Every CVE in this month's Microsoft Security Update document, ranked by composite priority. Search by CVE, product, or owner; filter by status or source; click a column to sort. 653 Microsoft-authored, 464 Edge/Chromium and 298 Linux/other that patch via their own vendor.
75 rated Critical (Microsoft) and 39 rated Critical (everything else). The status filter below spans the whole document, so its Critical count is the combined 114.
| CVE | Status | CVSS | Severity | Impact | Owner | Source | Title |
|---|---|---|---|---|---|---|---|
| CVE-2026-50522 | Exploited worm | 9.8 | Critical | Remote Code Execution | SharePoint owners | Microsoft | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2026-58644 | Exploited worm | 9.8 | Critical | Remote Code Execution | SharePoint owners | Microsoft | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2026-56164 | Exploited worm | 5.3 | Moderate | Elevation of Privilege | SharePoint owners | Microsoft | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2026-56155 | Exploited | 7.8 | Important | Elevation of Privilege | Identity / AD | Microsoft | Active Directory Federation Services Elevation of Privilege Vulnerability |
| CVE-2026-50661 | Zero-day | 6.1 | Important | Security Feature Bypass | Endpoints / Windows client | Microsoft | Windows BitLocker Security Feature Bypass Vulnerability |
| CVE-2026-50518 | Critical worm | 9.8 | Critical | Remote Code Execution | Network / infra servers | Microsoft | Windows DHCP Server Remote Code Execution Vulnerability |
| CVE-2026-55040 | Critical worm | 9.1 | Critical | Security Feature Bypass | SharePoint owners | Microsoft | Microsoft SharePoint Server Security Feature Bypass Vulnerability |
| CVE-2026-56159 | Critical worm | 9.8 | Critical | Remote Code Execution | Network / infra servers | Microsoft | DHCP Server Service Remote Code Execution Vulnerability |
| CVE-2026-55010 | Critical worm | 9.8 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Minecraft Bedrock Dedicated Server Remote Code Execution Vulnerability |
| CVE-2026-55944 | Critical worm | 9.8 | Critical | Remote Code Execution | Cloud / M365 apps | Microsoft | Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability |
| CVE-2026-56188 | Critical worm | 9.8 | Critical | Remote Code Execution | Network / infra servers | Microsoft | Windows Server Network driver Remote Code Execution Vulnerability |
| CVE-2026-54995 | Critical worm | 8.1 | Critical | Remote Code Execution | Endpoints / Windows client | Microsoft | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability |
| CVE-2026-50370 | Critical | 8.8 | Critical | Remote Code Execution | Network / infra servers | Microsoft | DHCP Server Service Remote Code Execution Vulnerability |
| CVE-2026-54128 | Critical | 8.4 | Critical | Remote Code Execution | Network / infra servers | Microsoft | Windows DHCP Client Remote Code Execution Vulnerability |
| CVE-2026-48564 | Critical | 8.8 | Critical | Remote Code Execution | Network / infra servers | Microsoft | DHCP Server Service Remote Code Execution Vulnerability |
| CVE-2026-55008 | Critical | 9.6 | Critical | Spoofing | Exchange / mail | Microsoft | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-57092 | Critical | 9.9 | Critical | Elevation of Privilege | Virtualization / Hyper-V | Microsoft | Microsoft Windows VMSwitch Elevation of Privilege Vulnerability |
| CVE-2026-49164 | Critical worm | 8.1 | Critical | Remote Code Execution | Identity / AD | Microsoft | Windows Active Directory Domain Services Remote Code Execution Vulnerability |
| CVE-2026-50694 | Critical worm | 8.1 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability |
| CVE-2026-56163 | Critical worm | 10.0 | Critical | Elevation of Privilege | Cloud / M365 apps | Microsoft | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability |
| CVE-2026-56191 | Critical worm | 10.0 | Critical | Tampering | Exchange / mail | Microsoft | Microsoft Exchange Online Tampering Vulnerability |
| CVE-2026-57106 | Critical worm | 10.0 | Critical | Elevation of Privilege | Other / general Windows | Microsoft | Data Quality Elevation of Privilege Vulnerability |
| CVE-2026-62825 | Critical worm | 10.0 | Critical | Elevation of Privilege | Cloud / M365 apps | Microsoft | Azure Key Vault Elevation of Privilege Vulnerability |
| CVE-2026-58630 | Critical worm | 10.0 | Critical | Elevation of Privilege | Cloud / M365 apps | Microsoft | Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability |
| CVE-2026-58275 | Critical worm | 10.0 | Critical | Elevation of Privilege | Network / infra servers | Microsoft | Azure DNS Elevation of Privilege Vulnerability |
| CVE-2026-56165 | Critical worm | 9.8 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Microsoft Account Remote Code Execution Vulnerability |
| CVE-2026-54992 | Critical | 8.4 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability |
| CVE-2026-62835 | Critical worm | 9.3 | Critical | Information Disclosure | Cloud / M365 apps | Microsoft | Azure Portal Information Disclosure Vulnerability |
| CVE-2026-45499 | Critical | 9.9 | Critical | Elevation of Privilege | Cloud / M365 apps | Microsoft | Azure OpenAI Elevation of Privilege Vulnerability |
| CVE-2026-57100 | Critical | 9.9 | Critical | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability |
| CVE-2026-54117 | Critical | 8.8 | Critical | Remote Code Execution | Database / SQL | Microsoft | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-54118 | Critical | 8.8 | Critical | Remote Code Execution | Database / SQL | Microsoft | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-58608 | Critical | 8.8 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Windows Print Spooler Remote Code Execution Vulnerability |
| CVE-2026-50444 | Critical | 8.8 | Critical | Elevation of Privilege | Other / general Windows | Microsoft | Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability |
| CVE-2026-54121 | Critical | 8.8 | Critical | Elevation of Privilege | Identity / AD | Microsoft | Active Directory Certificate Services Elevation of Privilege Vulnerability |
| CVE-2026-57090 | Critical | 8.8 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-57094 | Critical | 8.8 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-57087 | Critical | 8.8 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-50327 | Critical | 7.8 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Windows Media Remote Code Execution Vulnerability |
| CVE-2026-50655 | Critical | 7.8 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-41106 | Critical | 9.3 | Critical | Elevation of Privilege | Cloud / M365 apps | Microsoft | Microsoft 365 Copilot Elevation of Privilege Vulnerability |
| CVE-2026-42533 | Critical worm | 8.1 | Critical | — | Other / general Windows | Microsoft | NGINX Map directive and Regex matching vulnerability |
| CVE-2026-54998 | Critical | 8.8 | Critical | Elevation of Privilege | Exchange / mail | Microsoft | Microsoft Exchange Online Elevation of Privilege Vulnerability |
| CVE-2026-54120 | Critical | 9.9 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Microsoft Surface Remote Code Execution Vulnerability |
| CVE-2026-50517 | Critical | 9.9 | Critical | Remote Code Execution | Cloud / M365 apps | Microsoft | Microsoft M365 Copilot Remote Code Execution Vulnerability |
| CVE-2026-55045 | Critical | 8.4 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-54982 | Critical | 8.8 | Critical | Remote Code Execution | Endpoints / Windows client | Microsoft | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability |
| CVE-2026-54999 | Critical | 8.8 | Critical | Remote Code Execution | Network / infra servers | Microsoft | Windows TCP/IP Remote Code Execution Vulnerability |
| CVE-2026-50382 | Critical | 8.8 | Critical | Remote Code Execution | Other / general Windows | Microsoft | DirectX Graphics Kernel Remote Code Execution Vulnerability |
| CVE-2026-50314 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55018 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55022 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55033 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55127 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55129 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55132 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55056 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55140 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55123 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft PowerPoint Remote Code Execution Vulnerability |
| CVE-2026-50680 | Critical | 8.2 | Critical | Elevation of Privilege | Virtualization / Hyper-V | Microsoft | Windows Hyper-V Elevation of Privilege Vulnerability |
| CVE-2026-42982 | Critical | 7.8 | Critical | Elevation of Privilege | Other / general Windows | Microsoft | Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
| CVE-2026-55011 | Critical | 7.8 | Critical | Remote Code Execution | Cloud / M365 apps | Microsoft | Microsoft Defender Remote Code Execution Vulnerability |
| CVE-2026-55012 | Critical | 7.8 | Critical | Remote Code Execution | Cloud / M365 apps | Microsoft | Microsoft Defender Remote Code Execution Vulnerability |
| CVE-2026-49796 | Critical | 7.8 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Windows GDI+ Remote Code Execution Vulnerability |
| CVE-2026-50467 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55049 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55043 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft PowerPoint Remote Code Execution Vulnerability |
| CVE-2026-55120 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft PowerPoint Remote Code Execution Vulnerability |
| CVE-2026-56189 | Critical | 7.8 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-58542 | Critical | 7.8 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Windows Media Remote Code Execution Vulnerability |
| CVE-2026-56167 | Critical | 8.5 | Critical | Elevation of Privilege | Cloud / M365 apps | Microsoft | Azure AI Search Elevation of Privilege Vulnerability |
| CVE-2026-54127 | Critical | 7.4 | Critical | Elevation of Privilege | Virtualization / Hyper-V | Microsoft | Windows Hyper-V Elevation of Privilege Vulnerability |
| CVE-2026-35425 | Critical | 8.0 | Critical | Remote Code Execution | Cloud / M365 apps | Microsoft | Azure API Management (APIM) Remote Code Execution Vulnerability |
| CVE-2026-50392 | Critical | 7.0 | Critical | Elevation of Privilege | Other / general Windows | Microsoft | Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
| CVE-2026-49159 | Critical | 6.5 | Critical | Information Disclosure | Other / general Windows | Microsoft | Microsoft Graph Information Disclosure Vulnerability |
| CVE-2026-50380 | Critical | 9.6 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Windows GDI+ Remote Code Execution Vulnerability |
| CVE-2026-26145 | Critical | 4.8 | Critical | Elevation of Privilege | Cloud / M365 apps | Microsoft | Microsoft Azure Synapse Elevation of Privilege Vulnerability |
| CVE-2026-50474 | Critical | 8.8 | Critical | Remote Code Execution | Remote access / RDP | Microsoft | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-38968 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing. |
| CVE-2026-53386 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | iio: adc: ti-ads1298: add bounds check to pga_settings index |
| CVE-2026-53374 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | drm/amdgpu: zero-initialize GART table on allocation |
| CVE-2026-53376 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | drm/amdkfd: Add upper bound check for num_of_nodes |
| CVE-2026-63833 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | ntfs3: reject direct userspace writes to reserved $LX* xattrs |
| CVE-2026-63822 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | wifi: ath11k: fix warning when unbinding |
| CVE-2026-63828 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | apparmor: mediate the implicit connect of TCP fast open sendmsg |
| CVE-2026-63882 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | drm/amdkfd: fix NULL pointer bug in svm_range_set_attr |
| CVE-2026-64017 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | blk-mq: pop cached request if it is usable |
| CVE-2026-57433 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record |
| CVE-2026-15043 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text |
| CVE-2026-63816 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode |
| CVE-2026-53403 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var |
| CVE-2026-63818 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | f2fs: validate orphan inode entry count |
| CVE-2026-53387 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | iio: light: veml6075: add bounds check to veml6075_it_ms index |
| CVE-2026-53384 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails |
| CVE-2026-63824 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | KEYS: fix overflow in keyctl_pkey_params_get_2() |
| CVE-2026-63800 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | pNFS: Fix use-after-free in pnfs_update_layout() |
| CVE-2026-63797 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | rpmsg: char: Fix use-after-free on probe error path |
| CVE-2026-63814 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | f2fs: validate ACL entry sizes in f2fs_acl_from_disk() |
| CVE-2026-63827 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | apparmor: fix use-after-free in rawdata dedup loop |
| CVE-2026-64079 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | netfilter: x_tables: allocate hook ops while under mutex |
| CVE-2026-64138 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | ksmbd: validate SID in parent security descriptor during ACL inheritance |
| CVE-2026-63959 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT |
| CVE-2026-64070 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | powerpc/hv-gpci: fix preempt count leak in sysfs show paths |
| CVE-2026-63958 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | usb: typec: ucsi: validate connector number in ucsi_connector_change() |
| CVE-2026-64078 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | netfilter: x_tables: add and use xtables_unregister_table_exit |
| CVE-2026-63983 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | net/sched: fix packet loop on netem when duplicate is on |
| CVE-2026-63881 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger |
| CVE-2026-64111 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | lsm: hold cred_guard_mutex for lsm_set_self_attr() |
| CVE-2026-64076 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | netfilter: bridge: eb_tables: close module init race |
| CVE-2026-63979 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | net/handshake: hand off the pinned file reference to accept_doit |
| CVE-2026-63999 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | ethtool: rss: fix indir_table and hkey leak on get_rxfh failure |
| CVE-2026-63974 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close |
| CVE-2026-9547 | Critical worm | 9.1 | Critical | — | Other / general Windows | Linux / other | SSH improper host validation |
| CVE-2026-8926 | Critical worm | 9.1 | Critical | — | Office / productivity | Linux / other | password leak with netrc and user in URL |
| CVE-2026-60082 | Critical worm | 9.1 | Critical | — | Other / general Windows | Linux / other | DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row |
| CVE-2026-59873 | Critical worm | 7.5 | Critical | — | Other / general Windows | Linux / other | node-tar: Decompression/parse DoS via unlimited input |
| CVE-2026-48561 | Critical | — | Critical | Remote Code Execution | Cloud / M365 apps | Microsoft | Microsoft Edge Copilot Remote Code Execution Vulnerability |
| CVE-2026-56160 | Critical | — | Critical | Elevation of Privilege | Cloud / M365 apps | Microsoft | Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability |
| CVE-2026-56000 | Critical | — | Critical | — | Other / general Windows | Linux / other | xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent() |
| CVE-2026-49172 | Normal worm | 9.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows FTP Service Remote Code Execution Vulnerability |
| CVE-2026-50447 | Normal worm | 9.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability |
| CVE-2026-56190 | Normal worm | 9.8 | Important | Remote Code Execution | Remote access / RDP | Microsoft | Remote Desktop Protocol Remote Code Execution Vulnerability |
| CVE-2026-58289 | Normal worm | 9.0 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-49181 | Normal worm | 7.5 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DHCP Client Elevation of Privilege Vulnerability |
| CVE-2026-50429 | Normal worm | 8.2 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-50528 | Normal worm | 8.2 | Important | Security Feature Bypass | Other / general Windows | Microsoft | .NET Security Feature Bypass Vulnerability |
| CVE-2026-42900 | Normal worm | 8.1 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft Windows App Store Elevation of Privilege Vulnerability |
| CVE-2026-47304 | Normal worm | 8.1 | Important | Security Feature Bypass | Other / general Windows | Microsoft | .NET Security Feature Bypass Vulnerability |
| CVE-2026-50460 | Normal worm | 8.1 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50439 | Normal worm | 8.1 | Important | Remote Code Execution | Other / general Windows | Microsoft | Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability |
| CVE-2026-50487 | Normal worm | 8.1 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DNS Client Elevation of Privilege Vulnerability |
| CVE-2026-50686 | Normal worm | 8.1 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows OLE Remote Code Execution Vulnerability |
| CVE-2026-49798 | Normal | 9.3 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-57983 | Normal worm | 8.7 | Important | Security Feature Bypass | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2026-58596 | Normal | 8.3 | Important | Elevation of Privilege | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2026-58531 | Normal | 7.5 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows SMB Elevation of Privilege Vulnerability |
| CVE-2026-49795 | Normal | 8.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50489 | Normal | 8.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Win32k Elevation of Privilege Vulnerability |
| CVE-2026-58295 | Normal worm | 8.3 | Important | Security Feature Bypass | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2026-47302 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Microsoft | .NET Denial of Service Vulnerability |
| CVE-2026-50506 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Microsoft | OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability |
| CVE-2026-54983 | Normal worm | 7.5 | Important | Denial of Service | Identity / AD | Microsoft | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-50695 | Normal worm | 7.5 | Important | Denial of Service | Identity / AD | Microsoft | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-50696 | Normal worm | 7.5 | Important | Denial of Service | Exchange / mail | Microsoft | Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability |
| CVE-2026-54119 | Normal worm | 7.5 | Important | Denial of Service | Identity / AD | Microsoft | Windows Active Directory Denial of Service Vulnerability |
| CVE-2026-50524 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Microsoft | .NET Framework Denial of Service Vulnerability |
| CVE-2026-56170 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Microsoft | ASP.NET Core Denial of Service Vulnerability |
| CVE-2026-50652 | Normal worm | 7.5 | Important | Denial of Service | Identity / AD | Microsoft | Azure Active Directory Denial of Service Vulnerability |
| CVE-2026-50653 | Normal worm | 7.5 | Important | Denial of Service | Identity / AD | Microsoft | Azure Active Directory Denial of Service Vulnerability |
| CVE-2026-40378 | Normal worm | 7.5 | Important | Denial of Service | Identity / AD | Microsoft | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability |
| CVE-2026-45646 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Microsoft | OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability |
| CVE-2026-49787 | Normal worm | 7.5 | Important | Denial of Service | Network / infra servers | Microsoft | HTTP.sys Denial of Service Vulnerability |
| CVE-2026-49788 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Microsoft | HTTP/2 Denial of Service Vulnerability |
| CVE-2026-50304 | Normal worm | 7.5 | Important | Denial of Service | Identity / AD | Microsoft | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-50328 | Normal worm | 7.5 | Important | Tampering | Other / general Windows | Microsoft | Windows Server Update Service (WSUS) Tampering Vulnerability |
| CVE-2026-50368 | Normal worm | 7.5 | Important | Denial of Service | Identity / AD | Microsoft | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-50330 | Normal worm | 7.5 | Important | Elevation of Privilege | Remote access / RDP | Microsoft | Windows Remote Desktop Client Elevation of Privilege Vulnerability |
| CVE-2026-50355 | Normal worm | 7.5 | Important | Denial of Service | Identity / AD | Microsoft | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-50463 | Normal worm | 7.5 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-50411 | Normal worm | 7.5 | Important | Denial of Service | Identity / AD | Microsoft | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-50424 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Microsoft | Windows Domain Controller Denial of Service Vulnerability |
| CVE-2026-50470 | Normal worm | 7.5 | Important | Information Disclosure | Network / infra servers | Microsoft | Windows Network Policy Server SNMP Information Disclosure Vulnerability |
| CVE-2026-50496 | Normal worm | 7.5 | Important | Information Disclosure | Network / infra servers | Microsoft | Windows Network Policy Server SNMP Information Disclosure Vulnerability |
| CVE-2026-50525 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Microsoft | .NET Denial of Service Vulnerability |
| CVE-2026-50527 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Microsoft | .NET Framework Denial of Service Vulnerability |
| CVE-2026-50647 | Normal worm | 7.5 | Important | Denial of Service | Identity / AD | Microsoft | Active Directory Federation Server Denial of Service Vulnerability |
| CVE-2026-50648 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Microsoft | .NET Framework Denial of Service Vulnerability |
| CVE-2026-50651 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Microsoft | .NET Denial of Service Vulnerability |
| CVE-2026-57108 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Microsoft | .NET Denial of Service Vulnerability |
| CVE-2026-58627 | Normal worm | 7.5 | Important | Denial of Service | Network / infra servers | Microsoft | Windows DHCP Server Denial of Service Vulnerability |
| CVE-2026-58282 | Normal worm | 8.1 | Important | Spoofing | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-58283 | Normal worm | 8.1 | Important | Spoofing | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-58286 | Normal worm | 8.1 | Important | Spoofing | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-58293 | Normal worm | 8.1 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-50452 | Normal worm | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50348 | Normal worm | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-47300 | Normal | 8.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | ASP.NET Core Elevation of Privilege Vulnerability |
| CVE-2026-47303 | Normal | 8.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | ASP.NET Core Elevation of Privilege Vulnerability |
| CVE-2026-50663 | Normal | 8.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability |
| CVE-2026-55005 | Normal | 8.8 | Important | Remote Code Execution | Exchange / mail | Microsoft | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2026-57969 | Normal | 8.8 | Important | Elevation of Privilege | Cloud / M365 apps | Microsoft | Azure CycleCloud Elevation of Privilege Vulnerability |
| CVE-2026-49178 | Normal | 8.8 | Important | Remote Code Execution | Identity / AD | Microsoft | Windows Active Directory Domain Services Remote Code Execution Vulnerability |
| CVE-2026-50360 | Normal | 8.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows SMB Server Elevation of Privilege Vulnerability |
| CVE-2026-50398 | Normal | 8.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-50369 | Normal | 8.8 | Important | Elevation of Privilege | Remote access / RDP | Microsoft | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2026-47295 | Normal | 8.8 | Important | Elevation of Privilege | Database / SQL | Microsoft | Microsoft SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-50666 | Normal | 8.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Remote Access Elevation of Privilege Vulnerability |
| CVE-2026-55052 | Normal | 8.8 | Important | Elevation of Privilege | SharePoint owners | Microsoft | Microsoft SharePoint Elevation of Privilege Vulnerability |
| CVE-2026-41109 | Normal | 8.8 | Important | Security Feature Bypass | Cloud / M365 apps | Microsoft | GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-56196 | Normal | 8.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows Admin Center (WAC) Remote Code Execution Vulnerability |
| CVE-2026-56197 | Normal | 8.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows Admin Center (WAC) Remote Code Execution Vulnerability |
| CVE-2026-56642 | Normal | 8.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Microsoft Fabric Data Warehouse Remote Code Execution Vulnerability |
| CVE-2026-56194 | Normal | 8.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows NFS Server Elevation of Privilege Vulnerability |
| CVE-2026-56647 | Normal | 8.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerability |
| CVE-2026-57102 | Normal | 8.8 | Important | Security Feature Bypass | Other / general Windows | Microsoft | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-58277 | Normal | 8.8 | Important | Elevation of Privilege | SharePoint owners | Microsoft | Microsoft SharePoint Elevation of Privilege Vulnerability |
| CVE-2026-58594 | Normal | 8.8 | Important | Remote Code Execution | Remote access / RDP | Microsoft | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-58626 | Normal | 8.8 | Important | Remote Code Execution | Remote access / RDP | Microsoft | Windows Remote Desktop Services Remote Code Execution Vulnerability |
| CVE-2026-49170 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows StateRepository API Server file Elevation of Privilege Vulnerability |
| CVE-2026-54986 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-54114 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-58631 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows Admin Center (WAC) Remote Code Execution Vulnerability |
| CVE-2026-50351 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability |
| CVE-2026-50332 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50329 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-50343 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft Install Service Elevation of Privilege Vulnerability |
| CVE-2026-50433 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-50423 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50387 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows GDI Elevation of Privilege Vulnerability |
| CVE-2026-50436 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50454 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows User Interface Core Elevation of Privilege Vulnerability |
| CVE-2026-50476 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows Network Connections Service Elevation of Privilege Vulnerability |
| CVE-2026-50509 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability |
| CVE-2026-50667 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2026-50688 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-57091 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows File History Service Elevation of Privilege Vulnerability |
| CVE-2026-58536 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-58633 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-58298 | Normal worm | 7.2 | Important | Spoofing | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-50340 | Normal | 8.5 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50338 | Normal | 8.2 | Important | Elevation of Privilege | Cloud / M365 apps | Microsoft | Azure Spring Apps Elevation of Privilege Vulnerability |
| CVE-2026-60005 | Normal worm | 8.2 | Important | — | Other / general Windows | Microsoft | NGINX ngx_http_slice_module vulnerability |
| CVE-2026-50324 | Normal worm | 5.9 | Important | Denial of Service | Identity / AD | Microsoft | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-56649 | Normal worm | 5.9 | Important | Remote Code Execution | Network / infra servers | Microsoft | Windows Network File System Remote Code Execution Vulnerability |
| CVE-2026-56169 | Normal | 8.1 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Admin Center Elevation of Privilege Vulnerability |
| CVE-2026-58595 | Normal | 8.1 | Important | Spoofing | Other / general Windows | Microsoft | Microsoft Bing App for IOS Spoofing Vulnerability |
| CVE-2026-56186 | Normal | 8.1 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Secure Channel Information Disclosure Vulnerability |
| CVE-2026-58617 | Normal | 8.1 | Important | Elevation of Privilege | Cloud / M365 apps | Microsoft | M365 Copilot for iOS Elevation of Privilege Vulnerability |
| CVE-2026-57981 | Normal | 8.8 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-56645 | Normal | 8.8 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-57974 | Normal | 8.8 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-49169 | Normal | 8.0 | Important | Remote Code Execution | Network / infra servers | Microsoft | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-58647 | Normal | 8.0 | Important | Spoofing | Other / general Windows | Microsoft | Microsoft PowerBI Report Server Spoofing Vulnerability |
| CVE-2026-40400 | Normal | 8.0 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows PowerShell Remote Code Execution Vulnerability |
| CVE-2026-50502 | Normal | 8.0 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows Event Logging Service Remote Code Execution Vulnerability |
| CVE-2026-49805 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Win32k Elevation of Privilege Vulnerability |
| CVE-2026-50297 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Win32k Elevation of Privilege Vulnerability |
| CVE-2026-50325 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Win32k Elevation of Privilege Vulnerability |
| CVE-2026-50390 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-58281 | Normal | 8.3 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-58284 | Normal | 8.3 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-58285 | Normal | 8.3 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-58287 | Normal | 8.3 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-58288 | Normal | 8.3 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-44806 | Normal worm | 5.3 | Important | Denial of Service | Other / general Windows | Microsoft | Windows Secure Channel Denial of Service Vulnerability |
| CVE-2026-50415 | Normal worm | 5.3 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Media Information Disclosure Vulnerability |
| CVE-2026-50414 | Normal | 7.5 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-50379 | Normal | 7.5 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-50500 | Normal | 7.5 | Important | Elevation of Privilege | Identity / AD | Microsoft | Windows Netlogon Elevation of Privilege Vulnerability |
| CVE-2026-50505 | Normal | 7.5 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability |
| CVE-2026-50685 | Normal | 7.5 | Important | Remote Code Execution | Network / infra servers | Microsoft | Windows DHCP Server Remote Code Execution Vulnerability |
| CVE-2026-56648 | Normal | 7.5 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows NFS Server Elevation of Privilege Vulnerability |
| CVE-2026-57089 | Normal | 7.5 | Important | Remote Code Execution | Network / infra servers | Microsoft | Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability |
| CVE-2026-20214 | Normal worm | 7.5 | Important | — | Other / general Windows | Microsoft | ClamAV FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability |
| CVE-2026-20215 | Normal worm | 7.5 | Important | — | Other / general Windows | Microsoft | ClamAV 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability |
| CVE-2026-20216 | Normal worm | 7.5 | Important | — | Other / general Windows | Microsoft | ClamAV InstallShield File Format Processing Resource Exhaustion Vulnerability |
| CVE-2026-20217 | Normal worm | 7.5 | Important | — | Other / general Windows | Microsoft | ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability |
| CVE-2026-20244 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Microsoft | ClamAV DMG File Processing Denial of Service Vulnerability |
| CVE-2026-20213 | Normal worm | 7.5 | Important | — | Other / general Windows | Microsoft | ClamAV PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability |
| CVE-2026-20243 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Microsoft | ClamAV ALZ Archive Processing Denial of Service Vulnerability |
| CVE-2026-58525 | Normal | 8.2 | Important | Security Feature Bypass | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2026-54107 | Normal | 8.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-47632 | Normal | 8.8 | Important | Elevation of Privilege | Cloud / M365 apps | Microsoft | Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability |
| CVE-2026-50342 | Normal | 8.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows MIDI Service Module Elevation of Privileges Vulnerability |
| CVE-2026-50385 | Normal | 8.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50413 | Normal | 8.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50438 | Normal | 8.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft PC Manager Elevation of Privilege Vulnerability |
| CVE-2026-50477 | Normal | 8.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50670 | Normal | 8.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-50687 | Normal | 8.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-50692 | Normal | 8.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-58534 | Normal | 8.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Input Method Editor (IME) Elevation of Privilege Vulnerability |
| CVE-2026-55021 | Normal | 7.3 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-55034 | Normal | 7.3 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-55126 | Normal | 7.3 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-50375 | Normal | 6.3 | Important | Elevation of Privilege | Other / general Windows | Microsoft | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50682 | Normal | 7.1 | Important | Denial of Service | Identity / AD | Microsoft | Active Directory Denial of Service Vulnerability |
| CVE-2026-58529 | Normal | 7.1 | Important | Information Disclosure | Identity / AD | Microsoft | Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability |
| CVE-2026-58638 | Normal | 6.0 | Important | Security Feature Bypass | Other / general Windows | Microsoft | Windows Boot Loader Security Feature Bypass Vulnerability |
| CVE-2026-54122 | Normal | 8.4 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows GDI+ Remote Code Execution Vulnerability |
| CVE-2026-50520 | Normal | 8.4 | Important | Remote Code Execution | Other / general Windows | Microsoft | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-49184 | Normal | 8.4 | Important | Remote Code Execution | Endpoints / Windows client | Microsoft | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-57985 | Normal | 7.6 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-56181 | Normal | 8.3 | Moderate | Spoofing | Network / infra servers | Microsoft | Windows Network Address Translation (NAT) Spoofing Vulnerability |
| CVE-2026-57984 | Normal | 7.5 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-57986 | Normal | 7.5 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-57992 | Normal | 7.5 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-58276 | Normal | 7.5 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-57975 | Normal | 7.5 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-58290 | Normal | 7.5 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-58292 | Normal | 7.5 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-58294 | Normal | 7.5 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-58299 | Normal | 7.5 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge for Android Remote Code Execution Vulnerability |
| CVE-2026-57991 | Normal | 7.4 | Important | Information Disclosure | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2026-57993 | Normal | 7.4 | Important | Spoofing | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-42990 | Normal worm | 9.8 | Important | Remote Code Execution | Database / SQL | Microsoft | SQL Server ODBC driver Elevation of Privilege Vulnerability |
| CVE-2026-54990 | Normal worm | 9.8 | Important | Remote Code Execution | Remote access / RDP | Microsoft | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-47301 | Normal | 8.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Configuration Manager Elevation of Privilege Vulnerability |
| CVE-2026-50365 | Normal | 8.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability |
| CVE-2026-50683 | Normal | 8.0 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DHCP Client Elevation of Privilege Vulnerability |
| CVE-2026-47282 | Normal | 6.5 | Important | Information Disclosure | Cloud / M365 apps | Microsoft | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability |
| CVE-2026-55003 | Normal | 6.5 | Important | Information Disclosure | Remote access / RDP | Microsoft | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-54108 | Normal | 6.5 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-56185 | Normal | 6.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Admin Center Information Disclosure Vulnerability |
| CVE-2026-57976 | Normal | 6.5 | Important | Denial of Service | Identity / AD | Microsoft | Windows Active Directory Domain Services Denial of Service Vulnerability |
| CVE-2026-57979 | Normal | 6.5 | Important | Information Disclosure | Remote access / RDP | Microsoft | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-58279 | Normal | 6.5 | Important | Elevation of Privilege | Cloud / M365 apps | Microsoft | Azure CycleCloud Elevation of Privilege Vulnerability |
| CVE-2026-34348 | Normal | 6.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Event Logging Service Information Disclosure Vulnerability |
| CVE-2026-49799 | Normal | 6.5 | Important | Denial of Service | Identity / AD | Microsoft | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability |
| CVE-2026-50366 | Normal | 6.5 | Important | Denial of Service | Identity / AD | Microsoft | Windows Active Directory Domain Services Denial of Service Vulnerability |
| CVE-2026-50376 | Normal | 6.5 | Important | Information Disclosure | Remote access / RDP | Microsoft | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-50445 | Normal | 6.5 | Important | Information Disclosure | Remote access / RDP | Microsoft | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-50497 | Normal | 6.5 | Important | Information Disclosure | Remote access / RDP | Microsoft | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-50504 | Normal | 6.5 | Important | Information Disclosure | Remote access / RDP | Microsoft | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-50659 | Normal | 6.5 | Important | Spoofing | Other / general Windows | Microsoft | .NET Spoofing Vulnerability |
| CVE-2026-54126 | Normal | 6.5 | Important | Information Disclosure | Remote access / RDP | Microsoft | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-55054 | Normal | 6.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-55051 | Normal | 6.5 | Important | Information Disclosure | SharePoint owners | Microsoft | Microsoft SharePoint Server Information Disclosure Vulnerability |
| CVE-2026-50468 | Normal | 6.5 | Important | Information Disclosure | Database / SQL | Microsoft | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-54116 | Normal | 6.5 | Important | Information Disclosure | Database / SQL | Microsoft | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-56168 | Normal | 6.5 | Important | Denial of Service | Network / infra servers | Microsoft | Windows SMB Server Denial of Service Vulnerability |
| CVE-2026-57982 | Normal | 6.5 | Important | Information Disclosure | Remote access / RDP | Microsoft | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-58533 | Normal | 6.5 | Important | Information Disclosure | Remote access / RDP | Microsoft | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-58535 | Normal | 6.5 | Important | Information Disclosure | Remote access / RDP | Microsoft | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-58546 | Normal | 6.5 | Important | Information Disclosure | Remote access / RDP | Microsoft | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-58539 | Normal | 6.5 | Important | Information Disclosure | Remote access / RDP | Microsoft | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-56434 | Normal worm | 6.5 | Important | — | Other / general Windows | Microsoft | NGINX ngx_http_ssi_module vulnerability |
| CVE-2026-50475 | Normal | 5.5 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-57988 | Normal | 7.1 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-57977 | Normal | 7.1 | Important | Spoofing | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-58296 | Normal | 7.1 | Important | Information Disclosure | Browser (Edge auto-update) | Microsoft | Microsoft Edge for Android Information Disclosure Vulnerability |
| CVE-2026-58297 | Normal | 7.1 | Important | Information Disclosure | Browser (Edge auto-update) | Microsoft | Microsoft Edge for Android Information Disclosure Vulnerability |
| CVE-2026-47296 | Normal | 7.8 | Important | Elevation of Privilege | Database / SQL | Microsoft | Microsoft SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-49166 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Print Configuration Elevation of Privilege Vulnerability |
| CVE-2026-49176 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows WalletService Elevation of Privilege Vulnerability |
| CVE-2026-49175 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DNS Client Elevation of Privilege Vulnerability |
| CVE-2026-49173 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-54987 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Overlay Filter Elevation of Privilege Vulnerability |
| CVE-2026-50697 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2026-54991 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows USB Print Driver Elevation of Privilege Vulnerability |
| CVE-2026-54993 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-55001 | Normal | 7.8 | Important | Elevation of Privilege | Identity / AD | Microsoft | Active Directory Domain Services Elevation of Privilege Vulnerability |
| CVE-2026-54112 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-55004 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Print Configuration Elevation of Privilege Vulnerability |
| CVE-2026-54109 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2026-55006 | Normal | 7.8 | Important | Elevation of Privilege | Exchange / mail | Microsoft | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-55009 | Normal | 7.8 | Important | Elevation of Privilege | Exchange / mail | Microsoft | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-55002 | Normal | 7.8 | Important | Elevation of Privilege | Database / SQL | Microsoft | Microsoft SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-50675 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55899 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55948 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-57107 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Admin Center Elevation of Privilege Vulnerability |
| CVE-2026-55014 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Remote Help Defense Elevation of Privilege Vulnerability |
| CVE-2026-58602 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
| CVE-2026-58609 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-58610 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-58618 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-58635 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Narrator Braille Elevation of Privilege Vulnerability |
| CVE-2026-58636 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft PC Manager Elevation of Privilege Vulnerability |
| CVE-2026-44800 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-48581 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Surface Broker SDMA Elevation of Privilege Vulnerability |
| CVE-2026-49783 | Normal | 7.8 | Important | Security Feature Bypass | Other / general Windows | Microsoft | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-49792 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2026-49793 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2026-49797 | Normal | 7.8 | Important | Remote Code Execution | Endpoints / Windows client | Microsoft | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-49800 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability |
| CVE-2026-50308 | Normal | 7.8 | Important | Remote Code Execution | Endpoints / Windows client | Microsoft | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50311 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Server Elevation of Privilege Vulnerability |
| CVE-2026-50333 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Spaceport.sys Elevation of Privilege Vulnerability |
| CVE-2026-50318 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
| CVE-2026-49808 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50293 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Internal Task Bar Elevation of Privilege Vulnerability |
| CVE-2026-50305 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft Brokering File System Elevation of Privilege Vulnerability |
| CVE-2026-50363 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-50306 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows TCP/IP Elevation of Privilege Vulnerability |
| CVE-2026-50412 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-50337 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Notification Elevation of Privilege Vulnerability |
| CVE-2026-50386 | Normal | 7.8 | Important | Remote Code Execution | Endpoints / Windows client | Microsoft | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50400 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows App Package Installer Elevation of Privilege Vulnerability |
| CVE-2026-50309 | Normal | 7.8 | Important | Remote Code Execution | Endpoints / Windows client | Microsoft | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50326 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Unified Consent System Elevation of Privilege Vulnerability |
| CVE-2026-50313 | Normal | 7.8 | Important | Remote Code Execution | Endpoints / Windows client | Microsoft | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50440 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Audio Service Elevation of Privilege Vulnerability |
| CVE-2026-50407 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
| CVE-2026-50331 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Application Model Core API Elevation of Privilege Vulnerability |
| CVE-2026-50347 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows Data.dll Remote Code Execution Vulnerability |
| CVE-2026-50321 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows USB Driver Elevation of Privilege Vulnerability |
| CVE-2026-50425 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Internal System User Profile Elevation of Privilege Vulnerability |
| CVE-2026-50315 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Image Acquisition Elevation of Privilege Vulnerability |
| CVE-2026-50357 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
| CVE-2026-50335 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Operating Systems Elevation of Privilege Vulnerability |
| CVE-2026-50361 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft Brokering File System Elevation of Privilege Vulnerability |
| CVE-2026-50317 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Operating Systems Elevation of Privilege Vulnerability |
| CVE-2026-50373 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Search Service Elevation of Privilege Vulnerability |
| CVE-2026-50353 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50388 | Normal | 7.8 | Important | Remote Code Execution | Endpoints / Windows client | Microsoft | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50336 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-50391 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Group Policy Elevation of Privilege Vulnerability |
| CVE-2026-50378 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Key Guard Elevation of Privilege Vulnerability |
| CVE-2026-50346 | Normal | 7.8 | Important | Elevation of Privilege | Identity / AD | Microsoft | Netlogon RPC Elevation of Privilege Vulnerability |
| CVE-2026-50405 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Filtering Platform Elevation of Privilege Vulnerability |
| CVE-2026-50448 | Normal | 7.8 | Important | Remote Code Execution | Endpoints / Windows client | Microsoft | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50344 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows OLE Elevation of Privilege Vulnerability |
| CVE-2026-50471 | Normal | 7.8 | Important | Remote Code Execution | Endpoints / Windows client | Microsoft | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50469 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Projected File System Elevation of Privilege Vulnerability |
| CVE-2026-50427 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Content Delivery Manager Elevation of Privilege Vulnerability |
| CVE-2026-50422 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-50421 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Connected User Experiences and Telemetry Elevation of Privilege Vulnerability |
| CVE-2026-50367 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Sensor Data Service Elevation of Privilege Vulnerability |
| CVE-2026-50466 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft Brokering File System Elevation of Privilege Vulnerability |
| CVE-2026-50402 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | NTFS Elevation of Privilege Vulnerability |
| CVE-2026-50435 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Overlay Filter Elevation of Privilege Vulnerability |
| CVE-2026-50441 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
| CVE-2026-50462 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-50457 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50399 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50461 | Normal | 7.8 | Important | Remote Code Execution | Endpoints / Windows client | Microsoft | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50417 | Normal | 7.8 | Important | Remote Code Execution | Endpoints / Windows client | Microsoft | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50362 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2026-50458 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft Brokering File System Elevation of Privilege Vulnerability |
| CVE-2026-50450 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows Network Connections Service Elevation of Privilege Vulnerability |
| CVE-2026-50478 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50479 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows USB Hub Driver Elevation of Privilege Vulnerability |
| CVE-2026-50480 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability |
| CVE-2026-50484 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50493 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50486 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50488 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Clipboard User Service Elevation of Privilege Vulnerability |
| CVE-2026-50499 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2026-50494 | Normal | 7.8 | Important | Remote Code Execution | Endpoints / Windows client | Microsoft | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50498 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
| CVE-2026-50501 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2026-50510 | Normal | 7.8 | Important | Remote Code Execution | Cloud / M365 apps | Microsoft | GitHub Copilot Remote Code Execution Vulnerability |
| CVE-2026-50646 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | .NET Framework Remote Code Execution Vulnerability |
| CVE-2026-50649 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | .NET Remote Code Execution Vulnerability |
| CVE-2026-50650 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | .NET Framework Elevation of Privilege Vulnerability |
| CVE-2026-50673 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50676 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-50677 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-54115 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability |
| CVE-2026-50679 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Search Service Elevation of Privilege Vulnerability |
| CVE-2026-50689 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Clipboard Server Elevation of Privilege Vulnerability |
| CVE-2026-54125 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-47290 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-47642 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-50301 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55017 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55024 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55025 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55125 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55031 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55048 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55029 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55039 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55032 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55041 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55136 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55141 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55036 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55044 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55055 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55037 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55058 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55038 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55137 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55053 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55131 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55134 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55128 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55130 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55133 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft OneNote Remote Code Execution Vulnerability |
| CVE-2026-54131 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55947 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55949 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-56156 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-56176 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-56175 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-56182 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-50665 | Normal | 7.8 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-56643 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-56644 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-54124 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows Terminal Remote Code Execution Vulnerability |
| CVE-2026-56650 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows Network File System Elevation of Privilege Vulnerability |
| CVE-2026-57088 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Extensible Storage Engine (ESENT) Elevation of Privilege Vulnerability |
| CVE-2026-57096 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability |
| CVE-2026-57968 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability |
| CVE-2026-58527 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-58530 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2026-58538 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Bluetooth Service Elevation of Privilege Vulnerability |
| CVE-2026-58540 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-58532 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-58537 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege Vulnerability |
| CVE-2026-58541 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-47305 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Visual Studio Remote Code Execution Vulnerability |
| CVE-2026-58613 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-58628 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows Wireless Network Manager Elevation of Privilege Vulnerability |
| CVE-2026-58632 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
| CVE-2026-58634 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-55145 | Normal | 6.3 | Moderate | Tampering | Office / productivity | Microsoft | Outlook Copilot Tampering Vulnerability |
| CVE-2026-49171 | Normal | 7.5 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Speech Runtime Elevation of Privilege Vulnerability |
| CVE-2026-58640 | Normal | 7.3 | Important | Remote Code Execution | Endpoints / Windows client | Microsoft | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-49789 | Normal | 7.3 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-49790 | Normal | 7.3 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
| CVE-2026-50364 | Normal | 7.3 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Backup Service Elevation of Privilege Vulnerability |
| CVE-2026-50482 | Normal | 7.3 | Important | Remote Code Execution | Endpoints / Windows client | Microsoft | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-45489 | Normal | 6.5 | Moderate | Spoofing | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-57987 | Normal | 6.5 | Important | Spoofing | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-56646 | Normal | 6.5 | Important | Spoofing | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-58523 | Normal | 6.5 | Important | Security Feature Bypass | Browser (Edge auto-update) | Microsoft | Microsoft Edge for Android Security Feature Bypass Vulnerability |
| CVE-2026-49165 | Normal | 7.1 | Important | Information Disclosure | Other / general Windows | Microsoft | Microsoft Windows App Store Information Disclosure Vulnerability |
| CVE-2026-55144 | Normal | 7.1 | Important | Tampering | Other / general Windows | Microsoft | Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability |
| CVE-2026-56193 | Normal | 7.1 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-49791 | Normal | 7.1 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability |
| CVE-2026-50354 | Normal | 7.1 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50428 | Normal | 7.1 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability |
| CVE-2026-50451 | Normal | 7.1 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability |
| CVE-2026-50465 | Normal | 7.1 | Important | Tampering | Network / infra servers | Microsoft | Windows DNS Client Tampering Vulnerability |
| CVE-2026-55122 | Normal | 7.1 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-57101 | Normal | 7.1 | Important | Security Feature Bypass | Other / general Windows | Microsoft | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-48572 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows App Package Installer Elevation of Privilege Vulnerability |
| CVE-2026-48571 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows App Package Installer Elevation of Privilege Vulnerability |
| CVE-2026-49162 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft Brokering File System Elevation of Privilege Vulnerability |
| CVE-2026-49784 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft Windows App Store Elevation of Privilege Vulnerability |
| CVE-2026-54129 | Normal | 7.0 | Important | Elevation of Privilege | Virtualization / Hyper-V | Microsoft | Windows Hyper-V Elevation of Privilege Vulnerability |
| CVE-2026-54989 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability |
| CVE-2026-54111 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Universal Print Management Service Elevation of Privilege Vulnerability |
| CVE-2026-54996 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows USB Print Driver Elevation of Privilege Vulnerability |
| CVE-2026-58526 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Storage Elevation of Privilege Vulnerability |
| CVE-2026-49183 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Clipboard Server Elevation of Privilege Vulnerability |
| CVE-2026-49802 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows USB Print Driver Elevation of Privilege Vulnerability |
| CVE-2026-49806 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows USB Print Driver Elevation of Privilege Vulnerability |
| CVE-2026-49803 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows AppX Deployment Extensions Elevation of Privilege Vulnerability |
| CVE-2026-50323 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50296 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50356 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft Windows App Store Elevation of Privilege Vulnerability |
| CVE-2026-50384 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Clip Service Elevation of Privilege Vulnerability |
| CVE-2026-50372 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability |
| CVE-2026-50393 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
| CVE-2026-50307 | Normal | 7.0 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows TCP/IP Elevation of Privilege Vulnerability |
| CVE-2026-50396 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
| CVE-2026-50345 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50322 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50404 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-50358 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-50410 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50449 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50371 | Normal | 7.0 | Important | Elevation of Privilege | Virtualization / Hyper-V | Microsoft | Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-50403 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50397 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50406 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Backup Engine Elevation of Privilege Vulnerability |
| CVE-2026-50459 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50490 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-50491 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability |
| CVE-2026-50503 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50526 | Normal | 7.0 | Important | Tampering | Other / general Windows | Microsoft | .NET Tampering Vulnerability |
| CVE-2026-50658 | Normal | 7.0 | Important | Elevation of Privilege | Cloud / M365 apps | Microsoft | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability |
| CVE-2026-50669 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Telephony Server Elevation of Privilege Vulnerability |
| CVE-2026-50672 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-50674 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows USB Print Driver Elevation of Privilege Vulnerability |
| CVE-2026-50359 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft XML Core Services Elevation of Privilege Vulnerability |
| CVE-2026-56173 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows WebView Elevation of Privilege Vulnerability |
| CVE-2026-56183 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows MIDI Service Module Elevation of Privileges Vulnerability |
| CVE-2026-56187 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows MIDI Service Module Elevation of Privileges Vulnerability |
| CVE-2026-57093 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-58544 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Management Services Elevation of Privilege Vulnerability |
| CVE-2026-58619 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Sensor Data Service Elevation of Privilege Vulnerability |
| CVE-2026-58629 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-58637 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Client-Side Caching Elevation of Privilege Vulnerability |
| CVE-2026-56157 | Normal | 5.4 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-58291 | Normal | 6.1 | Important | Information Disclosure | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2026-49168 | Normal | 6.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Storage Spaces Direct Elevation of Privilege Vulnerability |
| CVE-2026-54132 | Normal | 6.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50299 | Normal | 6.8 | Important | Remote Code Execution | Endpoints / Windows client | Microsoft | Windows Storage Spaces Direct Remote Code Execution Vulnerability |
| CVE-2026-50298 | Normal | 6.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Spaceport.sys Elevation of Privilege Vulnerability |
| CVE-2026-50426 | Normal | 6.8 | Important | Remote Code Execution | Network / infra servers | Microsoft | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-50492 | Normal | 6.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2026-50668 | Normal | 6.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
| CVE-2026-58528 | Normal | 6.8 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Windows USB Audio Class Driver Information Disclosure Vulnerability |
| CVE-2026-50432 | Normal | 5.3 | Important | Denial of Service | Other / general Windows | Microsoft | Window Virtual Filtering Platform (VFP) Denial of Service Vulnerability |
| CVE-2026-59117 | Normal | 7.5 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows Terminal Remote Code Execution Vulnerability |
| CVE-2026-57990 | Normal | 7.4 | Important | Information Disclosure | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2026-57989 | Normal | 7.4 | Important | Information Disclosure | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2026-50678 | Normal | 6.6 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-49804 | Normal | 6.6 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows USB Video Driver Elevation of Privilege Vulnerability |
| CVE-2026-55000 | Normal | 6.4 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows USB Print Driver Elevation of Privilege Vulnerability |
| CVE-2026-57097 | Normal | 6.4 | Important | Security Feature Bypass | Other / general Windows | Microsoft | Microsoft XML Security Feature Bypass Vulnerability |
| CVE-2026-56171 | Normal | 7.1 | Important | Information Disclosure | Remote access / RDP | Microsoft | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-50374 | Normal | 6.3 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-57973 | Normal | 6.3 | Important | Tampering | Other / general Windows | Microsoft | Windows Subsystem for Linux (WSL2) Kernel Tampering Vulnerability |
| CVE-2026-58543 | Normal | 6.3 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Universal Print Management Service Elevation of Privilege Vulnerability |
| CVE-2026-50684 | Normal | 4.8 | Important | Spoofing | Identity / AD | Microsoft | Active Directory Federation Server Spoofing Vulnerability |
| CVE-2026-50294 | Normal | 6.2 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-49807 | Normal | 6.2 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows DirectX Information Disclosure Vulnerability |
| CVE-2026-50420 | Normal | 6.2 | Important | Information Disclosure | Network / infra servers | Microsoft | HTTP.sys Information Disclosure Vulnerability |
| CVE-2026-55026 | Normal | 6.2 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-57095 | Normal | 6.2 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Win32k Elevation of Privilege Vulnerability |
| CVE-2026-45488 | Normal | 5.4 | Moderate | Spoofing | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-58278 | Normal | 5.4 | Important | Spoofing | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-58524 | Normal | 5.4 | Important | Spoofing | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-49174 | Normal | 6.1 | Important | Tampering | Network / infra servers | Microsoft | DNS Client Tampering Vulnerability |
| CVE-2026-54988 | Normal | 6.1 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-50383 | Normal | 6.1 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Print Spooler Information Disclosure Vulnerability |
| CVE-2026-50453 | Normal | 6.1 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Windows USB Audio Class Driver Information Disclosure Vulnerability |
| CVE-2026-50495 | Normal | 6.1 | Important | Tampering | Network / infra servers | Microsoft | DNS Client Tampering Vulnerability |
| CVE-2026-55898 | Normal | 6.1 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-55016 | Normal | 4.6 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-55019 | Normal | 4.6 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-55020 | Normal | 4.6 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-55030 | Normal | 4.6 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-55135 | Normal | 4.6 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-58522 | Normal | 6.8 | Important | Information Disclosure | Browser (Edge auto-update) | Microsoft | Microsoft Edge for Android Information Disclosure Vulnerability |
| CVE-2026-50302 | Normal | 4.2 | Important | Security Feature Bypass | Other / general Windows | Microsoft | Windows Cryptographic Services Security Feature Bypass Vulnerability |
| CVE-2026-34349 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Media Information Disclosure Vulnerability |
| CVE-2026-34346 | Normal | 5.5 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability |
| CVE-2026-49177 | Normal | 5.5 | Important | Information Disclosure | Network / infra servers | Microsoft | Windows TCP/IP Information Disclosure Vulnerability |
| CVE-2026-45496 | Normal | 5.5 | Important | Security Feature Bypass | Other / general Windows | Microsoft | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-54997 | Normal | 5.5 | Important | Information Disclosure | Network / infra servers | Microsoft | Windows SMB Information Disclosure Vulnerability |
| CVE-2026-58614 | Normal | 5.5 | Important | Security Feature Bypass | Endpoints / Windows client | Microsoft | Windows Kernel Security Feature Bypass Vulnerability |
| CVE-2026-33842 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-34328 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Audio Service Information Disclosure Vulnerability |
| CVE-2026-40422 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-41087 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-49180 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability |
| CVE-2026-49801 | Normal | 5.5 | Important | Information Disclosure | Network / infra servers | Microsoft | Windows SMB Information Disclosure Vulnerability |
| CVE-2026-50316 | Normal | 5.5 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-50295 | Normal | 5.5 | Important | Security Feature Bypass | Network / infra servers | Microsoft | Windows Zero Trust DNS Security Feature Bypass Vulnerability |
| CVE-2026-50350 | Normal | 5.5 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability |
| CVE-2026-50381 | Normal | 5.5 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Composite Image File System driver (cimfs.sys) Information Disclosure Vulnerability |
| CVE-2026-50300 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-50303 | Normal | 5.5 | Important | Security Feature Bypass | Other / general Windows | Microsoft | Windows Key Guard Security Feature Bypass Vulnerability |
| CVE-2026-50341 | Normal | 5.5 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-50434 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-50339 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-50430 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-50377 | Normal | 5.5 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50401 | Normal | 5.5 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability |
| CVE-2026-50334 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-50352 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Cryptographic Services Information Disclosure Vulnerability |
| CVE-2026-50437 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-50455 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability |
| CVE-2026-50409 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Overlay Filter Information Disclosure Vulnerability |
| CVE-2026-50473 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-50442 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-50389 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-50456 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-50431 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability |
| CVE-2026-50394 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Media Information Disclosure Vulnerability |
| CVE-2026-50483 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Graphics Component Information Disclosure Vulnerability |
| CVE-2026-50681 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Secure Channel Information Disclosure Vulnerability |
| CVE-2026-50690 | Normal | 5.5 | Important | Information Disclosure | Network / infra servers | Microsoft | Windows SMB Information Disclosure Vulnerability |
| CVE-2026-48580 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-50408 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-55046 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-55023 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-55027 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-55028 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-55047 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-55050 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-55138 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-55124 | Normal | 5.5 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-55035 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-55057 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-55142 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-55042 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-55139 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-56184 | Normal | 5.5 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Win32k Information Disclosure Vulnerability |
| CVE-2026-56192 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-56195 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-56178 | Normal | 5.5 | Important | Elevation of Privilege | Cloud / M365 apps | Microsoft | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability |
| CVE-2026-57083 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Media Photo Codec Information Disclosure Vulnerability |
| CVE-2026-57084 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-57085 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Print Spooler Information Disclosure Vulnerability |
| CVE-2026-58547 | Normal | 5.5 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability |
| CVE-2026-58545 | Normal | 5.5 | Important | Security Feature Bypass | Endpoints / Windows client | Microsoft | Windows Kernel Security Feature Bypass Vulnerability |
| CVE-2026-55121 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-58300 | Normal | 6.2 | Important | Information Disclosure | Browser (Edge auto-update) | Microsoft | Microsoft Edge for Android Information Disclosure Vulnerability |
| CVE-2026-50418 | Normal | 5.1 | Important | Security Feature Bypass | Other / general Windows | Microsoft | Windows System Secure Feature Bypass Vulnerability |
| CVE-2026-58597 | Normal | 4.3 | Low | Spoofing | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-58598 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Backup Service Elevation of Privilege Vulnerability |
| CVE-2026-49167 | Normal | 4.7 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50310 | Normal | 4.7 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Human Interface Device Information Disclosure Vulnerability |
| CVE-2026-50312 | Normal | 4.7 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-50657 | Normal | 4.7 | Important | Information Disclosure | Cloud / M365 apps | Microsoft | Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability |
| CVE-2026-57980 | Normal | 5.4 | Important | Tampering | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Tampering Vulnerability |
| CVE-2026-57978 | Normal | 5.4 | Important | Spoofing | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-49794 | Normal | 4.6 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Windows USB Audio Class Driver Information Disclosure Vulnerability |
| CVE-2026-50485 | Normal | 4.5 | Important | Denial of Service | Virtualization / Hyper-V | Microsoft | Windows Hyper-V Denial of Service Vulnerability |
| CVE-2026-62826 | Normal | 4.6 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-55945 | Normal | 4.2 | Moderate | Information Disclosure | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2026-50419 | Normal | 3.3 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-50416 | Normal | 3.3 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Win32k Information Disclosure Vulnerability |
| CVE-2026-8924 | Normal worm | 9.1 | Important | — | Other / general Windows | Linux / other | trailing dot domain super cookie |
| CVE-2026-14740 | Normal worm | 9.1 | Important | — | Other / general Windows | Linux / other | DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment |
| CVE-2026-14739 | Normal worm | 8.6 | Important | — | Other / general Windows | Linux / other | DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders |
| CVE-2026-50721 | Normal worm | 8.1 | Important | Denial of Service | Other / general Windows | Linux / other | IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload |
| CVE-2026-50722 | Normal worm | 8.1 | Important | Denial of Service | Other / general Windows | Linux / other | IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload |
| CVE-2026-60002 | Normal worm | 7.7 | Important | — | Exchange / mail | Linux / other | ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.) |
| CVE-2026-9545 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | exposing HTTP/3 early data |
| CVE-2026-12413 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Linux / other | IKEv2 Denial of Service via malformed fragmentation |
| CVE-2026-8932 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | incomplete mTLS config matching in conn reuse |
| CVE-2026-38969 | Normal worm | 7.5 | Moderate | — | Other / general Windows | Linux / other | ruby webrick through v1.9.2 WEBrick reparses trailer Content-Length into canonical request state, enabling request smuggling. |
| CVE-2026-59925 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs |
| CVE-2026-57432 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack |
| CVE-2026-57219 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations |
| CVE-2026-48863 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Linux / other | Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service |
| CVE-2026-60081 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | DBI::ProfileData versions before 1.651 for Perl do not limit the path index |
| CVE-2026-59884 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Linux / other | pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs |
| CVE-2026-59886 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | pyasn1: Uncontrolled resource consumption when converting decoded REAL values |
| CVE-2026-62309 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | CoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — single 28-byte packet remote DoS |
| CVE-2026-38754 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Linux / other | A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. |
| CVE-2026-53375 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | drm/amdgpu/vce: Prevent partial address patches |
| CVE-2026-63836 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd |
| CVE-2026-55973 | Normal worm | 7.5 | Moderate | — | Network / infra servers | Linux / other | 'dns-error-reporting: yes' leads to stack buffer overflow |
| CVE-2026-40691 | Normal worm | 7.5 | Moderate | — | Other / general Windows | Linux / other | Packet of death for DNSCrypt over TCP |
| CVE-2026-32665 | Normal worm | 7.5 | Moderate | Denial of Service | Network / infra servers | Linux / other | Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass |
| CVE-2026-12064 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | proto-default skips SSH verification |
| CVE-2026-59928 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions |
| CVE-2026-59922 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert) |
| CVE-2026-59869 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | js-yaml: YAML merge-key chains can force quadratic CPU consumption |
| CVE-2026-58250 | Normal worm | 7.5 | Moderate | — | Other / general Windows | Linux / other | NATS Server: Pre-auth server crash via double INFO in leafnode handshake |
| CVE-2026-15308 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations |
| CVE-2026-59874 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | node-tar: Negative tar entry size causes infinite loop in archive replace |
| CVE-2026-57220 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS |
| CVE-2026-15711 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Linux / other | Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol violation |
| CVE-2026-15709 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Linux / other | Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of service |
| CVE-2026-59885 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Linux / other | pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service |
| CVE-2026-38755 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Linux / other | A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. |
| CVE-2026-62389 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | ws < 8.21.1 Default maxFragments Allows Memory Exhaustion DoS |
| CVE-2026-63793 | Normal worm | 7.5 | Important | — | Endpoints / Windows client | Linux / other | ntfs: serialize volume label accesses |
| CVE-2026-53400 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | i2c: core: fix adapter registration race |
| CVE-2026-63872 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | esp: fix page frag reference leak on skb_to_sgvec failure |
| CVE-2026-44690 | Normal worm | 7.5 | Moderate | — | Other / general Windows | Linux / other | Cross-zone wildcard cache poisoning via RRSIG.labels manipulation |
| CVE-2026-58208 | Normal worm | 6.8 | Moderate | — | Other / general Windows | Linux / other | NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled |
| CVE-2026-57216 | Normal worm | 6.8 | Moderate | — | Other / general Windows | Linux / other | RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks |
| CVE-2026-14380 | Normal | 8.8 | Important | — | Other / general Windows | Linux / other | DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile |
| CVE-2026-42975 | Normal | 8.0 | Important | Remote Code Execution | Endpoints / Windows client | Linux / other | Windows Bluetooth Port Driver Remote Code Execution |
| CVE-2026-60001 | Normal worm | 6.5 | Moderate | — | Other / general Windows | Linux / other | sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. |
| CVE-2026-15714 | Normal worm | 6.5 | Moderate | — | Other / general Windows | Linux / other | Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary string |
| CVE-2026-50248 | Normal worm | 6.5 | Moderate | — | Other / general Windows | Linux / other | BOGUS configured primary hostname accepted for XFR in auth/rpz zones |
| CVE-2026-57211 | Normal worm | 6.5 | Moderate | — | Other / general Windows | Linux / other | RabbitMQ: UNC SSRF affecting the management UI on Windows |
| CVE-2026-58601 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Linux / other | Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability |
| CVE-2026-56002 | Normal | 8.5 | Important | — | Other / general Windows | Linux / other | libXfont2 PCF Font Parsing Heap Buffer Overflow |
| CVE-2026-53366 | Normal | 8.5 | Important | — | Other / general Windows | Linux / other | ipv4: account for fraggap on the paged allocation path |
| CVE-2026-56001 | Normal | 8.5 | Important | — | Other / general Windows | Linux / other | libXfont2 BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow |
| CVE-2026-56003 | Normal | 8.5 | Important | — | Other / general Windows | Linux / other | libXfont2 computeProps Property Buffer Heap Buffer Overflow |
| CVE-2026-55999 | Normal | 8.5 | Important | — | Other / general Windows | Linux / other | xorg-server / xwayland glamor font atlas Heap Buffer Overflow |
| CVE-2026-8925 | Normal worm | 5.9 | Moderate | — | Other / general Windows | Linux / other | SASL double-free |
| CVE-2026-59999 | Normal worm | 5.9 | Moderate | — | Other / general Windows | Linux / other | In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not. |
| CVE-2026-15713 | Normal worm | 5.9 | Moderate | Denial of Service | Other / general Windows | Linux / other | Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via memory leak |
| CVE-2026-15712 | Normal worm | 5.9 | Moderate | — | Other / general Windows | Linux / other | Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over-read via invalid nul-termination assumption |
| CVE-2026-44621 | Normal worm | 5.9 | Moderate | — | Other / general Windows | Linux / other | Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated |
| CVE-2026-55717 | Normal worm | 5.9 | Moderate | — | Other / general Windows | Linux / other | 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash |
| CVE-2026-50046 | Normal worm | 5.9 | Moderate | — | Other / general Windows | Linux / other | Possible heap use-after-free in an error path when a DoT forwarded query is jostled out |
| CVE-2026-55990 | Normal worm | 5.9 | Moderate | — | Other / general Windows | Linux / other | Packet of death for a DNSCrypt misconfigured Unbound |
| CVE-2026-55991 | Normal worm | 5.9 | Moderate | — | Network / infra servers | Linux / other | Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2 |
| CVE-2026-52863 | Normal worm | 5.9 | Moderate | Denial of Service | Other / general Windows | Linux / other | Memory corruption could lead to crash and denial of service |
| CVE-2026-56444 | Normal worm | 5.9 | Moderate | — | Other / general Windows | Linux / other | Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration |
| CVE-2026-14586 | Normal worm | 5.9 | Moderate | — | Network / infra servers | Linux / other | Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments |
| CVE-2026-8286 | Normal | 8.1 | Important | — | Other / general Windows | Linux / other | wrong STARTTLS connection reuse |
| CVE-2026-53381 | Normal | 8.1 | Important | — | Other / general Windows | Linux / other | virtiofs: fix UAF on submount umount |
| CVE-2026-14355 | Normal worm | 5.6 | Moderate | — | Other / general Windows | Linux / other | ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD |
| CVE-2026-58207 | Normal | 7.7 | Important | — | Other / general Windows | Linux / other | NATS Server: Remote crash via integer overflow in Connz pagination |
| CVE-2026-11856 | Normal worm | 5.3 | Moderate | — | Other / general Windows | Linux / other | cross-origin Digest auth state leak |
| CVE-2026-42505 | Normal worm | 5.3 | Moderate | — | Other / general Windows | Linux / other | Invoking Encrypted Client Hello privacy leak in crypto/tls |
| CVE-2026-62299 | Normal worm | 5.3 | Moderate | — | Other / general Windows | Linux / other | CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record |
| CVE-2026-50251 | Normal worm | 5.3 | Moderate | — | Other / general Windows | Linux / other | Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush |
| CVE-2026-44508 | Normal worm | 5.3 | Moderate | — | Other / general Windows | Linux / other | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate. |
| CVE-2026-8927 | Normal worm | 5.3 | Moderate | — | Other / general Windows | Linux / other | env-set cross-proxy Digest auth state leak |
| CVE-2026-59871 | Normal worm | 5.3 | Moderate | — | Other / general Windows | Linux / other | node-tar: Process crash via PAX numeric path type confusion |
| CVE-2026-59875 | Normal worm | 5.3 | Moderate | — | Other / general Windows | Linux / other | node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records |
| CVE-2026-50045 | Normal worm | 5.3 | Moderate | — | Other / general Windows | Linux / other | 'max-global-quota' reset by DNSSEC validation restarts |
| CVE-2026-58253 | Normal | 8.8 | Important | — | Other / general Windows | Linux / other | NATS Server: Route API Auth Bypass |
| CVE-2026-63807 | Normal | 8.8 | Important | — | Other / general Windows | Linux / other | KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level |
| CVE-2026-59998 | Normal worm | 4.8 | Moderate | — | Identity / AD | Linux / other | sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory. |
| CVE-2026-26081 | Normal worm | 4.8 | Moderate | — | Other / general Windows | Linux / other | HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected. |
| CVE-2026-56416 | Normal worm | 4.8 | Moderate | — | Other / general Windows | Linux / other | Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name |
| CVE-2026-63803 | Normal | 8.4 | Important | — | Other / general Windows | Linux / other | hdlc_ppp: sync per-proto timers before freeing hdlc state |
| CVE-2026-63823 | Normal | 8.4 | Important | — | Other / general Windows | Linux / other | keys: Pin request_key_auth payload in instantiate paths |
| CVE-2026-63829 | Normal | 8.2 | Important | — | Other / general Windows | Linux / other | net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink |
| CVE-2026-8458 | Normal | 6.5 | Moderate | — | Other / general Windows | Linux / other | wrong reuse for different services |
| CVE-2026-58251 | Normal | 6.5 | Moderate | — | Other / general Windows | Linux / other | NATS Server: Queue Subscribe Authz Bypass |
| CVE-2026-58252 | Normal | 6.5 | Moderate | — | Other / general Windows | Linux / other | NATS Server: Subscribe Authz Bypass via Wildcard-Overlap |
| CVE-2026-47729 | Normal | 6.5 | Moderate | — | Other / general Windows | Linux / other | Squid: Memory disclosure in FTP gateway |
| CVE-2026-56145 | Normal | 6.5 | Moderate | Denial of Service | Other / general Windows | Linux / other | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-63140 | Normal | 6.5 | Moderate | Denial of Service | Other / general Windows | Linux / other | Reachable Assertion in Elasticsearch Leading to Denial of Service |
| CVE-2026-63136 | Normal | 6.5 | Moderate | Denial of Service | Other / general Windows | Linux / other | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-16277 | Normal | 6.5 | Moderate | — | Other / general Windows | Linux / other | Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist() |
| CVE-2026-49090 | Normal | 6.5 | Moderate | Denial of Service | Other / general Windows | Linux / other | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-59818 | Normal | 6.5 | Moderate | — | Other / general Windows | Linux / other | etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation |
| CVE-2026-57217 | Normal | 6.5 | Important | — | Network / infra servers | Linux / other | RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass |
| CVE-2026-54171 | Normal | 6.5 | Moderate | — | Other / general Windows | Linux / other | Excon: redact additional sensitive/risky headers when following redirects |
| CVE-2026-63263 | Normal | 6.5 | Moderate | Denial of Service | Other / general Windows | Linux / other | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-59856 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | Vim: Arbitrary Code Execution via PHP Omni-Completion |
| CVE-2026-39822 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | Root escape via symlink plus trailing slash in os |
| CVE-2026-3842 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write |
| CVE-2026-64192 | Normal | 7.8 | Important | — | Endpoints / Windows client | Linux / other | bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized |
| CVE-2026-14191 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader |
| CVE-2026-63853 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring |
| CVE-2026-63858 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | netfilter: nf_tables: add hook transactions for device deletions |
| CVE-2026-63832 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | wifi: mt76: add wcid publish check in mt76_sta_add |
| CVE-2026-53388 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | fuse: re-lock request before replacing page cache folio |
| CVE-2026-63794 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path |
| CVE-2026-63804 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | gfs2: fix use-after-free in gfs2_qd_dealloc |
| CVE-2026-63831 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | mac802154: llsec: add skb_cow_data() before in-place crypto |
| CVE-2026-63802 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | blk-cgroup: fix UAF in __blkcg_rstat_flush() |
| CVE-2026-64191 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | i2c: stub: Reject I2C block transfers with invalid length |
| CVE-2026-64600 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | xfs: resample the data fork mapping after cycling ILOCK |
| CVE-2026-63940 | Normal | 7.7 | Important | — | Other / general Windows | Linux / other | KVM: SEV: Ignore Port I/O requests of length '0' |
| CVE-2026-15392 | Normal | 7.7 | Important | — | Other / general Windows | Linux / other | DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location |
| CVE-2026-59926 | Normal | 6.1 | Moderate | — | Other / general Windows | Linux / other | Mistune: XSS via unescaped class option in Admonition directive |
| CVE-2026-58643 | Normal | — | Important | Spoofing | Other / general Windows | Microsoft | Windows Admin Center Spoofing Vulnerability |
| CVE-2026-9080 | Normal worm | 3.7 | Low | — | Other / general Windows | Linux / other | UAF after pause in socket callback |
| CVE-2026-60000 | Normal worm | 3.7 | Low | Denial of Service | Other / general Windows | Linux / other | sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication. |
| CVE-2026-44687 | Normal worm | 3.7 | Low | — | Other / general Windows | Linux / other | Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN |
| CVE-2026-46582 | Normal worm | 3.7 | Low | — | Other / general Windows | Linux / other | A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path |
| CVE-2026-42955 | Normal worm | 3.7 | Low | — | Other / general Windows | Linux / other | Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records |
| CVE-2026-26080 | Normal worm | 3.7 | Low | — | Other / general Windows | Linux / other | HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected. |
| CVE-2026-62994 | Normal worm | 3.7 | Low | — | Other / general Windows | Linux / other | CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin |
| CVE-2026-54478 | Normal worm | 3.7 | Low | — | Network / infra servers | Linux / other | DNS Cookie bypass when combined with proxy-protocol use |
| CVE-2026-41637 | Normal worm | 3.7 | Low | — | Network / infra servers | Linux / other | Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries |
| CVE-2026-64112 | Normal | 7.4 | Important | — | Other / general Windows | Linux / other | rbd: eliminate a race in lock_dwork draining on unmap |
| CVE-2026-53393 | Normal | 5.9 | Moderate | — | Other / general Windows | Linux / other | nfsd: reset write verifier on deferred writeback errors |
| CVE-2026-53362 | Normal | 7.3 | Important | — | Other / general Windows | Linux / other | ipv6: account for fraggap on the paged allocation path |
| CVE-2026-63806 | Normal | 7.3 | Important | — | Other / general Windows | Linux / other | KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() |
| CVE-2026-12080 | Normal | 7.3 | Moderate | — | Other / general Windows | Linux / other | Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys |
| CVE-2026-53343 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow |
| CVE-2026-53329 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | drm/amd/display: Use krealloc_array() in dal_vector_reserve() |
| CVE-2026-63810 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | block: Avoid mounting the bdev pseudo-filesystem in userspace |
| CVE-2026-63826 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | fbdev: fix use-after-free in store_modes() |
| CVE-2026-63796 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | ocfs2: reject oversized group bitmap descriptors |
| CVE-2026-63801 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done |
| CVE-2026-63808 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | exfat: fix potential use-after-free in exfat_find_dir_entry() |
| CVE-2026-64133 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | ALSA: asihpi: Fix potential OOB array access at reading cache |
| CVE-2026-63879 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | drm/amdgpu: fix amdgpu_hmm_range_get_pages |
| CVE-2026-64146 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | erofs: fix metabuf leak in inode xattr initialization |
| CVE-2026-64189 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | netfilter: ipset: fix race between dump and ip_set_list resize |
| CVE-2026-53354 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | arm64: errata: Mitigate TLBI errata on various Arm CPUs |
| CVE-2026-53356 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | drm/i915/gem: Fix phys BO pread/pwrite with offset |
| CVE-2026-63805 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | crypto: nx - fix nx_crypto_ctx_exit argument |
| CVE-2026-53402 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() |
| CVE-2026-53368 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage |
| CVE-2026-63817 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | f2fs: validate compress cache inode only when enabled |
| CVE-2026-53390 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | ksmbd: fix out-of-bounds read in smb_check_perm_dacl() |
| CVE-2026-53383 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | ksmbd: reject non-VALID session in compound request branch |
| CVE-2026-64015 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | security/keys: fix missed RCU read section on lookup |
| CVE-2026-64117 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb |
| CVE-2026-63961 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | usb: typec: altmodes/displayport: validate count before reading Status Update VDO |
| CVE-2026-63963 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers |
| CVE-2026-64154 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | drm/msm/adreno: Fix a reference leak in a6xx_gpu_init() |
| CVE-2026-63978 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | net/handshake: Drain pending requests at net namespace exit |
| CVE-2026-39879 | Normal | 7.1 | Important | — | Endpoints / Windows client | Linux / other | SQL injection in syslog-ng SQL destionation driver |
| CVE-2026-53359 | Normal | 7.0 | Important | — | Other / general Windows | Linux / other | KVM: x86: Fix shadow paging use-after-free due to unexpected role |
| CVE-2026-53401 | Normal | 7.0 | Important | — | Other / general Windows | Linux / other | fbdev: omap2: fix use-after-free in omapfb_mmap |
| CVE-2026-50012 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | Squid: Memory corruption in cache_digest reply handling |
| CVE-2026-53397 | Normal | 6.7 | Moderate | — | Other / general Windows | Linux / other | nfsd: fix posix_acl leak on SETACL decode failure |
| CVE-2026-14258 | Normal | 6.5 | Moderate | — | Network / infra servers | Linux / other | Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling |
| CVE-2026-53345 | Normal | 6.5 | Moderate | — | Other / general Windows | Linux / other | KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying |
| CVE-2026-44510 | Normal | 6.4 | Moderate | — | Other / general Windows | Linux / other | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate. |
| CVE-2026-56149 | Normal | 4.9 | Moderate | Denial of Service | Other / general Windows | Linux / other | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service |
| CVE-2026-63871 | Normal | 6.3 | Moderate | — | Other / general Windows | Linux / other | Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls |
| CVE-2026-57213 | Normal | 4.8 | Moderate | — | Identity / AD | Linux / other | RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering |
| CVE-2026-59890 | Normal | 6.1 | Moderate | — | Other / general Windows | Linux / other | setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+ |
| CVE-2026-64001 | Normal | 6.1 | Moderate | — | Other / general Windows | Linux / other | ALSA: pcm: oss: Fix setup list UAF on proc write error |
| CVE-2026-53357 | Normal | 5.9 | Moderate | — | Other / general Windows | Linux / other | Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() |
| CVE-2026-59831 | Normal | 4.4 | Moderate | Remote Code Execution | Other / general Windows | Linux / other | GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace |
| CVE-2026-64160 | Normal | 5.8 | Moderate | — | Other / general Windows | Linux / other | netfs: Fix potential for tearing in ->remote_i_size and ->zero_point |
| CVE-2026-14647 | Normal | 4.3 | Low | — | Other / general Windows | Linux / other | onnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-bounds |
| CVE-2026-59930 | Normal | 4.3 | Moderate | — | Other / general Windows | Linux / other | Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content |
| CVE-2026-58209 | Normal | 4.3 | Moderate | — | Other / general Windows | Linux / other | NATS Server: MQTT retained and QoS replay bypass subscribe deny filters |
| CVE-2026-63308 | Normal | 4.3 | Moderate | Denial of Service | Other / general Windows | Linux / other | Helm Files.Lines Denial of Service via Empty Chart Files |
| CVE-2026-59997 | Normal | 4.2 | Moderate | — | Other / general Windows | Linux / other | internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection. |
| CVE-2026-59996 | Normal | 4.2 | Moderate | — | Other / general Windows | Linux / other | scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations. |
| CVE-2026-59995 | Normal | 4.2 | Moderate | — | Other / general Windows | Linux / other | sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server. |
| CVE-2026-53355 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | net: rds: clear i_sends on setup unwind |
| CVE-2026-53347 | Normal | 5.5 | Moderate | — | Endpoints / Windows client | Linux / other | drm/virtio: Fix driver removal with disabled KMS |
| CVE-2026-53352 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() |
| CVE-2026-53349 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | netfilter: nf_conntrack: destroy stale expectfn expectations on unregister |
| CVE-2026-10536 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | HTTP/2 stream-dependency tree UAF |
| CVE-2026-12480 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/keras |
| CVE-2026-53392 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | NFSv4/flexfiles: reject zero filehandle version count |
| CVE-2026-63809 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | bpf: use kvfree() for replaced sysctl write buffer |
| CVE-2026-63834 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | batman-adv: tp_meter: restrict number of unacked list entries |
| CVE-2026-53391 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr |
| CVE-2026-63812 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node() |
| CVE-2026-53382 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si |
| CVE-2026-63795 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | 9p: avoid putting oldfid in p9_client_walk() error path |
| CVE-2026-64097 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/amd/display: Validate GPIO pin LUT table size before iterating |
| CVE-2026-64077 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | netfilter: ebtables: move to two-stage removal scheme |
| CVE-2026-64188 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() |
| CVE-2026-53332 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd |
| CVE-2026-53336 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | nvmem: layouts: onie-tlv: fix hang on unknown types |
| CVE-2026-53327 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | debugobjects: Do not fill_pool() if pi_blocked_on |
| CVE-2026-53337 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | net: bonding: fix NULL pointer dereference in bond_do_ioctl() |
| CVE-2026-53353 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | hsr: Remove WARN_ONCE() in hsr_addr_is_self(). |
| CVE-2026-53339 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() |
| CVE-2026-63825 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | gcov: use atomic counter updates to fix concurrent access crashes |
| CVE-2026-63811 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | f2fs: read COW data with the original inode during atomic write |
| CVE-2026-53377 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/msm: always recover the gpu |
| CVE-2026-53399 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | nfsd: release layout stid on setlease failure |
| CVE-2026-63821 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | wifi: rtw88: usb: fix memory leaks on USB write failures |
| CVE-2026-63798 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove |
| CVE-2026-53385 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write |
| CVE-2026-53398 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | NFSD: Fix SECINFO_NO_NAME decode error cleanup |
| CVE-2026-64038 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | hwmon: (lm90) Stop work before releasing hwmon device |
| CVE-2026-64036 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | cgroup/rstat: validate cpu before css_rstat_cpu() access |
| CVE-2026-63962 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() |
| CVE-2026-63954 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | hpfs: fix a crash if hpfs_map_dnode_bitmap fails |
| CVE-2026-63964 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | usb: typec: ucsi: ccg: reject firmware images without a ':' record header |
| CVE-2026-63960 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() |
| CVE-2026-64060 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | netfs: Fix leak of request in netfs_write_begin() error handling |
| CVE-2026-64187 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | xfs: fail recovery on a committed log item with no regions |
| CVE-2026-64205 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | i2c: i801: fix hardware state machine corruption in error path |
| CVE-2026-64190 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | net: team: fix NULL pointer dereference in team_xmit during mode change |
| CVE-2026-64206 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock |
| CVE-2026-15588 | Normal | 5.3 | Moderate | — | Other / general Windows | Linux / other | Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering |
| CVE-2026-64082 | Normal | 5.3 | Moderate | — | Other / general Windows | Linux / other | riscv: Fix register corruption from uninitialized cregs on error |
| CVE-2026-63815 | Normal | 5.0 | Moderate | — | Other / general Windows | Linux / other | f2fs: bound i_inline_xattr_size for non-inline-xattr inodes |
| CVE-2026-63819 | Normal | 5.0 | Moderate | — | Other / general Windows | Linux / other | f2fs: fix to do sanity check on f2fs_get_node_folio_ra() |
| CVE-2026-38753 | Normal | 4.9 | Moderate | Denial of Service | Other / general Windows | Linux / other | A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. |
| CVE-2026-53361 | Normal | 4.5 | Moderate | — | Other / general Windows | Linux / other | af_unix: Set gc_in_progress to true in unix_gc(). |
| CVE-2026-63835 | Normal | 4.4 | Moderate | — | Other / general Windows | Linux / other | batman-adv: v: prevent OGM aggregation on disabled hardif |
| CVE-2026-63830 | Normal | 4.4 | Moderate | — | Other / general Windows | Linux / other | net: skmsg: preserve sg.copy across SG transforms |
| CVE-2026-13221 | Normal | 4.0 | Moderate | — | Other / general Windows | Linux / other | Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk |
| CVE-2026-15028 | Normal | 3.9 | Low | — | Other / general Windows | Linux / other | Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header |
| CVE-2026-41579 | Normal | 3.3 | Low | — | Other / general Windows | Linux / other | runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations |
| CVE-2026-55708 | Normal | 3.1 | Low | — | Other / general Windows | Linux / other | Privacy/configuration issue when adding local data in views through 'unbound-control' |
| CVE-2026-38752 | Normal | 2.9 | Low | Denial of Service | Other / general Windows | Linux / other | A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. |
| CVE-2026-13862 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-13862 |
| CVE-2026-16419 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-16419 Out of bounds read and write in ANGLE |
| CVE-2026-16415 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-16415 Insufficient validation of untrusted input in Extensions |
| CVE-2026-16418 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-16418 Stack buffer overflow in V8 |
| CVE-2026-16417 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-16417 Uninitialized Use in Skia |
| CVE-2026-16413 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-16413 Out of bounds write in ANGLE |
| CVE-2026-16414 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-16414 Insufficient validation of untrusted input in Chromecast |
| CVE-2026-16416 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-16416 Integer overflow in Chromecast |
| CVE-2026-16424 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-16424 Use after free in GPU |
| CVE-2026-16421 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-16421 Inappropriate implementation in WebAudio |
| CVE-2026-16422 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-16422 Insufficient validation of untrusted input in Certificate |
| CVE-2026-16423 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-16423 Use after free in UI |
| CVE-2026-16804 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-16804 Use after free in Input |
| CVE-2026-16805 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-16805 Use after free in Blink |
| CVE-2026-16806 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-16806 Use after free in WebMCP |
| CVE-2026-13775 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13775 Use after free in GPU |
| CVE-2026-13776 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13776 Type Confusion in Dawn |
| CVE-2026-13779 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13779 Use after free in Chromoting |
| CVE-2026-13780 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13780 Insufficient validation of untrusted input in ANGLE |
| CVE-2026-13781 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13781 Insufficient validation of untrusted input in Skia |
| CVE-2026-13782 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13782 Use after free in Browser |
| CVE-2026-13783 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13783 Use after free in Views |
| CVE-2026-13784 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13784 Use after free in Views |
| CVE-2026-13786 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13786 Use after free in Ozone |
| CVE-2026-13787 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13787 Use after free in Chromoting |
| CVE-2026-13790 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13790 Side-channel information leakage in Scroll |
| CVE-2026-13793 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13793 Insufficient policy enforcement in SVG |
| CVE-2026-13794 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13794 Insufficient validation of untrusted input in WebAppInstalls |
| CVE-2026-13797 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13797 Insufficient validation of untrusted input in Chromecast |
| CVE-2026-13798 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13798 Heap buffer overflow in Chromecast |
| CVE-2026-13801 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13801 Integer overflow in Chromecast |
| CVE-2026-13802 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13802 Use after free in Views |
| CVE-2026-13803 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13803 Type Confusion in Chrome Tabs |
| CVE-2026-13804 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13804 Use after free in Chromecast |
| CVE-2026-13848 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13848 Use after free in Forms |
| CVE-2026-13849 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13849 Insufficient validation of untrusted input in Chromoting |
| CVE-2026-13853 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13853 Use after free in Journeys |
| CVE-2026-13855 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13855 Use after free in Ozone |
| CVE-2026-13857 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13857 Inappropriate implementation in Geometry |
| CVE-2026-13858 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13858 Out of bounds read in FFmpeg |
| CVE-2026-13859 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13859 Inappropriate implementation in ANGLE |
| CVE-2026-13854 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13854 Use after free in Ozone |
| CVE-2026-13860 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13860 Incorrect security UI in Autofill |
| CVE-2026-13864 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13864 Insufficient policy enforcement in WebHID |
| CVE-2026-13861 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13861 Use after free in Core |
| CVE-2026-13865 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13865 Insufficient validation of untrusted input in Enterprise |
| CVE-2026-13867 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13867 Inappropriate implementation in Geolocation |
| CVE-2026-13869 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13869 Use after free in Device |
| CVE-2026-13871 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13871 Insufficient data validation in GuestView |
| CVE-2026-13873 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13873 Out of bounds memory access in Layout |
| CVE-2026-13874 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13874 Inappropriate implementation in DataTransfer |
| CVE-2026-13876 | Normal | — | — | — | Network / infra servers | Edge / Chromium | Chromium: CVE-2026-13876 Inappropriate implementation in Network |
| CVE-2026-13877 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13877 Insufficient validation of untrusted input in ANGLE |
| CVE-2026-13875 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13875 Insufficient validation of untrusted input in GPU |
| CVE-2026-13879 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13879 Use after free in Bluetooth |
| CVE-2026-13882 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13882 Inappropriate implementation in USB |
| CVE-2026-13881 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13881 Insufficient data validation in WebAppInstalls |
| CVE-2026-13883 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13883 Type Confusion in ANGLE |
| CVE-2026-13886 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13886 Policy bypass in Isolated Web Apps |
| CVE-2026-13888 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13888 Use after free in Extensions |
| CVE-2026-13884 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13884 Heap buffer overflow in Chromecast |
| CVE-2026-13890 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13890 Out of bounds read in Chromecast |
| CVE-2026-13891 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13891 Insufficient validation of untrusted input in Extensions |
| CVE-2026-13893 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13893 Insufficient validation of untrusted input in WebUI |
| CVE-2026-13894 | Normal | — | — | — | Network / infra servers | Edge / Chromium | Chromium: CVE-2026-13894 Insufficient policy enforcement in Network |
| CVE-2026-13895 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13895 Inappropriate implementation in Autofill |
| CVE-2026-13896 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13896 Insufficient policy enforcement in Glic |
| CVE-2026-13897 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13897 Insufficient policy enforcement in Chromecast |
| CVE-2026-13898 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13898 Use after free in Cast Receiver |
| CVE-2026-13901 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13901 Insufficient validation of untrusted input in Serial |
| CVE-2026-13900 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13900 Insufficient validation of untrusted input in Chromecast |
| CVE-2026-13899 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13899 Use after free in HTML |
| CVE-2026-13903 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13903 Insufficient policy enforcement in Bluetooth |
| CVE-2026-13906 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13906 Out of bounds read in Codecs |
| CVE-2026-13909 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13909 Insufficient policy enforcement in DevTools |
| CVE-2026-13911 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13911 Insufficient data validation in Spellcheck |
| CVE-2026-13921 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13921 Insufficient validation of untrusted input in DeviceBoundSessionCredentials |
| CVE-2026-13922 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13922 Side-channel information leakage in Paint |
| CVE-2026-13920 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13920 Insufficient validation of untrusted input in Media |
| CVE-2026-13919 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13919 Insufficient data validation in Extensions |
| CVE-2026-13925 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13925 Inappropriate implementation in Downloads |
| CVE-2026-13928 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13928 Insufficient validation of untrusted input in Enterprise |
| CVE-2026-13931 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13931 Inappropriate implementation in Media |
| CVE-2026-13934 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13934 Insufficient validation of untrusted input in Dawn |
| CVE-2026-13933 | Normal | — | — | — | Office / productivity | Edge / Chromium | Chromium: CVE-2026-13933 Insufficient policy enforcement in Passwords |
| CVE-2026-13930 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13930 Insufficient policy enforcement in Actor |
| CVE-2026-13935 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13935 Side-channel information leakage in ComputePressure |
| CVE-2026-13937 | Normal | — | — | — | Office / productivity | Edge / Chromium | Chromium: CVE-2026-13937 Insufficient policy enforcement in Passwords |
| CVE-2026-13938 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13938 Integer overflow in Fonts |
| CVE-2026-13940 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13940 Uninitialized Use in Cast |
| CVE-2026-13942 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13942 Insufficient validation of untrusted input in Video Capture |
| CVE-2026-13941 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13941 Inappropriate implementation in SiteSettings |
| CVE-2026-13945 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13945 Insufficient policy enforcement in Extensions |
| CVE-2026-13947 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13947 Uninitialized Use in XR |
| CVE-2026-13948 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13948 Insufficient policy enforcement in Extensions |
| CVE-2026-13950 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13950 Uninitialized Use in GPU |
| CVE-2026-13951 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13951 Policy bypass in USB |
| CVE-2026-13952 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13952 Inappropriate implementation in PerformanceAPIs |
| CVE-2026-13953 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13953 Inappropriate implementation in SplitView |
| CVE-2026-13956 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13956 Incorrect security UI in PageInfo |
| CVE-2026-13958 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13958 Uninitialized Use in Codecs |
| CVE-2026-13957 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13957 Incorrect security UI in Extensions |
| CVE-2026-13959 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13959 Insufficient validation of untrusted input in Blink |
| CVE-2026-13960 | Normal | — | — | — | Office / productivity | Edge / Chromium | Chromium: CVE-2026-13960 Inappropriate implementation in Passwords |
| CVE-2026-13962 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13962 Insufficient data validation in PDF |
| CVE-2026-13963 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13963 Inappropriate implementation in DevTools |
| CVE-2026-13965 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13965 Use after free in Oilpan |
| CVE-2026-13967 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13967 Type Confusion in V8 |
| CVE-2026-13966 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13966 Inappropriate implementation in History |
| CVE-2026-13968 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13968 Insufficient validation of untrusted input in DevTools |
| CVE-2026-13970 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13970 Uninitialized Use in Media |
| CVE-2026-13972 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13972 Inappropriate implementation in Paint |
| CVE-2026-13971 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13971 Uninitialized Use in Skia |
| CVE-2026-13973 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13973 Inappropriate implementation in UI |
| CVE-2026-13976 | Normal | — | — | — | Endpoints / Windows client | Edge / Chromium | Chromium: CVE-2026-13976 Heap buffer overflow in Storage |
| CVE-2026-13977 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13977 Inappropriate implementation in HTMLParser |
| CVE-2026-13978 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13978 Insufficient policy enforcement in PageInfo |
| CVE-2026-13979 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13979 Inappropriate implementation in Paint |
| CVE-2026-13982 | Normal | — | — | — | Office / productivity | Edge / Chromium | Chromium: CVE-2026-13982 Incorrect security UI in Passwords |
| CVE-2026-13984 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13984 Incorrect security UI in TabStrip |
| CVE-2026-13985 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13985 Inappropriate implementation in MediaCapture |
| CVE-2026-13986 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13986 Inappropriate implementation in Media UI |
| CVE-2026-13989 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13989 Insufficient policy enforcement in PageInfo |
| CVE-2026-13988 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13988 Inappropriate implementation in Paint |
| CVE-2026-13993 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13993 Incorrect security UI in WebAppInstalls |
| CVE-2026-13990 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13990 Insufficient validation of untrusted input in DataTransfer |
| CVE-2026-13996 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13996 Incorrect security UI in Permissions |
| CVE-2026-13999 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13999 Inappropriate implementation in Extensions |
| CVE-2026-14000 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14000 Inappropriate implementation in XML |
| CVE-2026-14001 | Normal | — | — | — | Network / infra servers | Edge / Chromium | Chromium: CVE-2026-14001 Inappropriate implementation in Network |
| CVE-2026-14002 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14002 Inappropriate implementation in Geolocation |
| CVE-2026-14003 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14003 Insufficient policy enforcement in Extensions |
| CVE-2026-14004 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14004 Inappropriate implementation in CSS |
| CVE-2026-14006 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14006 Use after free in Navigation |
| CVE-2026-14007 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14007 Insufficient policy enforcement in PermissionsPolicy |
| CVE-2026-14008 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14008 Uninitialized Use in WebXR |
| CVE-2026-14009 | Normal | — | — | — | Office / productivity | Edge / Chromium | Chromium: CVE-2026-14009 Insufficient data validation in Passwords |
| CVE-2026-14010 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14010 Uninitialized Use in Codecs |
| CVE-2026-14011 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14011 Out of bounds read in SurfaceCapture |
| CVE-2026-14012 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14012 Side-channel information leakage in CSS |
| CVE-2026-14013 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14013 Inappropriate implementation in SVG |
| CVE-2026-14014 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14014 Inappropriate implementation in Paint |
| CVE-2026-14015 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14015 Inappropriate implementation in WebRTC |
| CVE-2026-14018 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14018 Use after free in Updater |
| CVE-2026-14016 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14016 Insufficient policy enforcement in SVG |
| CVE-2026-14017 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14017 Inappropriate implementation in Navigation |
| CVE-2026-14019 | Normal | — | — | — | Office / productivity | Edge / Chromium | Chromium: CVE-2026-14019 Inappropriate implementation in Passwords |
| CVE-2026-14020 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14020 Insufficient validation of untrusted input in WebXR |
| CVE-2026-14021 | Normal | — | — | — | Endpoints / Windows client | Edge / Chromium | Chromium: CVE-2026-14021 Insufficient validation of untrusted input in StorageAccessAPI |
| CVE-2026-14022 | Normal | — | — | — | Network / infra servers | Edge / Chromium | Chromium: CVE-2026-14022 Insufficient validation of untrusted input in Network |
| CVE-2026-14023 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14023 Insufficient validation of untrusted input in SanitizerAPI |
| CVE-2026-14025 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14025 Use after free in Views |
| CVE-2026-14024 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14024 Use after free in Ozone |
| CVE-2026-14027 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14027 Use after free in SignIn |
| CVE-2026-14031 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14031 Incorrect security UI in File Input |
| CVE-2026-14032 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14032 Use after free in Bluetooth |
| CVE-2026-14030 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14030 Incorrect security UI in SplitView |
| CVE-2026-14034 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14034 Inappropriate implementation in WebXR |
| CVE-2026-14033 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14033 Insufficient policy enforcement in Media |
| CVE-2026-14035 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14035 Insufficient policy enforcement in Bluetooth |
| CVE-2026-14036 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14036 Insufficient policy enforcement in Bluetooth |
| CVE-2026-14038 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14038 Insufficient validation of untrusted input in New Tab Page |
| CVE-2026-14039 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14039 Insufficient policy enforcement in GetUserMedia |
| CVE-2026-14037 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14037 Insufficient policy enforcement in GPU |
| CVE-2026-14040 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14040 Use after free in BrowserTag |
| CVE-2026-14042 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14042 Inappropriate implementation in Isolated Web Apps |
| CVE-2026-14041 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14041 Insufficient policy enforcement in Serial |
| CVE-2026-14043 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14043 Use after free in GetUserMedia |
| CVE-2026-14044 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14044 Use after free in ANGLE |
| CVE-2026-14045 | Normal | — | — | — | Network / infra servers | Edge / Chromium | Chromium: CVE-2026-14045 Insufficient validation of untrusted input in Network |
| CVE-2026-14046 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14046 Inappropriate implementation in CustomTabs |
| CVE-2026-14047 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14047 Insufficient policy enforcement in Extensions |
| CVE-2026-14048 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14048 Use after free in Chromecast |
| CVE-2026-14049 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14049 Inappropriate implementation in GPU |
| CVE-2026-14050 | Normal | — | — | — | Office / productivity | Edge / Chromium | Chromium: CVE-2026-14050 Insufficient policy enforcement in Passwords |
| CVE-2026-14051 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14051 Uninitialized Use in GamepadAPI |
| CVE-2026-14052 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14052 Insufficient policy enforcement in FileSystem |
| CVE-2026-14055 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14055 Insufficient validation of untrusted input in Device Trust |
| CVE-2026-14053 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14053 Insufficient policy enforcement in Extensions |
| CVE-2026-14056 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14056 Insufficient validation of untrusted input in Media |
| CVE-2026-14054 | Normal | — | — | — | Network / infra servers | Edge / Chromium | Chromium: CVE-2026-14054 Insufficient policy enforcement in Network |
| CVE-2026-14057 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14057 Insufficient policy enforcement in FedCM |
| CVE-2026-14058 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14058 Policy bypass in Parser |
| CVE-2026-14060 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14060 Insufficient validation of untrusted input in Chromoting |
| CVE-2026-14062 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14062 Inappropriate implementation in Views |
| CVE-2026-14059 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14059 Insufficient policy enforcement in Related-Website-Sets |
| CVE-2026-14061 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14061 Inappropriate implementation in Dawn |
| CVE-2026-14063 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14063 Out of bounds memory access in Chromecast |
| CVE-2026-14064 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14064 Use after free in PageInfo |
| CVE-2026-14065 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14065 Insufficient validation of untrusted input in PageInfo |
| CVE-2026-14068 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14068 Inappropriate implementation in Omnibox |
| CVE-2026-14026 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14026 Incorrect security UI in SplitView |
| CVE-2026-14069 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14069 Integer overflow in WebNN |
| CVE-2026-14070 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14070 Uninitialized Use in WebNN |
| CVE-2026-14072 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14072 Incorrect security UI in SplitView |
| CVE-2026-14071 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14071 Side-channel information leakage in WebAudio |
| CVE-2026-14073 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14073 Insufficient policy enforcement in WebXR |
| CVE-2026-14076 | Normal | — | — | — | Network / infra servers | Edge / Chromium | Chromium: CVE-2026-14076 Policy bypass in Network |
| CVE-2026-14077 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14077 Incorrect security UI in Select |
| CVE-2026-14078 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14078 Policy bypass in WebRTC |
| CVE-2026-14079 | Normal | — | — | — | Network / infra servers | Edge / Chromium | Chromium: CVE-2026-14079 Policy bypass in Network |
| CVE-2026-14081 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14081 Insufficient policy enforcement in DevTools |
| CVE-2026-14080 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14080 Insufficient validation of untrusted input in TabSwitcher |
| CVE-2026-14082 | Normal | — | — | — | Endpoints / Windows client | Edge / Chromium | Chromium: CVE-2026-14082 Race in Storage |
| CVE-2026-14074 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14074 Side-channel information leakage in WebAuthentication |
| CVE-2026-14083 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14083 Insufficient validation of untrusted input in HTML |
| CVE-2026-14084 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14084 Insufficient validation of untrusted input in Chromoting |
| CVE-2026-14085 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14085 Side-channel information leakage in CSS |
| CVE-2026-14086 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14086 Insufficient policy enforcement in HID |
| CVE-2026-14087 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14087 Insufficient validation of untrusted input in WebNN |
| CVE-2026-14089 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14089 Insufficient validation of untrusted input in PopupBlocker |
| CVE-2026-14088 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14088 Uninitialized Use in Canvas |
| CVE-2026-14090 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14090 Out of bounds read in CameraCapture |
| CVE-2026-14092 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14092 Insufficient policy enforcement in Privacy |
| CVE-2026-14095 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14095 Insufficient validation of untrusted input in Browser |
| CVE-2026-14093 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14093 Use after free in Cast |
| CVE-2026-14094 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14094 Use after free in Installer |
| CVE-2026-14097 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14097 Inappropriate implementation in WebAppInstalls |
| CVE-2026-14100 | Normal | — | — | — | Network / infra servers | Edge / Chromium | Chromium: CVE-2026-14100 Insufficient data validation in NetworkCache |
| CVE-2026-14102 | Normal | — | — | — | Office / productivity | Edge / Chromium | Chromium: CVE-2026-14102 Use after free in Passwords |
| CVE-2026-14104 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14104 Insufficient validation of untrusted input in WebAppInstalls |
| CVE-2026-14103 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14103 Use after free in SSL |
| CVE-2026-14098 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14098 Inappropriate implementation in CSS |
| CVE-2026-14105 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14105 Insufficient policy enforcement in Speech |
| CVE-2026-14106 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14106 Insufficient validation of untrusted input in Text |
| CVE-2026-14091 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14091 Use after free in DevTools |
| CVE-2026-14107 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14107 Use after free in Scheduling |
| CVE-2026-14108 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14108 Use after free in PDFium |
| CVE-2026-14109 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14109 Insufficient policy enforcement in Mojo |
| CVE-2026-14110 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14110 Inappropriate implementation in DarkMode |
| CVE-2026-14111 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14111 Use after free in WebProtect |
| CVE-2026-14113 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14113 Use after free in Updater |
| CVE-2026-14115 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14115 Insufficient validation of untrusted input in Cast |
| CVE-2026-14112 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14112 Inappropriate implementation in Enterprise |
| CVE-2026-14117 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14117 Insufficient validation of untrusted input in DevTools |
| CVE-2026-14118 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14118 Insufficient data validation in DevTools |
| CVE-2026-14119 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14119 Type Confusion in Bluetooth |
| CVE-2026-14120 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14120 Inappropriate implementation in DevTools |
| CVE-2026-14116 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14116 Insufficient validation of untrusted input in DevTools |
| CVE-2026-14121 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14121 Use after free in Chromoting |
| CVE-2026-14124 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14124 Inappropriate implementation in CredentialProvider |
| CVE-2026-14125 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14125 Uninitialized Use in ANGLE |
| CVE-2026-14122 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14122 Insufficient validation of untrusted input in WebAppInstalls |
| CVE-2026-14127 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14127 Inappropriate implementation in Printing |
| CVE-2026-14129 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14129 Incorrect security UI in PreviewTab |
| CVE-2026-14130 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14130 Incorrect security UI in Omnibox |
| CVE-2026-14133 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14133 Race in History Embeddings |
| CVE-2026-14131 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14131 Insufficient validation of untrusted input in WebAppInstalls |
| CVE-2026-14132 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14132 Inappropriate implementation in WebXR |
| CVE-2026-14134 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14134 Inappropriate implementation in Autofill |
| CVE-2026-14139 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14139 Inappropriate implementation in TabStrip |
| CVE-2026-14140 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14140 Insufficient validation of untrusted input in Input |
| CVE-2026-14141 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14141 Incorrect security UI in Document Picture-in-Picture |
| CVE-2026-14142 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14142 Inappropriate implementation in Extensions |
| CVE-2026-14135 | Normal | — | — | — | Network / infra servers | Edge / Chromium | Chromium: CVE-2026-14135 Insufficient validation of untrusted input in Network |
| CVE-2026-14138 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14138 Inappropriate implementation in WebAppInstalls |
| CVE-2026-14144 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14144 Incorrect security UI in Views |
| CVE-2026-14143 | Normal | — | — | — | Office / productivity | Edge / Chromium | Chromium: CVE-2026-14143 Incorrect security UI in Passwords |
| CVE-2026-14145 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14145 Inappropriate implementation in CSS |
| CVE-2026-14146 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14146 Inappropriate implementation in CSS |
| CVE-2026-14148 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14148 Type Confusion in CSS |
| CVE-2026-14147 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14147 Inappropriate implementation in CSS |
| CVE-2026-14152 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14152 Out of bounds write in ANGLE |
| CVE-2026-14150 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14150 Insufficient validation of untrusted input in Speech |
| CVE-2026-14149 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14149 Use after free in Audio |
| CVE-2026-14151 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14151 Inappropriate implementation in AI |
| CVE-2026-14155 | Normal | — | — | — | Endpoints / Windows client | Edge / Chromium | Chromium: CVE-2026-14155 Insufficient policy enforcement in StorageAccessAPI |
| CVE-2026-14153 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14153 Inappropriate implementation in Glic |
| CVE-2026-14154 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14154 Inappropriate implementation in DevTools |
| CVE-2026-14156 | Normal | — | — | — | Endpoints / Windows client | Edge / Chromium | Chromium: CVE-2026-14156 Policy bypass in StorageAccessAPI |
| CVE-2026-13961 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13961 Insufficient validation of untrusted input in DevTools |
| CVE-2026-13774 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13774 Use after free in Extensions |
| CVE-2026-13777 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13777 Insufficient validation of untrusted input in iOSWeb |
| CVE-2026-13778 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13778 Use after free in WebUSB |
| CVE-2026-13788 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13788 Use after free in Fullscreen |
| CVE-2026-13791 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13791 Insufficient validation of untrusted input in Downloads |
| CVE-2026-13795 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13795 Insufficient policy enforcement in Chrome for iOS |
| CVE-2026-13785 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13785 Use after free in Bluetooth |
| CVE-2026-13805 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13805 Use after free in GFX |
| CVE-2026-13807 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13807 Use after free in Import |
| CVE-2026-13812 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13812 Insufficient validation of untrusted input in Chrome for iOS |
| CVE-2026-13809 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13809 Side-channel information leakage in Safe Browsing |
| CVE-2026-13808 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13808 Insufficient data validation in Chrome for iOS |
| CVE-2026-13816 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13816 Insufficient validation of untrusted input in File Input |
| CVE-2026-13813 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13813 Insufficient validation of untrusted input in Chrome for iOS |
| CVE-2026-13825 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13825 Uninitialized Use in Dawn |
| CVE-2026-13819 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13819 Out of bounds read in ANGLE |
| CVE-2026-13822 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13822 Inappropriate implementation in Extensions |
| CVE-2026-13826 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13826 Inappropriate implementation in Autofill |
| CVE-2026-13827 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13827 Use after free in Updater |
| CVE-2026-13833 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13833 Uninitialized Use in ANGLE |
| CVE-2026-13843 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13843 Insufficient validation of untrusted input in Chrome for iOS |
| CVE-2026-13842 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13842 Incorrect security UI in Chrome for iOS |
| CVE-2026-13846 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13846 Use after free in USB |
| CVE-2026-13847 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13847 Insufficient validation of untrusted input in Chrome for iOS |
| CVE-2026-13792 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13792 Use after free in Touchbar |
| CVE-2026-13851 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13851 Insufficient validation of untrusted input in WebAppInstalls |
| CVE-2026-13852 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13852 Insufficient validation of untrusted input in WebAppInstalls |
| CVE-2026-13850 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13850 Insufficient validation of untrusted input in Chrome for iOS |
| CVE-2026-13856 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13856 Insufficient validation of untrusted input in Speech |
| CVE-2026-13863 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13863 Insufficient validation of untrusted input in CustomTabs |
| CVE-2026-13866 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13866 Insufficient validation of untrusted input in Input |
| CVE-2026-13868 | Normal | — | — | — | Network / infra servers | Edge / Chromium | Chromium: CVE-2026-13868 Inappropriate implementation in Network |
| CVE-2026-13870 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13870 Use after free in WebView |
| CVE-2026-13878 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13878 Use after free in Bluetooth |
| CVE-2026-13872 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13872 Insufficient validation of untrusted input in WebAppInstalls |
| CVE-2026-13880 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13880 Use after free in USB |
| CVE-2026-13885 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13885 Use after free in Skia |
| CVE-2026-13887 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13887 Insufficient policy enforcement in NFC |
| CVE-2026-13889 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13889 Insufficient validation of untrusted input in WebAuthentication |
| CVE-2026-13904 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13904 Incorrect security UI in Safe Browsing |
| CVE-2026-13892 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13892 Inappropriate implementation in Chrome for iOS |
| CVE-2026-13902 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13902 Inappropriate implementation in Chrome for iOS |
| CVE-2026-13905 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13905 Incorrect security UI in Chrome for iOS |
| CVE-2026-13914 | Normal | — | — | — | Office / productivity | Edge / Chromium | Chromium: CVE-2026-13914 Inappropriate implementation in Passwords |
| CVE-2026-13907 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13907 Inappropriate implementation in iOSWeb |
| CVE-2026-13912 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13912 Incorrect security UI in Safe Browsing |
| CVE-2026-13910 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13910 Insufficient policy enforcement in WebXR |
| CVE-2026-13913 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13913 Insufficient policy enforcement in Autofill |
| CVE-2026-13908 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13908 Insufficient validation of untrusted input in Omnibox |
| CVE-2026-13916 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13916 Inappropriate implementation in Chrome for iOS |
| CVE-2026-13915 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13915 Use after free in Chrome for iOS |
| CVE-2026-13917 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13917 Insufficient validation of untrusted input in Chrome for iOS |
| CVE-2026-13923 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13923 Uninitialized Use in GPU |
| CVE-2026-13926 | Normal | — | — | — | Network / infra servers | Edge / Chromium | Chromium: CVE-2026-13926 Insufficient validation of untrusted input in Network |
| CVE-2026-13918 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13918 Use after free in Chrome for iOS |
| CVE-2026-13924 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13924 Insufficient validation of untrusted input in WebView |
| CVE-2026-13929 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13929 Insufficient validation of untrusted input in DevTools |
| CVE-2026-13932 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13932 Inappropriate implementation in Sharing |
| CVE-2026-13936 | Normal | — | — | — | Office / productivity | Edge / Chromium | Chromium: CVE-2026-13936 Inappropriate implementation in Passwords |
| CVE-2026-13943 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13943 Uninitialized Use in CSS |
| CVE-2026-13939 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13939 Insufficient validation of untrusted input in WebShare |
| CVE-2026-13944 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13944 Inappropriate implementation in DataTransfer |
| CVE-2026-13946 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13946 Inappropriate implementation in ScriptInjections |
| CVE-2026-13949 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13949 Insufficient policy enforcement in Payments |
| CVE-2026-13955 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13955 Insufficient validation of untrusted input in CustomTabs |
| CVE-2026-13927 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13927 Insufficient validation of untrusted input in UI |
| CVE-2026-13964 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13964 Insufficient policy enforcement in WebView |
| CVE-2026-13969 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13969 Uninitialized Use in UI |
| CVE-2026-13975 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13975 Out of bounds read in ANGLE |
| CVE-2026-13974 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13974 Integer overflow in Safe Browsing |
| CVE-2026-13981 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13981 Inappropriate implementation in Chrome for iOS |
| CVE-2026-13980 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13980 Incorrect security UI in Chrome for iOS |
| CVE-2026-13987 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13987 Incorrect security UI in Mobile |
| CVE-2026-13991 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13991 Insufficient validation of untrusted input in Chrome for iOS |
| CVE-2026-13992 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13992 Inappropriate implementation in UI |
| CVE-2026-13994 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13994 Inappropriate implementation in Credential Management |
| CVE-2026-13995 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13995 Insufficient validation of untrusted input in Autofill |
| CVE-2026-13983 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13983 Incorrect security UI in Chrome for iOS |
| CVE-2026-13997 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13997 Incorrect security UI in Extensions |
| CVE-2026-13998 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13998 Incorrect security UI in File Input |
| CVE-2026-14005 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14005 Use after free in Omnibox |
| CVE-2026-14028 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14028 Incorrect security UI in Chrome for iOS |
| CVE-2026-14066 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14066 Insufficient validation of untrusted input in Chrome for iOS |
| CVE-2026-14067 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14067 Use after free in Chrome for iOS |
| CVE-2026-14075 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14075 Policy bypass in Chrome for iOS |
| CVE-2026-14096 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14096 Object lifecycle issue in Input |
| CVE-2026-14099 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14099 Use after free in Chrome for iOS |
| CVE-2026-14101 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14101 Insufficient policy enforcement in Sandbox |
| CVE-2026-14114 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14114 Inappropriate implementation in WebAppInstalls |
| CVE-2026-14123 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14123 Incorrect security UI in Chrome for iOS |
| CVE-2026-14126 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14126 Incorrect security UI in UI |
| CVE-2026-14128 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14128 Insufficient data validation in Chrome for iOS |
| CVE-2026-14136 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14136 Incorrect security UI in Chrome for iOS |
| CVE-2026-14385 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14385 Heap buffer overflow in ANGLE |
| CVE-2026-14137 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14137 Insufficient validation of untrusted input in Chrome for iOS |
| CVE-2026-14382 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14382 Insufficient validation of untrusted input in ANGLE |
| CVE-2026-14386 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14386 Out of bounds read in ANGLE |
| CVE-2026-14388 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14388 Out of bounds read in ANGLE |
| CVE-2026-14390 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14390 Use after free in ANGLE |
| CVE-2026-14392 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14392 Out of bounds write in Tint |
| CVE-2026-14393 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14393 Use after free in V8 |
| CVE-2026-14391 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14391 Integer overflow in ANGLE |
| CVE-2026-14395 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14395 Out of bounds write in V8 |
| CVE-2026-14396 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14396 Out of bounds read in ANGLE |
| CVE-2026-14394 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14394 Use after free in V8 |
| CVE-2026-14398 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14398 Use after free in ANGLE |
| CVE-2026-14397 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14397 Out of bounds write in ANGLE |
| CVE-2026-14399 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14399 Uninitialized Use in Dawn |
| CVE-2026-14401 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14401 Insufficient validation of untrusted input in ANGLE |
| CVE-2026-14400 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14400 Out of bounds write in ANGLE |
| CVE-2026-14403 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14403 Use after free in V8 |
| CVE-2026-14406 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14406 Out of bounds read in V8 |
| CVE-2026-14404 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14404 Inappropriate implementation in PDFium |
| CVE-2026-14402 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14402 Uninitialized Use in ANGLE |
| CVE-2026-14405 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14405 Uninitialized Use in V8 |
| CVE-2026-14407 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14407 Inappropriate implementation in V8 |
| CVE-2026-14409 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14409 Inappropriate implementation in V8 |
| CVE-2026-14408 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14408 Uninitialized Use in Dawn |
| CVE-2026-14411 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14411 Insufficient validation of untrusted input in ANGLE |
| CVE-2026-14410 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14410 Inappropriate implementation in Skia |
| CVE-2026-14412 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14412 Insufficient validation of untrusted input in ANGLE |
| CVE-2026-14413 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14413 Uninitialized Use in ANGLE |
| CVE-2026-14414 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14414 Insufficient validation of untrusted input in Skia |
| CVE-2026-14415 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14415 Inappropriate implementation in V8 |
| CVE-2026-14416 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14416 Out of bounds read in Dawn |
| CVE-2026-14417 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14417 Use after free in Dawn |
| CVE-2026-14420 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14420 Out of bounds read and write in Dawn |
| CVE-2026-14418 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14418 Uninitialized Use in ANGLE |
| CVE-2026-14419 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14419 Use after free in Skia |
| CVE-2026-14422 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14422 Out of bounds read and write in Tint |
| CVE-2026-14423 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14423 Type Confusion in Tint |
| CVE-2026-14421 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14421 Uninitialized Use in Dawn |
| CVE-2026-14424 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14424 Use after free in Dawn |
| CVE-2026-14425 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14425 Use after free in ANGLE |
| CVE-2026-14426 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14426 Use after free in V8 |
| CVE-2026-14427 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14427 Heap buffer overflow in Skia |
| CVE-2026-14428 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14428 Insufficient validation of untrusted input in Dawn |
| CVE-2026-14429 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14429 Insufficient validation of untrusted input in Skia |
| CVE-2026-14430 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14430 Integer overflow in V8 |
| CVE-2026-14432 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14432 Use after free in V8 |
| CVE-2026-14431 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-14431 Type Confusion in V8 |
| CVE-2026-15904 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-15904 Use after free in Ozone |
| CVE-2026-15903 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-15903 Out of bounds read and write in V8 |
| CVE-2026-15899 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-15899 Use after free in CameraCapture |
| CVE-2026-15778 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-15778 Insufficient validation of untrusted input in Navigation |
| CVE-2026-15776 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-15776 Type Confusion in V8 |
| CVE-2026-15775 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-15775 Insufficient policy enforcement in V8 |
| CVE-2026-15774 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-15774 Use after free in Skia |
| CVE-2026-15773 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-15773 Use after free in Core |
| CVE-2026-15770 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-15770 Uninitialized Use in V8 |
| CVE-2026-15900 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-15900 Use after free in GPU |
| CVE-2026-15901 | Normal | — | — | — | Network / infra servers | Edge / Chromium | Chromium: CVE-2026-15901 Use after free in Network |
| CVE-2026-15765 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-15765 Use after free in Ozone |
| CVE-2026-13954 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13954 Insufficient policy enforcement in XML |
| CVE-2026-13796 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13796 Integer overflow in Chromecast |
| CVE-2026-13799 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13799 Use after free in QUIC |
| CVE-2026-13800 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13800 Inappropriate implementation in Updater |
| CVE-2026-13806 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13806 Insufficient validation of untrusted input in Accessibility |
| CVE-2026-13810 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13810 Inappropriate implementation in Input |
| CVE-2026-13811 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13811 Use after free in IME |
| CVE-2026-13815 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13815 Use after free in Blink |
| CVE-2026-13818 | Normal | — | — | — | Office / productivity | Edge / Chromium | Chromium: CVE-2026-13818 Inappropriate implementation in Passwords |
| CVE-2026-13814 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13814 Use after free in Views |
| CVE-2026-13817 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13817 Insufficient validation of untrusted input in Glic |
| CVE-2026-13821 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13821 Use after free in Canvas |
| CVE-2026-13820 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13820 Out of bounds read in Skia |
| CVE-2026-13823 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13823 Use after free in Glic |
| CVE-2026-13824 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13824 Insufficient validation of untrusted input in Extensions |
| CVE-2026-13828 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13828 Inappropriate implementation in Enterprise |
| CVE-2026-13829 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13829 Insufficient validation of untrusted input in Settings |
| CVE-2026-13830 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13830 Use after free in Chromoting |
| CVE-2026-13831 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13831 Use after free in GPU |
| CVE-2026-13834 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13834 Insufficient validation of untrusted input in ANGLE |
| CVE-2026-13832 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13832 Use after free in Headless |
| CVE-2026-13836 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13836 Inappropriate implementation in CSS |
| CVE-2026-13835 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13835 Inappropriate implementation in XML |
| CVE-2026-13837 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13837 Inappropriate implementation in CSS |
| CVE-2026-13838 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13838 Inappropriate implementation in CSS |
| CVE-2026-13839 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13839 Inappropriate implementation in CSS |
| CVE-2026-13840 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13840 Insufficient policy enforcement in Canvas |
| CVE-2026-13841 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13841 Integer overflow in Skia |
| CVE-2026-13844 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13844 Use after free in Updater |
| CVE-2026-13845 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-13845 Use after free in DOM |
| CVE-2026-15777 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-15777 Use after free in UI |
| CVE-2026-15772 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-15772 Use after free in GPU |
| CVE-2026-15771 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-15771 Insufficient validation of untrusted input in Media |
| CVE-2026-15902 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-15902 Use after free in Cast |
| CVE-2026-15769 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-15769 Insufficient validation of untrusted input in Linux Toolkit Theming |
| CVE-2026-15768 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-15768 Insufficient policy enforcement in HTML-in-Canvas |
| CVE-2026-15766 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-15766 Uninitialized Use in Skia |
| CVE-2026-15764 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-15764 Use after free in Ozone |
| CVE-2026-15905 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-15905 Use after free in Aura |
| CVE-2026-16420 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-16420 Type Confusion in WebAudio |
| CVE-2026-16807 | Normal | — | — | — | Browser (Edge auto-update) | Edge / Chromium | Chromium: CVE-2026-16807 Out of bounds write in Codecs |
| CVE-2026-55952 | Normal | — | Important | Denial of Service | Other / general Windows | Linux / other | TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension |
| CVE-2026-54886 | Normal | — | Moderate | Denial of Service | Other / general Windows | Linux / other | SSH SFTP server denial of service via extended channel data infinite loop |
| CVE-2026-54908 | Normal | — | Moderate | Denial of Service | Exchange / mail | Linux / other | Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message |
| CVE-2026-56288 | Normal | — | Moderate | — | Other / general Windows | Linux / other | NULL Pointer Dereference in GNU patch |
| CVE-2026-40468 | Normal | — | Low | — | Other / general Windows | Linux / other | Heap buffer overflow in gawk |
| CVE-2026-26197 | Normal | — | Moderate | — | Other / general Windows | Linux / other | Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c |
| CVE-2026-53910 | Normal | — | Low | — | Other / general Windows | Linux / other | Heap-based Buffer Overflow in GNU diffutils |
| CVE-2026-50252 | Normal | — | Moderate | — | Other / general Windows | Linux / other | Possible cache poisoning attack by mapping source port population per thread |
| CVE-2026-50243 | Normal | — | Moderate | — | Other / general Windows | Linux / other | 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL |
| CVE-2026-15788 | Normal | — | Moderate | — | Endpoints / Windows client | Linux / other | WCOW cache mount source selector resolves NTFS junctions outside of cache root |
| CVE-2026-44509 | Normal | — | Moderate | — | Other / general Windows | Linux / other | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate. |
| CVE-2026-59676 | Normal | — | Moderate | — | Other / general Windows | Linux / other | Local File Deletion Attack Vector in rm_rf() in seunshare |
| CVE-2026-59677 | Normal | — | Moderate | — | Other / general Windows | Linux / other | Process Kill Attack Vector in killall() in seunshare |
| CVE-2026-9079 | Normal | — | Important | — | Office / productivity | Linux / other | stale proxy password leak |
| CVE-2026-54891 | Normal | — | Moderate | — | Other / general Windows | Linux / other | Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl |
| CVE-2026-56289 | Normal | — | Moderate | — | Other / general Windows | Linux / other | Loop with Unreachable Exit Condition in GNU patch |
| CVE-2026-14461 | Normal | — | Moderate | — | Other / general Windows | Linux / other | Out-of-bound read in mtr |
| CVE-2026-40553 | Normal | — | Moderate | — | Other / general Windows | Linux / other | Stack-based buffer overflow in gawk |
| CVE-2026-40469 | Normal | — | Moderate | — | Other / general Windows | Linux / other | Heap buffer overflow in gawk |
| CVE-2026-40467 | Normal | — | Moderate | — | Other / general Windows | Linux / other | Use after free in gawk |
| CVE-2026-57215 | Normal | — | Important | — | Other / general Windows | Linux / other | RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom |
| CVE-2026-45784 | Normal | — | Moderate | — | Other / general Windows | Linux / other | rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers |
| CVE-2026-26199 | Normal | — | Moderate | — | Other / general Windows | Linux / other | Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero |