CYBERSECURITYTRACKER
TRACKING7,183 stories in this site build1,510 vulnerability news stories in this site build
Vulnerabilities

April 2026 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 2 vulnerabilities with exploitation detected in the wild this month. This defender-focused view covers 1,520 vulnerabilities across 4,656 returned patch records from 4 vendors. Filter the complete month, or browse the static page trail without JavaScript.

4,656all patch recordsClear filters142criticalShow these records2Microsoft exploitation detectedShow these records6Microsoft in the Known Exploited Vulnerabilities catalogShow these records393tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 2 of 24 · records 201 to 400 of 4,656

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2023-20585 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation Less LikelyKB5082063KB5083769AMD: CVE-2023-20585 IOMMU Write Buffer Vulnerability
CVE-2026-0390 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation More LikelyKB5082123KB5082142
and 2 moreKB5082198KB5082200
UEFI Secure Boot Security Feature Bypass Vulnerability
CVE-2026-20806 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows COM Server Information Disclosure Vulnerability
CVE-2026-20928 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Recovery Environment Security Feature Bypass Vulnerability
CVE-2026-20930 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 5 moreKB5082063KB5082123KB5082142KB5082200KB5083769
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20945 ↗Microsoft SharePoint Enterprise Server 2016Important19%Microsoft rates: Exploitation Less LikelyKB5002853KB5002854
and 3 moreKB5002856KB5002861KB5002862
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-23653 ↗Microsoft Visual Studio Code CoPilot Chat ExtensionImportant1%Microsoft rates: Exploitation Less LikelyGitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
CVE-2026-23657 ↗Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyMicrosoft Word Remote Code Execution Vulnerability
CVE-2026-23670 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
CVE-2026-25184 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 3 moreKB5082063KB5083768KB5083769
Applocker Filter Driver (applockerfltr.sys) Elevation of Privilege Vulnerability
CVE-2026-25250 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
MITRE: CVE-2026-25250 Secure Boot disable Eazy Fix
CVE-2026-26143 ↗PowerShell 7.5Important1%Microsoft rates: Exploitation Less LikelyMicrosoft PowerShell Security Feature Bypass Vulnerability
CVE-2026-26149 ↗Microsoft Power Apps Desktop ClientImportant1%Microsoft rates: Exploitation Less LikelyMicrosoft Power Apps Desktop Client Spoofing Vulnerability
CVE-2026-26151 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant1%Microsoft rates: Exploitation More LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Remote Desktop Spoofing Vulnerability
CVE-2026-26152 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
CVE-2026-26153 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Encrypted File System (EFS) Elevation of Privilege Vulnerability
CVE-2026-26154 ↗Windows Server 2019Important1%Microsoft rates: Exploitation Less LikelyKB5082060KB5082063
and 5 moreKB5082123KB5082126KB5082127KB5082142KB5082198
Windows Server Update Service (WSUS) Tampering Vulnerability
CVE-2026-26155 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
CVE-2026-26156 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-26159 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Remote Desktop Licensing Service Elevation of Privilege Vulnerability
CVE-2026-26160 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Remote Desktop Licensing Service Elevation of Privilege Vulnerability
CVE-2026-26161 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Sensor Data Service Elevation of Privilege Vulnerability
CVE-2026-26162 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows OLE Elevation of Privilege Vulnerability
CVE-2026-26163 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 8 moreKB5082063KB5082123KB5082126KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-26165 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 4 moreKB5082063KB5082142KB5083768KB5083769
Windows Shell Elevation of Privilege Vulnerability
CVE-2026-26166 ↗Windows Server 2022Important0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 4 moreKB5082063KB5082142KB5083768KB5083769
Windows Shell Elevation of Privilege Vulnerability
CVE-2026-26167 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-26168 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-26169 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant2%Microsoft rates: Exploitation More LikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Kernel Memory Information Disclosure Vulnerability
CVE-2026-26170 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
PowerShell Elevation of Privilege Vulnerability
CVE-2026-26171 ↗PowerShell 7.5Important2%Microsoft rates: Exploitation Less LikelyKB5086095KB5086096
and 1 moreKB5086097
.NET Denial of Service Vulnerability
CVE-2026-26172 ↗Windows Server 2022Important0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 5 moreKB5082063KB5082142KB5082200KB5083768KB5083769
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-26173 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-26174 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
CVE-2026-26175 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Boot Manager Security Feature Bypass Vulnerability
CVE-2026-26176 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Client Side Caching driver (csc.sys) Elevation of Privilege Vulnerability
CVE-2026-26177 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-26178 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083769
Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability
CVE-2026-26179 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 3 moreKB5082063KB5083768KB5083769
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-26180 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-26181 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 3 moreKB5082063KB5083768KB5083769
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2026-26182 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-26183 ↗Windows Server 2019Important0%Microsoft rates: Exploitation Less LikelyKB5082060KB5082063
and 5 moreKB5082123KB5082126KB5082127KB5082142KB5082198
Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability
CVE-2026-26184 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-27906 ↗Windows 10 Version 21H2 for 32-bit SystemsImportant0%Microsoft rates: Exploitation More LikelyKB5082052KB5082200
and 2 moreKB5083768KB5083769
Windows Hello Security Feature Bypass Vulnerability
CVE-2026-27907 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 3 moreKB5082063KB5083768KB5083769
Windows Storage Spaces Controller Elevation of Privilege Vulnerability
CVE-2026-27908 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant2%Microsoft rates: Exploitation More LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability
CVE-2026-27909 ↗Windows 10 Version 1809 for 32-bit SystemsImportant2%Microsoft rates: Exploitation More LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Search Service Elevation of Privilege Vulnerability
CVE-2026-27910 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Installer Elevation of Privilege Vulnerability
CVE-2026-27911 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows User Interface Core Elevation of Privilege Vulnerability
CVE-2026-27912 ↗Windows Server 2019Important0%Microsoft rates: Exploitation Less LikelyKB5082060KB5082063
and 5 moreKB5082123KB5082126KB5082127KB5082142KB5082198
Windows Kerberos Elevation of Privilege Vulnerability
CVE-2026-27913 ↗Windows Server 2019Important0%Microsoft rates: Exploitation More LikelyKB5082060KB5082123
and 4 moreKB5082126KB5082127KB5082142KB5082198
Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-27914 ↗Windows 10 Version 1809 for 32-bit SystemsImportant2%Microsoft rates: Exploitation More LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Microsoft Management Console Elevation of Privilege Vulnerability
CVE-2026-27915 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2026-27916 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2026-27917 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 8 moreKB5082063KB5082123KB5082126KB5082142KB5082198KB5082200KB5083768KB5083769
Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) Elevation of Privilege Vulnerability
CVE-2026-27918 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Shell Elevation of Privilege Vulnerability
CVE-2026-27919 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2026-27920 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2026-27921 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant1%Microsoft rates: Exploitation More LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability
CVE-2026-27922 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-27923 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-27924 ↗Windows Server 2022Important0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 2 moreKB5082142KB5082200
Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-27925 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows UPnP Device Host Information Disclosure Vulnerability
CVE-2026-27926 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-27927 ↗Windows Server 2022 (Server Core installation)Important0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-27928 ↗Windows Server 2019Important0%Microsoft rates: Exploitation Less LikelyKB5082060KB5082063
and 3 moreKB5082123KB5082142KB5082198
Windows Hello Security Feature Bypass Vulnerability
CVE-2026-27929 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability
CVE-2026-27930 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows GDI Information Disclosure Vulnerability
CVE-2026-27931 ↗Windows Server 2022Important0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 5 moreKB5082063KB5082142KB5082200KB5083768KB5083769
Windows GDI Information Disclosure Vulnerability
CVE-2026-32068 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
CVE-2026-32069 ↗Windows Server 2022 (Server Core installation)Important0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-32070 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation More LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2026-32071 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2026-32072 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Active Directory Spoofing Vulnerability
CVE-2026-32073 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-32074 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-32075 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation More LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2026-32076 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 3 moreKB5082063KB5083768KB5083769
Windows Storage Spaces Controller Elevation of Privilege Vulnerability
CVE-2026-32077 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 10 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5082806KB5083768KB5083769
Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2026-32078 ↗Windows Server 2022 (Server Core installation)Important0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-32079 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Web Account Manager Information Disclosure Vulnerability
CVE-2026-32080 ↗Windows Server 2019Important0%Microsoft rates: Exploitation Less LikelyKB5082060KB5082063
and 3 moreKB5082123KB5082142KB5082198
Windows WalletService Elevation of Privilege Vulnerability
CVE-2026-32081 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Package Catalog Information Disclosure Vulnerability
CVE-2026-32082 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
CVE-2026-32083 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
CVE-2026-32084 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Print Spooler Information Disclosure Vulnerability
CVE-2026-32085 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Remote Procedure Call Information Disclosure Vulnerability
CVE-2026-32086 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
CVE-2026-32087 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
CVE-2026-32088 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Biometric Service Security Feature Bypass Vulnerability
CVE-2026-32089 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Speech Brokered Api Elevation of Privilege Vulnerability
CVE-2026-32090 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Speech Brokered Api Elevation of Privilege Vulnerability
CVE-2026-32091 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2026-32093 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant1%Microsoft rates: Exploitation More LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
CVE-2026-32149 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-32150 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
CVE-2026-32151 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Shell Information Disclosure Vulnerability
CVE-2026-32152 ↗Windows Server 2022Important0%Microsoft rates: Exploitation More LikelyKB5082052KB5082060
and 4 moreKB5082063KB5082142KB5083768KB5083769
Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-32153 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082123
and 3 moreKB5082200KB5083768KB5083769
Windows Speech Runtime Elevation of Privilege Vulnerability
CVE-2026-32154 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation More LikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-32155 ↗Windows Server 2022Important0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 4 moreKB5082063KB5082142KB5082200KB5083769
Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-32156 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows UPnP Device Host Remote Code Execution Vulnerability
CVE-2026-32158 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-32159 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-32160 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-32162 ↗Windows 10 Version 1809 for 32-bit SystemsImportant2%Microsoft rates: Exploitation More LikelyKB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows COM Elevation of Privilege Vulnerability
CVE-2026-32163 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows User Interface Core Elevation of Privilege Vulnerability
CVE-2026-32164 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows User Interface Core Elevation of Privilege Vulnerability
CVE-2026-32165 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows User Interface Core Elevation of Privilege Vulnerability
CVE-2026-32167 ↗Microsoft SQL Server 2025 for x64-based Systems (CU3)Important0%Microsoft rates: Exploitation Less LikelyKB5083245KB5083252
and 8 moreKB5084814KB5084815KB5084816KB5084817KB5084818KB5084819KB5084820KB5084821
SQL Server Elevation of Privilege Vulnerability
CVE-2026-32168 ↗Azure Monitor AgentImportant0%Microsoft rates: Exploitation Less LikelyAzure Monitor Agent Elevation of Privilege Vulnerability
CVE-2026-32171 ↗Azure Logic AppsImportant0%Microsoft rates: Exploitation Less LikelyAzure Logic Apps Elevation of Privilege Vulnerability
CVE-2026-32176 ↗Microsoft SQL Server 2025 for x64-based Systems (CU3)Important0%Microsoft rates: Exploitation Less LikelyKB5083245KB5083252
and 8 moreKB5084814KB5084815KB5084816KB5084817KB5084818KB5084819KB5084820KB5084821
SQL Server Elevation of Privilege Vulnerability
CVE-2026-32178 ↗Microsoft Visual Studio 2022 version 17.12Important2%Microsoft rates: Exploitation Less LikelyKB5086095KB5086096
and 1 moreKB5086097
.NET Spoofing Vulnerability
CVE-2026-32181 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 5 moreKB5082063KB5082142KB5082200KB5083768KB5083769
Connected User Experiences and Telemetry Service Denial of Service Vulnerability
CVE-2026-32183 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Snipping Tool Remote Code Execution Vulnerability
CVE-2026-32184 ↗Microsoft HPC Pack 2019Important2%Microsoft rates: Exploitation Less LikelyMicrosoft High Performance Compute (HPC) Pack Elevation of Privilege Vulnerability
CVE-2026-32188 ↗Office Online ServerImportant0%Microsoft rates: Exploitation Less LikelyKB5002855KB5002860Microsoft Excel Information Disclosure Vulnerability
CVE-2026-32189 ↗Office Online ServerImportant0%Microsoft rates: Exploitation Less LikelyKB5002855KB5002860Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-32192 ↗Azure Monitor AgentImportant2%Microsoft rates: Exploitation Less LikelyAzure Monitor Agent Elevation of Privilege Vulnerability
CVE-2026-32195 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5083768Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-32196 ↗Windows Admin CenterImportant0%Microsoft rates: Exploitation Less LikelyWindows Admin Center Spoofing Vulnerability
CVE-2026-32197 ↗Office Online ServerImportant0%Microsoft rates: Exploitation Less LikelyKB5002855KB5002860Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-32198 ↗Office Online ServerImportant0%Microsoft rates: Exploitation Less LikelyKB5002855KB5002860Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-32199 ↗Office Online ServerImportant0%Microsoft rates: Exploitation Less LikelyKB5002855KB5002860Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-32200 ↗Microsoft Office 2019 for 32-bit editionsImportant0%Microsoft rates: Exploitation Less LikelyKB5002808Microsoft PowerPoint Remote Code Execution Vulnerability
CVE-2026-32203 ↗Microsoft Visual Studio 2026 version 18.4Important2%Microsoft rates: Exploitation Less LikelyKB5086095KB5086096
and 1 moreKB5086097
.NET and Visual Studio Denial of Service Vulnerability
CVE-2026-32212 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
CVE-2026-32214 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
CVE-2026-32215 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 6 moreKB5082063KB5082123KB5082142KB5082200KB5083768KB5083769
Windows Kernel Information Disclosure Vulnerability
CVE-2026-32216 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5083768Windows Redirected Drive Buffering System Denial of Service Vulnerability
CVE-2026-32217 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Kernel Information Disclosure Vulnerability
CVE-2026-32218 ↗Windows Server 2022Important0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 5 moreKB5082063KB5082142KB5082200KB5083768KB5083769
Windows Kernel Information Disclosure Vulnerability
CVE-2026-32219 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation UnlikelyKB5082063KB5083768
and 1 moreKB5083769
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2026-32220 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082063KB5083768
and 1 moreKB5083769
UEFI Secure Boot Security Feature Bypass Vulnerability
CVE-2026-32221 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation Less LikelyKB5082063KB5083768
and 1 moreKB5083769
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-32222 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082063KB5083768
and 1 moreKB5083769
Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-32223 ↗Windows Server 2025 (Server Core installation)Important1%Microsoft rates: Exploitation Less LikelyKB5082063KB5083768
and 1 moreKB5083769
Windows USB Printing Stack (usbprint.sys) Elevation of Privilege Vulnerability
CVE-2026-32224 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5083768Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
CVE-2026-32225 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation More LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Shell Security Feature Bypass Vulnerability
CVE-2026-32226 ↗Microsoft .NET Framework 4.8 on Windows 10 Version 22H2 for x64-based SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5082398KB5082400
and 16 moreKB5082402KB5082403KB5082404KB5082406KB5082411KB5082413KB5082414KB5082417KB5082418KB5082419KB5082420KB5082421KB5082424KB5082425KB5082426KB5082427
.NET Framework Denial of Service Vulnerability
CVE-2026-32631 ↗Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3)Important0%Microsoft rates: Exploitation Less LikelyGitHub: CVE-2026-32631 'git clone' from manipulated repositories can leak NTLM hashes
CVE-2026-33095 ↗Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyMicrosoft Word Remote Code Execution Vulnerability
CVE-2026-33096 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 4 moreKB5082063KB5082142KB5083768KB5083769
HTTP.sys Denial of Service Vulnerability
CVE-2026-33098 ↗Windows Server 2019 (Server Core installation)Important0%Microsoft rates: Exploitation UnlikelyKB5082052KB5082060
and 7 moreKB5082063KB5082123KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability
CVE-2026-33099 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 7 moreKB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083769
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-33100 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-33101 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation UnlikelyKB5082060KB5082063
and 2 moreKB5083768KB5083769
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2026-33103 ↗Microsoft Dynamics 365 (on-premises) version 9.0Important0%Microsoft rates: Exploitation UnlikelyKB5078943Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2026-33104 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
Win32k Elevation of Privilege Vulnerability
CVE-2026-33116 ↗.NET 10.0 installed on Mac OSImportant2%Microsoft rates: Exploitation Less LikelyKB5082398KB5082400
and 17 moreKB5082402KB5082403KB5082411KB5082413KB5082414KB5082417KB5082418KB5082419KB5082420KB5082421KB5082424KB5082425KB5082426KB5082427KB5086095KB5086096KB5086097
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVE-2026-33120 ↗Microsoft SQL Server 2022 for x64-based Systems (GDR)Important1%Microsoft rates: Exploitation Less LikelyKB5084815Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-33822 ↗Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyMicrosoft Word Information Disclosure Vulnerability
CVE-2026-7246 ↗azl3 python-click 8.1.7-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablePallets Click contains a command injection via Unsanitized Filename "click.edit()"
CVE-2026-41082 ↗azl3 ocaml-dune 3.15.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableIn OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
CVE-2026-25833 ↗azl3 nodejs24 24.14.1-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableMbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function
CVE-2026-25835 ↗azl3 qemu 10.1.0-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableMbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).
CVE-2026-34876 ↗azl3 qemu 10.1.0-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableAn issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len parameter. This is caused by missing validation of the tag_len parameter against the size of the internal 16-byte authentication buffer. The issue affects the public multipart CCM API in Mbed TLS 3.x, where mbedtls_ccm_finish() can be invoked directly by applications. In Mbed TLS 4.x versions prior to the fix, the same missing validation exists in the internal implementation; however, the function is not exposed as part of the public API. Exploitation requires application-level invocation of the multipart CCM API.
CVE-2026-34874 ↗azl3 nodejs24 24.14.1-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableAn issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.
CVE-2026-33845 ↗azl3 gnutls 3.8.3-8 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableGnutls: gnutls: denial of service via dtls zero-length fragment
CVE-2026-40170 ↗cbl2 nodejs18 18.20.3-12 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablengtcp2 has a qlog transport parameter serialization stack buffer overflow
CVE-2026-32148 ↗cbl2 rabbitmq-server 3.11.24-3 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableLockfile checksums not verified in Hex allows dependency integrity bypass
CVE-2026-30656 ↗azl3 fio 3.37-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableA NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the fdp_pli option. The callback function str_fdp_pli_cb() does not validate the input pointer and calls strdup() on a NULL value when the option is specified without an argument. This results in a segmentation fault and process crash.
CVE-2026-6846 ↗azl3 gdb 13.2-7 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableBinutils: binutils: arbitrary code execution via malformed xcoff object file processing
CVE-2026-37555 ↗cbl2 libsndfile 1.0.31-4 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableAn issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 167) were not. When samplesperblock (int) * blocks (int) exceeds INT_MAX, the 32-bit multiplication overflows before being assigned to sf.frames (sf_count_t/int64). With samplesperblock=50000 and blocks=50000, the product 2500000000 overflows to -1794967296. This causes incorrect frame count leading to heap buffer overflow or denial of service. Both values come from the WAV file header and are attacker-controlled. This issue was discovered after an incomplete fix for CVE-2022-33065.
CVE-2026-31533 ↗azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenet/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
CVE-2026-41636 ↗cbl2 ceph 16.2.10-11 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableApache Thrift: Node.js skip() recursion
CVE-2026-41605 ↗azl3 thrift 0.15.0-5 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableApache Thrift: Swift Compact Protocol integer overflow
CVE-2026-41604 ↗azl3 thrift 0.15.0-5 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableApache Thrift: Swift Range crash in skip()

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-32203trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 10)aspnetcore-runtime-10.0-0:10.0.6-1.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32203trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 8)aspnetcore-runtime-8.0-0:8.0.26-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32203trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)aspnetcore-runtime-8.0-0:8.0.26-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32203trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 10)aspnetcore-runtime-8.0-0:8.0.26-1.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32203trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)aspnetcore-runtime-10.0-0:10.0.6-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32203trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 10)aspnetcore-runtime-9.0-0:9.0.15-1.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32203trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 8)aspnetcore-runtime-10.0-0:10.0.6-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32203trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32203trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 8)aspnetcore-runtime-9.0-0:9.0.15-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33116trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 10)aspnetcore-runtime-10.0-0:10.0.6-1.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33116trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 8)aspnetcore-runtime-8.0-0:8.0.26-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33116trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)aspnetcore-runtime-8.0-0:8.0.26-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33116trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 10)aspnetcore-runtime-8.0-0:8.0.26-1.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33116trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)aspnetcore-runtime-10.0-0:10.0.6-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33116trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 10)aspnetcore-runtime-9.0-0:9.0.15-1.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33116trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 8)aspnetcore-runtime-10.0-0:10.0.6-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33116trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33116trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 8)aspnetcore-runtime-9.0-0:9.0.15-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-21710trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 8)nodejs-1:20.20.2-1.module+el8.10.0+24197+1602b452.aarch64::nodejs:20Patch ↗Advisory ↗
Red HatCVE-2026-21710trackedCVSS 7.5Red Hat Enterprise Linux AppStream EUS (v.9.6)nodejs-1:22.22.2-1.module+el9.6.0+24196+39669d4e.aarch64::nodejs:22Patch ↗Advisory ↗
Red HatCVE-2026-21710trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 8)nodejs-1:24.14.1-2.module+el8.10.0+24190+49a46c75.aarch64::nodejs:24Patch ↗Advisory ↗
Red HatCVE-2026-21710trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 10)nodejs24-1:24.14.1-2.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-21710trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)nodejs-1:20.20.2-1.module+el9.7.0+24193+41b7b572.aarch64::nodejs:20Patch ↗Advisory ↗
Red HatCVE-2026-21710trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)nodejs-1:22.22.2-1.module+el9.7.0+24157+8ddb2461.aarch64::nodejs:22Patch ↗Advisory ↗
Red HatCVE-2026-21710trackedCVSS 7.5Red Hat Enterprise Linux AppStream EUS (v. 10.0)nodejs-1:22.22.2-2.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-21710trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)nodejs-1:24.14.1-2.module+el9.7.0+24166+51c9666b.aarch64::nodejs:24Patch ↗Advisory ↗
Red HatCVE-2026-21710trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 10)nodejs-1:22.22.2-1.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-21710trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 8)nodejs-1:22.22.2-1.module+el8.10.0+24148+847b6786.aarch64::nodejs:22Patch ↗Advisory ↗
Red HatCVE-2025-64720trackedCVSS 7.1Red Hat Hardened Imageslibpng-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2025-65018trackedCVSS 7.1Red Hat Hardened Imageslibpng-main@aarch64Patch ↗Advisory ↗

Glossary