11-06Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12726 Inappropriate implementation in Views.
CVE-2025-12727 ↗2025-11-06Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12727 Inappropriate implementation in V8
CVE-2025-12728 ↗2025-11-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12728 Inappropriate implementation in Omnibox
CVE-2025-12729 ↗2025-11-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12729 Inappropriate implementation in Omnibox
CVE-2025-13042 ↗2025-11-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13042 Inappropriate implementation in V8
CVE-2025-13223 ↗2025-11-18Microsoft Edge (Chromium-based)N/AOut-of-band5%CISA KEVVulnCheckENISAChromium: CVE-2025-13223 Type Confusion in V8
CVE-2025-13224 ↗2025-11-18Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13224 Type Confusion in V8
#

October 2025

Patch Tuesday October 14, 2025222 CVEs plus 205 Azure Linux package advisories · 21 critical · 3 exploitation detected · 4 in KEV427 CVEs · 41 critical · 3 exploitation detected · 4 in KEV · includes 205 Azure Linux package advisories
Risk matrix, October 2025
35 of these counts use a severity derived from CVSS because Microsoft assigned none.
35 of these counts use a severity derived from CVSS because Microsoft assigned none.
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2025-24990 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant6%Exploitation detectedCISA KEVVulnCheckENISAKB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows Agere Modem Driver Elevation of Privilege Vulnerability
CVE-2025-47827 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant4%Exploitation detectedCISA KEVVulnCheckENISAKB5066586KB5066780
and 8 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066873KB5066875
MITRE CVE-2025-47827: Secure Boot bypass in IGEL OS before 11
CVE-2025-59230 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant3%Exploitation detectedCISA KEVVulnCheckENISAKB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVE-2016-9535 ↗2025-10-14Microsoft Office for AndroidCritical5%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
MITRE CVE-2016-9535: LibTIFF Heap Buffer Overflow Vulnerability
CVE-2025-0033 ↗2025-10-13Azure Confidential Compute VM SKU ECasv5/ECadsv5CriticalOut-of-band0%AMD CVE-2025-0033: RMP Corruption During SNP Initialization
CVE-2025-2884 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsCritical0%KB5066780KB5066793
and 2 moreKB5066835KB5077179
Cert CC: CVE-2025-2884 Out-of-Bounds read vulnerability in TCG TPM2.0 reference implementation
CVE-2025-39898 ↗2025-10-02azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bande1000e: fix heap overflow in e1000_set_eeprom
CVE-2025-39907 ↗2025-10-02azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandmtd: rawnand: stm32_fmc2: avoid overlapping mappings on ECC buffer
CVE-2025-39910 ↗2025-10-02azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandmm/vmalloc, mm/kasan: respect gfp mask in kasan_populate_vmalloc()
CVE-2025-39925 ↗2025-10-02azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandcan: j1939: implement NETDEV_UNREGISTER notification handler
CVE-2025-39943 ↗2025-10-05azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandksmbd: smbdirect: validate data_offset and data_length field of smb_direct_data_transfer
CVE-2025-39967 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandfbcon: fix integer overflow in fbcon_do_set_font
CVE-2025-39968 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandi40e: add max boundary check for VF filters
CVE-2025-39970 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandi40e: fix input validation logic for action_meta
CVE-2025-39971 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandi40e: fix idx validation in config queues msg
CVE-2025-39972 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandi40e: fix idx validation in i40e_validate_queue_map
CVE-2025-39973 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandi40e: add validation for ring_len param
CVE-2025-39978 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandocteontx2-pf: Fix potential use after free in otx2_tc_add_flow()
CVE-2025-39981 ↗2025-10-16azl3 kernel 6.6.112.1-2 on Azure Linux 3.0CriticalOut-of-bandBluetooth: MGMT: Fix possible UAFs
CVE-2025-39985 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandcan: mcba_usb: populate ndo_change_mtu() to prevent buffer overflow
CVE-2025-39986 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandcan: sun4i_can: populate ndo_change_mtu() to prevent buffer overflow
CVE-2025-39994 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandmedia: tuner: xc5000: Fix use-after-free in xc5000_release
CVE-2025-39996 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandmedia: b2c2: Fix use-after-free causing by irq_check_work in flexcop_pci_remove
CVE-2025-40000 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandwifi: rtw89: fix use-after-free in rtw89_core_tx_kick_off_and_wait()
CVE-2025-49708 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
Microsoft Graphics Component Elevation of Privilege Vulnerability
CVE-2025-49844 ↗2025-10-08cbl2 redis 6.2.18-3 on CBL Mariner 2.0CriticalOut-of-band87%VulnCheck1 mentionsRedis Lua Use-After-Free may lead to remote code execution
CVE-2025-55321 ↗2025-10-09Azure MonitorCriticalOut-of-band0%Azure Monitor Log Analytics Spoofing Vulnerability
CVE-2025-59218 ↗2025-10-09Microsoft Entra IDCriticalOut-of-band1%Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-59227 ↗2025-10-14Microsoft Office 2016 (64-bit edition)Critical0%KB5002792Microsoft Office Remote Code Execution Vulnerability
CVE-2025-59234 ↗2025-10-14Microsoft Office 2016 (32-bit edition)Critical1%KB5002792Microsoft Office Remote Code Execution Vulnerability
CVE-2025-59236 ↗2025-10-14Office Online ServerCritical0%KB5002797Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-59246 ↗2025-10-09Microsoft Entra IDCriticalOut-of-band7%More likelyAzure Entra ID Elevation of Privilege Vulnerability
CVE-2025-59247 ↗2025-10-09Azure PlayFabCriticalOut-of-band1%Azure PlayFab Elevation of Privilege Vulnerability
CVE-2025-59252 ↗2025-10-09Microsoft 365 Word CopilotCriticalOut-of-band1%M365 Copilot Information Disclosure Vulnerability
CVE-2025-59271 ↗2025-10-09Azure Cache for Redis EnterpriseCriticalOut-of-band1%Redis Enterprise Elevation of Privilege Vulnerability
CVE-2025-59272 ↗2025-10-09Microsoft 365 Copilot's Business ChatCriticalOut-of-band1%Copilot Information Disclosure Vulnerability
CVE-2025-59273 ↗2025-10-23Azure Event Grid SystemCriticalOut-of-band0%Azure Event Grid System Elevation of Privilege Vulnerability
CVE-2025-59286 ↗2025-10-09Microsoft 365 Copilot's Business ChatCriticalOut-of-band1%Copilot Information Disclosure Vulnerability
CVE-2025-59287 ↗2025-10-14Windows Server 2019Critical100%More likelyCISA KEVVulnCheckENISAKB5070879KB5070881
and 7 moreKB5070882KB5070883KB5070884KB5070886KB5070887KB5070892KB5070893
1 mentionsWindows Server Update Service (WSUS) Remote Code Execution Vulnerability
CVE-2025-59291 ↗2025-10-14Azure Compute GalleryCritical0%Confidential Azure Container Instances Elevation of Privilege Vulnerability
CVE-2025-59292 ↗2025-10-14Azure Compute GalleryCritical0%Azure Compute Gallery Elevation of Privilege Vulnerability
CVE-2025-59500 ↗2025-10-23Azure Notification ServiceCriticalOut-of-band1%Azure Notification Service Elevation of Privilege Vulnerability
CVE-2025-59503 ↗2025-10-23Azure Compute Resource ProviderCriticalOut-of-band1%Azure Compute Resource Provider Elevation of Privilege Vulnerability
CVE-2025-62168 ↗2025-10-19azl3 squid 6.13-1 on Azure Linux 3.0CriticalOut-of-bandSquid vulnerable to information disclosure via authentication credential leakage in error handling
CVE-2023-53469 ↗2025-10-02azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandaf_unix: Fix null-ptr-deref in unix_stream_sendpage().
CVE-2023-53543 ↗2026-02-25cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandvdpa: Add max vqp attr to vdpa_nl_policy for nlattr length check
CVE-2025-10728 ↗2025-10-07azl3 qtsvg 6.6.1-2 on Azure Linux 3.0ImportantOut-of-bandUncontrolled recursion in Qt SVG module
CVE-2025-10729 ↗2025-10-07azl3 qtsvg 6.6.1-2 on Azure Linux 3.0ImportantOut-of-bandUse-after-free vulnerability in Qt SVG qsvghandler.cpp allows denial of service via crafted SVG
CVE-2025-12060 ↗2025-11-01azl3 keras 3.3.3-4 on Azure Linux 3.0ImportantOut-of-bandKeras keras.utils.get_file Utility Path Traversal Vulnerability
CVE-2025-12105 ↗2025-12-21azl3 libsoup 3.4.4-10 on Azure Linux 3.0ImportantOut-of-bandLibsoup: heap use-after-free in libsoup message queue handling during http/2 read completion
CVE-2025-24052 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant2%More likelyKB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows Agere Modem Driver Elevation of Privilege Vulnerability
CVE-2025-25004 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
PowerShell Elevation of Privilege Vulnerability
CVE-2025-39901 ↗2025-10-02azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandi40e: remove read access to debugfs files
CVE-2025-39905 ↗2025-10-02azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandnet: phylink: add lock for serializing concurrent pl->phydev writes with resolver
CVE-2025-39911 ↗2025-10-02azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandi40e: fix IRQ freeing in i40e_vsi_request_irq_msix error path
CVE-2025-39944 ↗2025-10-05azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandocteontx2-pf: Fix use-after-free bugs in otx2_sync_tstamp()
CVE-2025-39945 ↗2025-10-05azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandcnic: Fix use-after-free bugs in cnic_delete_task
CVE-2025-39952 ↗2025-10-05azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandwifi: wilc1000: avoid buffer overflow in WID string configuration
CVE-2025-39977 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandfutex: Prevent use-after-free during requeue-PI
CVE-2025-39980 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandnexthop: Forbid FDB status change while nexthop is in a group
CVE-2025-39982 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandBluetooth: hci_event: Fix UAF in hci_acl_create_conn_sync
CVE-2025-39987 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandcan: hi311x: populate ndo_change_mtu() to prevent buffer overflow
CVE-2025-39988 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandcan: etas_es58x: populate ndo_change_mtu() to prevent buffer overflow
CVE-2025-39993 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandmedia: rc: fix races with imon_disconnect()
CVE-2025-39995 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandmedia: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe
CVE-2025-39998 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandscsi: target: target_core_configfs: Add length check to avoid buffer overflow
CVE-2025-40001 ↗2025-10-19azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandscsi: mvsas: Fix use-after-free bugs in mvs_work_queue
CVE-2025-40003 ↗2025-10-19azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandnet: mscc: ocelot: Fix use-after-free caused by cyclic delayed work
CVE-2025-40018 ↗2025-10-25azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandipvs: Defer ip_vs_ftp unregister during netns cleanup
CVE-2025-40020 ↗2025-10-26azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandcan: peak_usb: fix shift-out-of-bounds issue
CVE-2025-40036 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandmisc: fastrpc: fix possible map leak in fastrpc_put_args
CVE-2025-40039 ↗2025-10-29cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandksmbd: Fix race condition in RPC handle list access
CVE-2025-40048 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-banduio_hv_generic: Let userspace take care of interrupt mask
CVE-2025-40055 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandocfs2: fix double free in user_cluster_connect()
CVE-2025-40057 ↗2025-10-29azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandptp: Add a upper bound on max_vclocks
CVE-2025-40065 ↗2025-10-29azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandRISC-V: KVM: Write hgatp register with valid mode bits
CVE-2025-40068 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandfs: ntfs3: Fix integer overflow in run_unpack()
CVE-2025-40074 ↗2025-10-29azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandipv4: start using dst_dev_rcu()
CVE-2025-40075 ↗2025-10-29azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandtcp_metrics: use dst_dev_net_rcu()
CVE-2025-40077 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandf2fs: fix to avoid overflow while left shift operation
CVE-2025-40081 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandperf: arm_spe: Prevent overflow in PERF_IDX2OFF()
CVE-2025-40082 ↗2026-02-28azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandhfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
CVE-2025-40090 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandksmbd: fix recursive locking in RPC handle list access
CVE-2025-40093 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandusb: gadget: f_ecm: Refactor bind path to use __free()
CVE-2025-40096 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-banddrm/sched: Fix potential double free in drm_sched_job_add_resv_dependencies
CVE-2025-40102 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandKVM: arm64: Prevent access to vCPU events before init
CVE-2025-40103 ↗2025-10-31azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandsmb: client: Fix refcount leak for cifs_sb_tlink
CVE-2025-40105 ↗2025-10-31azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandvfs: Don't leak disconnected dentries on umount
CVE-2025-40778 ↗2025-10-25azl3 bind 9.20.15-1 on Azure Linux 3.0ImportantOut-of-bandCache poisoning attacks with unsolicited RRs
CVE-2025-40780 ↗2025-10-25azl3 bind 9.20.15-1 on Azure Linux 3.0ImportantOut-of-bandCache poisoning due to weak PRNG
CVE-2025-46817 ↗2025-10-10azl3 valkey 8.0.4-1 on Azure Linux 3.0ImportantOut-of-bandLua library commands may lead to integer overflow and potential RCE
CVE-2025-47912 ↗2025-10-31cbl2 golang 1.18.8-10 on CBL Mariner 2.0ImportantOut-of-bandInsufficient validation of bracketed IPv6 hostnames in net/url
CVE-2025-47979 ↗2025-10-14Windows Server 2025 (Server Core installation)Important1%KB5066780KB5066835Microsoft Failover Cluster Information Disclosure Vulnerability
CVE-2025-47989 ↗2025-10-14Arc Enabled Servers - Azure Connected Machine AgentImportant1%Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2025-48004 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant2%More likelyKB5066780KB5066793
and 1 moreKB5066835
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2025-48813 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
Virtual Secure Mode Spoofing Vulnerability
CVE-2025-50152 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows Kernel Elevation of Privilege Vulnerability
CVE-2025-50174 ↗2025-10-14Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5066835Windows Device Association Broker Service Elevation of Privilege Vulnerability
CVE-2025-50175 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-53139 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066791KB5066793
and 1 moreKB5066835
Windows Hello Security Feature Bypass Vulnerability
CVE-2025-53150 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 3 moreKB5066791KB5066793KB5066835
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-53717 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066793KB5066835Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
CVE-2025-53768 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066791
and 4 moreKB5066793KB5066835KB5066836KB5066837
Xbox IStorageService Elevation of Privilege Vulnerability
CVE-2025-53782 ↗2025-10-14Microsoft Exchange Server 2019 Cumulative Update 15Important0%KB5066366KB5066367
and 2 moreKB5066368KB5066369
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2025-54132 ↗2025-10-14Microsoft Visual Studio 2022 version 17.14Important0%GitHub CVE-2025-54132: Arbitrary Image Fetch in Mermaid Diagram Tool
CVE-2025-54957 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant2%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
1 mentionsMITRE CVE-2025-54957: Integer overflow in Dolby Digital Plus audio decoder
CVE-2025-55240 ↗2025-10-14Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)Important0%Visual Studio Elevation of Privilege Vulnerability
CVE-2025-55247 ↗2025-10-14.NET 8.0 installed on LinuxImportant1%KB5068331KB5068332.NET Elevation of Privilege Vulnerability
CVE-2025-55248 ↗2025-10-14.NET 8.0 installed on LinuxImportant1%KB5066128KB5066129
and 14 moreKB5066131KB5066133KB5066136KB5066738KB5066739KB5066740KB5066741KB5066742KB5066743KB5066746KB5066747KB5066836KB5068331KB5068332
.NET, .NET Framework, and Visual Studio Information Disclosure Vulnerability
CVE-2025-55315 ↗2025-10-14ASP.NET Core 8.0Important66%KB5068331KB5068332ASP.NET Security Feature Bypass Vulnerability
CVE-2025-55320 ↗2025-10-14Microsoft Configuration Manager 2503Important1%Configuration Manager Elevation of Privilege Vulnerability
CVE-2025-55325 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows Storage Management Provider Information Disclosure Vulnerability
CVE-2025-55326 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
Windows Connected Devices Platform Service (Cdpsvc) Remote Code Execution Vulnerability
CVE-2025-55328 ↗2025-10-14Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-55330 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant1%KB5066780KB5066793
and 1 moreKB5066835
Windows BitLocker Security Feature Bypass Vulnerability
CVE-2025-55331 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066780KB5066782
and 3 moreKB5066791KB5066793KB5066835
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
CVE-2025-55332 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant1%KB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
Windows BitLocker Security Feature Bypass Vulnerability
CVE-2025-55333 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant1%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows BitLocker Security Feature Bypass Vulnerability
CVE-2025-55334 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066793KB5066835Windows Kernel Security Feature Bypass Vulnerability
CVE-2025-55335 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows NTFS Elevation of Privilege Vulnerability
CVE-2025-55336 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant1%KB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability
CVE-2025-55337 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066835Windows BitLocker Security Feature Bypass Vulnerability
CVE-2025-55338 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant3%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows BitLocker Security Feature Bypass Vulnerability
CVE-2025-55339 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066780KB5066782
and 2 moreKB5066793KB5066835
Windows Network Driver Interface Specification (NDIS) Driver Elevation of Privilege Vulnerability
CVE-2025-55340 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066780KB5066782
and 3 moreKB5066791KB5066793KB5066835
Windows Remote Desktop Protocol Security Feature Bypass
CVE-2025-55676 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant1%More likelyKB5066835Windows USB Video Class System Driver Information Disclosure Vulnerability
CVE-2025-55677 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066835Windows Device Association Broker Service Elevation of Privilege Vulnerability
CVE-2025-55678 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 10 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066875KB5066876
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2025-55679 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
Windows Kernel Information Disclosure Vulnerability
CVE-2025-55680 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%More likelyKB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2025-55681 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant5%More likelyKB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2025-55682 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066835Windows BitLocker Security Feature Bypass Vulnerability
CVE-2025-55683 ↗2025-10-14Windows Server 2019Important1%KB5066586KB5066780
and 3 moreKB5066782KB5066835KB5066836
Windows Kernel Information Disclosure Vulnerability
CVE-2025-55684 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066835Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
CVE-2025-55685 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066780KB5066782
and 3 moreKB5066791KB5066793KB5066835
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
CVE-2025-55686 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066780KB5066782
and 3 moreKB5066791KB5066793KB5066835
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
CVE-2025-55687 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 8 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066873KB5066875
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVE-2025-55688 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066835Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
CVE-2025-55689 ↗2025-10-14Windows Server 2022Important0%KB5066780KB5066782
and 3 moreKB5066791KB5066793KB5066835
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
CVE-2025-55690 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066835Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
CVE-2025-55691 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066835Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
CVE-2025-55692 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant3%More likelyKB5066586KB5066780
and 7 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066873
Windows Error Reporting Service Elevation of Privilege Vulnerability
CVE-2025-55693 ↗2025-10-14Windows Server 2025 (Server Core installation)Important2%More likelyKB5066835Windows Kernel Elevation of Privilege Vulnerability
CVE-2025-55694 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant3%More likelyKB5066780KB5066835Windows Error Reporting Service Elevation of Privilege Vulnerability
CVE-2025-55695 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows WLAN AutoConfig Service Information Disclosure Vulnerability
CVE-2025-55696 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
NtQueryInformation Token function (ntifs.h) Elevation of Privilege Vulnerability
CVE-2025-55697 ↗2025-10-14Windows Server 2025 (Server Core installation)Important0%KB5066780KB5066835Azure Local Elevation of Privilege Vulnerability
CVE-2025-55698 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant1%KB5066835DirectX Graphics Kernel Denial of Service Vulnerability
CVE-2025-55699 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows Kernel Information Disclosure Vulnerability
CVE-2025-55700 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant1%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-55701 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows Authentication Elevation of Privilege Vulnerability
CVE-2025-58185 ↗2025-10-31cbl2 golang 1.18.8-10 on CBL Mariner 2.0ImportantOut-of-bandParsing DER payload can cause memory exhaustion in encoding/asn1
CVE-2025-58187 ↗2025-10-31cbl2 gcc 11.2.0-8 on CBL Mariner 2.0ImportantOut-of-bandQuadratic complexity when checking name constraints in crypto/x509
CVE-2025-58188 ↗2025-10-31cbl2 gcc 11.2.0-8 on CBL Mariner 2.0ImportantOut-of-bandPanic when validating certificates with DSA public keys in crypto/x509
CVE-2025-58714 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-58715 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows Speech Runtime Elevation of Privilege Vulnerability
CVE-2025-58716 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows Speech Runtime Elevation of Privilege Vulnerability
CVE-2025-58717 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant1%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-58718 ↗2025-10-14Windows App Client for Windows DesktopImportant1%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2025-58719 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 5 moreKB5066782KB5066791KB5066793KB5066835KB5066836
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
CVE-2025-58720 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
Windows Cryptographic Services Information Disclosure Vulnerability
CVE-2025-58722 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant2%More likelyKB5066586KB5066780
and 5 moreKB5066782KB5066791KB5066793KB5066835KB5066836
Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-58724 ↗2025-10-14Arc Enabled Servers - Azure Connected Machine AgentImportant1%Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2025-58725 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows COM+ Event System Service Elevation of Privilege Vulnerability
CVE-2025-58726 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant1%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows SMB Server Elevation of Privilege Vulnerability
CVE-2025-58727 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066780KB5066791
and 2 moreKB5066793KB5066835
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
CVE-2025-58728 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 3 moreKB5066791KB5066793KB5066835
Windows Bluetooth Service Elevation of Privilege Vulnerability
CVE-2025-58729 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant1%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows Local Session Manager (LSM) Denial of Service Vulnerability
CVE-2025-58730 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 10 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066875KB5066876
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
CVE-2025-58731 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066780KB5066782
and 2 moreKB5066793KB5066835
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
CVE-2025-58732 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 10 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066875KB5066876
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
CVE-2025-58733 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
CVE-2025-58734 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
CVE-2025-58735 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
CVE-2025-58736 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
CVE-2025-58737 ↗2025-10-14Windows Server 2019Important0%KB5066586KB5066780
and 4 moreKB5066782KB5066835KB5066836KB5066873
Remote Desktop Protocol Remote Code Execution Vulnerability
CVE-2025-58738 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 5 moreKB5066782KB5066791KB5066793KB5066835KB5066837
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
CVE-2025-58739 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant1%KB5066586KB5066780
and 13 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066840KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Microsoft Windows File Explorer Spoofing Vulnerability
CVE-2025-59184 ↗2025-10-14Windows Server 2019Important0%KB5066586KB5066780
and 3 moreKB5066782KB5066835KB5066836
Storage Spaces Direct Information Disclosure Vulnerability
CVE-2025-59185 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant1%KB5066586KB5066780
and 7 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066873
NTLM Hash Disclosure Spoofing Vulnerability
CVE-2025-59186 ↗2025-10-14Windows Server 2019Important1%KB5066586KB5066780
and 3 moreKB5066782KB5066835KB5066836
Windows Kernel Information Disclosure Vulnerability
CVE-2025-59187 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows Kernel Elevation of Privilege Vulnerability
CVE-2025-59188 ↗2025-10-14Windows Server 2019Important0%KB5066586KB5066780
and 5 moreKB5066782KB5066835KB5066836KB5066873KB5066875
Microsoft Failover Cluster Information Disclosure Vulnerability
CVE-2025-59189 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066835Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2025-59190 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows Search Service Denial of Service Vulnerability
CVE-2025-59191 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
CVE-2025-59192 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Storport.sys Driver Elevation of Privilege Vulnerability
CVE-2025-59193 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
Windows Management Services Elevation of Privilege Vulnerability
CVE-2025-59194 ↗2025-10-14Windows 11 Version 22H2 for ARM64-based SystemsImportant2%More likelyKB5066780KB5066793
and 1 moreKB5066835
Windows Kernel Elevation of Privilege Vulnerability
CVE-2025-59195 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
Windows Graphics Component Denial of Service Vulnerability
CVE-2025-59196 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
CVE-2025-59197 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows ETL Channel Information Disclosure Vulnerability
CVE-2025-59198 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows Search Service Denial of Service Vulnerability
CVE-2025-59199 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant4%More likelyKB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
Software Protection Platform (SPP) Elevation of Privilege Vulnerability
CVE-2025-59200 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant1%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Data Sharing Service Spoofing Vulnerability
CVE-2025-59201 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Network Connection Status Indicator (NCSI) Elevation of Privilege Vulnerability
CVE-2025-59202 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 7 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066873KB5066875
Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVE-2025-59203 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows State Repository API Server File Information Disclosure Vulnerability
CVE-2025-59204 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
Windows Management Services Information Disclosure Vulnerability
CVE-2025-59205 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2025-59206 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066835Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
CVE-2025-59207 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
Windows Kernel Elevation of Privilege Vulnerability
CVE-2025-59208 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 13 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066840KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows MapUrlToZone Information Disclosure Vulnerability
CVE-2025-59209 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066586KB5066780
and 8 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066873KB5066875
Windows Push Notification Information Disclosure Vulnerability
CVE-2025-59210 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5066835Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
CVE-2025-59211 ↗2025-10-14Windows 11 Version 25H2 for x64-based SystemsImportant1%KB5066586KB5066780
and 8 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066873KB5066875
Windows Push Notification Information Disclosure Vulnerability
CVE-2025-59213 ↗2025-10-14Microsoft Configuration Manager 2409Important0%Configuration Manager Elevation of Privilege Vulnerability
CVE-2025-59214 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant2%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Microsoft Windows File Explorer Spoofing Vulnerability
CVE-2025-59221 ↗2025-10-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002787KB5002788
and 3 moreKB5002789KB5002796KB5002798
Microsoft Word Remote Code Execution Vulnerability
CVE-2025-59222 ↗2025-10-14Microsoft SharePoint Enterprise Server 2016Important0%KB5002787KB5002788
and 3 moreKB5002789KB5002796KB5002798
Microsoft Word Remote Code Execution Vulnerability
CVE-2025-59223 ↗2025-10-14Office Online ServerImportant0%KB5002794KB5002797Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-59224 ↗2025-10-14Office Online ServerImportant0%KB5002794KB5002797Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-59225 ↗2025-10-14Office Online ServerImportant0%KB5002794KB5002797Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-59226 ↗2025-10-14Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2025-59228 ↗2025-10-14Microsoft SharePoint Enterprise Server 2016Important1%KB5002786KB5002788
and 1 moreKB5002796
Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2025-59229 ↗2025-10-14Microsoft Office LTSC 2024 for 32-bit editionsImportant0%Microsoft Office Denial of Service Vulnerability
CVE-2025-59231 ↗2025-10-14Office Online ServerImportant0%KB5002794KB5002797Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-59232 ↗2025-10-14Office Online ServerImportant0%KB5002341KB5002719
and 6 moreKB5002720KB5002757KB5002788KB5002794KB5002796KB5002797
Microsoft Excel Information Disclosure Vulnerability
CVE-2025-59233 ↗2025-10-14Office Online ServerImportant0%KB5002794KB5002797Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-59235 ↗2025-10-14Office Online ServerImportant1%KB5002341KB5002719
and 6 moreKB5002720KB5002757KB5002788KB5002794KB5002796KB5002797
Microsoft Excel Information Disclosure Vulnerability
CVE-2025-59237 ↗2025-10-14Microsoft SharePoint Enterprise Server 2016Important2%KB5002786KB5002788
and 1 moreKB5002796
Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2025-59238 ↗2025-10-14Microsoft Office 2019 for 32-bit editionsImportant0%KB5002790Microsoft PowerPoint Remote Code Execution Vulnerability
CVE-2025-59241 ↗2025-10-14Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5066835Windows Health and Optimized Experiences Elevation of Privilege Vulnerability
CVE-2025-59242 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-59243 ↗2025-10-14Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-59244 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5066586KB5066780
and 7 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066873
NTLM Hash Disclosure Spoofing Vulnerability
CVE-2025-59248 ↗2025-10-14Microsoft Exchange Server Subscription Edition RTMImportant1%KB5066366KB5066367
and 2 moreKB5066368KB5066369
Microsoft Exchange Server Spoofing Vulnerability
CVE-2025-59249 ↗2025-10-14Microsoft Exchange Server 2016 Cumulative Update 23Important1%KB5066366KB5066367
and 2 moreKB5066368KB5066369
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2025-59250 ↗2025-10-14Microsoft JDBC Driver 12.4 for SQL ServerImportant1%JDBC Driver for SQL Server Spoofing Vulnerability
CVE-2025-59253 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 8 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066873KB5066875
Windows Search Service Denial of Service Vulnerability
CVE-2025-59254 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-59255 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 4 moreKB5066782KB5066791KB5066793KB5066835
Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-59257 ↗2025-10-14Windows Server 2025 (Server Core installation)Important1%KB5066780KB5066835Windows Local Session Manager (LSM) Denial of Service Vulnerability
CVE-2025-59258 ↗2025-10-14Windows Server 2019Important1%KB5066586KB5066780
and 5 moreKB5066782KB5066835KB5066836KB5066873KB5066875
Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability
CVE-2025-59259 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5066586KB5066780
and 8 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066873KB5066875
Windows Local Session Manager (LSM) Denial of Service Vulnerability
CVE-2025-59260 ↗2025-10-14Windows Server 2019Important0%KB5066586KB5066780
and 3 moreKB5066782KB5066835KB5066836
Microsoft Failover Cluster Virtual Driver Information Disclosure Vulnerability
CVE-2025-59261 ↗2025-10-14Windows Server 2022Important0%KB5066780KB5066782
and 2 moreKB5066793KB5066835
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2025-59275 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows Authentication Elevation of Privilege Vulnerability
CVE-2025-59277 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows Authentication Elevation of Privilege Vulnerability
CVE-2025-59278 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows Authentication Elevation of Privilege Vulnerability
CVE-2025-59280 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows SMB Client Tampering Vulnerability
CVE-2025-59281 ↗2025-10-14Xbox Gaming ServicesImportant0%Xbox Gaming Services Elevation of Privilege Vulnerability
CVE-2025-59282 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5066586KB5066780
and 12 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Internet Information Services (IIS) Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
CVE-2025-59284 ↗2025-10-14Windows 11 Version 22H2 for ARM64-based SystemsImportant1%KB5066793KB5066835Windows NTLM Spoofing Vulnerability
CVE-2025-59285 ↗2025-10-14Azure Monitor AgentImportant1%Azure Monitor Agent Elevation of Privilege Vulnerability
CVE-2025-59289 ↗2025-10-14Windows Server 2022Important0%KB5065306KB5065425
and 5 moreKB5065426KB5065429KB5065431KB5065432KB5065474
Windows Bluetooth Service Elevation of Privilege Vulnerability
CVE-2025-59290 ↗2025-10-14Windows Server 2022Important0%KB5065306KB5065425
and 5 moreKB5065426KB5065429KB5065431KB5065432KB5065474
Windows Bluetooth Service Elevation of Privilege Vulnerability
CVE-2025-59294 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows Taskbar Live Preview Information Disclosure Vulnerability
CVE-2025-59295 ↗2025-10-14Windows 11 Version 25H2 for ARM64-based SystemsImportant2%KB5066586KB5066780
and 13 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837KB5066840KB5066872KB5066873KB5066874KB5066875KB5066876KB5066877
Windows URL Parsing Remote Code Execution Vulnerability
CVE-2025-59489 ↗2025-10-03Avowed ArtbookImportantOut-of-band1%MITRE: CVE-2025-59489 Unity Gaming Engine Editor vulnerability
CVE-2025-59494 ↗2025-10-14Azure Monitor AgentImportant1%Azure Monitor Agent Elevation of Privilege Vulnerability
CVE-2025-59497 ↗2025-10-14Microsoft Defender for Endpoint for LinuxImportant0%Microsoft Defender for Linux Denial of Service Vulnerability
CVE-2025-59501 ↗2025-10-24Microsoft Configuration Manager 2403ImportantOut-of-band3%Microsoft Configuration Manager Spoofing Vulnerability
CVE-2025-59530 ↗2025-10-25azl3 coredns 1.11.4-10 on Azure Linux 3.0ImportantOut-of-bandquic-go has Client Crash Due to Premature HANDSHAKE_DONE Frame
CVE-2025-60711 ↗2025-10-31Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2025-61099 ↗2025-11-05cbl2 frr 8.5.5-4 on CBL Mariner 2.0ImportantOut-of-bandFRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LS Update packet.
CVE-2025-61100 ↗2025-11-02cbl2 frr 8.5.5-3 on CBL Mariner 2.0ImportantOut-of-bandFRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) under specific malformed LSA conditions.
CVE-2025-61101 ↗2025-11-02cbl2 frr 8.5.5-3 on CBL Mariner 2.0ImportantOut-of-bandFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVE-2025-61104 ↗2025-11-02cbl2 frr 8.5.5-3 on CBL Mariner 2.0ImportantOut-of-bandFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVE-2025-61723 ↗2025-10-31cbl2 gcc 11.2.0-8 on CBL Mariner 2.0ImportantOut-of-bandQuadratic complexity when parsing some invalid inputs in encoding/pem
CVE-2025-61725 ↗2025-10-31cbl2 golang 1.22.7-5 on CBL Mariner 2.0ImportantOut-of-bandExcessive CPU consumption in ParseAddress in net/mail
CVE-2025-62229 ↗2025-10-31azl3 xorg-x11-server-Xwayland 24.1.6-2 on Azure Linux 3.0ImportantOut-of-bandXorg: xmayland: use-after-free in xpresentnotify structure creation
CVE-2025-62230 ↗2025-11-02azl3 xorg-x11-server-Xwayland 24.1.6-2 on Azure Linux 3.0ImportantOut-of-bandXorg: xwayland: use-after-free in xkb client resource removal
CVE-2025-62231 ↗2025-10-31azl3 xorg-x11-server-Xwayland 24.1.6-2 on Azure Linux 3.0ImportantOut-of-bandXorg: xmayland: value overflow in xkbsetcompatmap()
CVE-2025-62518 ↗2025-10-25azl3 kata-containers-cc 3.15.0.aks0-6 on Azure Linux 3.0ImportantOut-of-bandastral-tokio-tar Vulnerable to PAX Header Desynchronization
CVE-2025-8677 ↗2025-10-25azl3 bind 9.20.15-1 on Azure Linux 3.0ImportantOut-of-bandResource exhaustion via malformed DNSKEY handling
CVE-2022-50461 ↗2026-01-18cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: ethernet: ti: am65-cpsw: Fix PM runtime leakage in am65_cpsw_nuss_ndo_slave_open()
CVE-2022-50464 ↗2026-01-18cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandmt76: mt7915: Fix PCI device refcount leak in mt7915_pci_init_hif2()
CVE-2022-50467 ↗2026-01-18cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandscsi: lpfc: Fix null ndlp ptr dereference in abnormal exit path for GFT_ID
CVE-2022-50502 ↗2025-10-06azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandmm: /proc/pid/smaps_rollup: fix no vma's null-deref
CVE-2023-53460 ↗2026-01-18cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandwifi: rtw88: fix memory leak in rtw_usb_probe()
CVE-2023-53466 ↗2026-01-21cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandwifi: mt76: mt7915: fix memory leak in mt7915_mcu_exit
CVE-2023-53642 ↗2026-02-18azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandx86: fix clear_user_rep_good() exception handling annotation
CVE-2024-31573 ↗2025-10-19cbl2 javapackages-bootstrap 1.5.0-7 on CBL Mariner 2.0ModerateOut-of-bandXMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.
CVE-2025-11234 ↗2025-10-07azl3 qemu 8.2.0-19 on Azure Linux 3.0ModerateOut-of-bandQemu-kvm: vnc websocket handshake use-after-free
CVE-2025-11411 ↗2025-10-24azl3 unbound 1.19.1-4 on Azure Linux 3.0ModerateOut-of-bandPossible domain hijacking via promiscuous records in the authority section
CVE-2025-11412 ↗2025-10-11cbl2 binutils 2.37-17 on CBL Mariner 2.0ModerateOut-of-bandGNU Binutils Linker elflink.c bfd_elf_gc_record_vtentry out-of-bounds
CVE-2025-11413 ↗2025-10-11cbl2 binutils 2.37-16 on CBL Mariner 2.0ModerateOut-of-bandGNU Binutils Linker elflink.c elf_link_add_object_symbols out-of-bounds
CVE-2025-11414 ↗2025-10-11cbl2 binutils 2.37-17 on CBL Mariner 2.0ModerateOut-of-bandGNU Binutils Linker elflink.c get_link_hash_entry out-of-bounds
CVE-2025-11494 ↗2025-11-29cbl2 binutils 2.37-19 on CBL Mariner 2.0ModerateOut-of-bandGNU Binutils Linker elfxx-x86.c _bfd_x86_elf_late_size_sections out-of-bounds
CVE-2025-11495 ↗2025-10-11cbl2 gdb 11.2-7 on CBL Mariner 2.0ModerateOut-of-bandGNU Binutils Linker elf64-x86-64.c elf_x86_64_relocate_section heap-based overflow
CVE-2025-12058 ↗2025-10-31azl3 keras 3.3.3-5 on Azure Linux 3.0ModerateOut-of-bandVulnerability in Keras Model.load_model Leading to Arbitrary Local File Loading and SSRF
CVE-2025-12464 ↗2025-11-05azl3 qemu 8.2.0-25 on Azure Linux 3.0ModerateOut-of-bandQemu-kvm: stack buffer overflow in e1000 device via short frames in loopback mode
CVE-2025-37727 ↗2025-10-11azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandElasticsearch Insertion of sensitive information in log file
CVE-2025-39891 ↗2025-10-02azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandwifi: mwifiex: Initialize the chan_stats array to zero
CVE-2025-39894 ↗2026-01-18cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnetfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm
CVE-2025-39895 ↗2025-10-02azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandsched: Fix sched_numa_find_nth_cpu() if mask offline
CVE-2025-39902 ↗2025-10-02azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandmm/slub: avoid accessing metadata when pointer is invalid in object_err()
CVE-2025-39909 ↗2025-10-02azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandmm/damon/lru_sort: avoid divide-by-zero in damon_lru_sort_apply_parameters()
CVE-2025-39913 ↗2025-10-02azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandtcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock->cork.
CVE-2025-39914 ↗2025-10-02azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandtracing: Silence warning when chunk allocation fails in trace_pid_write
CVE-2025-39916 ↗2025-10-02azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandmm/damon/reclaim: avoid divide-by-zero in damon_reclaim_apply_parameters()
CVE-2025-39920 ↗2025-10-02azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandpcmcia: Add error handling for add_interval() in do_validate_mem()
CVE-2025-39923 ↗2025-10-02azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-banddmaengine: qcom: bam_dma: Fix DT error handling for num-channels/ees
CVE-2025-39927 ↗2025-10-02azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandceph: fix race condition validating r_parent before applying state
CVE-2025-39929 ↗2025-10-05azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandsmb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path
CVE-2025-39931 ↗2025-10-05azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandcrypto: af_alg - Set merge to zero early in af_alg_sendmsg
CVE-2025-39932 ↗2025-10-05azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandsmb: client: let smbd_destroy() call disable_work_sync(&info->post_send_credits_work)
CVE-2025-39933 ↗2025-10-05azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandsmb: client: let recv_done verify data_offset, data_length and remaining_data_length
CVE-2025-39934 ↗2025-10-05azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-banddrm: bridge: anx7625: Fix NULL pointer dereference with early IRQ
CVE-2025-39937 ↗2025-10-05azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandnet: rfkill: gpio: Fix crash due to dereferencering uninitialized pointer
CVE-2025-39938 ↗2025-10-05azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandASoC: qcom: q6apm-lpass-dais: Fix NULL pointer dereference if source graph failed
CVE-2025-39940 ↗2025-10-05azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-banddm-stripe: fix a possible integer overflow
CVE-2025-39942 ↗2025-10-05azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandksmbd: smbdirect: verify remaining_data_length respects max_fragmented_recv_size
CVE-2025-39946 ↗2025-10-05azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandtls: make sure to abort the stream if headers are bogus
CVE-2025-39947 ↗2025-10-05azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandnet/mlx5e: Harden uplink netdev access against device unbind
CVE-2025-39949 ↗2025-10-05azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandqed: Don't collect too many protection override GRC elements
CVE-2025-39951 ↗2025-10-05azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandum: virtio_uml: Fix use-after-free after put_device in probe
CVE-2025-39953 ↗2025-10-05azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandcgroup: split cgroup_destroy_wq into 3 workqueues
CVE-2025-39955 ↗2025-10-10azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandtcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect().
CVE-2025-39961 ↗2025-10-11azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandiommu/amd/pgtbl: Fix possible race while increase page table level
CVE-2025-39964 ↗2025-10-15azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandcrypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
CVE-2025-39965 ↗2025-10-15azl3 kernel 6.6.104.2-1 on Azure Linux 3.0ModerateOut-of-bandxfrm: xfrm_alloc_spi shouldn't use 0 as SPI
CVE-2025-39969 ↗2025-10-16azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandi40e: fix validation of VF state in get resources
CVE-2025-39990 ↗2025-10-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandbpf: Check the helper function is valid in get_helper_proto
CVE-2025-40005 ↗2025-10-22azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandspi: cadence-quadspi: Implement refcount to handle unbind during busy
CVE-2025-40010 ↗2025-10-22azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandafs: Fix potential null pointer dereference in afs_put_server
CVE-2025-40011 ↗2025-10-22azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-banddrm/gma500: Fix null dereference in hdmi teardown
CVE-2025-40013 ↗2025-10-22azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandASoC: qcom: audioreach: fix potential null pointer dereference
CVE-2025-40016 ↗2025-10-22azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandmedia: uvcvideo: Mark invalid entities with id UVC_INVALID_ENTITY_ID
CVE-2025-40019 ↗2025-10-25azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandcrypto: essiv - Check ssize for decryption and in-place encryption
CVE-2025-40021 ↗2025-10-26azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandtracing: dynevent: Add a missing lockdown check on dynevent
CVE-2025-40024 ↗2025-10-26azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandvhost: Take a reference on the task in struct vhost_task.
CVE-2025-40025 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix to do sanity check on node footer for non inode dnode
CVE-2025-40029 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandbus: fsl-mc: Check return value of platform_get_resource()
CVE-2025-40030 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandpinctrl: check the return value of pinmux_ops::get_function_name()
CVE-2025-40032 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandPCI: endpoint: pci-epf-test: Add NULL check for DMA channels before release
CVE-2025-40033 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandremoteproc: pru: Fix potential NULL pointer dereference in pru_rproc_set_ctable()
CVE-2025-40035 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandInput: uinput - zero-initialize uinput_ff_upload_compat to avoid info leak
CVE-2025-40038 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandKVM: SVM: Skip fastpath emulation on VM-Exit if next RIP isn't valid
CVE-2025-40040 ↗2025-10-29azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandmm/ksm: fix flag-dropping behavior in ksm_madvise
CVE-2025-40042 ↗2025-10-29azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandtracing: Fix race condition in kprobe initialization causing NULL pointer dereference
CVE-2025-40043 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandnet: nfc: nci: Add parameter validation for packet data
CVE-2025-40044 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandfs: udf: fix OOB read in lengthAllocDescs handling
CVE-2025-40049 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandSquashfs: fix uninit-value in squashfs_get_parent
CVE-2025-40051 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandvhost: vringh: Modify the return value check
CVE-2025-40052 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandsmb: client: fix crypto buffers in non-linear memory
CVE-2025-40053 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandnet: dlink: handle copy_thresh allocation failure
CVE-2025-40056 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandvhost: vringh: Fix copy_to_iter return value check
CVE-2025-40060 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandcoresight: trbe: Return NULL pointer for allocation failures
CVE-2025-40061 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandRDMA/rxe: Fix race in do_task() when draining
CVE-2025-40064 ↗2025-10-29azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandsmc: Fix use-after-free in __pnet_find_base_ndev().
CVE-2025-40071 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandtty: n_gsm: Don't block input queue by waiting MSC
CVE-2025-40078 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandbpf: Explicitly check accesses to bpf_sock_addr
CVE-2025-40079 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandriscv, bpf: Sign extend struct ops return values properly
CVE-2025-40080 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandnbd: restrict sockets to TCP and UDP
CVE-2025-40083 ↗2025-10-31azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnet/sched: sch_qfq: Fix null-deref in agg_dequeue
CVE-2025-40084 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandksmbd: transport_ipc: validate payload size before reading handle
CVE-2025-40085 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandALSA: usb-audio: Fix NULL pointer deference in try_to_register_card
CVE-2025-40087 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandNFSD: Define a proc_layoutcommit for the FlexFiles layout type
CVE-2025-40088 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandhfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp()
CVE-2025-40092 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandusb: gadget: f_ncm: Refactor bind path to use __free()
CVE-2025-40094 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandusb: gadget: f_acm: Refactor bind path to use __free()
CVE-2025-40095 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandusb: gadget: f_rndis: Refactor bind path to use __free()
CVE-2025-40097 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandALSA: hda: Fix missing pointer check in hda_component_manager_init function
CVE-2025-40099 ↗2025-10-31azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandcifs: parse_dfs_referrals: prevent oob on malformed input
CVE-2025-40100 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandbtrfs: do not assert we found block group item when creating free space tree
CVE-2025-40104 ↗2025-10-31azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandixgbevf: fix mailbox API compatibility by negotiating supported features
CVE-2025-40106 ↗2025-11-01azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandcomedi: fix divide-by-zero in comedi_buf_munge()
CVE-2025-46818 ↗2025-10-10azl3 valkey 8.0.4-1 on Azure Linux 3.0ModerateOut-of-bandRedis: Authenticated users can execute LUA scripts as a different user
CVE-2025-46819 ↗2025-10-10azl3 valkey 8.0.4-1 on Azure Linux 3.0ModerateOut-of-bandRedis is vulnerable to DoS via specially crafted LUA scripts
CVE-2025-53040 ↗2025-10-23azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2025-53042 ↗2025-10-23cbl2 mysql 8.0.43-1 on CBL Mariner 2.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2025-53044 ↗2025-10-23azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2025-53045 ↗2025-10-23azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2025-53053 ↗2025-10-23azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).
CVE-2025-53054 ↗2025-10-23azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).
CVE-2025-53062 ↗2025-10-23azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2025-53069 ↗2025-10-23azl3 mysql 8.0.43-1 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2025-58183 ↗2025-10-31cbl2 cri-o 1.22.3-16 on CBL Mariner 2.0ModerateOut-of-bandUnbounded allocation when parsing GNU sparse map in archive/tar
CVE-2025-58186 ↗2025-10-31cbl2 gcc 11.2.0-8 on CBL Mariner 2.0ModerateOut-of-bandLack of limit when parsing cookies can cause memory exhaustion in net/http
CVE-2025-58189 ↗2025-10-31cbl2 golang 1.18.8-10 on CBL Mariner 2.0ModerateOut-of-bandALPN negotiation error contains attacker controlled information in crypto/tls
CVE-2025-59288 ↗2025-10-14microsoft/playwrightModerate0%Playwright Spoofing Vulnerability
CVE-2025-59502 ↗2025-10-14Windows 10 Version 1809 for 32-bit SystemsModerate1%More likelyKB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
Remote Procedure Call Denial of Service Vulnerability
CVE-2025-61102 ↗2025-10-31cbl2 frr 8.5.5-3 on CBL Mariner 2.0ModerateOut-of-bandFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVE-2025-61103 ↗2025-10-31cbl2 frr 8.5.5-4 on CBL Mariner 2.0ModerateOut-of-bandFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_lan_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVE-2025-61105 ↗2025-10-31azl3 frr 9.1.1-4 on Azure Linux 3.0ModerateOut-of-bandFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVE-2025-61106 ↗2025-10-31cbl2 frr 8.5.5-4 on CBL Mariner 2.0ModerateOut-of-bandFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVE-2025-61107 ↗2025-10-31azl3 frr 9.1.1-3 on Azure Linux 3.0ModerateOut-of-bandFRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LSA Update packet.
CVE-2025-61724 ↗2025-10-31cbl2 msft-golang 1.24.8-1 on CBL Mariner 2.0ModerateOut-of-bandExcessive CPU consumption in Reader.ReadResponse in net/textproto
CVE-2025-61985 ↗2025-10-08azl3 openssh 9.8p1-4 on Azure Linux 3.0ModerateOut-of-bandssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.
CVE-2025-62813 ↗2025-10-24cbl2 lz4 1.9.4-1 on CBL Mariner 2.0ModerateOut-of-bandLZ4 through 1.10.0 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact when the application processes untrusted LZ4 frames. For example, LZ4F_createCDict_advanced in lib/lz4frame.c mishandles NULL checks.
CVE-2025-8291 ↗2025-10-10azl3 python3 3.12.9-5 on Azure Linux 3.0ModerateOut-of-bandZIP64 End of Central Directory (EOCD) Locator record offset not checked
CVE-2025-11731 ↗2025-11-21cbl2 libxslt 1.1.34-8 on CBL Mariner 2.0LowOut-of-bandLibxslt: type confusion in exsltfuncresultcompfunction of libxslt
CVE-2025-11839 ↗2025-10-25azl3 binutils 2.41-9 on Azure Linux 3.0LowOut-of-bandGNU Binutils prdbg.c tg_tag_type return value
CVE-2025-11840 ↗2025-10-29cbl2 binutils 2.37-17 on CBL Mariner 2.0LowOut-of-bandGNU Binutils ldmisc.c vfinfo out-of-bounds
CVE-2025-39957 ↗2025-10-10azl3 kernel 6.6.96.2-2 on Azure Linux 3.0LowOut-of-bandwifi: mac80211: increase scan_ies_len for S1G
CVE-2025-39958 ↗2025-10-10azl3 kernel 6.6.96.2-2 on Azure Linux 3.0LowOut-of-bandiommu/s390: Make attach succeed when the device was surprise removed
CVE-2025-40026 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0LowOut-of-bandKVM: x86: Don't (re)check L1 intercepts when completing userspace I/O
CVE-2025-40027 ↗2025-10-29azl3 kernel 6.6.104.2-4 on Azure Linux 3.0LowOut-of-bandnet/9p: fix double req put in p9_fd_cancelled
CVE-2025-6075 ↗2025-11-05azl3 python3 3.12.9-5 on Azure Linux 3.0LowOut-of-bandQuadratic complexity in os.path.expandvars() with user-controlled template
CVE-2025-61984 ↗2025-10-08azl3 openssh 9.8p1-4 on Azure Linux 3.0LowOut-of-bandssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as an untrusted source.)
CVE-2025-11205 ↗2025-10-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-11205 Heap buffer overflow in WebGPU
CVE-2025-11206 ↗2025-10-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-11206 Heap buffer overflow in Video
CVE-2025-11207 ↗2025-10-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-11207 Side-channel information leakage in Storage
CVE-2025-11208 ↗2025-10-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-11208 Inappropriate implementation in Media
CVE-2025-11209 ↗2025-10-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-11209 Inappropriate implementation in Omnibox
CVE-2025-11210 ↗2025-10-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-11210 Side-channel information leakage in Tab
CVE-2025-11211 ↗2025-10-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-11211 Out of bounds read in Media
CVE-2025-11212 ↗2025-10-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-11212 Inappropriate implementation in Media
CVE-2025-11213 ↗2025-10-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-11213 Inappropriate implementation in Omnibox
CVE-2025-11215 ↗2025-10-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-11215 Off by one error in V8
CVE-2025-11216 ↗2025-10-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-11216 Inappropriate implementation in Storage
CVE-2025-11219 ↗2025-10-02Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-11219 Use after free in V8
CVE-2025-11458 ↗2025-10-09Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-11458 Heap buffer overflow in Sync
CVE-2025-11460 ↗2025-10-09Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-11460 Use after free in Storage
CVE-2025-11756 ↗2025-10-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-11756 Use after free in Safe Browsing
CVE-2025-12036 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band4%Chromium: CVE-2025-12036 Inappropriate implementation in V8
CVE-2025-12428 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band7%Chromium: CVE-2025-12428 Type Confusion in V8
CVE-2025-12429 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12429 Inappropriate implementation in V8
CVE-2025-12430 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12430 Object lifecycle issue in Media
CVE-2025-12431 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12431 Inappropriate implementation in Extensions
CVE-2025-12432 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12432 Race in V8
CVE-2025-12433 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12433 Inappropriate implementation in V8
CVE-2025-12434 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12434 Race in Storage
CVE-2025-12435 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12435 Incorrect security UI in Omnibox
CVE-2025-12436 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12436 Policy bypass in Extensions
CVE-2025-12437 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12437 Use after free in PageInfo
CVE-2025-12438 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12438 Use after free in Ozone
CVE-2025-12439 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12439 Inappropriate implementation in App-Bound Encryption
CVE-2025-12440 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12440 Inappropriate implementation in Autofill
CVE-2025-12441 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12441 Out of bounds read in V8
CVE-2025-12443 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12433 Inappropriate implementation in V8
CVE-2025-12444 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12444 Incorrect security UI in Fullscreen UI
CVE-2025-12445 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12445 Policy bypass in Extensions
CVE-2025-12446 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12446 Incorrect security UI in SplitView
CVE-2025-12447 ↗2025-10-31Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12447 Incorrect security UI in Omnibox
#

September 2025

Patch Tuesday September 9, 2025108 CVEs plus 293 Azure Linux package advisories · 13 critical · 0 exploitation detected · 1 in KEV401 CVEs · 15 critical · 0 exploitation detected · 2 in KEV · includes 293 Azure Linux package advisories
Risk matrix, September 2025
13 of these counts use a severity derived from CVSS because Microsoft assigned none.
13 of these counts use a severity derived from CVSS because Microsoft assigned none.
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2025-39743 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandjfs: truncate good inode pages when hard link is 0
CVE-2025-53799 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Imaging Component Information Disclosure Vulnerability
CVE-2025-53800 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5065306KB5065425
and 7 moreKB5065426KB5065427KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2025-54910 ↗2025-09-09Microsoft Office 2019 for 32-bit editionsCritical1%KB5002781Microsoft Office Remote Code Execution Vulnerability
CVE-2025-54914 ↗2025-09-04Azure NetworkingCriticalOut-of-band2%Azure Networking Elevation of Privilege Vulnerability
CVE-2025-54918 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsCritical19%More likelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows NTLM Elevation of Privilege Vulnerability
CVE-2025-55224 ↗2025-09-09Windows 10 Version 1809 for x64-based SystemsCritical0%KB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2025-55226 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Graphics Kernel Remote Code Execution Vulnerability
CVE-2025-55228 ↗2025-09-09Windows Server 2022Critical0%KB5065306KB5065425
and 5 moreKB5065426KB5065429KB5065431KB5065432KB5065474
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2025-55236 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
Graphics Kernel Remote Code Execution Vulnerability
CVE-2025-55238 ↗2025-09-04Dynamics 365 FastTrack ImplementationCriticalOut-of-band1%Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
CVE-2025-55241 ↗2025-09-04Microsoft Entra IDCriticalOut-of-band2%Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-55242 ↗2025-09-04Xbox Gaming ServicesCriticalOut-of-band1%Xbox Certification Bug Copilot Djando Information Disclosure Vulnerability
CVE-2025-55244 ↗2025-09-04Azure Bot ServiceCriticalOut-of-band1%Azure Bot Service Elevation of Privilege Vulnerability
CVE-2025-57052 ↗2025-09-07azl3 ceph 18.2.2-10 on Azure Linux 3.0CriticalOut-of-bandcJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters.
CVE-2022-50406 ↗2025-12-12cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandiomap: iomap: fix memory corruption when recording errors during writeback
CVE-2023-53187 ↗2025-12-03cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandbtrfs: fix use-after-free of new block group that became unused
CVE-2023-53218 ↗2025-12-05cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandrxrpc: Make it so that a waiting process can be aborted
CVE-2023-53254 ↗2025-12-05cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandcacheinfo: Fix shared_cpu_map to handle shared caches at different levels
CVE-2025-11021 ↗2025-09-29cbl2 libsoup 3.0.4-9 on CBL Mariner 2.0ImportantOut-of-bandLibsoup: out-of-bounds read in cookie date handling of libsoup http library
CVE-2025-38679 ↗2025-09-06azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandmedia: venus: Fix OOB read due to missing payload bound check
CVE-2025-38680 ↗2025-09-06cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandmedia: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format()
CVE-2025-38684 ↗2025-09-06cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandnet/sched: ets: use old 'nbands' while purging unused classes
CVE-2025-38685 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandfbdev: Fix vmalloc out-of-bounds write in fast_imageblit
CVE-2025-38688 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandiommufd: Prevent ALIGN() overflow
CVE-2025-38692 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandexfat: add cluster chain loop check for dir
CVE-2025-38697 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandjfs: upper bound check of tree index in dbAllocAG
CVE-2025-38699 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandscsi: bfa: Double-free fix
CVE-2025-38702 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandfbdev: fix potential buffer overflow in do_register_framebuffer()
CVE-2025-38703 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-banddrm/xe: Make dma-fences compliant with the safe access rules
CVE-2025-38707 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandfs/ntfs3: Add sanity check for file name
CVE-2025-38714 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandhfsplus: fix slab-out-of-bounds in hfsplus_bnode_read()
CVE-2025-38718 ↗2025-09-06cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandsctp: linearize cloned gso packets in sctp_rcv
CVE-2025-38724 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandnfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm()
CVE-2025-38728 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandsmb3: fix for slab out of bounds on mount to ksmbd
CVE-2025-38729 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandALSA: usb-audio: Validate UAC3 power domain descriptors, too
CVE-2025-38732 ↗2025-09-07cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandnetfilter: nf_reject: don't leak dst refcount for loopback packets
CVE-2025-38735 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandgve: prevent ethtool ops after shutdown
CVE-2025-39673 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandppp: fix race conditions in ppp_fill_forward_path
CVE-2025-39683 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandtracing: Limit access to parser->buffer when trace_get_user failed
CVE-2025-39685 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandcomedi: pcl726: Prevent invalid irq number
CVE-2025-39686 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandcomedi: Make insn_rw_emulate_bits() do insn->n samples
CVE-2025-39689 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandftrace: Also allocate and copy hash for reading of filter files
CVE-2025-39691 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandfs/buffer: fix use-after-free when call bh_read() helper
CVE-2025-39694 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bands390/sclp: Fix SCCB present check
CVE-2025-39702 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandipv6: sr: Fix MAC comparison to be constant-time
CVE-2025-39710 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandmedia: venus: Add a check for packet size after reading from shared memory
CVE-2025-39711 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandmedia: ivsc: Fix crash at shutdown due to missing mei_cldev_disable() calls
CVE-2025-39713 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandmedia: rainshadow-cec: fix TOCTOU race condition in rain_interrupt()
CVE-2025-39721 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandcrypto: qat - flush misc workqueue during device shutdown
CVE-2025-39730 ↗2025-09-09azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantNFS: Fix filehandle bounds checking in nfs_fh_to_dentry()
CVE-2025-39732 ↗2025-09-09azl3 kernel 6.6.96.2-1 on Azure Linux 3.0Importantwifi: ath11k: fix sleeping-in-atomic in ath11k_mac_op_set_bitrate_mask()
CVE-2025-39738 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandbtrfs: do not allow relocation of partially dropped subvolumes
CVE-2025-39742 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandRDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask()
CVE-2025-39746 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandwifi: ath10k: shutdown driver when hardware is unreliable
CVE-2025-39749 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandrcu: Protect ->defer_qs_iw_pending from data race
CVE-2025-39750 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandwifi: ath12k: Correct tid cleanup when tid setup fails
CVE-2025-39751 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandALSA: hda/ca0132: Fix buffer overflow in add_tuning_control
CVE-2025-39757 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandALSA: usb-audio: Validate UAC3 cluster segment descriptors
CVE-2025-39759 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandbtrfs: qgroup: fix race between quota disable and quota rescan ioctl
CVE-2025-39761 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandwifi: ath12k: Decrement TID on RX peer frag setup error handling
CVE-2025-39766 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandnet/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit
CVE-2025-39776 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandmm/debug_vm_pgtable: clear page table entries at destroy_args()
CVE-2025-39788 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandscsi: ufs: exynos: Fix programming of HCI_UTRL_NEXUS_TYPE
CVE-2025-39790 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandbus: mhi: host: Detect events pointing to unexpected TREs
CVE-2025-39806 ↗2026-01-18cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandHID: multitouch: fix slab out-of-bounds access in mt_report_fixup()
CVE-2025-39810 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandbnxt_en: Fix memory corruption when FW resources change during ifdown
CVE-2025-39817 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandefivarfs: Fix slab-out-of-bounds in efivarfs_d_compare
CVE-2025-39823 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandKVM: x86: use array_index_nospec with indices that come from guest
CVE-2025-39824 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandHID: asus: fix UAF via HID_CLAIMED_INPUT validation
CVE-2025-39825 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandsmb: client: fix race with concurrent opens in rename(2)
CVE-2025-39826 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandnet: rose: convert 'use' field to refcount_t
CVE-2025-39828 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandatm: atmtcp: Prevent arbitrary write in atmtcp_recv_control().
CVE-2025-39832 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandnet/mlx5: Fix lockdep assertion on sync reset unload event
CVE-2025-39833 ↗2025-09-20azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandmISDN: hfcpci: Fix warning when deleting uninitialized timer
CVE-2025-39835 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandxfs: do not propagate ENODATA disk errors into xattr code
CVE-2025-39839 ↗2025-09-21azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandbatman-adv: fix OOB read/write in network-coding decode
CVE-2025-39841 ↗2025-09-21cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandscsi: lpfc: Fix buffer free/clear order in deferred receive path
CVE-2025-39843 ↗2025-09-21azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandmm: slub: avoid wake up kswapd in set_track_prepare
CVE-2025-39850 ↗2025-09-21azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandvxlan: Fix NPD in {arp,neigh}_reduce() when using nexthop objects
CVE-2025-39851 ↗2025-09-21azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandvxlan: Fix NPD when refreshing an FDB entry with a nexthop object
CVE-2025-39853 ↗2025-09-21cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandi40e: Fix potential invalid access when MAC list is empty
CVE-2025-39859 ↗2025-09-21azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandptp: ocp: fix use-after-free bugs causing by ptp_ocp_watchdog
CVE-2025-39860 ↗2025-09-21azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandBluetooth: Fix use-after-free in l2cap_sock_cleanup_listen()
CVE-2025-39861 ↗2025-09-21azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandBluetooth: vhci: Prevent use-after-free by removing debugfs files early
CVE-2025-39863 ↗2025-09-21cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandwifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info work
CVE-2025-39864 ↗2025-09-21azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandwifi: cfg80211: fix use-after-free in cmp_bss()
CVE-2025-39865 ↗2025-09-21azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandtee: fix NULL pointer dereference in tee_shm_put
CVE-2025-39866 ↗2025-09-21azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandfs: writeback: fix use-after-free in __mark_inode_dirty()
CVE-2025-39873 ↗2025-09-24azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandcan: xilinx_can: xcan_write_frame(): fix use-after-free of transmitted SKB
CVE-2025-39883 ↗2025-09-24azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandmm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory
CVE-2025-40928 ↗2025-09-11cbl2 perl-JSON-XS 4.03-2 on CBL Mariner 2.0ImportantOut-of-bandJSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact
CVE-2025-41244 ↗2026-07-24azl3 open-vm-tools 12.3.5-2 on Azure Linux 3.0ImportantOut-of-band8%CISA KEVVulnCheckENISAVMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
CVE-2025-47906 ↗2025-09-03azl3 golang 1.24.5-1 on Azure Linux 3.0ImportantOut-of-bandUnexpected paths returned from LookPath in os/exec
CVE-2025-47997 ↗2025-09-09Microsoft SQL Server 2017 for x64-based Systems (GDR)Important1%KB5065220KB5065221
and 6 moreKB5065222KB5065223KB5065224KB5065225KB5065226KB5065227
Microsoft SQL Server Information Disclosure Vulnerability
CVE-2025-49692 ↗2025-09-09Azure Connected Machine AgentImportant0%Azure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2025-49728 ↗2025-09-16Microsoft PC ManagerImportantOut-of-band0%Microsoft PC Manager Security Feature Bypass Vulnerability
CVE-2025-49734 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 7 moreKB5065426KB5065427KB5065428KB5065429KB5065431KB5065432KB5065474
PowerShell Direct Elevation of Privilege Vulnerability
CVE-2025-53796 ↗2025-09-09Windows Server 2019Important1%KB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-53797 ↗2025-09-09Windows Server 2019Important1%KB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-53798 ↗2025-09-09Windows Server 2019Important1%KB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-53801 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 6 moreKB5065427KB5065428KB5065429KB5065430KB5065431KB5065432
Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-53802 ↗2025-09-09Windows Server 2022Important0%KB5065306KB5065425
and 5 moreKB5065426KB5065429KB5065431KB5065432KB5065474
Windows Bluetooth Service Elevation of Privilege Vulnerability
CVE-2025-53803 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant1%More likelyKB5065306KB5065425
and 10 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474KB5065507KB5065509
Windows Kernel Memory Information Disclosure Vulnerability
CVE-2025-53804 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant1%More likelyKB5065306KB5065425
and 10 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474KB5065507KB5065509
Windows Kernel-Mode Driver Information Disclosure Vulnerability
CVE-2025-53805 ↗2025-09-09Windows Server 2022Important1%KB5065306KB5065425
and 4 moreKB5065426KB5065431KB5065432KB5065474
HTTP.sys Denial of Service Vulnerability
CVE-2025-53806 ↗2025-09-09Windows Server 2019Important1%KB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-53807 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2025-53808 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Defender Firewall Service Elevation of Privilege Vulnerability
CVE-2025-53809 ↗2025-09-09Windows Server 2025 (Server Core installation)Important1%KB5065426KB5065474Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2025-53810 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Defender Firewall Service Elevation of Privilege Vulnerability
CVE-2025-54091 ↗2025-09-09Windows 10 Version 1809 for x64-based SystemsImportant0%KB5065306KB5065425
and 10 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474KB5065507KB5065509
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-54092 ↗2025-09-09Windows 10 Version 1809 for x64-based SystemsImportant0%KB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-54093 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows TCP/IP Driver Elevation of Privilege Vulnerability
CVE-2025-54094 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Defender Firewall Service Elevation of Privilege Vulnerability
CVE-2025-54095 ↗2025-09-09Windows Server 2019Important1%KB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-54096 ↗2025-09-09Windows Server 2019Important1%KB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-54097 ↗2025-09-09Windows Server 2019Important1%KB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-54098 ↗2025-09-09Windows 10 Version 1809 for x64-based SystemsImportant3%More likelyKB5065306KB5065425
and 12 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065509KB5065510
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-54099 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-54101 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant2%KB5065306KB5065425
and 8 moreKB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065507KB5065509
Windows SMB Client Remote Code Execution Vulnerability
CVE-2025-54102 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 7 moreKB5065426KB5065427KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
CVE-2025-54103 ↗2025-09-09Windows 10 Version 21H2 for 32-bit SystemsImportant0%KB5065425KB5065426
and 3 moreKB5065429KB5065431KB5065474
Windows Management Service Elevation of Privilege Vulnerability
CVE-2025-54104 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Defender Firewall Service Elevation of Privilege Vulnerability
CVE-2025-54105 ↗2025-09-09Windows Server 2025 (Server Core installation)Important0%KB5065425KB5065426
and 1 moreKB5065474
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2025-54106 ↗2025-09-09Windows Server 2019Important1%KB5065306KB5065425
and 6 moreKB5065426KB5065427KB5065428KB5065432KB5065474KB5065507
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-54107 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5065306KB5065425
and 15 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065435KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
MapUrlToZone Security Feature Bypass Vulnerability
CVE-2025-54108 ↗2025-09-09Windows Server 2025 (Server Core installation)Important0%KB5065426KB5065474Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
CVE-2025-54109 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Defender Firewall Service Elevation of Privilege Vulnerability
CVE-2025-54110 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant4%More likelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Kernel Elevation of Privilege Vulnerability
CVE-2025-54111 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 8 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474
Windows UI XAML Phone DatePickerFlyout Elevation of Privilege Vulnerability
CVE-2025-54112 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 8 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability
CVE-2025-54113 ↗2025-09-09Windows Server 2019Important1%KB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-54114 ↗2025-09-09Windows Server 2022Important0%KB5065306KB5065425
and 6 moreKB5065426KB5065427KB5065429KB5065431KB5065432KB5065474
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
CVE-2025-54115 ↗2025-09-09Windows 10 Version 1809 for x64-based SystemsImportant0%KB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-54116 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 8 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474
Windows MultiPoint Services Elevation of Privilege Vulnerability
CVE-2025-54894 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
CVE-2025-54895 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 12 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065509KB5065510
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Elevation of Privilege Vulnerability
CVE-2025-54896 ↗2025-09-09Office Online ServerImportant1%KB5002776KB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54897 ↗2025-09-09Microsoft SharePoint Enterprise Server 2016Important14%KB5002775KB5002778
and 1 moreKB5002784
Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2025-54898 ↗2025-09-09Office Online ServerImportant1%KB5002776KB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54899 ↗2025-09-09Microsoft Office 2019 for 32-bit editionsImportant1%KB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54900 ↗2025-09-09Office Online ServerImportant1%KB5002776KB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54901 ↗2025-09-09Microsoft Office 2019 for 32-bit editionsImportant1%KB5002762Microsoft Excel Information Disclosure Vulnerability
CVE-2025-54902 ↗2025-09-09Office Online ServerImportant1%KB5002776KB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54903 ↗2025-09-09Office Online ServerImportant1%KB5002776KB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54904 ↗2025-09-09Office Online ServerImportant1%KB5002776KB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54905 ↗2025-09-09Microsoft SharePoint Enterprise Server 2016Important1%KB5002774KB5002775
and 3 moreKB5002777KB5002778KB5002780
Microsoft Word Information Disclosure Vulnerability
CVE-2025-54906 ↗2025-09-09Microsoft SharePoint Enterprise Server 2016Important1%KB5002576KB5002766
and 3 moreKB5002775KB5002778KB5002781
Microsoft Office Remote Code Execution Vulnerability
CVE-2025-54907 ↗2025-09-09Microsoft Office 2019 for 32-bit editionsImportant0%Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2025-54908 ↗2025-09-09Microsoft Office 2019 for 32-bit editionsImportant1%KB5002779Microsoft PowerPoint Remote Code Execution Vulnerability
CVE-2025-54911 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5065306KB5065425
and 12 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065509KB5065510
Windows BitLocker Elevation of Privilege Vulnerability
CVE-2025-54912 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 12 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065509KB5065510
Windows BitLocker Elevation of Privilege Vulnerability
CVE-2025-54913 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 8 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474
Windows UI XAML Maps MapControlSettings Elevation of Privilege Vulnerability
CVE-2025-54915 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Defender Firewall Service Elevation of Privilege Vulnerability
CVE-2025-54916 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows NTFS Remote Code Execution Vulnerability
CVE-2025-54917 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5065306KB5065425
and 15 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065435KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
MapUrlToZone Security Feature Bypass Vulnerability
CVE-2025-54919 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2025-55223 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2025-55225 ↗2025-09-09Windows Server 2019Important1%KB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-55227 ↗2025-09-09Microsoft SQL Server 2017 for x64-based Systems (GDR)Important1%KB5065220KB5065221
and 6 moreKB5065222KB5065223KB5065224KB5065225KB5065226KB5065227
Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-55232 ↗2025-09-09Microsoft HPC Pack 2019Important2%Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability
CVE-2025-55234 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant19%More likelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows SMB Elevation of Privilege Vulnerability
CVE-2025-55243 ↗2025-09-09Microsoft OfficePLUSImportant1%Microsoft OfficePlus Spoofing Vulnerability
CVE-2025-55245 ↗2025-09-09Xbox Gaming ServicesImportant0%Xbox Gaming Services Elevation of Privilege Vulnerability
CVE-2025-55316 ↗2025-09-09Azure Connected Machine AgentImportant0%Azure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2025-55317 ↗2025-09-09Microsoft AutoUpdate for MacImportant0%Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
CVE-2025-55319 ↗2025-09-11Visual Studio CodeImportantOut-of-band1%More likelyAgentic AI and Visual Studio Code Remote Code Execution Vulnerability
CVE-2025-55322 ↗2025-09-24OmniParserImportantOut-of-band0%OmniParser Remote Code Execution Vulnerability
CVE-2025-55551 ↗2025-10-05azl3 pytorch 2.2.2-7 on Azure Linux 3.0ImportantOut-of-bandAn issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.
CVE-2025-55552 ↗2025-10-05azl3 pytorch 2.2.2-7 on Azure Linux 3.0ImportantOut-of-bandpytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.
CVE-2025-55553 ↗2025-10-01cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ImportantOut-of-bandA syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).
CVE-2025-55557 ↗2025-10-02cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ImportantOut-of-bandA Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).
CVE-2025-58060 ↗2025-09-12azl3 cups 2.4.10-1 on Azure Linux 3.0ImportantOut-of-bandcups has Authentication bypass with AuthType Negotiate
CVE-2025-58063 ↗2025-09-11azl3 coredns 1.11.4-7 on Azure Linux 3.0ImportantOut-of-bandCoreDNS: DNS Cache Pinning via etcd Lease ID Confusion
CVE-2025-58754 ↗2025-09-16azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandAxios is vulnerable to DoS attack through lack of data size check
CVE-2025-59215 ↗2025-09-18Windows Server 2025 (Server Core installation)ImportantOut-of-band0%KB5065426KB5065474Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2025-59216 ↗2025-09-18Windows Server 2025 (Server Core installation)ImportantOut-of-band0%KB5065426KB5065474Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2025-59220 ↗2025-09-18Windows Server 2022ImportantOut-of-band0%KB5065306KB5065425
and 5 moreKB5065426KB5065429KB5065431KB5065432KB5065474
Windows Bluetooth Service Elevation of Privilege Vulnerability
CVE-2025-59251 ↗2025-09-25Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2025-59362 ↗2025-09-28azl3 squid 6.13-1 on Azure Linux 3.0ImportantOut-of-bandSquid through 7.1 mishandles ASN.1 encoding of long SNMP OIDs. This occurs in asn_build_objid in lib/snmplib/asn1.c.
CVE-2025-9230 ↗2025-10-02azl3 openssl 3.3.3-3 on Azure Linux 3.0ImportantOut-of-bandOut-of-bounds read & write in RFC 3211 KEK Unwrap
CVE-2025-9566 ↗2025-09-07azl3 libcontainers-common 20240213-3 on Azure Linux 3.0ImportantOut-of-bandPodman: podman kube play command may overwrite host files
CVE-2025-9648 ↗2025-10-03azl3 ceph 18.2.2-10 on Azure Linux 3.0ImportantOut-of-bandDenial of Service in CivetWeb
CVE-2025-9900 ↗2025-09-27cbl2 libtiff 4.6.0-8 on CBL Mariner 2.0ImportantOut-of-bandLibtiff: libtiff write-what-where
CVE-2025-9905 ↗2025-09-20azl3 keras 3.3.3-3 on Azure Linux 3.0ImportantOut-of-bandArbitary Code execution in Keras load_model()
CVE-2025-9906 ↗2025-09-20azl3 keras 3.3.3-3 on Azure Linux 3.0ImportantOut-of-bandArbitrary Code execution in Keras Safe Mode
CVE-2022-50236 ↗2025-11-26cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandiommu/mediatek: Fix crash on isr after kexec()
CVE-2022-50256 ↗2025-11-27cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-banddrm/meson: remove drm bridges at aggregate driver unbind time
CVE-2022-50260 ↗2025-11-27cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-banddrm/msm: Make .remove and .shutdown HW shutdown consistent
CVE-2022-50266 ↗2025-12-04cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandkprobes: Fix check for probe enabled in kill_kprobe()
CVE-2022-50303 ↗2025-12-06cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-banddrm/amdkfd: Fix double release compute pasid
CVE-2022-50304 ↗2025-12-06cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandmtd: core: fix possible resource leak in init_mtd()
CVE-2022-50316 ↗2025-12-05cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandorangefs: Fix kmemleak in orangefs_sysfs_init()
CVE-2022-50327 ↗2026-01-18cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandACPI: processor: idle: Check acpi_fetch_acpi_dev() return value
CVE-2022-50350 ↗2025-12-03cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandscsi: target: iscsi: Fix a race condition between login_work and the login thread
CVE-2022-50357 ↗2025-12-11cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandusb: dwc3: core: fix some leaks in probe
CVE-2022-50380 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandmm: /proc/pid/smaps_rollup: fix no vma's null-deref
CVE-2022-50390 ↗2025-12-14cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-banddrm/ttm: fix undefined behavior in bit shift for TTM_TT_FLAG_PRIV_POPULATED
CVE-2022-50393 ↗2025-12-14cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-banddrm/amdgpu: SDMA update use unlocked iterator
CVE-2022-50407 ↗2025-12-12cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandcrypto: hisilicon/qm - increase the memory of local variables
CVE-2022-50418 ↗2025-12-14cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandwifi: ath11k: mhi: fix potential memory leak in ath11k_mhi_register()
CVE-2023-53149 ↗2025-11-27cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandext4: avoid deadlock in fs reclaim with page writeback
CVE-2023-53152 ↗2025-11-26cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-banddrm/amdgpu: fix calltrace warning in amddrm_buddy_fini
CVE-2023-53178 ↗2025-12-03cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandmm: fix zswap writeback race condition
CVE-2023-53209 ↗2025-12-06cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandwifi: mac80211_hwsim: Fix possible NULL dereference
CVE-2023-53221 ↗2025-12-05cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandbpf: Fix memleak due to fentry attach failure
CVE-2023-53231 ↗2025-12-06cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-banderofs: Fix detection of atomic context
CVE-2023-53240 ↗2025-12-05cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandxsk: check IFF_UP earlier in Tx path
CVE-2023-53247 ↗2025-12-05cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandbtrfs: set_page_extent_mapped after read_folio in btrfs_cont_expand
CVE-2023-53248 ↗2025-12-05cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-banddrm/amdgpu: install stub fence into potential unused fence pointers
CVE-2023-53261 ↗2025-12-04cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandcoresight: Fix memory leak in acpi_buffer->pointer
CVE-2023-53292 ↗2025-12-04cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandblk-mq: fix NULL dereference on q->elevator in blk_mq_elv_switch_none
CVE-2023-53323 ↗2025-12-12cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandext2/dax: Fix ext2_setsize when len is page aligned
CVE-2023-53332 ↗2025-12-12cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandgenirq/ipi: Fix NULL pointer deref in irq_data_get_affinity_mask()
CVE-2023-53347 ↗2025-12-12cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet/mlx5: Handle pairing of E-switch via uplink un/load APIs
CVE-2023-53348 ↗2025-12-12cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandbtrfs: fix deadlock when aborting transaction during relocation with scrub
CVE-2023-53353 ↗2025-12-12cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandaccel/habanalabs: postpone mem_mgr IDR destruction to hpriv_release()
CVE-2023-53355 ↗2025-12-12cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandstaging: pi433: fix memory leak with using debugfs_lookup()
CVE-2023-53366 ↗2025-12-13cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandblock: be a bit more careful in checking for NULL bdev while polling
CVE-2023-53367 ↗2025-12-13cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandaccel/habanalabs: fix mem leak in capture user mappings
CVE-2023-53370 ↗2025-12-14cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-banddrm/amdgpu: fix memory leak in mes self test
CVE-2023-53371 ↗2025-12-14cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet/mlx5e: fix memory leak in mlx5e_fs_tt_redirect_any_create
CVE-2023-53376 ↗2025-12-14cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandscsi: mpi3mr: Use number of bits to manage bitmap sizes
CVE-2023-53383 ↗2025-12-13cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandirqchip/gicv3: Workaround for NVIDIA erratum T241-FABRIC-4
CVE-2023-53387 ↗2025-12-13cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandscsi: ufs: core: Fix device management cmd timeout flow
CVE-2023-53401 ↗2025-12-13cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandmm: kmem: fix a NULL pointer dereference in obj_stock_flush_required()
CVE-2023-53410 ↗2025-12-12cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandUSB: ULPI: fix memory leak with using debugfs_lookup()
CVE-2023-53421 ↗2025-12-12cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandblk-cgroup: Reinit blkg_iostat_set after clearing in blkcg_reset_stats()
CVE-2023-53424 ↗2025-12-12cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandclk: mediatek: fix of_iomap memory leak
CVE-2023-53429 ↗2025-12-12cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandbtrfs: don't check PageError in __extent_writepage
CVE-2023-53438 ↗2025-12-12cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandx86/MCE: Always save CS register on AMD Zen IF Poison errors
CVE-2023-53447 ↗2025-12-14cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandf2fs: don't reset unchangable mount option in f2fs_remount()
CVE-2024-58241 ↗2025-12-14cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandBluetooth: hci_core: Disable works on hci_unregister_dev
CVE-2025-10148 ↗2025-09-11azl3 curl 8.11.1-3 on Azure Linux 3.0ModerateOut-of-bandpredictable WebSocket mask
CVE-2025-10823 ↗2025-09-24azl3 fio 3.37-2 on Azure Linux 3.0ModerateOut-of-bandaxboe fio options.c str_buffer_pattern_cb null pointer dereference
CVE-2025-10824 ↗2025-09-24azl3 fio 3.37-2 on Azure Linux 3.0ModerateOut-of-bandaxboe fio init.c __parse_jobs_ini use after free
CVE-2025-10911 ↗2025-09-29cbl2 libxslt 1.1.34-8 on CBL Mariner 2.0ModerateOut-of-bandLibxslt: use-after-free with key data stored cross-rvt
CVE-2025-11081 ↗2025-10-02cbl2 binutils 2.37-16 on CBL Mariner 2.0ModerateOut-of-bandGNU Binutils objdump.c dump_dwarf_section out-of-bounds
CVE-2025-11082 ↗2025-10-02cbl2 crash 8.0.1-4 on CBL Mariner 2.0ModerateOut-of-bandGNU Binutils Linker elf-eh-frame.c _bfd_elf_parse_eh_frame heap-based overflow
CVE-2025-11083 ↗2025-10-02azl3 binutils 2.41-7 on Azure Linux 3.0ModerateOut-of-bandGNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflow
CVE-2025-38678 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nf_tables: reject duplicate device on updates
CVE-2025-38681 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandmm/ptdump: take the memory hotplug lock inside ptdump_walk_pgd()
CVE-2025-38683 ↗2026-01-10cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandhv_netvsc: Fix panic during namespace deletion with VF
CVE-2025-38687 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandcomedi: fix race between polling and detaching
CVE-2025-38691 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandpNFS: Fix uninited ptr deref in block/scsi layout
CVE-2025-38693 ↗2026-01-11cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandmedia: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar
CVE-2025-38695 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandscsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport structure
CVE-2025-38696 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandMIPS: Don't crash in stack_top() for tasks without ABI or vDSO
CVE-2025-38698 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandjfs: Regular file corruption check
CVE-2025-38700 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandscsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated
CVE-2025-38701 ↗2025-09-06azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandext4: do not BUG when INLINE_DATA_FL lacks system.data xattr
CVE-2025-38704 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandrcu/nocb: Fix possible invalid rdp's->nocb_cb_kthread pointer access
CVE-2025-38705 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/pm: fix null pointer access
CVE-2025-38706 ↗2025-09-06azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandASoC: core: Check for rtd == NULL in snd_soc_remove_pcm_runtime()
CVE-2025-38708 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrbd: add missing kref_get in handle_write_conflicts
CVE-2025-38709 ↗2025-09-06azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandloop: Avoid updating block size under exclusive owner
CVE-2025-38710 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandgfs2: Validate i_depth for exhash directories
CVE-2025-38711 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandsmb/server: avoid deadlock when linking with ReplaceIfExists
CVE-2025-38712 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandhfsplus: don't use BUG_ON() in hfsplus_create_attributes_file()
CVE-2025-38713 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandhfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
CVE-2025-38715 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandhfs: fix slab-out-of-bounds in hfs_bnode_read()
CVE-2025-38716 ↗2025-09-06azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandhfs: fix general protection fault in hfs_find_init()
CVE-2025-38717 ↗2025-09-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: kcm: Fix race condition in kcm_unattach()
CVE-2025-38721 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: ctnetlink: fix refcount leak on table dump
CVE-2025-38722 ↗2025-09-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandhabanalabs: fix UAF in export_dmabuf()
CVE-2025-38723 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandLoongArch: BPF: Fix jump offset calculation in tailcall
CVE-2025-38725 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnet: usb: asix_devices: add phy_mask for ax88772 mdio bus
CVE-2025-38730 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandio_uring/net: commit partial buffers on retry
CVE-2025-38734 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnet/smc: fix UAF on smcsk after smc_listen_out()
CVE-2025-38736 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandnet: usb: asix_devices: Fix PHY address mask in MDIO bus initialization
CVE-2025-39675 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Add null pointer check in mod_hdcp_hdcp1_create_session()
CVE-2025-39676 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandscsi: qla4xxx: Prevent a potential error pointer dereference
CVE-2025-39677 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandnet/sched: Fix backlog accounting in qdisc_dequeue_internal
CVE-2025-39679 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/nouveau/nvif: Fix potential memory leak in nvif_vmm_ctor().
CVE-2025-39681 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandx86/cpu/hygon: Add missing resctrl_cpu_detect() in bsp_init helper
CVE-2025-39682 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandtls: fix handling of zero-length records on the rx_list
CVE-2025-39684 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandcomedi: Fix use of uninitialized memory in do_insn_ioctl() and do_insnlist_ioctl()
CVE-2025-39687 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandiio: light: as73211: Ensure buffer holes are zeroed
CVE-2025-39692 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandsmb: server: split ksmbd_rdma_stop_listening() out of ksmbd_rdma_destroy()
CVE-2025-39693 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Avoid a NULL pointer dereference
CVE-2025-39697 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNFS: Fix a race when updating an existing write
CVE-2025-39701 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandACPI: pfr_update: Fix the driver update version check
CVE-2025-39703 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnet, hsr: reject HSR frame if skb can't hold tag
CVE-2025-39705 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: fix a Null pointer dereference vulnerability
CVE-2025-39706 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-banddrm/amdkfd: Destroy KFD debugfs after destroy KFD wq
CVE-2025-39707 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: check if hubbub is NULL in debugfs/amdgpu_dm_capabilities
CVE-2025-39709 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandmedia: venus: protect against spurious interrupts during probe
CVE-2025-39714 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandmedia: usbtv: Lock resolution while streaming
CVE-2025-39715 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandparisc: Revise gateway LWS calls to probe user read access
CVE-2025-39716 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandparisc: Revise __get_user() to probe user read access
CVE-2025-39718 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandvsock/virtio: Validate length in packet header before skb_put()
CVE-2025-39719 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandiio: imu: bno055: fix OOB access of hw_xlate array
CVE-2025-39720 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandksmbd: fix refcount leak causing resource not released
CVE-2025-39724 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandserial: 8250: fix panic due to PSLVERR
CVE-2025-39726 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bands390/ism: fix concurrency management in ism_cmd()
CVE-2025-39731 ↗2025-09-09azl3 kernel 6.6.96.2-1 on Azure Linux 3.0Moderatef2fs: vm_unmap_ram() may be called from an invalid context
CVE-2025-39734 ↗2026-01-13cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandRevert "fs/ntfs3: Replace inode_trylock with inode_lock"
CVE-2025-39736 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandmm/kmemleak: avoid deadlock by moving pr_warn() outside kmemleak_lock
CVE-2025-39737 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandmm/kmemleak: avoid soft lockup in __kmemleak_do_cleanup()
CVE-2025-39739 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandiommu/arm-smmu-qcom: Add SM6115 MDSS compatible
CVE-2025-39744 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandrcu: Fix rcu_read_unlock() deadloop due to IRQ work
CVE-2025-39745 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandrcutorture: Fix rcutorture_one_extend_check() splat in RT kernels
CVE-2025-39747 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-banddrm/msm: Add error handling for krealloc in metadata setup
CVE-2025-39748 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandbpf: Forget ranges when refining tnum after JSET
CVE-2025-39752 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandARM: rockchip: fix kernel hang during smp initialization
CVE-2025-39753 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandgfs2: Set .migrate_folio in gfs2_{rgrp,meta}_aops
CVE-2025-39754 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandmm/smaps: fix race between smaps_hugetlb_range and migration
CVE-2025-39756 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandfs: Prevent file descriptor table allocations exceeding INT_MAX
CVE-2025-39758 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandRDMA/siw: Fix the sendmsg byte count in siw_tcp_sendpages
CVE-2025-39760 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandusb: core: config: Prevent OOB read in SS endpoint companion parsing
CVE-2025-39762 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: add null check
CVE-2025-39763 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandACPI: APEI: send SIGBUS to current task if synchronous memory error not recovered
CVE-2025-39764 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandnetfilter: ctnetlink: remove refcounting in expectation dumpers
CVE-2025-39767 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandLoongArch: Optimize module load time by optimizing PLT/GOT counting
CVE-2025-39770 ↗2026-01-18cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM
CVE-2025-39772 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-banddrm/hisilicon/hibmc: fix the hibmc loaded failed bug
CVE-2025-39773 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandnet: bridge: fix soft lockup in br_multicast_query_expired()
CVE-2025-39779 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandbtrfs: subpage: keep TOWRITE tag until folio is cleaned
CVE-2025-39781 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandparisc: Drop WARN_ON_ONCE() from flush_cache_vmap
CVE-2025-39782 ↗2026-01-18cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandjbd2: prevent softlockup in jbd2_log_do_checkpoint()
CVE-2025-39783 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandPCI: endpoint: Fix configfs group list head handling
CVE-2025-39787 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandsoc: qcom: mdt_loader: Ensure we don't read past the ELF header
CVE-2025-39789 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandcrypto: x86/aegis - Add missing error checks
CVE-2025-39794 ↗2025-09-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandARM: tegra: Use I/O memcpy to write to IRAM
CVE-2025-39795 ↗2025-09-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandblock: avoid possible overflow for chunk_sectors check in blk_stack_limits()
CVE-2025-39797 ↗2025-09-16cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandxfrm: Duplicate SPI Handling
CVE-2025-39798 ↗2025-09-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandNFS: Fix the setting of capabilities when automounting a new filesystem
CVE-2025-39800 ↗2025-09-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandbtrfs: abort transaction on unexpected eb generation at btrfs_copy_root()
CVE-2025-39801 ↗2025-09-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandusb: dwc3: Remove WARN_ON for device endpoint command timeouts
CVE-2025-39805 ↗2025-09-20azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: macb: fix unregister_netdev call order in macb_remove()
CVE-2025-39808 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandHID: hid-ntrig: fix unable to handle page fault in ntrig_report_version()
CVE-2025-39812 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandsctp: initialize more fields in sctp_v6_from_sk()
CVE-2025-39813 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandftrace: Fix potential warning in trace_printk_seq during ftrace_dump
CVE-2025-39819 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandfs/smb: Fix inconsistent refcnt update
CVE-2025-39827 ↗2025-09-20azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandnet: rose: include node references in rose_neigh refcount
CVE-2025-39829 ↗2025-09-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandtrace/fgraph: Fix the warning caused by missing unregister notifier
CVE-2025-39838 ↗2025-09-21azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandcifs: prevent NULL pointer dereference in UTF16 conversion
CVE-2025-39842 ↗2025-09-21azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandocfs2: prevent release journal inode after journal shutdown
CVE-2025-39844 ↗2025-09-21cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandmm: move page table sync declarations to linux/pgtable.h
CVE-2025-39845 ↗2025-09-21azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandx86/mm/64: define ARCH_PAGE_TABLE_SYNC_MASK and arch_sync_kernel_mappings()
CVE-2025-39846 ↗2025-09-21cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandpcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region()
CVE-2025-39847 ↗2025-09-21cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandppp: fix memory leak in pad_compress_skb
CVE-2025-39848 ↗2025-09-21azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandax25: properly unshare skbs in ax25_kiss_rcv()
CVE-2025-39849 ↗2025-09-21azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandwifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result()
CVE-2025-39857 ↗2025-09-21azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandnet/smc: fix one NULL pointer dereference in smc_ib_is_sg_need_sync()
CVE-2025-39862 ↗2025-09-21azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandwifi: mt76: mt7915: fix list corruption after hardware restart
CVE-2025-39867 ↗2025-09-24azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nft_set_pipapo: fix null deref for empty set
CVE-2025-39869 ↗2025-09-24azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-banddmaengine: ti: edma: Fix memory allocation size for queue_priority_map
CVE-2025-39876 ↗2025-09-24azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandnet: fec: Fix possible NPD in fec_enet_phy_reset_after_clk_enable()
CVE-2025-39877 ↗2025-09-24azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandmm/damon/sysfs: fix use-after-free in state_show()
CVE-2025-39880 ↗2025-09-24azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandlibceph: fix invalid accesses to ceph_connection_v1_info
CVE-2025-39881 ↗2025-09-24azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandkernfs: Fix UAF in polling when open file is released
CVE-2025-39885 ↗2025-09-24azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandocfs2: fix recursive semaphore deadlock in fiemap call
CVE-2025-39886 ↗2025-09-24azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandbpf: Tell memcg to use allow_spinning=false path in bpf_timer_init()
CVE-2025-40300 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandx86/vmscape: Add conditional IBPB mitigation
CVE-2025-46148 ↗2025-09-29cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ModerateOut-of-bandIn PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.
CVE-2025-46149 ↗2025-10-02cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ModerateOut-of-bandIn PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.
CVE-2025-46150 ↗2025-10-02azl3 pytorch 2.2.2-7 on Azure Linux 3.0ModerateOut-of-bandIn PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.
CVE-2025-46152 ↗2025-09-29cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ModerateOut-of-bandIn PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument.
CVE-2025-46153 ↗2025-10-02azl3 pytorch 2.2.2-7 on Azure Linux 3.0ModerateOut-of-bandPyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d, and nn.Dropout3d for fallback_random=True.
CVE-2025-48038 ↗2025-09-12azl3 erlang 26.2.5.13-1 on Azure Linux 3.0ModerateOut-of-bandUnverified File Handles can Cause Excessive Use of System Resources
CVE-2025-48039 ↗2025-09-12azl3 erlang 26.2.5.13-1 on Azure Linux 3.0ModerateOut-of-bandUnverified Paths can Cause Excessive Use of System Resources
CVE-2025-48040 ↗2025-09-13cbl2 erlang 25.3.2.21-2 on CBL Mariner 2.0ModerateOut-of-bandMalicious Key Exchange Messages may Lead to Excessive Resource Consumption
CVE-2025-48041 ↗2025-09-12azl3 erlang 26.2.5.13-1 on Azure Linux 3.0ModerateOut-of-bandSSH_FXP_OPENDIR may Lead to Exhaustion of File Handles
CVE-2025-4953 ↗2025-11-29azl3 skopeo 1.14.4-6 on Azure Linux 3.0ModerateOut-of-bandPodman: build context bind mount
CVE-2025-53791 ↗2025-09-05Microsoft Edge (Chromium-based)ModerateOut-of-band0%Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2025-55554 ↗2025-10-05cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ModerateOut-of-bandpytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().
CVE-2025-55558 ↗2025-10-02cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ModerateOut-of-bandA buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a Denial of Service (DoS).
CVE-2025-55560 ↗2025-10-02azl3 pytorch 2.2.2-7 on Azure Linux 3.0ModerateOut-of-bandAn issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor.
CVE-2025-58354 ↗2025-09-25azl3 kata-containers 3.19.1.kata2-1 on Azure Linux 3.0ModerateOut-of-bandKata Containers coco-tdx malicious host can circumvent initdata verification
CVE-2025-58364 ↗2025-09-12cbl2 cups 2.3.3-9 on CBL Mariner 2.0ModerateOut-of-bandcups: Remote DoS via null dereference
CVE-2025-59375 ↗2025-09-16cbl2 expat 2.6.4-2 on CBL Mariner 2.0ModerateOut-of-bandlibexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
CVE-2025-59825 ↗2025-09-27azl3 kata-containers-cc 3.15.0.aks0-6 on Azure Linux 3.0ModerateOut-of-bandastral-tokio-tar has a path traversal in tar extraction
CVE-2025-60018 ↗2025-09-29azl3 glib-networking 2.78.0-1 on Azure Linux 3.0ModerateOut-of-bandGlib-networking: out of bound reads on glib-networking through tls/openssl/gtlscertificate-openssl.c via "g_tls_certificate_openssl_get_property()"
CVE-2025-8869 ↗2025-09-27azl3 python-pip 24.2-3 on Azure Linux 3.0ModerateOut-of-bandFallback tar extraction in pip doesn't check symbolic links point to extraction directory
CVE-2025-9086 ↗2025-09-13azl3 curl 8.11.1-3 on Azure Linux 3.0ModerateOut-of-bandOut of bounds read for cookie path
CVE-2025-9231 ↗2025-10-02azl3 openssl 3.3.3-3 on Azure Linux 3.0ModerateOut-of-bandTiming side-channel in SM2 algorithm on 64 bit ARM
CVE-2025-9232 ↗2025-10-02azl3 openssl 3.3.3-3 on Azure Linux 3.0ModerateOut-of-bandOut-of-bounds read in HTTP client no_proxy handling
CVE-2025-9901 ↗2025-09-07azl3 libsoup 3.4.4-9 on Azure Linux 3.0ModerateOut-of-bandLibsoup: improper handling of http vary header in libsoup caching
CVE-2025-47967 ↗2025-09-16Microsoft Edge (Chromium-based)LowOut-of-band0%Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2025-58749 ↗2025-09-21cbl2 fluent-bit 3.0.6-4 on CBL Mariner 2.0LowOut-of-bandWAMR runtime hangs or crashes with large memory.fill addresses in LLVM-JIT mode
CVE-2025-58767 ↗2025-09-21azl3 ruby 3.3.5-6 on Azure Linux 3.0LowOut-of-bandREXML has a DoS condition when parsing malformed XML file
CVE-2025-60019 ↗2025-09-29cbl2 glib-networking 2.70.0-1 on CBL Mariner 2.0LowOut-of-bandGlib-networking: uninitialized memory dereferences on glib-networking through glib-networking/tls/openssl/gtlsbio.c via g_tls_bio_new_from_iostream() and g_tls_bio_new_from_datagram_based()
CVE-2025-7039 ↗2025-09-05cbl2 glib 2.71.0-5 on CBL Mariner 2.0LowOut-of-bandGlib: buffer under-read on glib through glib/gfileutils.c via get_tmp_file()
CVE-2025-8277 ↗2025-09-11cbl2 libssh 0.10.6-2 on CBL Mariner 2.0LowOut-of-bandLibssh: memory exhaustion via repeated key exchange in libssh
CVE-2024-21907 ↗2025-09-09Microsoft SQL Server 2017 for x64-based Systems (GDR)N/A33%KB5065222KB5065223
and 4 moreKB5065224KB5065225KB5065226KB5065227
VulnCheck: CVE-2024-21907 Improper Handling of Exceptional Conditions in Newtonsoft.Json
CVE-2025-10200 ↗2025-09-11Microsoft Edge (Chromium-based)N/AOut-of-band1%Chromium: CVE-2025-10200 Use after free in Serviceworker
CVE-2025-10201 ↗2025-09-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-10201 Inappropriate implementation in Mojo
CVE-2025-10500 ↗2025-09-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-10500 Use after free in Dawn
CVE-2025-10501 ↗2025-09-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-10501 Use after free in WebRTC
CVE-2025-10502 ↗2025-09-19Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-10502 Heap buffer overflow in ANGLE
CVE-2025-10585 ↗2025-09-19Microsoft Edge (Chromium-based)N/AOut-of-band5%CISA KEVVulnCheckENISAChromium: CVE-2025-10585 Type Confusion in V8
CVE-2025-10890 ↗2025-09-25Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-10890 Side-channel information leakage in V8
CVE-2025-10891 ↗2025-09-25Microsoft Edge (Chromium-based)N/AOut-of-band7%Chromium: CVE-2025-10891 Integer overflow in V8
CVE-2025-10892 ↗2025-09-25Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-10892 Integer overflow in V8
CVE-2025-39799 ↗2025-09-16azl3 kernel 6.6.96.2-2 on Azure Linux 3.0N/AOut-of-bandACPI: processor: perflib: Move problematic pr->performance check
CVE-2025-9864 ↗2025-09-05Microsoft Edge (Chromium-based)N/AOut-of-bandChromium: CVE-2025-9864 Use after free in V8
CVE-2025-9865 ↗2025-09-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-9865 Inappropriate implementation in Toolbar
CVE-2025-9866 ↗2025-09-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-9866 Inappropriate implementation in Extensions
CVE-2025-9867 ↗2025-09-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-9867 Inappropriate implementation in Downloads
#

August 2025

Patch Tuesday August 12, 2025134 CVEs plus 152 Azure Linux package advisories · 19 critical · 0 exploitation detected · 0 in KEV286 CVEs · 21 critical · 0 exploitation detected · 0 in KEV · includes 152 Azure Linux package advisories
Risk matrix, August 2025
18 of these counts use a severity derived from CVSS because Microsoft assigned none.
18 of these counts use a severity derived from CVSS because Microsoft assigned none.
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2025-38561 ↗2025-09-04azl3 kernel 6.6.96.1-1 on Azure Linux 3.0CriticalOut-of-bandksmbd: fix Preauh_HashValue race condition
CVE-2025-38615 ↗2025-09-04azl3 kernel 6.6.96.1-1 on Azure Linux 3.0CriticalOut-of-bandfs/ntfs3: cancle set bad inode after removing name fails
CVE-2025-48807 ↗2025-08-12Windows 10 Version 1809 for x64-based SystemsCritical0%KB5065306KB5065425
and 7 moreKB5065426KB5065427KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2025-49707 ↗2025-08-12DCasv5-series Azure VMCritical0%Azure Virtual Machines Spoofing Vulnerability
CVE-2025-50165 ↗2025-08-12Windows Server 2025 (Server Core installation)Critical10%KB5063878KB5064010Windows Graphics Component Remote Code Execution Vulnerability
CVE-2025-50176 ↗2025-08-12Windows Server 2022Critical0%KB5063812KB5063875
and 4 moreKB5063878KB5063880KB5063899KB5064010
DirectX Graphics Kernel Remote Code Execution Vulnerability
CVE-2025-50177 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsCritical4%More likelyKB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2025-53731 ↗2025-08-12Microsoft Office 2019 for 32-bit editionsCritical1%KB5002756Microsoft Office Remote Code Execution Vulnerability
CVE-2025-53733 ↗2025-08-12Microsoft SharePoint Enterprise Server 2016Critical0%KB5002763KB5002769
and 3 moreKB5002770KB5002771KB5002772
Microsoft Word Remote Code Execution Vulnerability
CVE-2025-53740 ↗2025-08-12Microsoft Office 2019 for 32-bit editionsCritical1%KB5002756Microsoft Office Remote Code Execution Vulnerability
CVE-2025-53763 ↗2025-08-21Microsoft Purview Data GovernanceCriticalOut-of-band1%Azure Databricks Elevation of Privilege Vulnerability
CVE-2025-53766 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsCritical7%KB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
GDI+ Remote Code Execution Vulnerability
CVE-2025-53767 ↗2025-08-07Azure Open AICriticalOut-of-band1%Azure OpenAI Elevation of Privilege Vulnerability
CVE-2025-53774 ↗2025-08-07Microsoft 365 Copilot's Business ChatCriticalOut-of-band1%Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
CVE-2025-53778 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsCritical38%More likelyKB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows NTLM Elevation of Privilege Vulnerability
CVE-2025-53781 ↗2025-08-12DCasv5-series Azure VMCritical1%Azure Virtual Machines Information Disclosure Vulnerability
CVE-2025-53784 ↗2025-08-12Microsoft 365 Apps for Enterprise for 32-bit SystemsCritical0%Microsoft Word Remote Code Execution Vulnerability
CVE-2025-53787 ↗2025-08-07Microsoft 365 Copilot's Business ChatCriticalOut-of-band1%Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
CVE-2025-53792 ↗2025-08-07Azure PortalCriticalOut-of-band1%Azure Portal Elevation of Privilege Vulnerability
CVE-2025-53793 ↗2025-08-12Azure Stack Hub 2408Critical1%Azure Stack Hub Information Disclosure Vulnerability
CVE-2025-53795 ↗2025-08-21Microsoft PC ManagerCriticalOut-of-band1%Microsoft PC Manager Elevation of Privilege Vulnerability
CVE-2024-58240 ↗2026-01-11cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandtls: separate no-async decryption request handling from async
CVE-2025-24999 ↗2025-08-12Microsoft SQL Server 2017 for x64-based Systems (GDR)Important2%KB5063756KB5063757
and 6 moreKB5063758KB5063759KB5063760KB5063761KB5063762KB5063814
Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-25005 ↗2025-08-12Microsoft Exchange Server 2019 Cumulative Update 14Important1%KB5063221KB5063222
and 2 moreKB5063223KB5063224
Microsoft Exchange Server Tampering Vulnerability
CVE-2025-25006 ↗2025-08-12Microsoft Exchange Server 2019 Cumulative Update 15Important1%KB5063221KB5063222
and 2 moreKB5063223KB5063224
Microsoft Exchange Server Spoofing Vulnerability
CVE-2025-25007 ↗2025-08-12Microsoft Exchange Server Subscription Edition RTMImportant1%KB5063221KB5063222
and 2 moreKB5063223KB5063224
Microsoft Exchange Server Spoofing Vulnerability
CVE-2025-33051 ↗2025-08-12Microsoft Exchange Server 2019 Cumulative Update 14Important1%KB5063221KB5063222
and 2 moreKB5063223KB5063224
Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2025-3770 ↗2025-09-03azl3 edk2 20240524git3e722403cd16-9 on Azure Linux 3.0ImportantOut-of-bandSMM IDT Privilege Escalation Vulnerability
CVE-2025-38499 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandclone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns
CVE-2025-38500 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandxfrm: interface: fix use-after-free after changing collect_md xfrm interface
CVE-2025-38502 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandbpf: Fix oob access in cgroup local storage
CVE-2025-38527 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandsmb: client: fix use-after-free in cifs_oplock_break
CVE-2025-38530 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandcomedi: pcl812: Fix bit shift out of bounds
CVE-2025-38532 ↗2025-09-04azl3 kernel 6.6.96.1-1 on Azure Linux 3.0ImportantOut-of-bandnet: libwx: properly reset Rx ring descriptor
CVE-2025-38533 ↗2025-09-04azl3 kernel 6.6.96.1-1 on Azure Linux 3.0ImportantOut-of-bandnet: libwx: fix the using of Rx buffer DMA
CVE-2025-38535 ↗2025-09-04cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandphy: tegra: xusb: Fix unbalanced regulator disable in UTMI PHY mode
CVE-2025-38538 ↗2025-09-04azl3 kernel 6.6.96.1-1 on Azure Linux 3.0ImportantOut-of-banddmaengine: nbpfaxi: Fix memory corruption in probe()
CVE-2025-38543 ↗2025-09-04azl3 kernel 6.6.96.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/tegra: nvdec: Fix dma_alloc_coherent error check
CVE-2025-38548 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandhwmon: (corsair-cpro) Validate the size of the received input buffer
CVE-2025-38552 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandmptcp: plug races between subflow fail and subflow creation
CVE-2025-38555 ↗2025-09-04azl3 kernel 6.6.96.1-1 on Azure Linux 3.0ImportantOut-of-bandusb: gadget : fix use-after-free in composite_dev_cleanup()
CVE-2025-38556 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandHID: core: Harden s32ton() against conversion to 0 bits
CVE-2025-38563 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandperf/core: Prevent VMA split of buffer mappings
CVE-2025-38565 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandperf/core: Exit early on perf_mmap() fail
CVE-2025-38568 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandnet/sched: mqprio: fix stack out-of-bounds write in tc entry parsing
CVE-2025-38572 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandipv6: reject malicious packets in ipv6_gso_segment()
CVE-2025-38574 ↗2025-09-04cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandpptp: ensure minimal skb length in pptp_xmit()
CVE-2025-38579 ↗2025-09-04cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandf2fs: fix KMSAN uninit-value in extent_info usage
CVE-2025-38582 ↗2025-11-28azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandRDMA/hns: Fix double destruction of rsv_qp
CVE-2025-38584 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandpadata: Fix pd UAF once and for all
CVE-2025-38585 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandstaging: media: atomisp: Fix stack buffer overflow in gmin_get_var_int()
CVE-2025-38595 ↗2025-11-28azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandxen: fix UAF in dmabuf_exp_from_pages()
CVE-2025-38605 ↗2025-09-04azl3 kernel 6.6.96.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: ath12k: Pass ab pointer directly to ath12k_dp_tx_get_encap_type()
CVE-2025-38609 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandPM / devfreq: Check governor before using governor->name
CVE-2025-38617 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandnet/packet: fix a race in packet_set_ring() and packet_notifier()
CVE-2025-38618 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandvsock: Do not allow binding to VMADDR_PORT_ANY
CVE-2025-38652 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandf2fs: fix to avoid out-of-boundary access in devs.path
CVE-2025-38656 ↗2025-11-28azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandwifi: iwlwifi: Fix error code in iwl_op_mode_dvm_start()
CVE-2025-38660 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-band[ceph] parse_longname(): strrchr() expects NUL-terminated string
CVE-2025-38665 ↗2025-09-03cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandcan: netlink: can_changelink(): fix NULL pointer deref of struct can_priv::do_set_mode
CVE-2025-38666 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandnet: appletalk: Fix use-after-free in AARP proxy probe
CVE-2025-38668 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandregulator: core: fix NULL dereference on unbind due to stale coupling data
CVE-2025-38676 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandiommu/amd: Avoid stack buffer overflow from kernel cmdline
CVE-2025-38677 ↗2025-09-04cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandf2fs: fix to avoid out-of-boundary access in dnode page
CVE-2025-47907 ↗2025-09-03azl3 golang 1.24.5-1 on Azure Linux 3.0ImportantOut-of-bandIncorrect results returned from Rows.Scan in database/sql
CVE-2025-47954 ↗2025-08-12Microsoft SQL Server 2022 for x64-based Systems (GDR)Important1%KB5063756KB5063814Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-49712 ↗2025-08-12Microsoft SharePoint Enterprise Server 2016Important14%KB5002769KB5002771Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2025-49743 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2025-49745 ↗2025-08-12Microsoft Dynamics 365 (on-premises) version 9.1Important1%KB5059086Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2025-49751 ↗2025-08-12Windows 10 Version 1809 for x64-based SystemsImportant0%KB5063709KB5063812
and 7 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063899KB5064010
Windows Hyper-V Denial of Service Vulnerability
CVE-2025-49757 ↗2025-08-12Windows Server 2019Important1%KB5062553KB5062557
and 9 moreKB5062560KB5062570KB5062572KB5062592KB5062597KB5062618KB5062619KB5062624KB5062632
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-49758 ↗2025-08-12Microsoft SQL Server 2017 for x64-based Systems (GDR)Important1%KB5063756KB5063757
and 6 moreKB5063758KB5063759KB5063760KB5063761KB5063762KB5063814
Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-49759 ↗2025-08-12Microsoft SQL Server 2017 for x64-based Systems (GDR)Important1%KB5063756KB5063757
and 6 moreKB5063758KB5063759KB5063760KB5063761KB5063762KB5063814
Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-49761 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5063709KB5063812
and 12 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063889KB5063899KB5063906KB5063927KB5063947KB5063950KB5064010
Windows Kernel Elevation of Privilege Vulnerability
CVE-2025-49762 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-50153 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5063709KB5063812
and 9 moreKB5063871KB5063875KB5063877KB5063880KB5063889KB5063906KB5063927KB5063947KB5063950
Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2025-50154 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant26%KB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Microsoft Windows File Explorer Spoofing Vulnerability
CVE-2025-50155 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5063709KB5063812
and 10 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063889KB5063899KB5063906KB5063950KB5064010
Windows Push Notifications Apps Elevation of Privilege Vulnerability
CVE-2025-50156 ↗2025-08-12Windows Server 2019Important1%KB5063812KB5063871
and 11 moreKB5063877KB5063878KB5063880KB5063888KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-50157 ↗2025-08-12Windows Server 2019Important1%KB5063812KB5063871
and 11 moreKB5063877KB5063878KB5063880KB5063888KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-50158 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows NTFS Information Disclosure Vulnerability
CVE-2025-50159 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5063709KB5063812
and 10 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063889KB5063899KB5063906KB5063950KB5064010
Remote Access Point-to-Point Protocol (PPP) EAP-TLS Elevation of Privilege Vulnerability
CVE-2025-50160 ↗2025-08-12Windows Server 2019Important1%KB5063812KB5063871
and 11 moreKB5063877KB5063878KB5063880KB5063888KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-50161 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Win32k Elevation of Privilege Vulnerability
CVE-2025-50162 ↗2025-08-12Windows Server 2019Important1%KB5063812KB5063871
and 11 moreKB5063877KB5063878KB5063880KB5063888KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-50163 ↗2025-08-12Windows Server 2019Important1%KB5063812KB5063871
and 11 moreKB5063877KB5063878KB5063880KB5063888KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-50164 ↗2025-08-12Windows Server 2019Important1%KB5063812KB5063871
and 11 moreKB5063877KB5063878KB5063880KB5063888KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-50166 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Distributed Transaction Coordinator (MSDTC) Information Disclosure Vulnerability
CVE-2025-50167 ↗2025-08-12Windows 10 Version 1809 for x64-based SystemsImportant0%More likelyKB5063709KB5063812
and 10 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063889KB5063899KB5063906KB5063950KB5064010
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-50168 ↗2025-08-12Windows 11 Version 22H2 for ARM64-based SystemsImportant1%More likelyKB5063875KB5063878
and 2 moreKB5063899KB5064010
Win32k Elevation of Privilege Vulnerability
CVE-2025-50169 ↗2025-08-12Windows Server 2025 (Server Core installation)Important1%KB5063878KB5064010Windows SMB Remote Code Execution Vulnerability
CVE-2025-50170 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5063709KB5063812
and 6 moreKB5063875KB5063877KB5063878KB5063880KB5063899KB5064010
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2025-50171 ↗2025-08-12Windows Server 2022Important1%KB5063709KB5063812
and 5 moreKB5063875KB5063878KB5063880KB5063899KB5064010
Remote Desktop Spoofing Vulnerability
CVE-2025-50172 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5063709KB5063812
and 6 moreKB5063875KB5063877KB5063878KB5063880KB5063899KB5064010
DirectX Graphics Kernel Denial of Service Vulnerability
CVE-2025-50173 ↗2025-08-12Multimedia Redirection InstallerImportant0%KB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Installer Elevation of Privilege Vulnerability
CVE-2025-52194 ↗2025-09-03cbl2 libsndfile 1.0.31-3 on CBL Mariner 2.0ImportantOut-of-bandA buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio files. The vulnerability occurs in the ircam_read_header function at src/ircam.c:164 during sample rate processing, leading to memory corruption and potential code execution.
CVE-2025-53131 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5063709KB5063812
and 6 moreKB5063875KB5063877KB5063878KB5063880KB5063899KB5064010
Windows Media Remote Code Execution Vulnerability
CVE-2025-53132 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Win32k Elevation of Privilege Vulnerability
CVE-2025-53133 ↗2025-08-12Windows Server 2025 (Server Core installation)Important0%KB5063878KB5064010Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
CVE-2025-53134 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-53135 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5063709KB5063812
and 9 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063889KB5063899KB5063950KB5064010
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2025-53136 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
NT OS Kernel Information Disclosure Vulnerability
CVE-2025-53137 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-53138 ↗2025-08-12Windows Server 2019Important1%KB5063812KB5063871
and 11 moreKB5063877KB5063878KB5063880KB5063888KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-53140 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Kernel Transaction Manager Elevation of Privilege Vulnerability
CVE-2025-53141 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-53142 ↗2025-08-12Windows 11 Version 22H2 for ARM64-based SystemsImportant0%KB5063875KB5063878
and 2 moreKB5063899KB5064010
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2025-53143 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant6%KB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2025-53144 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant6%KB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2025-53145 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant6%KB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2025-53147 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-53148 ↗2025-08-12Windows Server 2019Important1%KB5063812KB5063871
and 11 moreKB5063877KB5063878KB5063880KB5063888KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-53149 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
CVE-2025-53151 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5063709KB5063812
and 6 moreKB5063875KB5063877KB5063878KB5063880KB5063899KB5064010
Windows Kernel Elevation of Privilege Vulnerability
CVE-2025-53152 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5063709KB5063812
and 9 moreKB5063871KB5063875KB5063877KB5063880KB5063889KB5063906KB5063927KB5063947KB5063950
Desktop Windows Manager Remote Code Execution Vulnerability
CVE-2025-53153 ↗2025-08-12Windows Server 2019Important1%KB5063812KB5063871
and 11 moreKB5063877KB5063878KB5063880KB5063888KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-53154 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-53155 ↗2025-08-12Windows 10 Version 1809 for x64-based SystemsImportant0%KB5063709KB5063812
and 10 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063889KB5063899KB5063906KB5063950KB5064010
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-53156 ↗2025-08-12Windows Server 2025 (Server Core installation)Important1%More likelyKB5063878KB5063899
and 1 moreKB5064010
Windows Storage Port Driver Information Disclosure Vulnerability
CVE-2025-53716 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5063709KB5063812
and 6 moreKB5063875KB5063877KB5063878KB5063880KB5063899KB5064010
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2025-53718 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5063709KB5063812
and 14 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063888KB5063889KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-53719 ↗2025-08-12Windows Server 2019Important1%KB5063812KB5063871
and 11 moreKB5063877KB5063878KB5063880KB5063888KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-53720 ↗2025-08-12Windows Server 2019Important1%KB5063812KB5063871
and 11 moreKB5063877KB5063878KB5063880KB5063888KB5063899KB5063906KB5063927KB5063947KB5063948KB5063950KB5064010
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-53721 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5063709KB5063812
and 6 moreKB5063875KB5063877KB5063878KB5063880KB5063899KB5064010
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
CVE-2025-53722 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant18%KB5063709KB5063812
and 12 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063889KB5063899KB5063906KB5063927KB5063947KB5063950KB5064010
Windows Remote Desktop Services Denial of Service Vulnerability
CVE-2025-53723 ↗2025-08-12Windows 10 Version 1809 for x64-based SystemsImportant0%KB5063709KB5063812
and 10 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063889KB5063899KB5063906KB5063950KB5064010
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-53724 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5063709KB5063812
and 10 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063889KB5063899KB5063906KB5063950KB5064010
Windows Push Notifications Apps Elevation of Privilege Vulnerability
CVE-2025-53725 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5063709KB5063812
and 10 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063889KB5063899KB5063906KB5063950KB5064010
Windows Push Notifications Apps Elevation of Privilege Vulnerability
CVE-2025-53726 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5063709KB5063812
and 10 moreKB5063871KB5063875KB5063877KB5063878KB5063880KB5063889KB5063899KB5063906KB5063950KB5064010
Windows Push Notifications Apps Elevation of Privilege Vulnerability
CVE-2025-53727 ↗2025-08-12Microsoft SQL Server 2022 for x64-based Systems (CU 20)Important1%KB5063756KB5063757
and 6 moreKB5063758KB5063759KB5063760KB5063761KB5063762KB5063814
Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-53728 ↗2025-08-12Microsoft Dynamics 365 (on-premises) version 9.1Important1%KB5064483Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2025-53729 ↗2025-08-12Azure File Sync v18Important0%Microsoft Azure File Sync Elevation of Privilege Vulnerability
CVE-2025-53730 ↗2025-08-12Microsoft Office 2019 for 32-bit editionsImportant0%Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2025-53732 ↗2025-08-12Microsoft Office for AndroidImportant0%Microsoft Office Remote Code Execution Vulnerability
CVE-2025-53734 ↗2025-08-12Microsoft Office 2019 for 32-bit editionsImportant0%Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2025-53735 ↗2025-08-12Office Online ServerImportant1%KB5002752KB5002758Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-53736 ↗2025-08-12Microsoft SharePoint Enterprise Server 2016Important1%KB5002763KB5002769
and 3 moreKB5002770KB5002771KB5002772
Microsoft Word Information Disclosure Vulnerability
CVE-2025-53737 ↗2025-08-12Office Online ServerImportant1%KB5002752KB5002758Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-53738 ↗2025-08-12Microsoft Office 2019 for 32-bit editionsImportant1%KB5002763Microsoft Word Remote Code Execution Vulnerability
CVE-2025-53739 ↗2025-08-12Office Online ServerImportant1%KB5002752KB5002758Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-53741 ↗2025-08-12Office Online ServerImportant1%KB5002752KB5002758Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-53759 ↗2025-08-12Office Online ServerImportant1%KB5002752Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-53760 ↗2025-08-12Microsoft SharePoint Enterprise Server 2016Important10%KB5002769KB5002771
and 1 moreKB5002773
Microsoft SharePoint Elevation of Privilege Vulnerability
CVE-2025-53761 ↗2025-08-12Microsoft Office 2019 for 32-bit editionsImportant1%KB5002765Microsoft PowerPoint Remote Code Execution Vulnerability
CVE-2025-53765 ↗2025-08-12Azure Stack HubImportant0%Azure Stack Hub Information Disclosure Vulnerability
CVE-2025-53769 ↗2025-08-12Windows Security AppImportant0%Windows Security App Spoofing Vulnerability
CVE-2025-53772 ↗2025-08-12Web Deploy 4.0Important22%VulnCheckWeb Deploy Remote Code Execution Vulnerability
CVE-2025-53773 ↗2025-08-12Microsoft Visual Studio 2022 version 17.14Important3%GitHub Copilot and Visual Studio Remote Code Execution Vulnerability
CVE-2025-53783 ↗2025-08-12Teams for D365 Remote Assist HoloLensImportant1%Microsoft Teams Remote Code Execution Vulnerability
CVE-2025-53786 ↗2025-08-12Microsoft Exchange Server Subscription Edition RTMImportant7%More likelyKB5047155KB5050672
and 2 moreKB5050673KB5050674
Microsoft Exchange Server Hybrid Deployment Elevation of Privilege Vulnerability
CVE-2025-53788 ↗2025-08-12Windows Subsystem for Linux (WSL2)Important0%Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability
CVE-2025-53789 ↗2025-08-12Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5062552KB5062553
and 6 moreKB5062554KB5062557KB5062560KB5062561KB5062570KB5062572
Windows StateRepository API Server file Elevation of Privilege Vulnerability
CVE-2025-54351 ↗2025-09-03cbl2 iperf3 3.18-1 on CBL Mariner 2.0ImportantOut-of-bandIn iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
CVE-2025-55229 ↗2025-08-21Windows 10 Version 1809 for 32-bit SystemsImportantOut-of-band0%KB5058379KB5058383
and 7 moreKB5058384KB5058385KB5058387KB5058392KB5058405KB5058411KB5058500
Windows Certificate Spoofing Vulnerability
CVE-2025-55230 ↗2025-08-21Windows 10 Version 1809 for 32-bit SystemsImportantOut-of-band0%KB5062552KB5062553
and 12 moreKB5062554KB5062557KB5062560KB5062561KB5062570KB5062572KB5062592KB5062597KB5062618KB5062619KB5062624KB5062632
Windows MBT Transport Driver Elevation of Privilege Vulnerability
CVE-2025-55231 ↗2025-08-21Windows Server 2019ImportantOut-of-band0%KB5062553KB5062557
and 3 moreKB5062560KB5062572KB5062597
Windows Storage-based Management Service Remote Code Execution Vulnerability
CVE-2025-8714 ↗2025-09-04azl3 postgresql 16.9-1 on Azure Linux 3.0ImportantOut-of-bandPostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client
CVE-2025-8715 ↗2025-09-04cbl2 postgresql 14.18-1 on CBL Mariner 2.0ImportantOut-of-bandPostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server
CVE-2025-8747 ↗2025-09-03azl3 keras 3.3.3-2 on Azure Linux 3.0ImportantOut-of-bandKeras safe_mode bypass allows arbitrary code execution when loading a malicious model.
CVE-2025-9288 ↗2025-09-03cbl2 reaper 3.1.1-19 on CBL Mariner 2.0ImportantOut-of-bandMissing type checks leading to hash rewind and passing on crafted data
CVE-2022-50233 ↗2025-11-21cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandBluetooth: eir: Fix using strlen with hdev->{dev_name,short_name}
CVE-2025-38501 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandksmbd: limit repeated connections from clients with the same IP
CVE-2025-38503 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix assertion when building free space tree
CVE-2025-38507 ↗2025-11-21azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandHID: nintendo: avoid bluetooth suspend/resume stalls
CVE-2025-38510 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandkasan: remove kasan_find_vm_area() to prevent possible deadlock
CVE-2025-38512 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandwifi: prevent A-MSDU attacks in mesh networks
CVE-2025-38513 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandwifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev()
CVE-2025-38514 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandrxrpc: Fix oops due to non-existence of prealloc backlog struct
CVE-2025-38515 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/sched: Increment job count before swapping tail spsc queue
CVE-2025-38516 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandpinctrl: qcom: msm: mark certain pins as invalid for interrupts
CVE-2025-38520 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdkfd: Don't call mmput from MMU notifier callback
CVE-2025-38524 ↗2025-09-04cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandrxrpc: Fix recv-recv race of completed call
CVE-2025-38526 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandice: add NULL check in eswitch lag check
CVE-2025-38528 ↗2025-09-04cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandbpf: Reject %p% format string in bprintf-like helpers
CVE-2025-38529 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandcomedi: aio_iiro_16: Fix bit shift out of bounds
CVE-2025-38531 ↗2025-09-04azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandiio: common: st_sensors: Fix use of uninitialize device structs
CVE-2025-38537 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnet: phy: Don't register LEDs for genphy
CVE-2025-38539 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandtracing: Add down_write(trace_event_sem) when adding trace event
CVE-2025-38540 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandHID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras
CVE-2025-38542 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnet: appletalk: Fix device refcount leak in atrtr_create()
CVE-2025-38544 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandrxrpc: Fix bug due to prealloc collision
CVE-2025-38546 ↗2025-09-04cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandatm: clip: Fix memory leak of struct clip_vcc.
CVE-2025-38550 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandipv6: mcast: Delay put pmc->idev in mld_del_delrec()
CVE-2025-38553 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnet/sched: Restrict conditions for adding duplicating netems to qdisc tree
CVE-2025-38560 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandx86/sev: Evict cache lines during SNP memory validation
CVE-2025-38562 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: fix null pointer dereference error in generate_encryptionkey
CVE-2025-38566 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandsunrpc: fix handling of server side tls alerts
CVE-2025-38569 ↗2026-01-10cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandbenet: fix BUG when creating VFs
CVE-2025-38571 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandsunrpc: fix client side handling of tls alerts
CVE-2025-38576 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandpowerpc/eeh: Make EEH driver device hotplug safe
CVE-2025-38577 ↗2025-09-04cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandf2fs: fix to avoid panic in f2fs_evict_inode
CVE-2025-38578 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix to avoid UAF in f2fs_sync_inode_meta()
CVE-2025-38581 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: ccp - Fix crash when rebind ccp device for ccp.ko
CVE-2025-38583 ↗2025-09-04cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandclk: xilinx: vcu: unregister pll_post only if registered correctly
CVE-2025-38590 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnet/mlx5e: Remove skb secpath if xfrm state is not found
CVE-2025-38591 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Reject narrower access to pointer ctx fields
CVE-2025-38593 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandBluetooth: hci_sync: fix double free in 'hci_discovery_filter_clear()'
CVE-2025-38597 ↗2025-11-28azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/rockchip: vop2: fail cleanly if missing a primary plane for a video-port
CVE-2025-38601 ↗2025-09-04cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandwifi: ath11k: clear initialized flag for deinit-ed srng lists
CVE-2025-38602 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandiwlwifi: Add missing check for alloc_ordered_workqueue
CVE-2025-38604 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandwifi: rtl818x: Kill URBs before clearing tx status queue
CVE-2025-38608 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandbpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls
CVE-2025-38610 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandpowercap: dtpm_cpu: Fix NULL pointer dereference in get_pd_power_uw()
CVE-2025-38612 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandstaging: fbtft: fix potential memory leak in fbtft_framebuffer_alloc()
CVE-2025-38614 ↗2025-09-04azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandeventpoll: Fix semi-unbounded recursion
CVE-2025-38616 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandtls: handle data disappearing from under the TLS ULP
CVE-2025-38622 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnet: drop UFO packets in udp_rcv_segment()
CVE-2025-38623 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandPCI: pnv_php: Fix surprise plug detection and recovery
CVE-2025-38624 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandPCI: pnv_php: Clean up allocated IRQs on unplug
CVE-2025-38625 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandvfio/pds: Fix missing detach_ioas op
CVE-2025-38626 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix to trigger foreground gc during f2fs_map_blocks() in lfs mode
CVE-2025-38627 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandf2fs: compress: fix UAF of f2fs_inode_info in f2fs_free_dic
CVE-2025-38630 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandfbdev: imxfb: Check fb_add_videomode to prevent null-ptr-deref
CVE-2025-38634 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandpower: supply: cpcap-charger: Fix null check for power_supply_get_by_name
CVE-2025-38635 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandclk: davinci: Add NULL check in davinci_lpsc_clk_register()
CVE-2025-38636 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandrv: Use strings in da monitors tracepoints
CVE-2025-38639 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: xt_nfacct: don't assume acct name is null-terminated
CVE-2025-38640 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Disable migration in nf_hook_run_bpf().
CVE-2025-38643 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandwifi: cfg80211: Add missing lock in cfg80211_check_and_end_cac()
CVE-2025-38644 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mac80211: reject TDLS operations when station is not associated
CVE-2025-38645 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnet/mlx5: Check device memory pointer before usage
CVE-2025-38646 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandwifi: rtw89: avoid NULL dereference when RX problematic packet on unsupported 6 GHz band
CVE-2025-38648 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandspi: stm32: Check for cfg availability in stm32_spi_probe
CVE-2025-38650 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandhfsplus: remove mutex_lock check in hfsplus_free_extents
CVE-2025-38653 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandproc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al
CVE-2025-38659 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandgfs2: No more self recovery
CVE-2025-38663 ↗2025-09-03azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandnilfs2: reject invalid file types when reading inodes
CVE-2025-38664 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandice: Fix a null pointer dereference in ice_copy_and_init_pkg()
CVE-2025-38670 ↗2025-09-03azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandarm64/entry: Mask DAIF in cpu_switch_to(), call_on_irq_stack()
CVE-2025-38671 ↗2025-09-03cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandi2c: qup: jump out of the loop in case of timeout
CVE-2025-38675 ↗2026-05-25azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandxfrm: state: initialize state_ptrs earlier in xfrm_state_find
CVE-2025-4877 ↗2025-09-03cbl2 libssh 0.10.6-2 on CBL Mariner 2.0ModerateOut-of-bandLibssh: write beyond bounds in binary to base64 conversion functions
CVE-2025-49736 ↗2025-08-12Microsoft Edge for AndroidModerate0%Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2025-53779 ↗2025-08-12Windows Server 2025 (Server Core installation)Moderate3%KB5063878KB5064010Windows Kerberos Elevation of Privilege Vulnerability
CVE-2025-53859 ↗2025-09-04cbl2 nginx 1.22.1-13 on CBL Mariner 2.0ModerateOut-of-bandNGINX ngx_mail_smtp_module vulnerability
CVE-2025-54349 ↗2025-09-04azl3 iperf3 3.17.1-3 on Azure Linux 3.0ModerateOut-of-bandIn iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.
CVE-2025-54389 ↗2025-09-03cbl2 aide 0.16-16 on CBL Mariner 2.0ModerateOut-of-bandAIDE improper output neutralization vulnerability
CVE-2025-54409 ↗2025-09-04azl3 aide 0.18.6-2 on Azure Linux 3.0ModerateOut-of-bandAIDE null pointer dereference when reading incorrectly encoded xattr attributes from database (local DoS)
CVE-2025-55159 ↗2026-01-21azl3 rust 1.90.0-1 on Azure Linux 3.0ModerateOut-of-bandslab allows out-of-bounds access in `get_disjoint_mut` due to incorrect bounds check
CVE-2025-55198 ↗2025-09-04cbl2 helm 3.14.2-7 on CBL Mariner 2.0ModerateOut-of-bandHelm May Panic Due To Incorrect YAML Content
CVE-2025-55199 ↗2025-09-04cbl2 helm 3.14.2-7 on CBL Mariner 2.0ModerateOut-of-bandHelm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion
CVE-2025-58058 ↗2025-09-04cbl2 containerized-data-importer 1.55.0-23 on CBL Mariner 2.0ModerateOut-of-bandgithub.com/ulikunitz/xz leaks memory when decoding a corrupted multiple LZMA archives
CVE-2025-8733 ↗2025-09-03azl3 bison 3.8.2-1 on Azure Linux 3.0ModerateOut-of-bandGNU Bison obprintf.c __obstack_vprintf_internal assertion
CVE-2025-8734 ↗2025-09-03azl3 bison 3.8.2-1 on Azure Linux 3.0ModerateOut-of-bandGNU Bison scan-code.c code_free double free
CVE-2025-8836 ↗2025-09-03azl3 jasper 4.2.1-2 on Azure Linux 3.0ModerateOut-of-bandJasPer JPEG2000 Encoder jpc_enc.c jpc_floorlog2 assertion
CVE-2025-8837 ↗2025-09-03azl3 jasper 4.2.1-2 on Azure Linux 3.0ModerateOut-of-bandJasPer JPEG2000 File jpc_dec.c jpc_dec_dump use after free
CVE-2025-8842 ↗2025-09-03cbl2 nasm 2.16-1 on CBL Mariner 2.0ModerateOut-of-bandNASM Netwide Assember preproc.c do_directive use after free
CVE-2025-8843 ↗2025-09-03cbl2 nasm 2.16-1 on CBL Mariner 2.0ModerateOut-of-bandNASM Netwide Assember outmacho.c macho_no_dead_strip heap-based overflow
CVE-2025-8844 ↗2025-09-03cbl2 tensorflow 2.11.1-2 on CBL Mariner 2.0ModerateOut-of-bandNASM Netwide Assember preproc.c parse_smacro_template null pointer dereference
CVE-2025-8845 ↗2025-09-03azl3 nasm 2.16.01-1 on Azure Linux 3.0ModerateOut-of-bandNASM Netwide Assember nasm.c assemble_file stack-based overflow
CVE-2025-8846 ↗2025-09-03azl3 nasm 2.16.01-2 on Azure Linux 3.0ModerateOut-of-bandNASM Netwide Assember parser.c parse_line stack-based overflow
CVE-2025-8851 ↗2025-09-03azl3 libtiff 4.6.0-7 on Azure Linux 3.0ModerateOut-of-bandLibTIFF tiffcrop tiffcrop.c readSeparateStripsetoBuffer stack-based overflow
CVE-2025-9165 ↗2025-09-03azl3 libtiff 4.6.0-7 on Azure Linux 3.0ModerateOut-of-bandLibTIFF tiffcmp tiffcmp.c InitCCITTFax3 memory leak
CVE-2025-9390 ↗2025-09-03azl3 vim 9.1.1552-1 on Azure Linux 3.0ModerateOut-of-bandvim xxd xxd.c main buffer overflow
CVE-2025-9403 ↗2025-09-03cbl2 jq 1.6-4 on CBL Mariner 2.0ModerateOut-of-bandjqlang jq JSON jq_test.c run_jq_tests assertion
CVE-2023-26819 ↗2025-08-07azl3 ceph 18.2.2-10 on Azure Linux 3.0LowOut-of-bandcJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.
CVE-2024-13978 ↗2025-09-13azl3 libtiff 4.6.0-8 on Azure Linux 3.0LowOut-of-bandLibTIFF fax2ps tiff2pdf.c t2p_read_tiff_init null pointer dereference
CVE-2025-49755 ↗2025-08-12Microsoft Edge for AndroidLow0%Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2025-50422 ↗2025-09-03azl3 cairo 1.18.0-1 on Azure Linux 3.0LowOut-of-bandCairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.
CVE-2025-54350 ↗2025-09-04azl3 iperf3 3.17.1-3 on Azure Linux 3.0LowOut-of-bandIn iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.
CVE-2025-58160 ↗2025-12-31azl3 kata-containers 3.19.1.kata2-2 on Azure Linux 3.0LowOut-of-bandTracing logging user input may result in poisoning logs with ANSI escape sequences
CVE-2025-8534 ↗2025-09-03cbl2 libtiff 4.6.0-8 on CBL Mariner 2.0LowOut-of-bandlibtiff tiff2ps tiff2ps.c PS_Lvl2page null pointer dereference
CVE-2025-8713 ↗2025-09-03azl3 postgresql 16.9-1 on Azure Linux 3.0LowOut-of-bandPostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table
CVE-2025-8732 ↗2025-09-03azl3 libxml2 2.11.5-6 on Azure Linux 3.0LowOut-of-bandlibxml2 xmlcatalog xmlParseSGMLCatalog recursion
CVE-2025-8835 ↗2025-09-03azl3 jasper 4.2.1-3 on Azure Linux 3.0LowOut-of-bandJasPer Image Color Space Conversion jas_image.c jas_image_chclrspc null pointer dereference
CVE-2025-8961 ↗2025-09-04azl3 libtiff 4.6.0-7 on Azure Linux 3.0LowOut-of-bandLibTIFF tiffcrop tiffcrop.c main memory corruption
CVE-2025-9301 ↗2025-09-03cbl2 cmake 3.21.4-18 on CBL Mariner 2.0LowOut-of-bandcmake cmForEachCommand.cxx ReplayItems assertion
CVE-2015-3310 ↗2025-08-07MicrosoftN/AOut-of-band5%Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) via a start accounting message to the RADIUS server.
CVE-2022-4743 ↗2025-08-07MicrosoftN/AOut-of-band1%A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerability allows an attacker to cause a denial of service attack. The vulnerability affects SDL2 v2.0.4 and above. SDL-1.x are not affected.
CVE-2023-37464 ↗2025-08-07MicrosoftN/AOut-of-band1%Incorrect Authentication Tag length usage in AES GCM decryption in OpenIDC/cjose
CVE-2025-38611 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0N/AOut-of-bandvmci: Prevent the dispatching of uninitialized payloads
CVE-2025-8576 ↗2025-08-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-8576 Use after free in Extensions
CVE-2025-8577 ↗2025-08-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-8577 Inappropriate implementation in Picture In Picture
CVE-2025-8578 ↗2025-08-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-8578 Use after free in Cast
CVE-2025-8579 ↗2025-08-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-8579 Inappropriate implementation in Gemini Live in Chrome
CVE-2025-8580 ↗2025-08-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-8580 Inappropriate implementation in Filesystems
CVE-2025-8581 ↗2025-08-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-8581 Inappropriate implementation in Extensions
CVE-2025-8582 ↗2025-08-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-8582 Insufficient validation of untrusted input in DOM
CVE-2025-8583 ↗2025-08-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-8583 Inappropriate implementation in Permissions
CVE-2025-8879 ↗2025-08-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-8879 Heap buffer overflow in libaom
CVE-2025-8880 ↗2025-08-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-8880 Race in V8
CVE-2025-8881 ↗2025-08-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-8881 Inappropriate implementation in File Picker
CVE-2025-8882 ↗2025-08-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-8882 Use after free in Aura
CVE-2025-8901 ↗2025-08-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-8901 Out of bounds write in ANGLE
CVE-2025-9132 ↗2025-08-21Microsoft Edge (Chromium-based)N/AOut-of-band3%Chromium: CVE-2025-9132 Out of bounds write in V8
CVE-2025-9478 ↗2025-08-28Microsoft Edge (Chromium-based)N/AOut-of-band4%Chromium: CVE-2025-9478 Use after free in ANGLE

Source: the MSRC Common Vulnerability Reporting Framework (CVRF) API, refreshed on the structured-fetch cadence. MSRC severity and the exploitation assessment are Microsoft's published values. Every CVE id links to the MSRC update guide; release CVEs are followed by this site's vulnerability pipeline, and expanding a row shows the same detail panel the vulnerabilities table uses. KB chips are the month's Vendor Fix update numbers, each linking to its Microsoft Update Catalog search. Azure Linux (formerly CBL-Mariner) package advisories are shown and counted here but join the vulnerability tracker only when the operator enables msrc.track_azure_linux, a documented scope choice: they are distro package rebuilds rather than Windows-ecosystem vulnerabilities.

Cross-vendor Patch Day

Beyond Microsoft, vendors that publish a credential-free, machine-readable link from a Common Vulnerabilities and Exposures (CVE) identifier to its patch. Each row links the CVE into this site's vulnerability view and links the specific fix, the Android Open Source Project commit or the Cisco remediation. Severity is shown on each vendor's own scale: a Common Vulnerability Scoring System (CVSS) number where the vendor publishes one, Android's qualitative rating where it does not.

Vendor

July 2026

VendorCVESeverityProductFixed versionPatchAdvisory
CiscoCVE-2026-20150trackedCVSS 8.8Patch ↗Advisory ↗
CiscoCVE-2026-20156trackedCVSS 8.1Patch ↗Advisory ↗
CiscoCVE-2026-20153trackedCVSS 7.5Patch ↗Advisory ↗
CiscoCVE-2026-20157trackedCVSS 7.5Patch ↗Advisory ↗
CiscoCVE-2026-20158trackedCVSS 7.5Patch ↗Advisory ↗
CiscoCVE-2026-20187trackedCVSS 7.5Patch ↗Advisory ↗

June 2026

VendorCVESeverityProductFixed versionPatchAdvisory
CiscoCVE-2026-20230trackedCVSS 8.6Patch ↗Advisory ↗
CiscoCVE-2026-20245trackedCVSS 7.8Patch ↗Advisory ↗
CiscoCVE-2026-20262trackedCVSS 6.5Patch ↗Advisory ↗
AndroidCVE-2025-64505Critical (Android rating)platform/external/libpngPatch ↗Advisory ↗
AndroidCVE-2025-64720trackedCritical (Android rating)platform/external/libpngPatch ↗Advisory ↗
AndroidCVE-2025-65018trackedCritical (Android rating)platform/external/libpngPatch ↗Advisory ↗
AndroidCVE-2026-0039Critical (Android rating)platform/external/dng_sdkPatch ↗Advisory ↗
AndroidCVE-2026-0040Critical (Android rating)platform/external/dng_sdkPatch ↗Advisory ↗
AndroidCVE-2026-0041Critical (Android rating)platform/external/dng_sdkPatch ↗Advisory ↗
AndroidCVE-2026-0042Critical (Android rating)platform/external/dng_sdkPatch ↗Advisory ↗
AndroidCVE-2026-0043Critical (Android rating)platform/external/dng_sdkPatch ↗Advisory ↗
AndroidCVE-2026-0044Critical (Android rating)platform/external/dng_sdkPatch ↗Advisory ↗
AndroidCVE-2026-0051Critical (Android rating)platform/external/dng_sdkPatch ↗Advisory ↗
AndroidCVE-2026-0052Critical (Android rating)platform/external/dng_sdkPatch ↗Advisory ↗
AndroidCVE-2026-0080Critical (Android rating)platform/external/dng_sdkPatch ↗Advisory ↗
AndroidCVE-2026-0097Critical (Android rating)platform/packages/modules/BluetoothPatch ↗Advisory ↗
AndroidCVE-2026-0126Critical (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0132Critical (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0135Critical (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0139Critical (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0149Critical (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0153Critical (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0154Critical (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0160Critical (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0161Critical (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0162Critical (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0164Critical (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-21352Critical (Android rating)platform/external/dng_sdkPatch ↗Advisory ↗
AndroidCVE-2026-21353Critical (Android rating)platform/external/dng_sdkPatch ↗Advisory ↗
AndroidCVE-2025-22424High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-22426High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-26418High (Android rating)platform/packages/services/CarPatch ↗Advisory ↗
AndroidCVE-2025-32348High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-48570High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-48581High (Android rating)platform/buildPatch ↗Advisory ↗
AndroidCVE-2025-48595trackedHigh (Android rating)platform/external/sqlitePatch ↗Advisory ↗
AndroidCVE-2025-48600High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-48612High (Android rating)platform/packages/apps/SettingsPatch ↗Advisory ↗
AndroidCVE-2025-48615High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-48616High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-48648High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-48649High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-48652High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-71251High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-71252High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-71253High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-71254High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-71255High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-71256High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0009High (Android rating)platform/packages/providers/MediaProviderPatch ↗Advisory ↗
AndroidCVE-2026-0016High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0018High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0036High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0045High (Android rating)platform/packages/modules/BluetoothPatch ↗Advisory ↗
AndroidCVE-2026-0046High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0048High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0050High (Android rating)platform/packages/modules/BluetoothPatch ↗Advisory ↗
AndroidCVE-2026-0055High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0056High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0059High (Android rating)platform/packages/modules/BluetoothPatch ↗Advisory ↗
AndroidCVE-2026-0060High (Android rating)platform/packages/apps/SettingsPatch ↗Advisory ↗
AndroidCVE-2026-0061High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0067High (Android rating)platform/external/dng_sdkPatch ↗Advisory ↗
AndroidCVE-2026-0069High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0070High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0074High (Android rating)platform/packages/apps/Launcher3Patch ↗Advisory ↗
AndroidCVE-2026-0075High (Android rating)platform/packages/providers/ContactsProviderPatch ↗Advisory ↗
AndroidCVE-2026-0076High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0077High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0078High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0079High (Android rating)platform/external/dng_sdkPatch ↗Advisory ↗
AndroidCVE-2026-0085High (Android rating)platform/packages/providers/ContactsProviderPatch ↗Advisory ↗
AndroidCVE-2026-0086High (Android rating)platform/packages/apps/SettingsPatch ↗Advisory ↗
AndroidCVE-2026-0087High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0088High (Android rating)platform/packages/apps/CertInstallerPatch ↗Advisory ↗
AndroidCVE-2026-0089High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0091High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0093High (Android rating)platform/packages/apps/SettingsPatch ↗Advisory ↗
AndroidCVE-2026-0094High (Android rating)platform/packages/apps/KeyChainPatch ↗Advisory ↗
AndroidCVE-2026-0095High (Android rating)platform/packages/modules/BluetoothPatch ↗Advisory ↗
AndroidCVE-2026-0096High (Android rating)platform/packages/apps/SettingsPatch ↗Advisory ↗
AndroidCVE-2026-0098High (Android rating)platform/packages/apps/DocumentsUIPatch ↗Advisory ↗
AndroidCVE-2026-0099High (Android rating)platform/packages/modules/NfcPatch ↗Advisory ↗
AndroidCVE-2026-0100High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0125High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0128High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0129High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0130High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0131High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0133High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0136High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0140High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0141High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0142High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0145High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0146High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0147High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0148High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0150High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0151High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0152High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0155High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0157High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0165High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20431High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20432High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20433High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20435High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20447High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20448High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20449High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20450High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20453High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20454High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20454High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20455High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20455High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-21538High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-21539High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-21540High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-21541High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-21542High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-21543High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-21544High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-21545High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-21546High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-21547High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-21736High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-22163High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-22167High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-24085High (Android rating)abl/tianocore/edk2Patch ↗Advisory ↗
AndroidCVE-2026-24089High (Android rating)abl/tianocore/edk2Patch ↗Advisory ↗
AndroidCVE-2026-28574High (Android rating)platform/packages/modules/NfcPatch ↗Advisory ↗
AndroidCVE-2026-28577High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-28578High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-28580High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-28586High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-59609Moderate (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0127Moderate (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0134Moderate (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0137Moderate (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0138Moderate (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0143Moderate (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0144Moderate (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0156Moderate (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0158Moderate (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-24077Moderate (Android rating)no patch linkAdvisory ↗

May 2026

VendorCVESeverityProductFixed versionPatchAdvisory
CiscoCVE-2026-20182trackedCVSS 10.0Patch ↗Advisory ↗
CiscoCVE-2026-20171CVSS 6.8Cisco Nexus 3000 Series SwitchesPatch ↗Advisory ↗
AndroidCVE-2026-0073Critical (Android rating)platform/packages/modules/adbPatch ↗Advisory ↗

April 2026

VendorCVESeverityProductFixed versionPatchAdvisory
AndroidCVE-2026-0049Critical (Android rating)platform/external/dng_sdkPatch ↗Advisory ↗
AndroidCVE-2025-48651High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-48651High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-48651High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-48651High (Android rating)no patch linkAdvisory ↗

March 2026

VendorCVESeverityProductFixed versionPatchAdvisory
CiscoCVE-2026-20079CVSS 10.0Cisco Secure Firewall Management Center (FMC) AppliancesPatch ↗Advisory ↗
CiscoCVE-2026-20131trackedCVSS 10.0Cisco Secure Firewall Management Center (FMC) AppliancesPatch ↗Advisory ↗
CiscoCVE-2026-20012CVSS 8.6Cisco Firepower 2100 Series3.5EPatch ↗Advisory ↗
CiscoCVE-2026-20101CVSS 8.6Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20103CVSS 8.6Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20002CVSS 8.1Cisco Secure Firewall Management Center (FMC) AppliancesPatch ↗Advisory ↗
CiscoCVE-2026-20014CVSS 7.7Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20100CVSS 7.7Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20105CVSS 7.7Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20020CVSS 6.8Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20024CVSS 6.8Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20025CVSS 6.8Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20050CVSS 6.8Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20001CVSS 6.5Cisco Secure Firewall Management Center (FMC) AppliancesPatch ↗Advisory ↗
CiscoCVE-2026-20064CVSS 6.5Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20022CVSS 6.1Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20023CVSS 6.1Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20070CVSS 6.1Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20102CVSS 6.1Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20008CVSS 6.0Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20016CVSS 6.0Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20017CVSS 6.0Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20063CVSS 6.0Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20018CVSS 5.9Cisco Secure Firewall Management Center (FMC) AppliancesPatch ↗Advisory ↗
CiscoCVE-2026-20005CVSS 5.8Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20006CVSS 5.8Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20007CVSS 5.8Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20013CVSS 5.8Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20015CVSS 5.8Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20065CVSS 5.8Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20066CVSS 5.8Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20067CVSS 5.8Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20068CVSS 5.8Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20009CVSS 5.3Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20106CVSS 5.3Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20003CVSS 4.9Cisco Secure Firewall Management Center (FMC) AppliancesPatch ↗Advisory ↗
CiscoCVE-2026-20021CVSS 4.3Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20069CVSS 4.3Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
AndroidCVE-2024-43859Critical (Android rating):linux_kernel:Patch ↗Advisory ↗
AndroidCVE-2025-48631Critical (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0006Critical (Android rating)platform/external/libopenapvPatch ↗Advisory ↗
AndroidCVE-2026-0027Critical (Android rating):linux_kernel:Patch ↗Advisory ↗
AndroidCVE-2026-0028Critical (Android rating):linux_kernel:Patch ↗Advisory ↗
AndroidCVE-2026-0030Critical (Android rating):linux_kernel:Patch ↗Advisory ↗
AndroidCVE-2026-0031Critical (Android rating):linux_kernel:Patch ↗Advisory ↗
AndroidCVE-2026-0037Critical (Android rating):linux_kernel:Patch ↗Advisory ↗
AndroidCVE-2026-0038Critical (Android rating):linux_kernel:Patch ↗Advisory ↗
AndroidCVE-2026-0047Critical (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0114Critical (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0120Critical (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0122Critical (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0124Critical (Android rating)no patch linkAdvisory ↗
AndroidCVE-2024-43766High (Android rating)platform/packages/modules/BluetoothPatch ↗Advisory ↗
AndroidCVE-2025-10865High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-13952High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-20760High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-20761High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-20762High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-20793High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-20794High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-20794High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-20795High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-2879High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-32313High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-38616High (Android rating):linux_kernel:Patch ↗Advisory ↗
AndroidCVE-2025-38618High (Android rating):linux_kernel:Patch ↗Advisory ↗
AndroidCVE-2025-39682High (Android rating):linux_kernel:Patch ↗Advisory ↗
AndroidCVE-2025-39946High (Android rating):linux_kernel:Patch ↗Advisory ↗
AndroidCVE-2025-39946High (Android rating):linux_kernel:Patch ↗Advisory ↗
AndroidCVE-2025-40266High (Android rating):linux_kernel:Patch ↗Advisory ↗
AndroidCVE-2025-47388High (Android rating)platform/vendor/qcom/opensource/dsp-kernelPatch ↗Advisory ↗
AndroidCVE-2025-47394High (Android rating)platform/vendor/qcom/opensource/dsp-kernelPatch ↗Advisory ↗
AndroidCVE-2025-47396High (Android rating)platform/vendor/qcom/opensource/graphics-kernelPatch ↗Advisory ↗
AndroidCVE-2025-47397High (Android rating):linux_kernel:QualcommPatch ↗Advisory ↗
AndroidCVE-2025-47398High (Android rating):linux_kernel:QualcommPatch ↗Advisory ↗
AndroidCVE-2025-48544High (Android rating)platform/packages/providers/MediaProviderPatch ↗Advisory ↗
AndroidCVE-2025-48567High (Android rating)platform/packages/providers/MediaProviderPatch ↗Advisory ↗
AndroidCVE-2025-48568High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-48574High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-48577High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-48578High (Android rating)platform/packages/providers/MediaProviderPatch ↗Advisory ↗
AndroidCVE-2025-48579High (Android rating)platform/packages/providers/MediaProviderPatch ↗Advisory ↗
AndroidCVE-2025-48582High (Android rating)platform/packages/providers/MediaProviderPatch ↗Advisory ↗
AndroidCVE-2025-48585High (Android rating)platform/packages/modules/ProfilingPatch ↗Advisory ↗
AndroidCVE-2025-48587High (Android rating)platform/packages/modules/ProfilingPatch ↗Advisory ↗
AndroidCVE-2025-48602High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-48609High (Android rating)platform/packages/providers/TelephonyProviderPatch ↗Advisory ↗
AndroidCVE-2025-48611High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-48613High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-48619High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-48630High (Android rating)platform/frameworks/nativePatch ↗Advisory ↗
AndroidCVE-2025-48634High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-48635High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-48641High (Android rating)platform/hardware/st/nfcPatch ↗Advisory ↗
AndroidCVE-2025-48642High (Android rating)platform/packages/modules/VirtualizationPatch ↗Advisory ↗
AndroidCVE-2025-48644High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-48645High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-48646High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-48654High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2025-58407High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-58408High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-58409High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-58411High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-59600High (Android rating):linux_kernel:QualcommPatch ↗Advisory ↗
AndroidCVE-2025-61612High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-61613High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-61614High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-61615High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-61616High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-64783High (Android rating)platform/external/dng_sdkPatch ↗Advisory ↗
AndroidCVE-2025-64784High (Android rating)platform/external/dng_sdkPatch ↗Advisory ↗
AndroidCVE-2025-64893High (Android rating)platform/external/dng_sdkPatch ↗Advisory ↗
AndroidCVE-2025-69278High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2025-69279High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0005High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0011High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0012High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0013High (Android rating)platform/packages/apps/DocumentsUIPatch ↗Advisory ↗
AndroidCVE-2026-0014High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0015High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0017High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0020High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0021High (Android rating)platform/packages/apps/SettingsPatch ↗Advisory ↗
AndroidCVE-2026-0023High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0024High (Android rating)platform/packages/providers/MediaProviderPatch ↗Advisory ↗
AndroidCVE-2026-0025High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0026High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0029High (Android rating):linux_kernel:Patch ↗Advisory ↗
AndroidCVE-2026-0032High (Android rating):linux_kernel:Patch ↗Advisory ↗
AndroidCVE-2026-0034High (Android rating)platform/frameworks/basePatch ↗Advisory ↗
AndroidCVE-2026-0035High (Android rating)platform/packages/providers/MediaProviderPatch ↗Advisory ↗
AndroidCVE-2026-0107High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0108High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0110High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0111High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0112High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0113High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0116High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0117High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0118High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0119High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0121High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20401High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20402High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20403High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20403High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20404High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20405High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20406High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20420High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20421High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20422High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20425High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20425High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20425High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20425High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20426High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20426High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20426High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20426High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20427High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20427High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20427High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20427High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20428High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20428High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20428High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20428High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-20434High (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-21385trackedHigh (Android rating):linux_kernel:QualcommPatch ↗Advisory ↗
AndroidCVE-2025-36920Moderate (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0109Moderate (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0115Moderate (Android rating)no patch linkAdvisory ↗
AndroidCVE-2026-0123Moderate (Android rating)no patch linkAdvisory ↗

February 2026

VendorCVESeverityProductFixed versionPatchAdvisory
CiscoCVE-2026-20127trackedCVSS 10.0Patch ↗Advisory ↗
CiscoCVE-2026-20048CVSS 7.7Cisco Nexus 9000 Series SwitchesPatch ↗Advisory ↗
CiscoCVE-2026-20128trackedCVSS 7.5Patch ↗Advisory ↗
CiscoCVE-2026-20010CVSS 7.4Cisco Nexus 3000 Series SwitchesPatch ↗Advisory ↗
CiscoCVE-2026-20033CVSS 7.4Cisco Nexus 9000 Series SwitchesPatch ↗Advisory ↗
CiscoCVE-2026-20051CVSS 7.4Cisco Nexus 3000 Series SwitchesPatch ↗Advisory ↗
CiscoCVE-2026-20099CVSS 6.7Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20133trackedCVSS 6.5Patch ↗Advisory ↗
CiscoCVE-2026-20122trackedCVSS 5.4Patch ↗Advisory ↗
CiscoCVE-2026-20091CVSS 4.8Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
AndroidCVE-2026-0106High (Android rating)no patch linkAdvisory ↗

Vendor coverage

What this page covers, and why some vendors are not yet ingested. This is stated plainly so the page never implies coverage it lacks.

  • MicrosoftCoveredPatch Tuesday: the Microsoft Security Response Center monthly release, tracked in depth on this page.
  • AndroidCoveredGoogle Android Security Bulletins via the OSV feed. The fix commit is the CVE-to-patch link; severity is Android's qualitative rating (no CVSS).
  • CiscoCoveredCisco public CSAF 2.0 advisories: per-CVE CVSS, a Security Impact Rating, and vendor-fix remediation links.
  • SAPNo machine-readable feedSAP Security Patch Day notes list the CVEs, but the patch detail (the Note that maps a CVE to its fix) requires an S-user support login. No anonymous machine-readable CVE-to-patch mapping exists.
  • AdobeNo machine-readable feedAdobe publishes security bulletins (APSB) as HTML pages only, with no structured feed and no machine-readable CVE-to-patch mapping.
  • FortinetNo machine-readable feedFortiGuard PSIRT advisories are HTML and RSS only, with no CSAF or JSON feed carrying a machine-readable CVE-to-fixed-version mapping.
  • IvantiNo machine-readable feedIvanti security advisories are HTML only, with no structured feed and no machine-readable CVE-to-patch mapping.