CYBERSECURITYTRACKER
TRACKING3,829 stories703 vuln stories
Patch Day month

May 2026 vulnerabilities

A defender-focused view of 1,487 vulnerabilities across 2,620 returned patch records from 4 vendors. Filter the complete month, or browse the static page trail without JavaScript.

2,620all patch recordsClear filters147criticalShow these records3Microsoft exploitation detectedShow these records4Microsoft in CISA KEVShow these records549tracked hereShow these records

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as “no.” “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An EPSS percentage is the global 30-day exploitation probability in the wild, not specific to you.

Page 14 of 14 · records 2,601–2,620 of 2,620

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-8015 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8015 Inappropriate implementation in Media
CVE-2026-8016 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8016 Use after free in WebRTC
CVE-2026-8017 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8017 Side-channel information leakage in Media
CVE-2026-8018 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8018 Insufficient policy enforcement in DevTools
CVE-2026-8019 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8019 Insufficient policy enforcement in WebApp
CVE-2026-8021 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8021 Script injection in UI
CVE-2026-8022 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8022 Inappropriate implementation in MHTML
CVE-2026-46242 ↗2026-05-31azl3 kernel 6.6.139.1-1 on Azure Linux 3.0N/AOut-of-bandeventpoll: fix ep_remove struct eventpoll / struct file UAF
CVE-2026-43421 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-bandusb: gadget: f_ncm: Fix net_device lifecycle with device_move
CVE-2026-43398 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-banddrm/amdgpu: add upper bound check on user inputs in wait ioctl
CVE-2026-43400 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-banddrm/amdgpu: add upper bound check on user inputs in signal ioctl
CVE-2026-43317 ↗2026-05-09azl3 kernel 6.6.138.1-1 on Azure Linux 3.0N/AOut-of-bandmost: core: fix leak on early registration failure
CVE-2026-43443 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-bandASoC: amd: acp-mach-common: Add missing error check for clock acquisition
CVE-2026-43320 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-banddrm/amd/display: Fix dsc eDP issue
CVE-2025-71302 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-banddrm/panthor: fix for dma-fence safe access rules
CVE-2026-43474 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-bandfs: init flags_valid before calling vfs_fileattr_get
CVE-2026-43045 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0N/AOut-of-bandmshv: Fix error handling in mshv_region_pin
CVE-2026-43021 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0N/AOut-of-bandBluetooth: hci_sync: fix leaks when hci_cmd_sync_queue_once fails
CVE-2026-43022 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0N/AOut-of-bandBluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists
CVE-2026-31769 ↗2026-05-02azl3 kernel 6.6.134.1-2 on Azure Linux 3.0N/AOut-of-bandgpib: fix use-after-free in IO ioctl handlers