CYBERSECURITYTRACKER
TRACKING3,763 stories692 vuln stories
Patch Day month

July 2026 vulnerabilities

A defender-focused view of 2,795 vulnerabilities across 4,813 returned patch records from 3 vendors. Filter the complete month, or browse the static page trail without JavaScript.

4,813all patch recordsClear filters189criticalShow these records3Microsoft exploitation detectedShow these records4Microsoft in CISA KEVShow these records1,923tracked hereShow these records

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as “no.” “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

Page 25 of 25 · records 4,801–4,813 of 4,813

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-13956 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13956 Incorrect security UI in PageInfo
CVE-2026-14022 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14022 Insufficient validation of untrusted input in Network
CVE-2026-14076 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14076 Policy bypass in Network
CVE-2026-14132 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14132 Inappropriate implementation in WebXR
CVE-2026-13799 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13799 Use after free in QUIC
CVE-2026-13875 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13875 Insufficient validation of untrusted input in GPU
CVE-2026-13954 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-13954 Insufficient policy enforcement in XML
CVE-2026-14021 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14021 Insufficient validation of untrusted input in StorageAccessAPI
CVE-2026-14074 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14074 Side-channel information leakage in WebAuthentication
CVE-2026-14153 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14153 Inappropriate implementation in Glic
CVE-2026-14090 ↗2026-07-03Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-14090 Out of bounds read in CameraCapture
CVE-2026-54522 ↗2026-08-07azl3 rubygem-msgpack 1.7.2-1 on Azure Linux 3.0N/AOut-of-bandMessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
CVE-2026-54787 ↗2026-08-07azl3 gh 2.62.0-20 on Azure Linux 3.0N/AOut-of-bandsigstore-go fails to check signature timestamps against a signing key's validity period