CYBERSECURITYTRACKER
TRACKING3,612 stories653 vuln stories
Patch Day month

February 2026 vulnerabilities

A server-rendered hunting trail for February 2026: 190 returned patch records across 3 vendors. Browse page by page, or use “Load next” to keep adding rows without losing your place.

190all patches
14critical
6exploitation detected
7in CISA KEV
84tracked here
Microsoft 169Cisco 20Android 1

Page 1 of 1 · records 1–190 of 190

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-24051 ↗2026-04-29azl3 ignition-flatcar 2.22.0-1 on Azure Linux 3.0ModerateOut-of-bandOpenTelemetry-Go Affected by Arbitrary Code Execution via PATH Hijacking
CVE-2026-27623 ↗2026-03-25azl3 valkey 8.0.7-1 on Azure Linux 3.0ImportantOut-of-bandValkey has Pre-Authentication DOS from malformed RESP request
CVE-2026-23100 ↗2026-03-22cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandmm/hugetlb: fix hugetlb_pmd_shared()
CVE-2026-23204 ↗2026-03-21cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandnet/sched: cls_u32: use skb_header_pointer_careful()
CVE-2026-23208 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandALSA: usb-audio: Prevent excessive number of frames
CVE-2026-23191 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandALSA: aloop: Fix racy access at PCM trigger
CVE-2026-23171 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandbonding: fix use-after-free due to enslave fail after slave array update
CVE-2026-23169 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandmptcp: fix race in mptcp_pm_nl_flush_addrs_doit()
CVE-2026-23157 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandbtrfs: do not strictly require dirty metadata threshold for metadata writepages
CVE-2026-23154 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: fix segmentation of forwarding fraglist GRO
CVE-2026-23126 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandnetdevsim: fix a race issue related to the operation on bpf_bound_progs list
CVE-2026-23118 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandrxrpc: Fix data-race warning and potential load/store tearing
CVE-2026-23113 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandio_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop
CVE-2026-23110 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandscsi: core: Wake up the error handler when final completions race against each other
CVE-2025-71221 ↗2026-03-20cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-banddmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue()
CVE-2026-23207 ↗2026-03-20azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: tegra210-quad: Protect curr_xfer check in IRQ handler
CVE-2026-23141 ↗2026-03-19cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandbtrfs: send: check for inline extents in range_is_hole_in_parent()
CVE-2026-23138 ↗2026-03-19cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandtracing: Add recursion protection in kernel stack trace recording
CVE-2026-23137 ↗2026-03-19cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandof: unittest: Fix memory leak in unittest_data_add()
CVE-2026-23088 ↗2026-03-19cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandtracing: Fix crash on synthetic stacktrace field usage
CVE-2026-23086 ↗2026-03-19cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandvsock/virtio: cap TX credit to local buffer size
CVE-2025-71202 ↗2026-03-19cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandiommu/sva: invalidate stale IOTLB entries for kernel address space
CVE-2026-23069 ↗2026-03-15cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandvsock/virtio: fix potential underflow in virtio_transport_get_credit()
CVE-2026-23068 ↗2026-03-15cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandspi: spi-sprd-adi: Fix double free in probe error path
CVE-2026-23066 ↗2026-03-15cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandrxrpc: Fix recvmsg() unconditional requeue
CVE-2025-68121 ↗2026-03-05azl3 golang 1.26.0-1 on Azure Linux 3.0ImportantOut-of-bandUnexpected session resumption in crypto/tls
CVE-2026-27141 ↗2026-03-05cbl2 azcopy 10.25.1-6 on CBL Mariner 2.0ImportantOut-of-bandSending certain HTTP/2 frames can cause a server to panic in golang.org/x/net
CVE-2026-25541 ↗2026-03-04azl3 trident 0.21.0-1 on Azure Linux 3.0ModerateOut-of-bandBytes is vulnerable to integer overflow in BytesMut::reserve
CVE-2026-28422 ↗2026-03-01azl3 vim 9.1.1616-1 on Azure Linux 3.0LowOut-of-bandVim has stack-buffer-overflow in build_stl_str_hl()
CVE-2026-28419 ↗2026-03-01azl3 vim 9.1.1616-1 on Azure Linux 3.0ModerateOut-of-bandVim has Heap-based Buffer Underflow in Emacs tags parsing
CVE-2026-28418 ↗2026-03-01azl3 vim 9.1.1616-1 on Azure Linux 3.0ModerateOut-of-bandVim has Heap-based Buffer Overflow in Emacs tags parsing
CVE-2026-28420 ↗2026-03-01azl3 vim 9.1.1616-1 on Azure Linux 3.0ModerateOut-of-bandVim has Heap-based Buffer Overflow and OOB Read in :terminal
CVE-2026-28421 ↗2026-03-01azl3 vim 9.1.1616-1 on Azure Linux 3.0ModerateOut-of-bandVim has a heap-buffer-overflow and a segmentation fault
CVE-2026-28417 ↗2026-03-01azl3 vim 9.1.1616-1 on Azure Linux 3.0ModerateOut-of-bandVim has OS Command Injection in netrw
CVE-2026-28364 ↗2026-02-28azl3 ocaml 5.1.1-1 on Azure Linux 3.0ImportantOut-of-bandIn OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.
CVE-2026-27571 ↗2026-02-27cbl2 telegraf 1.29.4-18 on CBL Mariner 2.0ModerateOut-of-bandnats-server websockets are vulnerable to pre-auth memory DoS
CVE-2025-69873 ↗2026-02-27cbl2 python-tensorboard 2.11.0-3 on CBL Mariner 2.0LowOut-of-bandajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., "^(a|a)*$") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with $data: true for dynamic schema validation.
CVE-2026-27969 ↗2026-02-27cbl2 vitess 17.0.7-12 on CBL Mariner 2.0CriticalOut-of-bandVitess users with backup storage access can write to arbitrary file paths on restore
CVE-2026-27965 ↗2026-02-27cbl2 vitess 17.0.7-14 on CBL Mariner 2.0ImportantOut-of-bandVitess users with backup storage access can gain unauthorized access to production deployment environments
CVE-2026-3063 ↗2026-02-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3063 Inappropriate implementation in DevTools
CVE-2026-3062 ↗2026-02-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3062 Out of bounds read and write in Tint
CVE-2026-3061 ↗2026-02-26Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-3061 Out of bounds read in Media
CVE-2025-11563 ↗2026-02-26azl3 mysql 8.0.45-1 on Azure Linux 3.0N/AOut-of-bandwcurl path traversal with percent-encoded slashes
CVE-2025-62878 ↗2026-02-26cbl2 local-path-provisioner 0.0.21-20 on CBL Mariner 2.0CriticalOut-of-bandLocal Path Provisioner vulnerable to Path Traversal via parameters.pathPattern
CVE-2026-21863 ↗2026-02-26azl3 valkey 8.0.6-1 on Azure Linux 3.0ImportantOut-of-bandMalformed Valkey Cluster bus message can lead to Remote DoS
CVE-2025-67733 ↗2026-02-26azl3 valkey 8.0.6-1 on Azure Linux 3.0ImportantOut-of-bandValkey Affected by RESP Protocol Injection via Lua error_reply
CVE-2025-61145 ↗2026-02-26azl3 libtiff 4.6.0-11 on Azure Linux 3.0N/AOut-of-bandlibtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.
CVE-2025-61144 ↗2026-02-26azl3 libtiff 4.6.0-11 on Azure Linux 3.0CriticalOut-of-bandlibtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.
CVE-2025-61143 ↗2026-02-26azl3 libtiff 4.6.0-11 on Azure Linux 3.0ModerateOut-of-bandlibtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.
CVE-2026-2739 ↗2026-02-25cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ModerateOut-of-bandThis affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely.
CVE-2026-21620 ↗2026-02-25azl3 erlang 26.2.5.15-1 on Azure Linux 3.0LowOut-of-bandTFTP Path Traversal
CVE-2026-27211 ↗2026-02-25azl3 cloud-hypervisor 48.0.246-1 on Azure Linux 3.0CriticalOut-of-bandCloud Hypervisor: Host File Exfiltration via QCOW Backing File Abuse
CVE-2026-27199 ↗2026-02-25azl3 python-werkzeug 3.0.3-2 on Azure Linux 3.0ModerateOut-of-bandWerkzeug safe_join() allows Windows special device names
CVE-2026-24834 ↗2026-02-23cbl2 kata-containers 3.2.0.azl2-7 on CBL Mariner 2.0CriticalOut-of-bandKata Container to Guest micro VM privilege escalation
CVE-2026-2492 ↗2026-02-23azl3 tensorflow 2.16.1-10 on Azure Linux 3.0ImportantOut-of-bandTensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
CVE-2026-2243 ↗2026-02-23azl3 qemu 8.2.0-27 on Azure Linux 3.0ModerateOut-of-bandQemu-kvm: heap buffer out-of-bounds read in vmdk compressed grain parsing
CVE-2026-26960 ↗2026-02-22azl3 tar 1.35-2 on Azure Linux 3.0ImportantOut-of-bandnode-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction
CVE-2025-69299 ↗2026-02-22azl3 doxygen 1.9.8-2 on Azure Linux 3.0ImportantOut-of-bandWordPress Oxygen theme <= 6.0.8 - Server Side Request Forgery (SSRF) vulnerability
CVE-2026-23225 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandsched/mmcid: Don't assume CID is CPU owned on mode switch
CVE-2026-23224 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-banderofs: fix UAF issue for file-backed mounts w/ directio option
CVE-2026-23227 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/exynos: vidi: use ctx->lock to protect struct vidi_context member variables related to memory alloc/free
CVE-2025-71232 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: qla2xxx: Free sp in error path to fix system crash
CVE-2025-71237 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandnilfs2: Fix potential block overflow that cause system hang
CVE-2026-23220 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error paths
CVE-2025-71236 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandscsi: qla2xxx: Validate sp before freeing associated memory
CVE-2025-71233 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandPCI: endpoint: Avoid creating sub-groups asynchronously
CVE-2025-71229 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: rtw88: Fix alignment fault in rtw_core_enable_beacon()
CVE-2025-71234 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: rtl8xxxu: fix slab-out-of-bounds in rtl8xxxu_sta_add
CVE-2026-23226 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandksmbd: add chann_lock to protect ksmbd_chann_list xarray
CVE-2025-71235 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: qla2xxx: Delay module unload while fabric scan in progress
CVE-2026-23223 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandxfs: fix UAF in xchk_btree_check_block_owner
CVE-2025-71231 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandcrypto: iaa - Fix out-of-bounds index in find_empty_iaa_compression_mode
CVE-2026-23221 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandbus: fsl-mc: fix use-after-free in driver_override_show()
CVE-2026-23228 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandsmb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection()
CVE-2025-71230 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandhfs: ensure sb->s_fs_info is always cleaned up
CVE-2026-23230 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandsmb: client: split cached_fid bitfields to avoid shared-byte RMW races
CVE-2026-23222 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly
CVE-2026-23229 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: virtio - Add spinlock protection with virtqueue notification
CVE-2026-1703 ↗2026-02-21azl3 python-virtualenv 20.36.1-1 on Azure Linux 3.0LowOut-of-bandLimited path traversal when installing wheel archives
CVE-2026-1979 ↗2026-02-21azl3 nghttp2 1.61.0-2 on Azure Linux 3.0ModerateOut-of-bandmruby JMPNOT-to-JMPIF Optimization vm.c mrb_vm_exec use after free
CVE-2026-2443 ↗2026-02-21azl3 libsoup 3.4.4-11 on Azure Linux 3.0ModerateOut-of-bandLibsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure
CVE-2026-27171 ↗2026-02-21azl3 zlib 1.3.1-1 on Azure Linux 3.0LowOut-of-bandzlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
CVE-2025-71226 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: iwlwifi: Implement settime64 as stub for MVM/MLD PTP
CVE-2025-71227 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mac80211: don't WARN for connections on invalid channels
CVE-2026-23214 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandbtrfs: reject new transactions if the fs is fully read-only
CVE-2025-71225 ↗2026-02-21cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandmd: suspend array while updating raid_disks via sysfs
CVE-2026-23217 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandriscv: trace: fix snapshot deadlock with sbi ecall
CVE-2026-23215 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandx86/vmware: Fix hypercall clobbers
CVE-2026-23212 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ModerateOut-of-bandbonding: annotate data-races around slave->last_rx
CVE-2026-23216 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandscsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count()
CVE-2026-23213 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/amd/pm: Disable MMIO access during SMU Mode 1 reset
CVE-2025-71228 ↗2026-02-21azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandLoongArch: Set correct protection_map[] for VM_NONE/VM_SHARED
CVE-2026-2650 ↗2026-02-20Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-2650 Heap buffer overflow in Media
CVE-2026-2649 ↗2026-02-20Microsoft Edge (Chromium-based)N/AOut-of-band1%Chromium: CVE-2026-2649 Integer overflow in V8
CVE-2026-2648 ↗2026-02-20Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-2648 Heap buffer overflow in PDFium
CVE-2026-21535 ↗2026-02-19Microsoft TeamsCriticalOut-of-band1%Microsoft Teams Information Disclosure Vulnerability
CVE-2026-2322 ↗2026-02-18Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-2322 Heap buffer overflow in Codecs
CVE-2026-2319 ↗2026-02-18Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-2319 Race in DevTools
CVE-2026-2316 ↗2026-02-18Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-2316 Insufficient policy enforcement in Frames
CVE-2026-2314 ↗2026-02-18Microsoft Edge (Chromium-based)N/AOut-of-band4%Chromium: CVE-2026-2314 Heap buffer overflow in Codecs
CVE-2026-2441 ↗2026-02-17Microsoft Edge (Chromium-based)N/AOut-of-band22%CISA KEVVulnCheckENISAChromium: CVE-2026-2441 Use after free in CSS
CVE-2026-2320 ↗2026-02-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-2320 Inappropriate implementation in File input
CVE-2026-2323 ↗2026-02-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-2323 Inappropriate implementation in Downloads
CVE-2026-2317 ↗2026-02-17Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-2317 Inappropriate implementation in Animation
CVE-2026-2318 ↗2026-02-17Microsoft Edge (Chromium-based)N/AOut-of-band0%CVE-2026-2318
CVE-2026-2313 ↗2026-02-17Microsoft Edge (Chromium-based)N/AOut-of-band4%Chromium: CVE-2026-2313 Use after free in CSS
CVE-2026-0102 ↗2026-02-17Microsoft Edge (Chromium-based)LowOut-of-band0%Microsoft Edge (Chromium-based) Defense in Depth Vulnerability
CVE-2026-26119 ↗2026-02-17Windows Admin CenterCriticalOut-of-band1%More likelyWindows Admin Center Elevation of Privilege Vulnerability
CVE-2023-2804 ↗2026-02-10Windows Server 2022, 23H2 Edition (Server Core installation)Important1%KB5075897Red Hat, Inc. CVE-2023-2804: Heap Based Overflow libjpeg-turbo
CVE-2026-20841 ↗2026-02-10Windows NotepadImportant12%1 mentionsWindows Notepad App Remote Code Execution Vulnerability
CVE-2026-20846 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant1%KB5075897KB5075899
and 12 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077179KB5077181KB5077212
GDI+ Denial of Service Vulnerability
CVE-2026-21218 ↗2026-02-10.NET 10.0 installed on Mac OSImportant1%KB5077862KB5077863
and 1 moreKB5077864
.NET Spoofing Vulnerability
CVE-2026-21222 ↗2026-02-10Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5075897KB5075899
and 10 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075999KB5077181KB5077212
Windows Kernel Information Disclosure Vulnerability
CVE-2026-21228 ↗2026-02-10Azure LocalImportant1%Azure Local Remote Code Execution Vulnerability
CVE-2026-21229 ↗2026-02-10Power BI Report ServerImportant1%Power BI Remote Code Execution Vulnerability
CVE-2026-21231 ↗2026-02-10Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5075897KB5075899
and 12 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077179KB5077181KB5077212
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-21232 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5075897KB5075899
and 5 moreKB5075941KB5075942KB5077179KB5077181KB5077212
Windows HTTP.sys Elevation of Privilege Vulnerability
CVE-2026-21234 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5075897KB5075899
and 9 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5077179KB5077181KB5077212
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
CVE-2026-21235 ↗2026-02-10Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5075904KB5075906
and 7 moreKB5075912KB5075941KB5075943KB5075970KB5075971KB5075999KB5077179
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2026-21236 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5075897KB5075899
and 12 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077179KB5077181KB5077212
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-21237 ↗2026-02-10Windows Server 2022Important0%KB5075897KB5075899
and 8 moreKB5075906KB5075912KB5075941KB5075942KB5075943KB5077179KB5077181KB5077212
Windows Subsystem for Linux Elevation of Privilege Vulnerability
CVE-2026-21238 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant3%More likelyKB5075897KB5075899
and 12 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077179KB5077181KB5077212
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-21239 ↗2026-02-10Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5075897KB5075899
and 11 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077181KB5077212
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-21240 ↗2026-02-10Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5075897KB5075899
and 9 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5077179KB5077181KB5077212
Windows HTTP.sys Elevation of Privilege Vulnerability
CVE-2026-21241 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant2%More likelyKB5075897KB5075899
and 7 moreKB5075906KB5075941KB5075942KB5075943KB5077179KB5077181KB5077212
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-21242 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5075897KB5075899
and 8 moreKB5075906KB5075912KB5075941KB5075942KB5075943KB5077179KB5077181KB5077212
Windows Subsystem for Linux Elevation of Privilege Vulnerability
CVE-2026-21243 ↗2026-02-10Windows Server 2019Important1%KB5075897KB5075899
and 4 moreKB5075904KB5075906KB5075942KB5075943
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
CVE-2026-21244 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant1%KB5075897KB5075899
and 10 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075999KB5077179KB5077181KB5077212
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-21245 ↗2026-02-10Windows Server 2025 (Server Core installation)Important0%KB5075899KB5075942
and 3 moreKB5077179KB5077181KB5077212
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-21246 ↗2026-02-10Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5075897KB5075899
and 11 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077181KB5077212
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2026-21247 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant1%KB5075897KB5075899
and 10 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075999KB5077179KB5077181KB5077212
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-21248 ↗2026-02-10Windows 10 Version 1809 for x64-based SystemsImportant1%KB5075897KB5075899
and 10 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075999KB5077179KB5077181KB5077212
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-21249 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant11%KB5075897KB5075899
and 11 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075999KB5077179KB5077181KB5077212
Windows NTLM Spoofing Vulnerability
CVE-2026-21250 ↗2026-02-10Windows Server 2025 (Server Core installation)Important1%KB5075897KB5075899
and 4 moreKB5075942KB5077179KB5077181KB5077212
Windows HTTP.sys Elevation of Privilege Vulnerability
CVE-2026-21251 ↗2026-02-10Windows Server 2019Important0%KB5075897KB5075899
and 5 moreKB5075904KB5075906KB5075942KB5075943KB5075999
Cluster Client Failover (CCF) Elevation of Privilege Vulnerability
CVE-2026-21253 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant1%More likelyKB5075897KB5075899
and 12 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077179KB5077181KB5077212
Mailslot File System Elevation of Privilege Vulnerability
CVE-2026-21255 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant0%KB5075897KB5075899
and 10 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075999KB5077179KB5077181KB5077212
Windows Hyper-V Security Feature Bypass Vulnerability
CVE-2026-21256 ↗2026-02-10Microsoft Visual Studio 2022 version 17.14Important1%GitHub Copilot and Visual Studio Remote Code Execution Vulnerability
CVE-2026-21257 ↗2026-02-10Microsoft Visual Studio 2022 version 17.14Important1%GitHub Copilot and Visual Studio Elevation of Privilege Vulnerability
CVE-2026-21258 ↗2026-02-10Office Online ServerImportant1%KB5002835KB5002837Microsoft Excel Information Disclosure Vulnerability
CVE-2026-21259 ↗2026-02-10Office Online ServerImportant1%KB5002835KB5002837Microsoft Excel Elevation of Privilege Vulnerability
CVE-2026-21260 ↗2026-02-10Microsoft SharePoint Enterprise Server 2016Important1%KB5002833KB5002834
and 4 moreKB5002836KB5002839KB5002840KB5002841
Microsoft Outlook Spoofing Vulnerability
CVE-2026-21261 ↗2026-02-10Office Online ServerImportant1%KB5002835KB5002837Microsoft Excel Information Disclosure Vulnerability
CVE-2026-21508 ↗2026-02-10Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5075897KB5075899
and 12 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077179KB5077181KB5077212
Windows Storage Elevation of Privilege Vulnerability
CVE-2026-21510 ↗2026-02-10Windows 10 Version 1809 for 32-bit SystemsImportant26%Exploitation detectedCISA KEVVulnCheckENISAKB5075897KB5075899
and 12 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077179KB5077181KB5077212
Windows Shell Security Feature Bypass Vulnerability
CVE-2026-21511 ↗2026-02-10Microsoft SharePoint Enterprise Server 2016Important4%More likelyKB5002833KB5002834
and 4 moreKB5002836KB5002839KB5002840KB5002841
Microsoft Outlook Spoofing Vulnerability
CVE-2026-21512 ↗2026-02-10Azure DevOps Server 2022Important1%Azure DevOps Server Cross-Site Scripting Vulnerability
CVE-2026-21513 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant15%Exploitation detectedCISA KEVVulnCheckENISAKB5075897KB5075899
and 12 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077179KB5077181KB5077212
MSHTML Framework Security Feature Bypass Vulnerability
CVE-2026-21514 ↗2026-02-10Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant2%Exploitation detectedCISA KEVVulnCheckENISAMicrosoft Word Security Feature Bypass Vulnerability
CVE-2026-21516 ↗2026-02-10GitHub Copilot Plugin for JetBrains IDEsImportant1%GitHub Copilot for Jetbrains Remote Code Execution Vulnerability
CVE-2026-21517 ↗2026-02-10Windows App for MacImportant0%Windows App for Mac Installer Elevation of Privilege Vulnerability
CVE-2026-21518 ↗2026-02-10Visual Studio CodeImportant1%GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-21519 ↗2026-02-10Windows 10 Version 1809 for 32-bit SystemsImportant2%Exploitation detectedCISA KEVVulnCheckENISAKB5075897KB5075899
and 10 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075999KB5077179KB5077181KB5077212
Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-21522 ↗2026-02-10Microsoft ACI Confidential ContainersCritical0%Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability
CVE-2026-21523 ↗2026-02-10Microsoft Visual Studio Code CoPilot Chat ExtensionImportant1%GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability
CVE-2026-21525 ↗2026-02-10Windows 10 Version 1809 for 32-bit SystemsModerate5%Exploitation detectedCISA KEVVulnCheckENISAKB5075897KB5075899
and 12 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077179KB5077181KB5077212
Windows Remote Access Connection Manager Denial of Service Vulnerability
CVE-2026-21527 ↗2026-02-10Microsoft Exchange Server Subscription Edition RTMImportant8%KB5074992KB5074993
and 2 moreKB5074994KB5074995
Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-21528 ↗2026-02-10Azure IoT ExplorerImportant1%Azure IoT Explorer Information Disclosure Vulnerability
CVE-2026-21529 ↗2026-02-10Azure HDInsightImportant1%Azure HDInsight Spoofing Vulnerability
CVE-2026-21531 ↗2026-02-10Azure AI Language AuthoringImportant2%Azure SDK for Python Remote Code Execution Vulnerability
CVE-2026-21533 ↗2026-02-10Windows 11 Version 26H1 for ARM64-based SystemsImportant4%Exploitation detectedCISA KEVVulnCheckENISAKB5075897KB5075899
and 12 moreKB5075904KB5075906KB5075912KB5075941KB5075942KB5075943KB5075970KB5075971KB5075999KB5077179KB5077181KB5077212
Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVE-2026-21537 ↗2026-02-10Microsoft Defender for Endpoint for LinuxImportant1%Microsoft Defender for Endpoint Linux Extension Remote Code Execution Vulnerability
CVE-2026-23655 ↗2026-02-10Microsoft ACI Confidential ContainersCritical1%Microsoft ACI Confidential Containers Information Disclosure Vulnerability
CVE-2026-1862 ↗2026-02-06Microsoft Edge (Chromium-based)N/AOut-of-band1%Chromium: CVE-2026-1862 Type Confusion in V8
CVE-2026-1861 ↗2026-02-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-1861 Heap buffer overflow in libvpx
CVE-2026-0391 ↗2026-02-05Microsoft Edge (Chromium-based)ModerateOut-of-band1%Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2026-21532 ↗2026-02-05Azure FunctionsCriticalOut-of-band1%Azure Function Information Disclosure Vulnerability
CVE-2026-24300 ↗2026-02-05Azure Front DoorCriticalOut-of-band1%Azure Front Door Elevation of Privilege Vulnerability
CVE-2026-24302 ↗2026-02-05Azure ARCCriticalOut-of-band2%Azure Arc Elevation of Privilege Vulnerability

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
CiscoCVE-2026-20010CVSS 7.4Cisco Nexus 3000 Series SwitchesPatch ↗Advisory ↗
CiscoCVE-2026-20033CVSS 7.4Cisco Nexus 9000 Series SwitchesPatch ↗Advisory ↗
CiscoCVE-2026-20048CVSS 7.7Cisco Nexus 9000 Series SwitchesPatch ↗Advisory ↗
CiscoCVE-2026-20051CVSS 7.4Cisco Nexus 3000 Series SwitchesPatch ↗Advisory ↗
CiscoCVE-2026-20091CVSS 4.8Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20099CVSS 6.7Cisco Firepower 2100 SeriesPatch ↗Advisory ↗
CiscoCVE-2026-20122trackedCVSS 5.4Patch ↗Advisory ↗
CiscoCVE-2026-20127trackedCVSS 10.0Patch ↗Advisory ↗
CiscoCVE-2026-20128trackedCVSS 7.5Patch ↗Advisory ↗
CiscoCVE-2026-20133trackedCVSS 6.5Patch ↗Advisory ↗
AndroidCVE-2026-0106High (Android rating)no patch linkAdvisory ↗