CYBERSECURITYTRACKER
TRACKING7,183 stories in this site build1,510 vulnerability news stories in this site build
Vulnerabilities

January 2026 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 2 vulnerabilities with exploitation detected in the wild this month. This defender-focused view covers 315 vulnerabilities across 315 returned patch records from 1 vendor. Filter the complete month, or browse the static page trail without JavaScript.

315all patch recordsClear filters30criticalShow these records2Microsoft exploitation detectedShow these records3Microsoft in the Known Exploited Vulnerabilities catalogShow these records139tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 1 of 2 · records 1 to 200 of 315

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-21509 ↗Microsoft Office 2019 for 32-bit editionsImportantOut-of-band73%Microsoft rates: Exploitation DetectedCISA KEVVulnCheckENISAKB50027131 mentionsMicrosoft Office Security Feature Bypass Vulnerability
CVE-2026-20805 ↗Windows 10 Version 1809 for 32-bit SystemsImportant5%Microsoft rates: Exploitation DetectedCISA KEVVulnCheckENISAKB5073379KB5073450
and 8 moreKB5073455KB5073457KB5073696KB5073698KB5073722KB5073723KB5073724KB5074109
Desktop Window Manager Information Disclosure Vulnerability
CVE-2026-20963 ↗Microsoft SharePoint Enterprise Server 2016Important33%Microsoft rates: Exploitation Less LikelyCISA KEVVulnCheckENISAKB5002822KB5002825
and 1 moreKB5002828
1 mentionsMicrosoft SharePoint Remote Code Execution Vulnerability
CVE-2026-21227 ↗Azure Logic AppsCriticalOut-of-band1%Microsoft rates: N/AAzure Logic Apps Elevation of Privilege Vulnerability
CVE-2026-21264 ↗Microsoft AccountCriticalOut-of-band0%Microsoft rates: N/AMicrosoft Account Spoofing Vulnerability
CVE-2026-21520 ↗Microsoft Copilot StudioCriticalOut-of-band1%Microsoft rates: N/ACopilot Studio Information Disclosure Vulnerability
CVE-2026-21521 ↗Microsoft 365 Word CopilotCriticalOut-of-band1%Microsoft rates: N/AWord Copilot Information Disclosure Vulnerability
CVE-2026-21524 ↗Azure Data ExplorerCriticalOut-of-band1%Microsoft rates: N/AAzure Data Explorer Information Disclosure Vulnerability
CVE-2026-24304 ↗Azure Resource ManagerCriticalOut-of-band1%Microsoft rates: N/AAzure Resource Manager Elevation of Privilege Vulnerability
CVE-2026-24305 ↗Microsoft Entra IDCriticalOut-of-band1%Microsoft rates: N/AAzure Entra ID Elevation of Privilege Vulnerability
CVE-2026-24306 ↗Azure Front DoorCriticalOut-of-band1%Microsoft rates: N/AAzure Front Door Elevation of Privilege Vulnerability
CVE-2026-24307 ↗Microsoft 365 CopilotCriticalOut-of-band1%Microsoft rates: N/AM365 Copilot Information Disclosure Vulnerability
CVE-2026-20822 ↗Windows 10 Version 1809 for 32-bit SystemsCritical0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2026-20854 ↗Windows Server 2025 (Server Core installation)Critical1%Microsoft rates: Exploitation Less LikelyKB5073379KB5074109Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
CVE-2026-20876 ↗Windows Server 2025 (Server Core installation)Critical1%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 2 moreKB5073455KB5074109
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
CVE-2026-20944 ↗Microsoft 365 Apps for Enterprise for 32-bit SystemsCritical1%Microsoft rates: Exploitation Less LikelyMicrosoft Word Remote Code Execution Vulnerability
CVE-2026-20952 ↗Microsoft Office 2019 for 64-bit editionsCritical1%Microsoft rates: Exploitation Less LikelyKB5002826Microsoft Office Remote Code Execution Vulnerability
CVE-2026-20953 ↗Microsoft Office 2019 for 64-bit editionsCritical1%Microsoft rates: Exploitation Less LikelyKB5002826Microsoft Office Remote Code Execution Vulnerability
CVE-2026-20955 ↗Office Online ServerCritical1%Microsoft rates: Exploitation Less LikelyKB5002824Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-20957 ↗Office Online ServerCritical0%Microsoft rates: Exploitation Less LikelyKB5002824KB5002831Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-24821 ↗cbl2 ceph 16.2.10-11 on CBL Mariner 2.0CriticalOut-of-bandNot availableMicrosoft rating unavailableA heap-based buffer over-read that might affect a system that compiles untrusted Lua code in turanszkij/WickedEngine.
CVE-2025-71074 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0CriticalOut-of-bandNot availableMicrosoft rating unavailablefunctionfs: fix the open/removal races
CVE-2025-71098 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableip6_gre: make ip6gre_header() robust
CVE-2025-71064 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablenet: hns3: using the num_tqps in the vf driver to apply for resources
CVE-2025-68819 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablemedia: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg()
CVE-2025-71072 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableshmem: fix recovery on rename failures
CVE-2025-71066 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablenet/sched: ets: Always remove class from active list before deleting in ets_qdisc_change
CVE-2025-68814 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableio_uring: fix filename leak in __io_openat_prep()
CVE-2025-71073 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableInput: lkkbd - disable pending work before freeing device
CVE-2025-68789 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablehwmon: (ibmpex) fix use-after-free in high/low store
CVE-2025-68822 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableInput: alps - fix use-after-free bugs caused by dev3_register_work
CVE-2025-68823 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableublk: fix deadlock when reading partition table
CVE-2026-22184 ↗cbl2 binutils 2.37-19 on CBL Mariner 2.0CriticalOut-of-bandNot availableMicrosoft rating unavailablezlib <= 1.3.1.2 untgz Global Buffer Overflow in TGZfname()
CVE-2026-0899 ↗Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft rating unavailableChromium: CVE-2026-0899 Out of bounds memory access in V8
CVE-2026-20960 ↗Microsoft Power Apps Desktop ClientImportantOut-of-band1%Microsoft rates: Exploitation Less LikelyPowerApps Desktop Client Remote Code Execution Vulnerability
CVE-2023-31096 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation More LikelyPublicly disclosedKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
MITRE: CVE-2023-31096 Windows Agere Soft Modem Driver Elevation of Privilege Vulnerability
CVE-2024-55414 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Motorola Soft Modem Driver Elevation of Privilege Vulnerability
CVE-2026-0386 ↗Windows Server 2019Important1%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 9 moreKB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723
Windows Deployment Services Remote Code Execution Vulnerability
CVE-2026-20803 ↗Microsoft SQL Server 2022 for x64-based Systems (GDR)Important1%Microsoft rates: Exploitation Less LikelyKB5072936KB5073031
and 1 moreKB5073177
Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-20804 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Windows Hello Tampering Vulnerability
CVE-2026-20808 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 1 moreKB5074109
Windows File Explorer Elevation of Privilege Vulnerability
CVE-2026-20809 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 7 moreKB5073455KB5073457KB5073696KB5073722KB5073723KB5073724KB5074109
Windows Kernel Memory Elevation of Privilege Vulnerability
CVE-2026-20810 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5073723KB5073724Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-20811 ↗Windows Server 2022Important0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 3 moreKB5073455KB5073457KB5074109
Win32k Elevation of Privilege Vulnerability
CVE-2026-20812 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
LDAP Tampering Vulnerability
CVE-2026-20814 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2026-20815 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation Less LikelyKB5073379KB5074109Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
CVE-2026-20816 ↗Windows 10 Version 1809 for 32-bit SystemsImportant2%Microsoft rates: Exploitation More LikelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Installer Elevation of Privilege Vulnerability
CVE-2026-20817 ↗Windows Server 2022Important6%Microsoft rates: Exploitation More LikelyKB5073379KB5073450
and 4 moreKB5073455KB5073457KB5073724KB5074109
Windows Error Reporting Service Elevation of Privilege Vulnerability
CVE-2026-20818 ↗Windows Server 2019Important1%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 3 moreKB5073457KB5073722KB5073723
Windows Kernel Information Disclosure Vulnerability
CVE-2026-20819 ↗Windows 11 Version 25H2 for x64-based SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5073455KB5074109Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability
CVE-2026-20820 ↗Windows Server 2022 (Server Core installation)Important3%Microsoft rates: Exploitation More LikelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2026-20821 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Remote Procedure Call Information Disclosure Vulnerability
CVE-2026-20823 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Windows File Explorer Information Disclosure Vulnerability
CVE-2026-20824 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 8 moreKB5073455KB5073457KB5073696KB5073698KB5073722KB5073723KB5073724KB5074109
Windows Remote Assistance Security Feature Bypass Vulnerability
CVE-2026-20825 ↗Windows 10 Version 1809 for x64-based SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Hyper-V Information Disclosure Vulnerability
CVE-2026-20826 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure Vulnerability
CVE-2026-20827 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure Vulnerability
CVE-2026-20828 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows rndismp6.sys Information Disclosure Vulnerability
CVE-2026-20829 ↗Windows 10 Version 1809 for x64-based SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
TPM Trustlet Information Disclosure Vulnerability
CVE-2026-20830 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation UnlikelyKB5073379Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
CVE-2026-20831 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-20832 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability
CVE-2026-20833 ↗Windows Server 2019Important1%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 9 moreKB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723
Windows Kerberos Information Disclosure Vulnerability
CVE-2026-20834 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Spoofing Vulnerability
CVE-2026-20835 ↗Windows Server 2025 (Server Core installation)Important1%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 1 moreKB5074109
Capability Access Management Service (camsvc) Information Disclosure Vulnerability
CVE-2026-20836 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2026-20837 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Media Remote Code Execution Vulnerability
CVE-2026-20838 ↗Windows Server 2022Important1%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 3 moreKB5073455KB5073457KB5074109
Windows Kernel Information Disclosure Vulnerability
CVE-2026-20839 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 10 moreKB5073455KB5073457KB5073695KB5073696KB5073698KB5073699KB5073722KB5073723KB5073724KB5074109
Windows Client-Side Caching (CSC) Service Information Disclosure Vulnerability
CVE-2026-20840 ↗Windows 10 Version 1809 for 32-bit SystemsImportant5%Microsoft rates: Exploitation More LikelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-20842 ↗Windows Server 2022Important0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 4 moreKB5073455KB5073457KB5073724KB5074109
Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-20843 ↗Windows 10 Version 1809 for 32-bit SystemsImportant3%Microsoft rates: Exploitation More LikelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
CVE-2026-20844 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Windows Clipboard Server Elevation of Privilege Vulnerability
CVE-2026-20847 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 10 moreKB5073455KB5073457KB5073695KB5073696KB5073698KB5073699KB5073722KB5073723KB5073724KB5074109
Microsoft Windows File Explorer Spoofing Vulnerability
CVE-2026-20848 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 8 moreKB5073455KB5073457KB5073696KB5073698KB5073722KB5073723KB5073724KB5074109
Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-20849 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Kerberos Elevation of Privilege Vulnerability
CVE-2026-20851 ↗Windows Server 2025 (Server Core installation)Important1%Microsoft rates: Exploitation Less LikelyKB5073379KB5074109Capability Access Management Service (camsvc) Information Disclosure Vulnerability
CVE-2026-20852 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Windows Hello Tampering Vulnerability
CVE-2026-20853 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073455KB5073722
and 3 moreKB5073723KB5073724KB5074109
Windows WalletService Elevation of Privilege Vulnerability
CVE-2026-20856 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 8 moreKB5073455KB5073457KB5073696KB5073698KB5073722KB5073723KB5073724KB5074109
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
CVE-2026-20857 ↗Windows 11 Version 25H2 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-20858 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20859 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation Less LikelyKB5073379KB5074109Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2026-20860 ↗Windows 10 Version 1809 for 32-bit SystemsImportant8%Microsoft rates: Exploitation More LikelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-20861 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20862 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Information Disclosure Vulnerability
CVE-2026-20863 ↗Windows Server 2022Important0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 3 moreKB5073455KB5073457KB5074109
Win32k Elevation of Privilege Vulnerability
CVE-2026-20864 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
CVE-2026-20865 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20866 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20867 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20868 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2026-20869 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability
CVE-2026-20870 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation Less LikelyKB5073379KB5074109Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
CVE-2026-20871 ↗Windows Server 2022Important4%Microsoft rates: Exploitation More LikelyKB5073379KB5073450
and 4 moreKB5073455KB5073457KB5073724KB5074109
Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-20872 ↗Windows 10 Version 1809 for 32-bit SystemsImportant20%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
NTLM Hash Disclosure Spoofing Vulnerability
CVE-2026-20873 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20874 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20875 ↗Windows 10 Version 1809 for 32-bit SystemsImportant2%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2026-20877 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20918 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20919 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 8 moreKB5073455KB5073457KB5073696KB5073698KB5073722KB5073723KB5073724KB5074109
Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-20920 ↗Windows Server 2022Important1%Microsoft rates: Exploitation UnlikelyKB5073450KB5073455
and 1 moreKB5073457
Win32k Elevation of Privilege Vulnerability
CVE-2026-20921 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-20922 ↗Windows Server 2022 (Server Core installation)Important1%Microsoft rates: Exploitation More LikelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-20923 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20924 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20925 ↗Windows 10 Version 1809 for 32-bit SystemsImportant18%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
NTLM Hash Disclosure Spoofing Vulnerability
CVE-2026-20926 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 8 moreKB5073455KB5073457KB5073696KB5073698KB5073722KB5073723KB5073724KB5074109
Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-20927 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows SMB Server Denial of Service Vulnerability
CVE-2026-20929 ↗Windows 10 Version 1809 for 32-bit SystemsImportant3%Microsoft rates: Exploitation UnlikelyKB5073450KB5073455
and 10 moreKB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724
1 mentionsWindows HTTP.sys Elevation of Privilege Vulnerability
CVE-2026-20931 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyVulnCheckKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-20932 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Windows File Explorer Information Disclosure Vulnerability
CVE-2026-20934 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 8 moreKB5073455KB5073457KB5073696KB5073698KB5073722KB5073723KB5073724KB5074109
Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-20935 ↗Windows 11 Version 25H2 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073455KB5074109Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability
CVE-2026-20936 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 12 moreKB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109
Windows NDIS Information Disclosure Vulnerability
CVE-2026-20937 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Windows File Explorer Information Disclosure Vulnerability
CVE-2026-20938 ↗Windows 11 Version 25H2 for x64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073455KB5074109Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
CVE-2026-20939 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5073379KB5073450
and 6 moreKB5073455KB5073457KB5073722KB5073723KB5073724KB5074109
Windows File Explorer Information Disclosure Vulnerability
CVE-2026-20940 ↗Windows 10 Version 22H2 for 32-bit SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5073455KB5073457
and 9 moreKB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-20941 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation Less LikelyKB5073379KB5074109Host Process for Windows Tasks Elevation of Privilege Vulnerability
CVE-2026-20943 ↗Microsoft SharePoint Server 2019Important1%Microsoft rates: Exploitation Less LikelyKB5002822KB5002825
and 2 moreKB5002826KB5002828
Microsoft Office Click-To-Run Remote Code Execution Vulnerability
CVE-2026-20946 ↗Microsoft Office 2019 for 32-bit editionsImportant1%Microsoft rates: Exploitation Less LikelyKB5002831Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-20947 ↗Microsoft SharePoint Enterprise Server 2016Important19%Microsoft rates: Exploitation UnlikelyKB5002822KB5002823
and 3 moreKB5002825KB5002827KB5002828
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-20948 ↗Microsoft SharePoint Enterprise Server 2016Important1%Microsoft rates: Exploitation Less LikelyKB5002823KB5002825
and 3 moreKB5002827KB5002828KB5002829
Microsoft Word Remote Code Execution Vulnerability
CVE-2026-20949 ↗Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyMicrosoft Excel Security Feature Bypass Vulnerability
CVE-2026-20950 ↗Office Online ServerImportant0%Microsoft rates: Exploitation Less LikelyKB5002824KB5002831Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-20951 ↗Microsoft SharePoint Enterprise Server 2016Important1%Microsoft rates: Exploitation Less LikelyKB5002822KB5002825
and 1 moreKB5002828
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-20956 ↗Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyMicrosoft Excel Remote Code Execution Vulnerability
CVE-2026-20958 ↗Microsoft SharePoint Enterprise Server 2016Important0%Microsoft rates: Exploitation Less LikelyKB5002822KB5002825
and 1 moreKB5002828
Microsoft SharePoint Information Disclosure Vulnerability
CVE-2026-20959 ↗Microsoft SharePoint Enterprise Server 2016Important8%Microsoft rates: Exploitation Less LikelyKB5002822KB5002825
and 1 moreKB5002828
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-20962 ↗Windows 11 Version 25H2 for x64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5073379KB5073450
and 5 moreKB5073455KB5073457KB5073723KB5073724KB5074109
Dynamic Root of Trust for Measurement (DRTM) Information Disclosure Vulnerability
CVE-2026-20965 ↗Windows Admin Center in Azure PortalImportant0%Microsoft rates: Exploitation Less LikelyWindows Admin Center Elevation of Privilege Vulnerability
CVE-2026-21219 ↗Windows SDKImportant0%Microsoft rates: Exploitation UnlikelyInbox COM Objects (Global Memory) Remote Code Execution Vulnerability
CVE-2026-21221 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation UnlikelyKB5073379KB5074109Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
CVE-2026-21224 ↗Azure Connected Machine AgentImportant0%Microsoft rates: Exploitation Less LikelyAzure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2026-21226 ↗Azure Core shared client library for PythonImportant1%Microsoft rates: Exploitation Less LikelyAzure Core shared client library for Python Remote Code Execution Vulnerability
CVE-2026-21265 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyPublicly disclosedKB5073379KB5073450
and 8 moreKB5073455KB5073457KB5073696KB5073698KB5073722KB5073723KB5073724KB5074109
Secure Boot Certificate Expiration Security Feature Bypass Vulnerability
CVE-2025-68119 ↗azl3 golang 1.27.0-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableUnexpected code execution when invoking toolchain in cmd/go
CVE-2025-61731 ↗azl3 golang 1.27.0-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableArbitrary file write using cgo pkg-config directive in cmd/go
CVE-2025-61726 ↗azl3 golang 1.27.0-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableMemory exhaustion in query parameter parsing in net/url
CVE-2026-22984 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablelibceph: prevent potential out-of-bounds reads in handle_auth_done()
CVE-2026-22980 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenfsd: provide locking for v4_end_grace
CVE-2025-71162 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledmaengine: tegra-adma: Fix use-after-free
CVE-2025-71152 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenet: dsa: properly keep track of conduit reference
CVE-2026-23490 ↗azl3 python-pyasn1 0.4.8-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablepyasn1 has a DoS vulnerability in decoder
CVE-2025-62291 ↗azl3 strongswan 5.9.14-7 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableIn the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.
CVE-2026-0897 ↗azl3 keras 3.3.3-5 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableDenial of Service in Keras via Excessive Memory Allocation in HDF5 Metadata
CVE-2025-71105 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablef2fs: use global inline_xattr_slab instead of per-sb slab cache
CVE-2025-71130 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledrm/i915/gem: Zero-initialize the eb.vma array in i915_gem_do_execbuffer
CVE-2025-71122 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableiommufd/selftest: Check for overflow in IOMMU_TEST_OP_ADD_RESERVED
CVE-2025-71143 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableclk: samsung: exynos-clkout: Assign .num before accessing .hws
CVE-2025-71109 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableMIPS: ftrace: Fix memory corruption when kernel is located beyond 32 bits
CVE-2025-71114 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablevia_wdt: fix critical boot hang due to unnamed resource allocation
CVE-2025-71133 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableRDMA/irdma: avoid invalid read in irdma_net_event
CVE-2025-71101 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableplatform/x86: hp-bioscfg: Fix out-of-bounds array access in ACPI package parsing
CVE-2025-68786 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableksmbd: skip lock-range check on equal size to avoid size==0 underflow
CVE-2025-68771 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableocfs2: fix kernel BUG in ocfs2_find_victim_chain
CVE-2025-71081 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableASoC: stm32: sai: fix OF node leak on probe
CVE-2025-68817 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableksmbd: fix use-after-free in ksmbd_tree_connect_put under concurrency
CVE-2025-68795 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableethtool: Avoid overflowing userspace buffer on stats query
CVE-2025-71067 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablentfs: set dummy blocksize to read boot_block when mounting
CVE-2025-71075 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablescsi: aic94xx: fix use-after-free in device removal path
CVE-2025-71068 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablesvcrdma: bound check rq_pages index in inline path
CVE-2025-68801 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemlxsw: spectrum_router: Fix neighbour use-after-free
CVE-2025-68782 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablescsi: target: Reset t_task_cdb pointer in error case
CVE-2025-68808 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemedia: vidtv: initialize local pointers upon transfer of memory ownership
CVE-2025-71082 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableBluetooth: btusb: revert use of devm_kzalloc in btusb
CVE-2025-68785 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenet: openvswitch: fix middle attribute validation in push_nsh() action
CVE-2025-71089 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableiommu: disable SVA when CONFIG_X86 is set
CVE-2025-71087 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableiavf: fix off-by-one issues in iavf_config_rss_reg()
CVE-2025-68781 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableusb: phy: fsl-usb: Fix use-after-free in delayed work during device removal
CVE-2026-0719 ↗azl3 libsoup 3.4.4-11 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableLibsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authentication
CVE-2025-69195 ↗azl3 wget 2.1.0-6 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableWget2: gnu wget2: memory corruption and crash via filename sanitization logic with attacker-controlled urls
CVE-2025-69194 ↗azl3 wget 2.1.0-6 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableWget2: arbitrary file write via metalink path traversal in gnu wget2
CVE-2025-15444 ↗azl3 libsodium 1.0.19-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableCrypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium
CVE-2026-21441 ↗azl3 tensorflow 2.16.1-9 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableurllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
CVE-2026-22185 ↗azl3 openldap 2.6.7-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableOpenLDAP <= 2.6.10 LMDB mdb_load Heap Buffer Underflow in readline()
CVE-2025-68756 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableblock: Use RCU in blk_mq_[un]quiesce_tagset() instead of set->tag_list_lock
CVE-2025-68766 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableirqchip/mchp-eic: Fix error code in mchp_eic_domain_alloc()
CVE-2025-68759 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablewifi: rtl818x: Fix potential memory leaks in rtl8180_init_rx_ring()
CVE-2025-68753 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableALSA: firewire-motu: add bounds check in put_user loop for DSP events
CVE-2025-61728 ↗azl3 golang 1.27.0-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableExcessive CPU consumption when building archive index in archive/zip
CVE-2025-61730 ↗azl3 golang 1.27.0-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableHandshake messages may be processed at the incorrect encryption level in crypto/tls
CVE-2025-15504 ↗azl3 nodejs24 24.14.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelief-project LIEF ELF Binary Parser.tcc parse_binary null pointer dereference
CVE-2026-23004 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledst: fix races in rt6_uncached_list_del() and rt_del_uncached_list()
CVE-2025-71184 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: fix NULL dereference on root when tracing inode eviction
CVE-2025-71183 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: always detect conflicting inodes when logging inode refs
CVE-2026-22999 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/sched: sch_qfq: do not free existing class in qfq_change_class()
CVE-2026-22998 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec
CVE-2026-22997 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: can: j1939: j1939_xtp_rx_rts_session_active(): deactivate session upon receiving the second rts
CVE-2026-22996 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/mlx5e: Don't store mlx5e_priv in mlx5e_dev devlink priv
CVE-2026-22992 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibceph: return the handler error from mon_handle_auth_done()
CVE-2026-22991 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibceph: make free_choose_arg_map() resilient to partial allocation
CVE-2026-22990 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibceph: replace overzealous BUG_ON in osdmap_apply_incremental()
CVE-2026-22982 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: mscc: ocelot: Fix crash when adding interface under a lag
CVE-2026-22979 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: fix memory leak in skb_segment_list for GRO packets
CVE-2026-22977 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: sock: fix hardened usercopy panic in sock_recv_errqueue
CVE-2026-22976 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/sched: sch_qfq: Fix NULL deref when deactivating inactive aggregate in qfq_reset

Glossary