CYBERSECURITYTRACKER
TRACKING7,183 stories in this site build1,510 vulnerability news stories in this site build
Vulnerabilities

January 2026 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 2 vulnerabilities with exploitation detected in the wild this month. This defender-focused view covers 315 vulnerabilities across 315 returned patch records from 1 vendor. Filter the complete month, or browse the static page trail without JavaScript.

315all patch recordsClear filters30criticalShow these records2Microsoft exploitation detectedShow these records3Microsoft in the Known Exploited Vulnerabilities catalogShow these records139tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 2 of 2 · records 201 to 315 of 315

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2025-71163 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledmaengine: idxd: fix device leaks on compat bind and unbind
CVE-2025-71161 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledm-verity: disable recursive forward error correction
CVE-2025-71160 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: nf_tables: avoid chain re-validation if possible
CVE-2025-71154 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: usb: rtl8150: fix memory leak on usb_submit_urb() failure
CVE-2025-71150 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableksmbd: Fix refcount leak when invalid session is found on session lookup
CVE-2025-71147 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableKEYS: trusted: Fix a memory leak in tpm2_load_cmd
CVE-2026-23000 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/mlx5e: Fix crash on profile change rollback failure
CVE-2025-56226 ↗azl3 libsndfile 1.2.2-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableLibsndfile <=1.2.2 contains a memory leak vulnerability in the mpeg_l3_encoder_init() function within the mpeg_l3_encode.c file.
CVE-2025-24528 ↗azl3 krb5 1.21.3-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableIn MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update size to resize() in kdb_log.c. An authenticated attacker can cause an out-of-bounds write and kadmind daemon crash.
CVE-2025-15281 ↗azl3 glibc 2.38-16 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory
CVE-2026-0990 ↗cbl2 libxml2 2.10.4-9 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableLibxml2: libxml2: denial of service via uncontrolled recursion in xml catalog processing
CVE-2026-0716 ↗azl3 libsoup 3.4.4-14 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableLibsoup: out-of-bounds read in libsoup websocket frame processing
CVE-2026-0915 ↗azl3 glibc 2.38-16 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablegetnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler
CVE-2025-71120 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableSUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf
CVE-2025-71107 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablef2fs: ensure node page reads complete before f2fs_put_super() finishes
CVE-2025-71102 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescs: fix a wrong parameter in __scs_magic
CVE-2025-71138 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/msm/dpu: Add missing NULL pointer check for pingpong interface
CVE-2025-71113 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecrypto: af_alg - zero initialize memory allocated via sock_kmalloc
CVE-2025-71125 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletracing: Do not register unsupported perf events
CVE-2025-71131 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecrypto: seqiv - Do not use req->iv after crypto_aead_encrypt
CVE-2025-71127 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: mac80211: Discard Beacon frames to non-broadcast address
CVE-2025-71121 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableparisc: Do not reprogram affinitiy on ASP chip
CVE-2025-71129 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableLoongArch: BPF: Sign extend kfunc call arguments
CVE-2025-71115 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableum: init cpu_tasks[] earlier
CVE-2025-71108 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableusb: typec: ucsi: Handle incorrect num_connectors capability
CVE-2025-71137 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableocteontx2-pf: fix "UBSAN: shift-out-of-bounds error"
CVE-2025-71112 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: hns3: add VLAN id validation before using
CVE-2025-71132 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesmc91x: fix broken irq-context in PREEMPT_RT
CVE-2025-71119 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepowerpc/kexec: Enable SMT before waking offline CPUs
CVE-2025-71118 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableACPICA: Avoid walking the Namespace if start_node is NULL
CVE-2025-71111 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablehwmon: (w83791d) Convert macros to functions to avoid TOCTOU
CVE-2025-71136 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemedia: adv7842: Avoid possible out-of-bounds array accesses in adv7842_cp_log_status()
CVE-2025-71116 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibceph: make decode_pool() more resilient against corrupted osdmaps
CVE-2026-0861 ↗cbl2 glibc 2.35-7 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableInteger overflow in memalign leads to heap corruption
CVE-2025-68780 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesched/deadline: only set free_cpus for online runqueues
CVE-2025-71069 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablef2fs: invalidate dentry cache on failed whiteout creation
CVE-2025-68794 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableiomap: adjust read range correctly for non-block-aligned positions
CVE-2025-71091 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableteam: fix check for port enabled in team_queue_override_port_prio_changed()
CVE-2025-68776 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/hsr: fix NULL pointer dereference in prp_get_untagged_frame()
CVE-2025-68797 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablechar: applicom: fix NULL pointer dereference in ac_ioctl
CVE-2025-68775 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/handshake: duplicate handshake cancellations leak socket
CVE-2025-71088 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemptcp: fallback earlier on simult connection
CVE-2025-68777 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableInput: ti_am335x_tsc - fix off-by-one error in wire_order validation
CVE-2025-68788 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefsnotify: do not generate ACCESS/MODIFY events on child for special files
CVE-2025-68774 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablehfsplus: fix missing hfs_bnode_get() in __hfs_bnode_create
CVE-2025-71077 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletpm: Cap the number of PCR banks
CVE-2025-68816 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/mlx5: fw_tracer, Validate format string parameters
CVE-2025-68815 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/sched: ets: Remove drr class from the active list if it changes to strict
CVE-2025-68809 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableksmbd: vfs: fix race on m_flags in vfs_cache
CVE-2025-71084 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRDMA/cm: Fix leaking the multicast GID table reference
CVE-2025-68773 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablespi: fsl-cpm: Check length parity before switching to 16 bit mode
CVE-2025-68818 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescsi: Revert "scsi: qla2xxx: Perform lockless command completion in abort path"
CVE-2025-71097 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableipv4: Fix reference count leak when using error routes with nexthop objects
CVE-2025-68769 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablef2fs: fix return value of f2fs_recover_fsync_data()
CVE-2025-68787 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetrom: Fix memory leak in nr_sendmsg()
CVE-2025-68772 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablef2fs: fix to avoid updating compression context during writeback
CVE-2025-71065 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablef2fs: fix to avoid potential deadlock
CVE-2025-68800 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemlxsw: spectrum_mr: Fix use-after-free when updating multicast route stats
CVE-2025-68783 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableALSA: usb-mixer: us16x08: validate meter packet indices
CVE-2025-71083 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/ttm: Avoid NULL pointer deref for evicted BOs
CVE-2025-68768 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableinet: frags: flush pending skbs in fqdir_pre_exit()
CVE-2025-68798 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableperf/x86/amd: Check event before enable to avoid GPF
CVE-2025-71096 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRDMA/core: Check for the presence of LS_NLA_TYPE_DGID correctly
CVE-2025-68778 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: don't log conflicting inode if it's a dir moved in the current transaction
CVE-2025-71079 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: nfc: fix deadlock between nfc_unregister_device and rfkill_fop_write
CVE-2025-71093 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablee1000: fix OOB in e1000_tbi_should_accept()
CVE-2025-68799 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecaif: fix integer underflow in cffrml_receive()
CVE-2025-68767 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablehfsplus: Verify inode mode when loading from disk
CVE-2025-68806 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableksmbd: fix buffer validation by including null terminator size in EA length
CVE-2025-71078 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepowerpc/64s/slb: Fix SLB multihit issue during SLB preload
CVE-2025-68796 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablef2fs: fix to avoid updating zero-sized extent in extent cache
CVE-2025-71095 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: stmmac: fix the crash issue for zero copy XDP_TX action
CVE-2025-68803 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableNFSD: NFSv4 file creation neglects setting ACL
CVE-2025-68471 ↗cbl2 avahi 0.8-4 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableAvahi has a reachable assertion in lookup_start
CVE-2025-68468 ↗cbl2 avahi 0.8-4 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableAvahi has a reachable assertion in lookup_multicast_callback
CVE-2025-68276 ↗cbl2 avahi 0.8-4 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableAvahi has a reachable assertion in avahi_wide_area_scan_cache
CVE-2026-22695 ↗cbl2 libpng 1.6.52-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableLIBPNG has a heap buffer over-read in png_image_read_direct_scaled (regression from CVE-2025-65018 fix)
CVE-2026-22801 ↗azl3 libpng 1.6.52-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableLIBPNG has an integer truncation causing heap buffer over-read in png_image_write_*
CVE-2026-22701 ↗cbl2 python-filelock 3.0.12-13 on CBL Mariner 2.0ModerateNot availableMicrosoft rating unavailablefilelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock
CVE-2026-22702 ↗cbl2 python-virtualenv 20.26.6-3 on CBL Mariner 2.0ModerateNot availableMicrosoft rating unavailablevirtualenv Has TOCTOU Vulnerabilities in Directory Creation
CVE-2026-21860 ↗cbl2 python-tensorboard 2.11.0-3 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableWerkzeug safe_join() allows Windows special device names with compound extensions
CVE-2026-22693 ↗azl3 harfbuzz 8.3.0-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableNull Pointer Dereference in SubtableUnicodesCache::create leading to DoS
CVE-2025-68151 ↗azl3 coredns 1.11.4-12 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableCoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages
CVE-2025-14819 ↗azl3 curl 8.11.1-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableOpenSSL partial chain store policy bypass
CVE-2025-15079 ↗cbl2 cmake 3.21.4-20 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibssh global known_hosts override
CVE-2025-14524 ↗azl3 cmake 3.30.3-10 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebearer token leak on cross-protocol redirect
CVE-2025-14017 ↗azl3 curl 8.11.1-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebroken TLS options for threaded LDAPS
CVE-2025-13034 ↗azl3 curl 8.11.1-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableNo QUIC certificate pinning with GnuTLS
CVE-2026-21444 ↗azl3 libtpms 0.9.6-8 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibtpms returns wrong initialization vector when certain symmetric ciphers are used
CVE-2025-68758 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebacklight: led-bl: Add devlink to supplier LEDs
CVE-2025-68757 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/vgem-fence: Fix potential deadlock on release
CVE-2025-68763 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecrypto: starfive - Correctly handle return of sg_nents_for_len
CVE-2025-68765 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemt76: mt7615: Fix memory leak in mt7615_mcu_wtbl_sta_add()
CVE-2025-68755 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablestaging: most: remove broken i2c driver
CVE-2025-68764 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableNFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags
CVE-2026-22978 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0LowOut-of-bandNot availableMicrosoft rating unavailablewifi: avoid kernel-infoleak from struct iw_point
CVE-2026-0992 ↗azl3 libxml2 2.11.5-7 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableLibxml2: libxml2: denial of service via crafted xml catalogs
CVE-2026-0989 ↗cbl2 libxml2 2.10.4-9 on CBL Mariner 2.0LowOut-of-bandNot availableMicrosoft rating unavailableLibxml2: unbounded relaxng include recursion leading to stack overflow
CVE-2025-71094 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablenet: usb: asix: validate PHY address before use
CVE-2026-21895 ↗azl3 kata-containers-cc 3.15.0.aks0-5 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablersa crate has potential panic on a prime being equal to 1
CVE-2025-15224 ↗azl3 cmake 3.30.3-10 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablelibssh key passphrase bypass without agent set
CVE-2025-13151 ↗azl3 gnutls 3.8.3-6 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableCVE-2025-13151
CVE-2026-1504 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rating unavailableChromium: CVE-2026-1504 Inappropriate implementation in Background Fetch API
CVE-2026-1220 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rating unavailableChromium: CVE-2026-1220 Race in V8
CVE-2026-0908 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rating unavailableChromium: CVE-2026-0908 Use after free in ANGLE
CVE-2026-0907 ↗Microsoft Edge (Chromium-based)N/AOut-of-band9%Microsoft rating unavailableChromium: CVE-2026-0907 Incorrect security UI in Split View
CVE-2026-0905 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rating unavailableChromium: CVE-2026-0905 Insufficient policy enforcement in Network
CVE-2026-0906 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rating unavailableChromium: CVE-2026-0906 Incorrect security UI
CVE-2026-0904 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rating unavailableChromium: CVE-2026-0904 Incorrect security UI in Digital Credentials
CVE-2026-0903 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rating unavailableChromium: CVE-2026-0903 Insufficient validation of untrusted input in Downloads
CVE-2026-0902 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rating unavailableChromium: CVE-2026-0902 Inappropriate implementation in V8
CVE-2026-0901 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rating unavailableChromium: CVE-2026-0901 Inappropriate implementation in Blink
CVE-2026-0900 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rating unavailableChromium: CVE-2026-0900 Inappropriate implementation in V8
CVE-2026-21223 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rates: Exploitation Less LikelyMicrosoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2026-0628 ↗Microsoft Edge (Chromium-based)N/AOut-of-band7%Microsoft rating unavailableChromium: CVE-2026-0628 Insufficient policy enforcement in WebView tag

Glossary