Every CVE in this month's Microsoft Security Update document, ranked by composite priority. Search by CVE, product, or owner; filter by status or source; click a column to sort. 426 Microsoft-authored, 0 Edge/Chromium and 364 Linux/other that patch via their own vendor.
62 rated Critical (Microsoft) and 46 rated Critical (everything else). The status filter below spans the whole document, so its Critical count is the combined 108.
| CVE | Status | CVSS | Severity | Impact | Owner | Source | Title |
|---|---|---|---|---|---|---|---|
| CVE-2026-68820 | Exploited | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-62832 | Zero-day | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows User Profile Service Elevation of Privilege Vulnerability |
| CVE-2026-72971 | Zero-day | 5.5 | Important | Tampering | Endpoints / Windows client | Microsoft | Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability |
| CVE-2026-62893 | Critical worm | 9.8 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Windows Deployment Services TFTP Server Remote Code Execution Vulnerability |
| CVE-2026-63508 | Critical worm | 10.0 | Critical | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability |
| CVE-2026-56162 | Critical worm | 10.0 | Critical | Elevation of Privilege | Cloud / M365 apps | Microsoft | Azure SQL Database Elevation of Privilege Vulnerability |
| CVE-2026-65667 | Critical worm | 10.0 | Critical | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft Teams Elevation of Privilege Vulnerability |
| CVE-2026-62873 | Critical worm | 9.8 | Critical | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft 365 Admin Center Elevation of Privilege Vulnerability |
| CVE-2026-62815 | Critical worm | 9.8 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Microsoft QUIC Remote Code Execution Vulnerability |
| CVE-2026-62878 | Critical worm | 9.8 | Critical | Remote Code Execution | Network / infra servers | Microsoft | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-65791 | Critical worm | 9.8 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Windows iSCSI Target Service Remote Code Execution Vulnerability |
| CVE-2026-50516 | Critical worm | 9.4 | Critical | Elevation of Privilege | Cloud / M365 apps | Microsoft | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability |
| CVE-2026-65665 | Critical | 8.8 | Critical | Remote Code Execution | SharePoint owners | Microsoft | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-62836 | Critical worm | 8.7 | Critical | Elevation of Privilege | Cloud / M365 apps | Microsoft | Azure SQL Managed Instance Elevation of Privilege Vulnerability |
| CVE-2026-62819 | Critical worm | 8.1 | Critical | Remote Code Execution | Network / infra servers | Microsoft | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
| CVE-2026-62820 | Critical worm | 8.1 | Critical | Remote Code Execution | Network / infra servers | Microsoft | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-62889 | Critical worm | 8.1 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability |
| CVE-2026-65789 | Critical worm | 8.1 | Critical | Remote Code Execution | Network / infra servers | Microsoft | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-66802 | Critical worm | 8.1 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability |
| CVE-2026-71331 | Critical worm | 8.1 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability |
| CVE-2026-50515 | Critical | 9.9 | Critical | Remote Code Execution | Cloud / M365 apps | Microsoft | Azure Service Bus Remote Code Execution Vulnerability |
| CVE-2026-59115 | Critical | 9.9 | Critical | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability |
| CVE-2026-50481 | Critical | 9.9 | Critical | Elevation of Privilege | Identity / AD | Microsoft | Azure Active Directory Elevation of Privilege Vulnerability |
| CVE-2026-62830 | Critical | 9.9 | Critical | Elevation of Privilege | Cloud / M365 apps | Microsoft | Azure SRE Agent Elevation of Privilege Vulnerability |
| CVE-2026-62823 | Critical | 8.8 | Critical | Remote Code Execution | Network / infra servers | Microsoft | Windows DHCP Server Remote Code Execution Vulnerability |
| CVE-2026-62918 | Critical worm | 7.5 | Critical | Spoofing | Other / general Windows | Microsoft | Microsoft Teams Spoofing Vulnerability |
| CVE-2026-62896 | Critical | 9.6 | Critical | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft Teams Elevation of Privilege Vulnerability |
| CVE-2026-70332 | Critical | 9.6 | Critical | Spoofing | SharePoint owners | Microsoft | Microsoft Office SharePoint Spoofing Vulnerability |
| CVE-2026-56161 | Critical | 9.6 | Critical | Information Disclosure | Cloud / M365 apps | Microsoft | Azure Logic Apps Information Disclosure Vulnerability |
| CVE-2026-59118 | Critical | 9.3 | Critical | Elevation of Privilege | Cloud / M365 apps | Microsoft | Copilot Cowork Elevation of Privilege Vulnerability |
| CVE-2026-68823 | Critical | 9.1 | Critical | Remote Code Execution | Cloud / M365 apps | Microsoft | Azure Confidential Ledger Remote Code Execution Vulnerability |
| CVE-2026-62827 | Critical | 8.8 | Critical | Elevation of Privilege | SharePoint owners | Microsoft | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2026-65668 | Critical | 8.8 | Critical | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft Purview eDiscovery Elevation of Privilege Vulnerability |
| CVE-2026-62818 | Critical | 8.8 | Critical | Remote Code Execution | Identity / AD | Microsoft | Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability |
| CVE-2026-62824 | Critical | 8.8 | Critical | Remote Code Execution | Remote access / RDP | Microsoft | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-62822 | Critical | 8.8 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Windows GDI+ Remote Code Execution Vulnerability |
| CVE-2026-64921 | Critical | 8.8 | Critical | Elevation of Privilege | SharePoint owners | Microsoft | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2026-49163 | Critical | 8.8 | Critical | Elevation of Privilege | Other / general Windows | Microsoft | Application Insights Profiler Elevation of Privilege Vulnerability |
| CVE-2026-62869 | Critical | 8.8 | Critical | Spoofing | Cloud / M365 apps | Microsoft | Azure Entra ID Spoofing Vulnerability |
| CVE-2026-62911 | Critical | 8.0 | Critical | Elevation of Privilege | Exchange / mail | Microsoft | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-62816 | Critical | 8.8 | Critical | Remote Code Execution | Endpoints / Windows client | Microsoft | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability |
| CVE-2026-62817 | Critical | 8.8 | Critical | Remote Code Execution | Network / infra servers | Microsoft | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-70130 | Critical | 8.4 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-62890 | Critical | 7.8 | Critical | Remote Code Execution | Other / general Windows | Microsoft | Windows GDI+ Elevation of Privilege Vulnerability |
| CVE-2026-63513 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-63515 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-63518 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-63519 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-65657 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-65664 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-66799 | Critical | 7.8 | Critical | Elevation of Privilege | Other / general Windows | Microsoft | Windows Key Guard Elevation of Privilege Vulnerability |
| CVE-2026-68794 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68816 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-63525 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-63526 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-63532 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64898 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64903 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64907 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-64909 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64910 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64911 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-66807 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-68804 | Critical | 7.8 | Critical | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-63522 | Critical | 7.8 | Critical | Elevation of Privilege | Cloud / M365 apps | Microsoft | Azure SQL Database Elevation of Privilege Vulnerability |
| CVE-2026-64564 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | sctp: don't free the ASCONF's own transport in DEL-IP processing |
| CVE-2026-64562 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | KVM: nVMX: Hide shadow VMCS right after VMCLEAR |
| CVE-2026-68407 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | wifi: nl80211: free RNR data on MBSSID mismatch |
| CVE-2026-68395 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered |
| CVE-2026-68143 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | net: slip: serialize receive against buffer reallocation |
| CVE-2026-68176 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev |
| CVE-2026-68131 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | rbd: Reset positive result codes to zero in object map update path |
| CVE-2026-68218 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | media: pci: dm1105: Free allocated workqueue |
| CVE-2026-68406 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | wifi: cfg80211: validate PMSR FTM preamble range |
| CVE-2026-68364 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | drm/amd/display: Fix ISM dc_lock deadlock during suspend |
| CVE-2026-68354 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | firewire: net: Fix fragmented datagram reassembly |
| CVE-2026-68180 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | intel_th: fix MSC output device reference leak |
| CVE-2026-68357 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() |
| CVE-2026-68402 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | wifi: cfg80211: bound element ID read when checking non-inheritance |
| CVE-2026-68310 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | wifi: mt76: mt7915: guard HE capability lookups |
| CVE-2026-68140 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | net/iucv: fix use-after-free of a severed iucv_path |
| CVE-2026-68349 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | wifi: carl9170: fix buffer overflow in rx_stream failover path |
| CVE-2026-68212 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | media: saa7134: Fix a possible memory leak in saa7134_video_init1 |
| CVE-2026-68377 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | net/sched: act_tunnel_key: Defer dst_release to RCU callback |
| CVE-2026-68146 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | ftrace: Add global mutex to serialize trace_parser access |
| CVE-2026-68214 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | media: rtl2832: fix use-after-free in rtl2832_remove() |
| CVE-2026-68360 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop |
| CVE-2026-68359 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop |
| CVE-2026-68324 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() |
| CVE-2026-68121 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | pppoe: reload header pointer after dev_hard_header() |
| CVE-2026-68132 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | super: fix emergency thaw deadlock on frozen block devices |
| CVE-2026-68325 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | iommu/amd: Bound the early ACPI HID map |
| CVE-2026-64565 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() |
| CVE-2026-68210 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | media: stm32: dcmi: unregister notifier on probe failure |
| CVE-2026-68399 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | bpf: Fix UAF in sock clone early bailouts |
| CVE-2026-68127 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | ila: reload IPv6 header after pskb_may_pull in checksum adjust |
| CVE-2026-68391 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds |
| CVE-2026-68185 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | LoongArch: Move jump_label_init() before parse_early_param() |
| CVE-2026-68287 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | drop_monitor: fix size calculations for 64-bit attributes |
| CVE-2026-68166 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | userfaultfd: prevent registration of special VMAs |
| CVE-2026-68198 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | wifi: ath6kl: fix use-after-free in aggr_reset_state() |
| CVE-2026-68207 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | media: ti: vpe: unwind v4l2 device registration on probe error |
| CVE-2026-68142 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | geneve: require CAP_NET_ADMIN in the device netns for changelink |
| CVE-2026-68144 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | phonet: pep: fix use-after-free in pep_get_sb() |
| CVE-2026-68236 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | drm/amd/display: set new_stream to NULL after release |
| CVE-2026-68340 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | hwmon: occ: validate poll response sensor blocks |
| CVE-2026-68153 | Critical worm | 9.8 | Critical | — | Other / general Windows | Linux / other | libceph: remove debugfs files before client teardown |
| CVE-2026-34191 | Critical worm | 9.1 | Critical | — | Other / general Windows | Linux / other | Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle |
| CVE-2026-68160 | Critical worm | 9.1 | Critical | — | Other / general Windows | Linux / other | ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() |
| CVE-2026-50540 | Critical | 9.6 | Critical | — | Other / general Windows | Linux / other | Kata Containers: Config Path Annotation Arbitrary File Loading |
| CVE-2026-47243 | Critical | — | Critical | — | Other / general Windows | Linux / other | Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs |
| CVE-2026-59124 | Normal worm | 9.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability |
| CVE-2026-63520 | Normal worm | 8.1 | Important | Remote Code Execution | SharePoint owners | Microsoft | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-59132 | Normal worm | 7.5 | Important | Denial of Service | Network / infra servers | Microsoft | Windows TCP/IP Denial of Service Vulnerability |
| CVE-2026-59133 | Normal | 8.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability |
| CVE-2026-62792 | Normal worm | 8.1 | Important | Remote Code Execution | Network / infra servers | Microsoft | Windows TCP/IP Remote Code Execution Vulnerability |
| CVE-2026-62778 | Normal worm | 8.1 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-62781 | Normal worm | 8.1 | Important | Remote Code Execution | Other / general Windows | Microsoft | RPC Runtime Library Remote Code Execution Vulnerability |
| CVE-2026-65679 | Normal worm | 8.1 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows iSCSI Target Service Remote Code Execution Vulnerability |
| CVE-2026-70355 | Normal | 7.3 | Important | Elevation of Privilege | SharePoint owners | Microsoft | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2026-54113 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Microsoft | Remote Procedure Call Denial of Service Vulnerability |
| CVE-2026-62901 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Microsoft | .NET Denial of Service Vulnerability |
| CVE-2026-65681 | Normal worm | 7.5 | Important | Denial of Service | Other / general Windows | Microsoft | Windows iSCSI Target Service Denial of Service Vulnerability |
| CVE-2026-62898 | Normal worm | 7.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Microsoft QUIC Information Disclosure Vulnerability |
| CVE-2026-70306 | Normal | 9.3 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft Office SharePoint Spoofing Vulnerability |
| CVE-2026-62702 | Normal worm | 6.8 | Important | Denial of Service | Other / general Windows | Microsoft | Windows Graphics Kernel Denial of Service Vulnerability |
| CVE-2026-65768 | Normal | 8.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Microsoft Teams Remote Code Execution Vulnerability |
| CVE-2026-63514 | Normal | 8.8 | Important | Remote Code Execution | SharePoint owners | Microsoft | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-49179 | Normal | 8.8 | Important | Remote Code Execution | Identity / AD | Microsoft | Windows Active Directory Domain Services Remote Code Execution Vulnerability |
| CVE-2026-59113 | Normal | 8.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-62785 | Normal | 8.8 | Important | Remote Code Execution | Identity / AD | Microsoft | Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability |
| CVE-2026-62784 | Normal | 8.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability |
| CVE-2026-62795 | Normal | 8.8 | Important | Remote Code Execution | Identity / AD | Microsoft | Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability |
| CVE-2026-62913 | Normal | 8.8 | Important | Remote Code Execution | Exchange / mail | Microsoft | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2026-65658 | Normal | 8.8 | Important | Remote Code Execution | SharePoint owners | Microsoft | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-65663 | Normal | 8.8 | Important | Remote Code Execution | SharePoint owners | Microsoft | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-65807 | Normal | 8.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-65811 | Normal | 8.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Power BI Remote Code Execution Vulnerability |
| CVE-2026-65815 | Normal | 8.8 | Important | Remote Code Execution | Cloud / M365 apps | Microsoft | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability |
| CVE-2026-69320 | Normal | 8.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-70321 | Normal | 8.8 | Important | Remote Code Execution | SharePoint owners | Microsoft | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2026-70324 | Normal | 8.8 | Important | Elevation of Privilege | SharePoint owners | Microsoft | Microsoft SharePoint Elevation of Privilege Vulnerability |
| CVE-2026-70329 | Normal | 8.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2026-70336 | Normal | 8.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-57104 | Normal | 8.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Azure Storage Explorer Elevation of Privilege Vulnerability |
| CVE-2026-62800 | Normal | 8.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows SMBv3 Server Remote Code Execution Vulnerability |
| CVE-2026-62790 | Normal | 8.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows SMBv3 Server Remote Code Execution Vulnerability |
| CVE-2026-62872 | Normal | 8.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | .NET Framework Elevation of Privilege Vulnerability |
| CVE-2026-64901 | Normal | 8.8 | Important | Remote Code Execution | SharePoint owners | Microsoft | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-66805 | Normal | 8.8 | Important | Remote Code Execution | SharePoint owners | Microsoft | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-66808 | Normal | 8.8 | Important | Remote Code Execution | SharePoint owners | Microsoft | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-70326 | Normal | 8.8 | Important | Elevation of Privilege | SharePoint owners | Microsoft | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2026-70337 | Normal | 8.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Microsoft PowerShell Remote Code Execution Vulnerability |
| CVE-2026-65767 | Normal | 8.8 | Important | Spoofing | Other / general Windows | Microsoft | Microsoft Teams for Android and iOS Spoofing Vulnerability |
| CVE-2026-58650 | Normal | 7.8 | Important | Security Feature Bypass | Other / general Windows | Microsoft | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-61925 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-61930 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-62688 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows MIDI Service Module Elevation of Privileges Vulnerability |
| CVE-2026-62696 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability |
| CVE-2026-62713 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-62712 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-62735 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows HTTP.sys Elevation of Privilege Vulnerability |
| CVE-2026-62737 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-62783 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
| CVE-2026-69278 | Normal | 7.8 | Important | Security Feature Bypass | Other / general Windows | Microsoft | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-70335 | Normal | 7.8 | Important | Elevation of Privilege | Cloud / M365 apps | Microsoft | GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability |
| CVE-2026-66804 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability |
| CVE-2026-61358 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability |
| CVE-2026-62698 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft Digest Authentication Elevation of Privilege Vulnerability |
| CVE-2026-62721 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability |
| CVE-2026-62741 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows HTTP.sys Elevation of Privilege Vulnerability |
| CVE-2026-62888 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-65775 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-69306 | Normal | 8.2 | Important | Security Feature Bypass | Other / general Windows | Microsoft | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-62899 | Normal worm | 5.9 | Important | Security Feature Bypass | Other / general Windows | Microsoft | .NET Security Feature Bypass Vulnerability |
| CVE-2026-62900 | Normal worm | 5.9 | Important | Information Disclosure | Other / general Windows | Microsoft | .NET Information Disclosure Vulnerability |
| CVE-2026-68819 | Normal worm | 5.9 | Important | Denial of Service | Network / infra servers | Microsoft | Windows Network File System Denial of Service Vulnerability |
| CVE-2026-65796 | Normal worm | 5.9 | Important | Denial of Service | Other / general Windows | Microsoft | Windows iSCSI Target Service Denial of Service Vulnerability |
| CVE-2026-70340 | Normal | 8.1 | Important | Elevation of Privilege | Cloud / M365 apps | Microsoft | Azure CycleCloud Elevation of Privilege Vulnerability |
| CVE-2026-57105 | Normal | 8.0 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft Office SharePoint Spoofing Vulnerability |
| CVE-2026-61348 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-62766 | Normal | 7.0 | Important | Elevation of Privilege | Identity / AD | Microsoft | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2026-65788 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-70307 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-61929 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-62788 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-59134 | Normal | 7.5 | Important | Remote Code Execution | Remote access / RDP | Microsoft | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-62787 | Normal | 7.5 | Important | Remote Code Execution | Network / infra servers | Microsoft | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-61352 | Normal | 7.5 | Important | Remote Code Execution | Remote access / RDP | Microsoft | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-61363 | Normal | 7.5 | Important | Remote Code Execution | Remote access / RDP | Microsoft | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-20348 | Normal worm | 7.5 | Important | — | Other / general Windows | Microsoft | ClamAV XAR File Format Processing Memory Corruption Vulnerability |
| CVE-2026-20339 | Normal worm | 7.5 | Important | — | Other / general Windows | Microsoft | ClamAV PESpin File Format Processing Integer Overflow Vulnerability |
| CVE-2026-20338 | Normal worm | 7.5 | Important | — | Other / general Windows | Microsoft | ClamAV ZIP File Format Processing Memory Corruption Vulnerability |
| CVE-2026-20347 | Normal worm | 7.5 | Important | — | Other / general Windows | Microsoft | ClamAV Mach-O File Format Processing Memory Corruption Vulnerability |
| CVE-2026-20337 | Normal worm | 7.5 | Important | — | Other / general Windows | Microsoft | ClamAV ZIP File Format Processing Memory Corruption Vulnerability |
| CVE-2026-20346 | Normal worm | 7.5 | Important | — | Other / general Windows | Microsoft | ClamAV PDF File Format Processing Memory Corruption Vulnerability |
| CVE-2026-20345 | Normal worm | 7.5 | Important | — | Other / general Windows | Microsoft | ClamAV GPT File Format Processing Memory Corruption Vulnerability |
| CVE-2026-58612 | Normal | 7.4 | Important | Information Disclosure | Other / general Windows | Microsoft | PowerShell Information Disclosure Vulnerability |
| CVE-2026-62914 | Normal | 7.3 | Important | Spoofing | Exchange / mail | Microsoft | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-64900 | Normal | 7.3 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47299 | Normal | 7.2 | Important | Elevation of Privilege | Cloud / M365 apps | Microsoft | Azure Monitor Agent Elevation of Privilege Vulnerability |
| CVE-2026-62910 | Normal | 7.2 | Important | Elevation of Privilege | Exchange / mail | Microsoft | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-65675 | Normal | 7.1 | Important | Security Feature Bypass | Cloud / M365 apps | Microsoft | CoPilot Chat Security Feature Bypass Vulnerability |
| CVE-2026-56179 | Normal | 8.3 | Moderate | Spoofing | Network / infra servers | Microsoft | Windows Network Address Translation (NAT) Spoofing Vulnerability |
| CVE-2026-61920 | Normal | 6.6 | Important | Remote Code Execution | Network / infra servers | Microsoft | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-62837 | Normal | 6.5 | Important | Information Disclosure | SharePoint owners | Microsoft | Microsoft SharePoint Server Information Disclosure Vulnerability |
| CVE-2026-63512 | Normal | 6.5 | Important | Tampering | SharePoint owners | Microsoft | Microsoft SharePoint Server Tampering Vulnerability |
| CVE-2026-63516 | Normal | 6.5 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-40375 | Normal | 6.5 | Important | Information Disclosure | Cloud / M365 apps | Microsoft | Microsoft Dynamics Business Central Information Disclosure Vulnerability |
| CVE-2026-47285 | Normal | 6.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Visual Studio Code Information Disclosure Vulnerability |
| CVE-2026-59138 | Normal | 6.5 | Important | Denial of Service | Other / general Windows | Microsoft | Microsoft Remote Registry Service Denial of Service Vulnerability |
| CVE-2026-61345 | Normal | 6.5 | Important | Denial of Service | Other / general Windows | Microsoft | Microsoft Remote Registry Service Denial of Service Vulnerability |
| CVE-2026-61924 | Normal | 6.5 | Important | Information Disclosure | Remote access / RDP | Microsoft | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-62902 | Normal | 6.5 | Important | Information Disclosure | Other / general Windows | Microsoft | .NET Information Disclosure Vulnerability |
| CVE-2026-62912 | Normal | 6.5 | Important | Denial of Service | Exchange / mail | Microsoft | Microsoft Exchange Server Denial of Service Vulnerability |
| CVE-2026-62915 | Normal | 6.5 | Important | Security Feature Bypass | Exchange / mail | Microsoft | Microsoft Exchange Server Security Feature Bypass Vulnerability |
| CVE-2026-65660 | Normal | 6.5 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-65813 | Normal | 6.5 | Important | Elevation of Privilege | Exchange / mail | Microsoft | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-65769 | Normal | 6.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Microsoft Teams iOS Information Disclosure Vulnerability |
| CVE-2026-66301 | Normal | 6.5 | Important | Information Disclosure | Cloud / M365 apps | Microsoft | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability |
| CVE-2026-70327 | Normal | 6.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-70328 | Normal | 6.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-65806 | Normal | 6.5 | Important | Information Disclosure | Cloud / M365 apps | Microsoft | Azure CycleCloud Information Disclosure Vulnerability |
| CVE-2026-61918 | Normal | 6.5 | Important | Information Disclosure | Remote access / RDP | Microsoft | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-61921 | Normal | 6.5 | Important | Information Disclosure | Remote access / RDP | Microsoft | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-62782 | Normal | 6.5 | Important | Information Disclosure | Network / infra servers | Microsoft | Windows SMB Client Information Disclosure Vulnerability |
| CVE-2026-65794 | Normal | 6.5 | Important | Information Disclosure | Network / infra servers | Microsoft | Windows SMB Client Information Disclosure Vulnerability |
| CVE-2026-58639 | Normal | 6.5 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-62839 | Normal | 6.5 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-56174 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Narrator Braille Elevation of Privilege Vulnerability |
| CVE-2026-54984 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Windows Imaging Component Remote Code Execution Vulnerability |
| CVE-2026-59127 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-61353 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-61356 | Normal | 7.8 | Important | Elevation of Privilege | Remote access / RDP | Microsoft | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2026-61367 | Normal | 7.8 | Important | Elevation of Privilege | Remote access / RDP | Microsoft | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2026-61923 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Display Enhancement Service Elevation of Privilege Vulnerability |
| CVE-2026-61937 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows HTTP.sys Elevation of Privilege Vulnerability |
| CVE-2026-62692 | Normal | 7.8 | Important | Elevation of Privilege | Remote access / RDP | Microsoft | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2026-61932 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-61934 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Bind Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-62695 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Storage Elevation of Privilege Vulnerability |
| CVE-2026-62707 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability |
| CVE-2026-62719 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Message Queuing Elevation of Privilege Vulnerability |
| CVE-2026-62722 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Bind Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-62739 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows HTTP.sys Elevation of Privilege Vulnerability |
| CVE-2026-62747 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Device Association Service Elevation of Privilege Vulnerability |
| CVE-2026-62754 | Normal | 7.8 | Important | Elevation of Privilege | Identity / AD | Microsoft | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2026-62755 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DHCP Client Elevation of Privilege Vulnerability |
| CVE-2026-62758 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
| CVE-2026-62772 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege Vulnerability |
| CVE-2026-62777 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows License Manager Elevation of Privilege Vulnerability |
| CVE-2026-62779 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Schannel Elevation of Privilege Vulnerability |
| CVE-2026-62797 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-62812 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DHCP Server Elevation of Privilege Vulnerability |
| CVE-2026-62876 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-62877 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-62894 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-62909 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | .NET Elevation of Privilege Vulnerability |
| CVE-2026-65656 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-65661 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-65671 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Remote Access API Elevation of Privilege Vulnerability |
| CVE-2026-65672 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Remote Access API Elevation of Privilege Vulnerability |
| CVE-2026-65786 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-65787 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-65814 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability |
| CVE-2026-68792 | Normal | 7.8 | Important | Elevation of Privilege | Office / productivity | Microsoft | Microsoft Office Elevation of Privilege Vulnerability |
| CVE-2026-68793 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68795 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68796 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68800 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68807 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68806 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68810 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68811 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68815 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-70311 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-70313 | Normal | 7.8 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft PowerPoint Remote Code Execution Vulnerability |
| CVE-2026-70344 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-70345 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-70346 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-70347 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-42976 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability |
| CVE-2026-54981 | Normal | 7.8 | Important | Security Feature Bypass | Other / general Windows | Microsoft | Visual Studio Code Python Extension Security Feature Bypass Vulnerability |
| CVE-2026-58641 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | .NET Elevation of Privilege Vulnerability |
| CVE-2026-58651 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-61349 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Work Folder Service Elevation of Privilege Vulnerability |
| CVE-2026-61359 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Storage Elevation of Privilege Vulnerability |
| CVE-2026-61355 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Sensor Data Service Elevation of Privilege Vulnerability |
| CVE-2026-61364 | Normal | 7.8 | Important | Elevation of Privilege | Remote access / RDP | Microsoft | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2026-61365 | Normal | 7.8 | Important | Elevation of Privilege | Remote access / RDP | Microsoft | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2026-61357 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Application Information Services Elevation of Privilege Vulnerability |
| CVE-2026-61926 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows USB Driver Elevation of Privilege Vulnerability |
| CVE-2026-62700 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-62701 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62710 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Device Association Service Elevation of Privilege Vulnerability |
| CVE-2026-62711 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-62717 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Message Queuing Elevation of Privilege Vulnerability |
| CVE-2026-62733 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-62732 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62736 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DHCP Client Elevation of Privilege Vulnerability |
| CVE-2026-62751 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Projected File System Elevation of Privilege Vulnerability |
| CVE-2026-62752 | Normal | 7.8 | Important | Elevation of Privilege | Identity / AD | Microsoft | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2026-62771 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-62761 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DHCP Server Elevation of Privilege Vulnerability |
| CVE-2026-62768 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-62770 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Shell Elevation of Privilege Vulnerability |
| CVE-2026-62799 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows SMB Client Elevation of Privilege Vulnerability |
| CVE-2026-62776 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DHCP Server Elevation of Privilege Vulnerability |
| CVE-2026-62803 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DHCP Server Elevation of Privilege Vulnerability |
| CVE-2026-62807 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DHCP Server Elevation of Privilege Vulnerability |
| CVE-2026-62811 | Normal | 7.8 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows HTTP.sys Elevation of Privilege Vulnerability |
| CVE-2026-62871 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | .NET Elevation of Privilege Vulnerability |
| CVE-2026-62880 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-62885 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-62886 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | .NET Elevation of Privilege Vulnerability |
| CVE-2026-63527 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-63533 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64904 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64905 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-64906 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Microsoft Access Remote Code Execution Vulnerability |
| CVE-2026-64912 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Microsoft Access Remote Code Execution Vulnerability |
| CVE-2026-64908 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Microsoft Access Remote Code Execution Vulnerability |
| CVE-2026-64914 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Microsoft Access Remote Code Execution Vulnerability |
| CVE-2026-64915 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-64920 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Microsoft Access Remote Code Execution Vulnerability |
| CVE-2026-64919 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | Microsoft Access Remote Code Execution Vulnerability |
| CVE-2026-65673 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft Entra Connect Elevation of Privilege Vulnerability |
| CVE-2026-65773 | Normal | 7.8 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-65774 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-65790 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Message Queuing Elevation of Privilege Vulnerability |
| CVE-2026-65810 | Normal | 7.8 | Important | Elevation of Privilege | Other / general Windows | Microsoft | .NET Framework Elevation of Privilege Vulnerability |
| CVE-2026-68798 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68801 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68803 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68805 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68812 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68814 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68817 | Normal | 7.8 | Important | Remote Code Execution | Office / productivity | Microsoft | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-70338 | Normal | 7.8 | Important | Security Feature Bypass | Other / general Windows | Microsoft | Microsoft PowerShell Security Feature Bypass Vulnerability |
| CVE-2026-70354 | Normal | 7.8 | Important | Remote Code Execution | Other / general Windows | Microsoft | .NET Core Remote Code Execution Vulnerability |
| CVE-2026-68821 | Normal | 7.3 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Package Manager Elevation of Privilege Vulnerability |
| CVE-2026-59119 | Normal | 7.3 | Important | Elevation of Privilege | Other / general Windows | Microsoft | PowerShell Elevation of Privilege Vulnerability |
| CVE-2026-50472 | Normal | 7.0 | Important | Elevation of Privilege | Virtualization / Hyper-V | Microsoft | Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-61346 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-61361 | Normal | 7.0 | Important | Remote Code Execution | Network / infra servers | Microsoft | Windows DHCP Client Remote Code Execution Vulnerability |
| CVE-2026-61366 | Normal | 7.0 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows Network Connection Broker Elevation of Privilege Vulnerability |
| CVE-2026-61927 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Bind Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-61939 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Winlogon Elevation of Privilege Vulnerability |
| CVE-2026-62690 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-62693 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows MIDI Service Module Elevation of Privileges Vulnerability |
| CVE-2026-62705 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Bind Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-62723 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62724 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62748 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62729 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62753 | Normal | 7.0 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows HTTP.sys Elevation of Privilege Vulnerability |
| CVE-2026-62773 | Normal | 7.0 | Important | Elevation of Privilege | Identity / AD | Microsoft | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2026-62774 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-62892 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability |
| CVE-2026-62897 | Normal | 7.0 | Important | Remote Code Execution | Other / general Windows | Microsoft | .NET Framework Remote Code Execution Vulnerability |
| CVE-2026-62908 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Backup Engine Elevation of Privilege Vulnerability |
| CVE-2026-65678 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-65783 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Autopilot Elevation of Privilege Vulnerability |
| CVE-2026-59122 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-59126 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Event Logging Service Elevation of Privilege Vulnerability |
| CVE-2026-61938 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-62725 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62726 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62728 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2026-62734 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62749 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-62780 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-65776 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-65779 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Autopilot Elevation of Privilege Vulnerability |
| CVE-2026-65780 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Autopilot Elevation of Privilege Vulnerability |
| CVE-2026-65778 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Autopilot Elevation of Privilege Vulnerability |
| CVE-2026-65782 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Autopilot Elevation of Privilege Vulnerability |
| CVE-2026-65781 | Normal | 7.0 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Windows Autopilot Elevation of Privilege Vulnerability |
| CVE-2026-62699 | Normal | 6.8 | Important | Remote Code Execution | Endpoints / Windows client | Microsoft | Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability |
| CVE-2026-62757 | Normal | 5.3 | Important | Security Feature Bypass | Other / general Windows | Microsoft | Windows Schannel Security Feature Bypass Vulnerability |
| CVE-2026-65777 | Normal | 5.3 | Important | Security Feature Bypass | Identity / AD | Microsoft | Active Directory Security Feature Bypass Vulnerability |
| CVE-2026-70304 | Normal | 6.7 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-70330 | Normal | 6.7 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-62769 | Normal | 6.7 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-62881 | Normal | 6.7 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-62883 | Normal | 6.7 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-65680 | Normal | 6.7 | Important | Elevation of Privilege | Other / general Windows | Microsoft | Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability |
| CVE-2026-65795 | Normal | 6.7 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-65797 | Normal | 6.7 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-65799 | Normal | 6.7 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-65798 | Normal | 6.7 | Important | Elevation of Privilege | Network / infra servers | Microsoft | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-62718 | Normal | 6.5 | Important | Information Disclosure | Network / infra servers | Microsoft | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62715 | Normal | 6.5 | Important | Information Disclosure | Network / infra servers | Microsoft | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62716 | Normal | 6.5 | Important | Information Disclosure | Network / infra servers | Microsoft | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62742 | Normal | 6.5 | Important | Information Disclosure | Network / infra servers | Microsoft | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62745 | Normal | 6.5 | Important | Information Disclosure | Network / infra servers | Microsoft | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62750 | Normal | 6.5 | Important | Tampering | Other / general Windows | Microsoft | Windows HTTP Protocol Stack Tampering Vulnerability |
| CVE-2026-65785 | Normal | 6.5 | Important | Denial of Service | Network / infra servers | Microsoft | Windows DHCP Client Denial of Service Vulnerability |
| CVE-2026-62720 | Normal | 6.5 | Important | Information Disclosure | Network / infra servers | Microsoft | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62714 | Normal | 6.5 | Important | Information Disclosure | Network / infra servers | Microsoft | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62814 | Normal | 6.5 | Important | Information Disclosure | Network / infra servers | Microsoft | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62708 | Normal | 6.4 | Important | Elevation of Privilege | Endpoints / Windows client | Microsoft | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-62829 | Normal | 4.6 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-64922 | Normal | 4.6 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-64897 | Normal | 4.6 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-64902 | Normal | 4.6 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-64916 | Normal | 4.6 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-62917 | Normal | 4.6 | Important | Spoofing | SharePoint owners | Microsoft | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-62882 | Normal | 4.3 | Important | Spoofing | Office / productivity | Microsoft | Microsoft Outlook Spoofing Vulnerability |
| CVE-2026-59130 | Normal | 5.6 | Important | Information Disclosure | Other / general Windows | Microsoft | AMD Zen Information Disclosure Vulnerability |
| CVE-2026-59131 | Normal | 5.6 | Important | Information Disclosure | Other / general Windows | Microsoft | AMD Zen Information Disclosure Vulnerability |
| CVE-2026-59128 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Encrypting File System (EFS) Information Disclosure Vulnerability |
| CVE-2026-59135 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Microsoft Windows Search Component Information Disclosure Vulnerability |
| CVE-2026-59136 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Microsoft COM for Windows Information Disclosure Vulnerability |
| CVE-2026-59137 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Event Logging Service Information Disclosure Vulnerability |
| CVE-2026-61347 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Event Logging Service Information Disclosure Vulnerability |
| CVE-2026-61928 | Normal | 5.5 | Important | Tampering | Other / general Windows | Microsoft | Windows Hello Tampering Vulnerability |
| CVE-2026-61933 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-61936 | Normal | 5.5 | Important | Security Feature Bypass | Cloud / M365 apps | Microsoft | Windows Defender Firewall Service Security Feature Bypass Vulnerability |
| CVE-2026-62703 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-62746 | Normal | 5.5 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Win32k Information Disclosure Vulnerability |
| CVE-2026-62740 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Imaging Component Information Disclosure Vulnerability |
| CVE-2026-62798 | Normal | 5.5 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Win32k Information Disclosure Vulnerability |
| CVE-2026-62796 | Normal | 5.5 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-54123 | Normal | 5.5 | Important | Information Disclosure | Cloud / M365 apps | Microsoft | Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability |
| CVE-2026-63517 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Graphics Component Information Disclosure Vulnerability |
| CVE-2026-63521 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-65662 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows GDI Information Disclosure Vulnerability |
| CVE-2026-65784 | Normal | 5.5 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-68802 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-68808 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-68809 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-68813 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-70312 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-70310 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-70316 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-70315 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-70318 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-70314 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-70317 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-70325 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-70319 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-70320 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-70323 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-70322 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-70348 | Normal | 5.5 | Important | Denial of Service | Other / general Windows | Microsoft | Windows Management Services Denial of Service Vulnerability |
| CVE-2026-61360 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows GDI Information Disclosure Vulnerability |
| CVE-2026-62709 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows GDI+ Information Disclosure Vulnerability |
| CVE-2026-62743 | Normal | 5.5 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Win32k Information Disclosure Vulnerability |
| CVE-2026-62730 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Wired AutoConfig Service Information Disclosure Vulnerability |
| CVE-2026-62775 | Normal | 5.5 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability |
| CVE-2026-62786 | Normal | 5.5 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Win32k Information Disclosure Vulnerability |
| CVE-2026-62793 | Normal | 5.5 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-62887 | Normal | 5.5 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-62842 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Graphics Component Information Disclosure Vulnerability |
| CVE-2026-63524 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-63528 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-63529 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-63530 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-63531 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-64899 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-64917 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-66806 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-66810 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-66809 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Office Graphics Component Information Disclosure Vulnerability |
| CVE-2026-68797 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-68799 | Normal | 5.5 | Important | Information Disclosure | Office / productivity | Microsoft | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-62738 | Normal | 5.5 | Important | Information Disclosure | Other / general Windows | Microsoft | Windows Management Instrumentation Information Disclosure Vulnerability |
| CVE-2026-6727 | Normal | 5.9 | Important | Information Disclosure | Other / general Windows | Microsoft | MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability |
| CVE-2026-61368 | Normal | 5.0 | Important | Information Disclosure | Virtualization / Hyper-V | Microsoft | Windows Hyper-V Information Disclosure Vulnerability |
| CVE-2026-70339 | Normal | 5.4 | Important | Remote Code Execution | Browser (Edge auto-update) | Microsoft | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-61350 | Normal | 4.6 | Important | Information Disclosure | Endpoints / Windows client | Microsoft | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-64584 | Normal worm | 9.8 | Important | — | Other / general Windows | Linux / other | usb: gadget: f_midi: cancel pending IN work before freeing the midi object |
| CVE-2026-64594 | Normal worm | 9.8 | Important | — | Other / general Windows | Linux / other | usb: gadget: f_fs: initialize reset_work at allocation time |
| CVE-2026-64593 | Normal worm | 9.8 | Important | — | Other / general Windows | Linux / other | btrfs: do not trim a device which is not writeable |
| CVE-2026-64597 | Normal worm | 8.6 | Important | — | Network / infra servers | Linux / other | smb: client: fix double-free in SMB2_close() replay |
| CVE-2026-68082 | Normal worm | 8.2 | Important | — | Other / general Windows | Linux / other | libceph: fix two unsafe bare decodes in decode_lockers() |
| CVE-2026-64577 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | gtp: check skb_pull_data() return in gtp1u_send_echo_resp() |
| CVE-2026-69152 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation |
| CVE-2025-49506 | Normal worm | 7.5 | Important | — | Office / productivity | Linux / other | Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack |
| CVE-2026-34501 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | Apache Portable Runtime Utility: Heap buffer overflow in APR redis client |
| CVE-2026-34502 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client |
| CVE-2026-54876 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | Client-Side Memory Leak in OCSP Response Checking |
| CVE-2026-65819 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | gopacket: Multiple layer decoders panic on crafted packets (out-of-bounds/underflow) enabling unauthenticated remote DoS via DecodingLayerParser |
| CVE-2026-68155 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | libceph: Reject monmaps advertising zero monitors |
| CVE-2026-68320 | Normal worm | 7.5 | Important | — | Other / general Windows | Linux / other | sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid |
| CVE-2026-68373 | Normal worm | 7.5 | Moderate | — | Other / general Windows | Linux / other | wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() |
| CVE-2026-68299 | Normal worm | 7.5 | Moderate | — | Other / general Windows | Linux / other | vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets |
| CVE-2026-71225 | Normal worm | 6.5 | Moderate | — | Other / general Windows | Linux / other | Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries |
| CVE-2026-68158 | Normal worm | 6.5 | Moderate | — | Other / general Windows | Linux / other | libceph: Fix multiplication overflow in decode_new_up_state_weight() |
| CVE-2026-64578 | Normal worm | 6.5 | Moderate | — | Other / general Windows | Linux / other | ksmbd: validate compound request size before reading StructureSize2 |
| CVE-2026-70368 | Normal worm | 6.5 | Moderate | — | Other / general Windows | Linux / other | Stunnel: stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message |
| CVE-2026-68381 | Normal worm | 5.9 | Moderate | — | Other / general Windows | Linux / other | ksmbd: pin conn during async oplock break notification |
| CVE-2026-68366 | Normal | 8.1 | Important | — | Other / general Windows | Linux / other | usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer |
| CVE-2026-6726 | Normal | 7.9 | Important | Spoofing | Other / general Windows | Linux / other | MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot Reuse |
| CVE-2026-59125 | Normal | 7.0 | Important | Elevation of Privilege | Endpoints / Windows client | Linux / other | Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability |
| CVE-2026-32327 | Normal worm | 5.3 | Moderate | — | Other / general Windows | Linux / other | Apache Portable Runtime Utility: apr-util XML stack recursion crash |
| CVE-2026-69153 | Normal worm | 5.3 | Moderate | — | Other / general Windows | Linux / other | PostCSS: incomplete fix of CVE-2026-45623 — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset |
| CVE-2026-68118 | Normal worm | 5.3 | Moderate | — | Other / general Windows | Linux / other | tcp: challenge ACK for non-exact RST in SYN-RECEIVED |
| CVE-2026-68343 | Normal worm | 5.3 | Moderate | — | Network / infra servers | Linux / other | smb: client: validate DFS referral PathConsumed |
| CVE-2026-68480 | Normal | 8.8 | Important | — | Other / general Windows | Linux / other | x86/bugs: Make Safe-RET robust against interrupt injection |
| CVE-2026-71556 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | go-git: Worktree operations may follow symlinks |
| CVE-2026-68130 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | ksmbd: defer destroy_previous_session() until after NTLM authentication |
| CVE-2026-64604 | Normal | 8.4 | Important | — | Other / general Windows | Linux / other | KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode |
| CVE-2026-68129 | Normal | 6.5 | Moderate | — | Other / general Windows | Linux / other | gve: fix Rx queue stall on alloc failure |
| CVE-2026-68116 | Normal | 6.5 | Moderate | — | Other / general Windows | Linux / other | vxlan: mdb: Fix source list corruption on a failed replace |
| CVE-2026-68098 | Normal | 6.5 | Moderate | — | Other / general Windows | Linux / other | ksmbd: bound DACL dedup walk to copied ACEs |
| CVE-2026-68186 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | binfmt_misc: set have_execfd only once the interpreter is opened |
| CVE-2026-68152 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | amt: fix use-after-free in AMT delayed works |
| CVE-2026-68318 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | pds_core: fix use-after-free on workqueue during remove |
| CVE-2026-68335 | Normal | 7.8 | Important | — | Network / infra servers | Linux / other | rds: drop incoming messages that cross network namespace boundaries |
| CVE-2026-68416 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | mtd: fix double free and WARN_ON in add_mtd_device() error paths |
| CVE-2026-68188 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | Bluetooth: RFCOMM: Fix session UAF in set_termios |
| CVE-2026-68181 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | mei: bus: access mei_device under device_lock on cleanup |
| CVE-2026-68108 | Normal | 7.8 | Important | — | Other / general Windows | Linux / other | drm/amdgpu/vce: fix integer overflow in image size |
| CVE-2026-68097 | Normal | 6.3 | Moderate | — | Other / general Windows | Linux / other | ksmbd: validate ACE size against SID sub-authorities |
| CVE-2026-71557 | Normal | 6.3 | Moderate | — | Endpoints / Windows client | Linux / other | go-git: Malicious reference names may modify files outside the reference storage |
| CVE-2026-68124 | Normal | 7.7 | Important | — | Other / general Windows | Linux / other | mctp: serial: handle zero-length frames to prevent rx buffer overflow |
| CVE-2026-68376 | Normal worm | 3.7 | Low | — | Other / general Windows | Linux / other | sctp: fix auth_hmacs array size in struct sctp_cookie |
| CVE-2026-71226 | Normal | 7.3 | Important | — | Other / general Windows | Linux / other | Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path |
| CVE-2026-68337 | Normal | 7.3 | Moderate | — | Other / general Windows | Linux / other | bpf: Reject redirect helpers without a bpf_net_context |
| CVE-2026-64590 | Normal | 7.1 | Important | — | Other / general Windows | Linux / other | dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning |
| CVE-2026-64583 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown |
| CVE-2026-68353 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler |
| CVE-2026-68351 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read |
| CVE-2026-68083 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | ksmbd: fix path resolution in ksmbd_vfs_kern_path_create |
| CVE-2026-68352 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | wifi: ath6kl: fix OOB read from firmware IE lengths in connect event |
| CVE-2026-68397 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | net/iucv: take a reference on the socket found in afiucv_hs_rcv() |
| CVE-2026-68350 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | wifi: carl9170: fix OOB read from off-by-two in TX status handler |
| CVE-2026-68371 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | usb: musb: omap2430: Do not put borrowed of_node in probe |
| CVE-2026-68414 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | wifi: cfg80211: cancel sched scan results work on unregister |
| CVE-2026-68182 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | comedi: comedi_parport: deal with premature interrupt |
| CVE-2026-68284 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() |
| CVE-2026-68165 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | mm/damon/core: validate ranges in damon_set_regions() |
| CVE-2026-68199 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | wifi: ath6kl: fix OOB access from firmware ADDBA window size |
| CVE-2026-68368 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() |
| CVE-2026-68135 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | net: hip04: fix RX buffer leak on build_skb failure |
| CVE-2026-68294 | Normal | 7.1 | Moderate | — | Network / infra servers | Linux / other | net: qrtr: restrict socket creation to the initial network namespace |
| CVE-2026-68162 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | sctp: avoid auth_enable sysctl UAF during netns teardown |
| CVE-2026-68085 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled |
| CVE-2026-68104 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | drm/amdgpu: invoke pm_genpd_remove() before freeing genpd |
| CVE-2026-68348 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | ASoC: tas2781: bound firmware description string parsing |
| CVE-2026-68365 | Normal | 7.1 | Moderate | — | Browser (Edge auto-update) | Linux / other | USB: serial: io_edgeport: cap received transmit credits |
| CVE-2026-68286 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | drop_monitor: perform u64_stats updates under IRQ-disabled section |
| CVE-2026-68306 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() |
| CVE-2026-68138 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | net/sched: serialize qdisc_rtab_list against concurrent get/put |
| CVE-2026-68088 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | usb: gadget: function: rndis: add length check to response query |
| CVE-2026-68204 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | media: vivid: check for vb2_is_busy() when toggling caps |
| CVE-2026-68084 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | staging: vme_user: fix location monitor leak in tsi148 bridge |
| CVE-2026-72568 | Normal | 7.1 | Moderate | — | Other / general Windows | Linux / other | Redis - Heap Out-of-Bounds Read in Cluster Bus PING Message Handler |
| CVE-2026-68329 | Normal | 7.0 | Moderate | — | Other / general Windows | Linux / other | iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() |
| CVE-2026-70367 | Normal | 5.4 | Moderate | — | Other / general Windows | Linux / other | Stunnel: ssrf bypass in stunnel socks proxy via ipv4-mapped ipv6 loopback and unspecified addresses allows access to loopback-only services |
| CVE-2026-68156 | Normal | 5.3 | Moderate | — | Other / general Windows | Linux / other | libceph: refresh auth->authorizer_buf{,_len} after authorizer update |
| CVE-2026-68093 | Normal | 6.7 | Moderate | — | Other / general Windows | Linux / other | KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug |
| CVE-2026-68086 | Normal | 6.6 | Moderate | — | Other / general Windows | Linux / other | mm/khugepaged: write all dirty file folios when collapsing |
| CVE-2026-68411 | Normal | 6.5 | Moderate | — | Other / general Windows | Linux / other | wifi: mac80211_hwsim: clamp virtio RX length before skb_put |
| CVE-2026-68136 | Normal | 6.5 | Moderate | — | Other / general Windows | Linux / other | net: gro: fix double aggregation of flush-marked skbs |
| CVE-2026-68125 | Normal | 6.5 | Moderate | — | Other / general Windows | Linux / other | mac802154: llsec: reject frames shorter than the authentication tag |
| CVE-2026-68159 | Normal | 6.5 | Moderate | — | Other / general Windows | Linux / other | libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE |
| CVE-2026-68323 | Normal | 6.3 | Moderate | — | Other / general Windows | Linux / other | tipc: serialize udp bearer replicast list updates |
| CVE-2026-68361 | Normal | 6.3 | Moderate | — | Other / general Windows | Linux / other | hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop |
| CVE-2026-68196 | Normal | 6.3 | Moderate | — | Other / general Windows | Linux / other | wifi: wilc1000: validate assoc response length before subtracting header |
| CVE-2026-64573 | Normal | 6.3 | Moderate | — | Other / general Windows | Linux / other | Bluetooth: qca: fix NVM tag length underflow in TLV parser |
| CVE-2026-72522 | Normal | 6.2 | Moderate | — | Other / general Windows | Linux / other | libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions. |
| CVE-2026-71497 | Normal | 4.7 | Moderate | — | Other / general Windows | Linux / other | jsoup: Cleaner may expose markup with custom raw-text elements |
| CVE-2026-68273 | Normal | 6.1 | Moderate | — | Other / general Windows | Linux / other | drm/amdgpu: Fix context pstate override handling |
| CVE-2026-68187 | Normal | 6.1 | Moderate | — | Other / general Windows | Linux / other | exec: fix unsigned loop counter wrap in transfer_args_to_stack() |
| CVE-2026-68326 | Normal | 6.1 | Moderate | — | Other / general Windows | Linux / other | wifi: mwifiex: bound uAP association event IEs to the event buffer |
| CVE-2026-68081 | Normal | 6.0 | Moderate | — | Other / general Windows | Linux / other | KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state |
| CVE-2026-68100 | Normal | 4.3 | Moderate | — | Other / general Windows | Linux / other | ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl |
| CVE-2026-68099 | Normal | 4.3 | Moderate | — | Other / general Windows | Linux / other | ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL |
| CVE-2026-64676 | Normal | 5.7 | Moderate | — | Other / general Windows | Linux / other | Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memory |
| CVE-2026-15534 | Normal | 5.7 | Moderate | — | Other / general Windows | Linux / other | Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch |
| CVE-2026-68123 | Normal | 5.7 | Moderate | — | Other / general Windows | Linux / other | openvswitch: fix GSO userspace truncation underflow |
| CVE-2026-64569 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n |
| CVE-2026-64561 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | KVM: x86: Check for invalid/obsolete root *after* making MMU pages available |
| CVE-2026-64585 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | can: esd_usb: kill anchored URBs before freeing netdevs |
| CVE-2026-64586 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | wifi: brcmfmac: drain bus_reset work on device removal |
| CVE-2026-64599 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | crypto: amlogic - avoid double cleanup in meson_crypto_probe() |
| CVE-2026-64598 | Normal | 5.5 | Moderate | — | Network / infra servers | Linux / other | smb/client: Fix error code in smb2_aead_req_alloc() |
| CVE-2026-44605 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | Rpm: heap buffer overflow in ndb slot table parsing |
| CVE-2026-68258 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/amdkfd: Check bounds on CRIU restore queue type and mqd size |
| CVE-2026-68203 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | media: vivid: fix cleanup bugs in vivid_init() |
| CVE-2026-68114 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON() |
| CVE-2026-68183 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | firmware: stratix10-svc: fix memory leaks and list corruption bugs |
| CVE-2026-68412 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan() |
| CVE-2026-68242 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/i915/gt: Fix NULL deref on sched_engine alloc failure |
| CVE-2026-68252 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() |
| CVE-2026-68374 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | usb: core: sysfs: add lock to bos_descriptors_read() |
| CVE-2026-68254 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/i915/vrr: require valid min/max vfreq for VRR |
| CVE-2026-68272 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 |
| CVE-2026-68197 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper |
| CVE-2026-68249 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() |
| CVE-2026-68297 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | tipc: fix u16 MTU truncation in media and bearer MTU validation |
| CVE-2026-68141 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() |
| CVE-2026-68110 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() |
| CVE-2026-68206 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | media: v4l2-ctrls: validate HEVC active reference counts |
| CVE-2026-68195 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses |
| CVE-2026-68111 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() |
| CVE-2026-68145 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | iomap: fix out-of-bounds bitmap_set() with zero-length range |
| CVE-2026-68255 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/virtio: bound EDID block reads to the response buffer |
| CVE-2026-68115 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() |
| CVE-2026-68222 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | media: msi2500: Return queued buffers on start_streaming() failure |
| CVE-2026-68331 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | dpaa2-eth: put MAC endpoint device on disconnect |
| CVE-2026-68231 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | media: airspy: Return queued buffers on start_streaming() failure |
| CVE-2026-68112 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() |
| CVE-2026-68175 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | tracing: Fix resource leak on mmiotrace trace_pipe close |
| CVE-2026-68328 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | nfp: Check resource mutex allocation |
| CVE-2026-68217 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | media: pwc: Drain fill_buf on start_streaming() failure |
| CVE-2026-68250 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() |
| CVE-2026-68408 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock |
| CVE-2026-68369 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | usb: gadget: printer: fix infinite loop in printer_read() |
| CVE-2026-68137 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | net/x25: fix use-after-free in x25_kill_by_neigh() |
| CVE-2026-68202 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | ALSA: seq: close a re-opened queue timer in the destructor |
| CVE-2026-68154 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | libceph: reject zero bucket types in crush_decode |
| CVE-2026-68223 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | media: meson: vdec: Fix memory leak in error path of vdec_open |
| CVE-2026-68303 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/vc4: hvs/v3d: Fix null dereference in unbind |
| CVE-2026-68109 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON() |
| CVE-2026-68336 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | bonding: fix devconf_all NULL dereference when IPv6 is disabled |
| CVE-2026-68300 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | sctp: auth: verify auth requirement when auth_chunk is NULL |
| CVE-2026-68257 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/amdkfd: fix 32-bit overflow in CWSR total size calculation |
| CVE-2026-68157 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | libceph: guard missing CRUSH type name lookup |
| CVE-2026-68392 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync |
| CVE-2026-68113 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() |
| CVE-2026-68367 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | usb: gadget: f_tcm: synchronize delayed set_alt with teardown |
| CVE-2026-68386 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | bpf, sockmap: Reject unhashed UDP sockets on sockmap update |
| CVE-2026-68219 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | media: nxp: imx8-isi: Fix potential out-of-bounds issues |
| CVE-2026-68396 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | scsi: core: wake eh reliably when using scsi_schedule_eh |
| CVE-2026-68246 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() |
| CVE-2026-68106 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/amdgpu: fix division by zero with invalid uvd dimensions |
| CVE-2026-68293 | Normal | 5.5 | Moderate | — | Office / productivity | Linux / other | net/mlx5: Fix MCIA register buffer overflow on 32 dword reads |
| CVE-2026-68149 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | fs: preserve ACL_DONT_CACHE state in forget_cached_acl() |
| CVE-2026-68410 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | wifi: libertas: fix memory leak in helper_firmware_cb() |
| CVE-2026-68418 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | RDMA/irdma: Prevent user-triggered null deref on QP create |
| CVE-2026-68090 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | debugobjects: Plug race against a concurrent OOM disable |
| CVE-2026-68247 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/i915/bios: range check LFP Data Block panel_type2 |
| CVE-2026-68147 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | fscrypt: Avoid dynamic allocation in fscrypt_get_devices() |
| CVE-2026-68184 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | cdrom: fix stack out-of-bounds read in CDROMVOLCTRL |
| CVE-2026-68401 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit() |
| CVE-2026-68322 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled |
| CVE-2026-68327 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | wan: wanxl: Only reset hardware after BAR mapping |
| CVE-2026-68271 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/nouveau: fix reversed error cleanup order in ucopy functions |
| CVE-2026-68313 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | tipc: fix infinite loop in __tipc_nl_compat_dumpit |
| CVE-2026-68102 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/amdgpu: fix aperture mapping leak |
| CVE-2026-68370 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback |
| CVE-2026-68243 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU |
| CVE-2026-64563 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | rhashtable: clear stale iter->p on table restart |
| CVE-2026-64602 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | iio: adc: spear: Initialize completion before requesting IRQ |
| CVE-2026-68289 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() |
| CVE-2026-68308 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() |
| CVE-2026-68333 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | dpaa2-switch: put MAC endpoint device on disconnect |
| CVE-2026-68427 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings |
| CVE-2026-68161 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | sctp: close UDP tunnel sockets during netns teardown |
| CVE-2026-68338 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | net/packet: avoid fanout hook re-registration after unregister |
| CVE-2026-68096 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | audit: fix recursive locking deadlock in audit_dupe_exe() |
| CVE-2026-68389 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | Bluetooth: hci_qca: Clear memdump state on invalid dump size |
| CVE-2026-68194 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses |
| CVE-2026-68215 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | media: radio-si476x: Unregister v4l2_device on probe failure |
| CVE-2026-68091 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | HID: wacom: stop hardware after post-start probe failures |
| CVE-2026-68205 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() |
| CVE-2026-68259 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/amdkfd: Check bounds in allocate_event_notification_slot |
| CVE-2026-68164 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | mm/damon/core: disallow overlapping input ranges for damon_set_regions() |
| CVE-2026-68253 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/i915/hdcp: check streams[] bounds before overflow |
| CVE-2026-68339 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | Bluetooth: btusb: validate Realtek vendor event length |
| CVE-2026-68216 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | media: pwc: Return queued buffers on start_streaming() failure |
| CVE-2026-68251 | Normal | 5.5 | Moderate | — | Other / general Windows | Linux / other | drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() |
| CVE-2026-68315 | Normal | 5.3 | Moderate | — | Other / general Windows | Linux / other | sctp: validate stream count in sctp_process_strreset_inreq() |
| CVE-2026-64581 | Normal | 5.1 | Moderate | — | Other / general Windows | Linux / other | xfrm: fix sk_dst_cache double-free in xfrm_user_policy() |
| CVE-2026-71227 | Normal | 5.1 | Moderate | Denial of Service | Other / general Windows | Linux / other | Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return |
| CVE-2026-68151 | Normal | 5.0 | Moderate | — | Other / general Windows | Linux / other | binfmt_elf_fdpic: only honour the first PT_INTERP |
| CVE-2026-68409 | Normal | 4.8 | Moderate | — | Other / general Windows | Linux / other | wifi: mac80211: defer link RX stats percpu free to RCU |
| CVE-2026-64572 | Normal | 4.7 | Moderate | — | Other / general Windows | Linux / other | ipv4: fib: free fib_alias with kfree_rcu() on insert error path |
| CVE-2026-68189 | Normal | 4.7 | Moderate | — | Other / general Windows | Linux / other | Bluetooth: hci_sync: Protect UUID list traversal |
| CVE-2026-68362 | Normal | 4.7 | Moderate | — | Other / general Windows | Linux / other | wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin |
| CVE-2026-68148 | Normal | 4.7 | Moderate | — | Other / general Windows | Linux / other | fscrypt: Add missing superblock check in find_or_insert_direct_key() |
| CVE-2026-68405 | Normal | 4.7 | Moderate | — | Other / general Windows | Linux / other | wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock |
| CVE-2026-68404 | Normal | 4.7 | Moderate | — | Other / general Windows | Linux / other | wifi: cfg80211: use wiphy work for socket owner autodisconnect |
| CVE-2026-68426 | Normal | 4.7 | Moderate | — | Other / general Windows | Linux / other | xfrm: fix stale skb->prev after async crypto steals a GSO segment |
| CVE-2026-68245 | Normal | 4.7 | Moderate | — | Other / general Windows | Linux / other | drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() |
| CVE-2026-68233 | Normal | 4.7 | Moderate | — | Other / general Windows | Linux / other | drm/vc4: Shut down BO cache timer before teardown |
| CVE-2026-68169 | Normal | 4.7 | Moderate | — | Other / general Windows | Linux / other | mptcp: pm: userspace: fix use-after-free in get_local_id |
| CVE-2026-68241 | Normal | 4.6 | Moderate | — | Other / general Windows | Linux / other | drm/i915/mst: limit DP MST ESI service loop |
| CVE-2026-68278 | Normal | 4.6 | Moderate | — | Other / general Windows | Linux / other | drm/dp/mst: fix buffer overflows in sideband chunk accumulation |
| CVE-2026-64567 | Normal | 4.4 | Moderate | — | Other / general Windows | Linux / other | btrfs: reject free space cache with more entries than pages |
| CVE-2026-68388 | Normal | 4.4 | Moderate | — | Network / infra servers | Linux / other | smb/client: handle overlapping allocated ranges in fallocate |
| CVE-2026-68419 | Normal | 4.4 | Moderate | — | Other / general Windows | Linux / other | RDMA/irdma: Prevent rereg_mr for non-mem regions |
| CVE-2026-68103 | Normal | 4.4 | Moderate | — | Other / general Windows | Linux / other | drm/amdgpu: reject mapping a reserved doorbell to a new queue |
| CVE-2026-18508 | Normal | 4.4 | Moderate | — | Other / general Windows | Linux / other | Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite |
| CVE-2026-18477 | Normal | 4.4 | Moderate | — | Other / general Windows | Linux / other | Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape |
| CVE-2026-68190 | Normal | 4.3 | Moderate | — | Other / general Windows | Linux / other | staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() |
| CVE-2026-68235 | Normal | 4.3 | Moderate | — | Other / general Windows | Linux / other | drm/amd/display: dce100: skip non-DP stream encoders for DP MST |
| CVE-2026-68425 | Normal | 4.3 | Moderate | — | Other / general Windows | Linux / other | IB/mad: Drop unmatched RMPP responses before reassembly |
| CVE-2026-64576 | Normal | 4.1 | Moderate | — | Other / general Windows | Linux / other | nexthop: initialize extack in nh_res_bucket_migrate() |
| CVE-2026-68317 | Normal | 4.1 | Moderate | — | Other / general Windows | Linux / other | pds_core: fix auxiliary device add/del races |
| CVE-2026-68192 | Normal | 4.1 | Moderate | — | Other / general Windows | Linux / other | wifi: brcmfmac: make release_scratchbuffers idempotent |
| CVE-2026-68126 | Normal | 4.1 | Moderate | — | Other / general Windows | Linux / other | mac802154: hold an interface reference across the scan worker |
| CVE-2026-64574 | Normal | 4.1 | Moderate | — | Other / general Windows | Linux / other | wifi: mac80211: tear down new links on vif update error path |
| CVE-2026-64579 | Normal | 4.1 | Moderate | — | Other / general Windows | Linux / other | xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert |
| CVE-2026-64580 | Normal | 4.1 | Moderate | — | Other / general Windows | Linux / other | xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() |
| CVE-2026-68105 | Normal | 4.1 | Moderate | — | Endpoints / Windows client | Linux / other | drm/amdgpu: Fix kernel panic during driver load failure |
| CVE-2026-68117 | Normal | 3.6 | Low | — | Other / general Windows | Linux / other | tipc: clear sock->sk on the failed-insert path in tipc_sk_create() |
| CVE-2026-64652 | Normal | 3.3 | — | — | Other / general Windows | Linux / other | GitHub CLI: Partial token disclosure in `gh auth status` output |
| CVE-2026-68288 | Normal | 3.3 | Low | — | Other / general Windows | Linux / other | net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD |
| CVE-2026-68256 | Normal | 3.3 | Low | — | Other / general Windows | Linux / other | drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference |
| CVE-2026-68238 | Normal | 3.3 | Low | — | Other / general Windows | Linux / other | drm/amdgpu: Release VFCT ACPI table reference |
| CVE-2026-68312 | Normal | 3.3 | Low | — | Other / general Windows | Linux / other | cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths |
| CVE-2026-68234 | Normal | 3.3 | Low | — | Other / general Windows | Linux / other | drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved |
| CVE-2026-68277 | Normal | 3.3 | Low | — | Other / general Windows | Linux / other | drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers |
| CVE-2026-68280 | Normal | 3.3 | Low | — | Other / general Windows | Linux / other | drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() |
| CVE-2026-68422 | Normal | 3.3 | Low | — | Other / general Windows | Linux / other | btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() |
| CVE-2026-68301 | Normal | 3.3 | Low | — | Other / general Windows | Linux / other | net: hsr: fix memory leak on slave unregistration by removing synced VLANs |
| CVE-2026-68229 | Normal | 3.3 | Low | — | Other / general Windows | Linux / other | media: cedrus: skip invalid H.264 reference list entries |
| CVE-2026-68209 | Normal | 3.3 | Low | — | Other / general Windows | Linux / other | media: sun4i-csi: Return queued buffers on start_streaming() failure |
| CVE-2026-68304 | Normal | 3.3 | Low | — | Other / general Windows | Linux / other | wifi: brcmfmac: fix 802.1X-SHA256 call trace warning |
| CVE-2026-68244 | Normal | 3.3 | Low | — | Other / general Windows | Linux / other | drm/i915/gem: Do not leak siblings[] on proto context error |
| CVE-2026-68302 | Normal | 3.3 | Low | — | Other / general Windows | Linux / other | amt: re-read skb header pointers after every pull |
| CVE-2026-68220 | Normal | 3.3 | Low | — | Other / general Windows | Linux / other | media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe |
| CVE-2026-64571 | Normal | 3.2 | Low | — | Other / general Windows | Linux / other | wifi: p54: validate RX frame length in p54_rx_eeprom_readback() |
| CVE-2026-18739 | Normal | 2.5 | Low | — | Other / general Windows | Linux / other | Popt-devel: popt-static: off-by-one in poptstuffargs |
| CVE-2026-68355 | Normal | 2.5 | Low | — | Other / general Windows | Linux / other | wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() |
| CVE-2026-68417 | Normal | 2.5 | Low | — | Other / general Windows | Linux / other | RDMA/siw: publish QP after initialization |
| CVE-2026-68309 | Normal | 2.5 | Low | — | Other / general Windows | Linux / other | wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() |
| CVE-2026-68248 | Normal | 2.5 | Low | — | Other / general Windows | Linux / other | drm/i915: Return NULL on error in active_instance |
| CVE-2026-68269 | Normal | 2.5 | Low | — | Other / general Windows | Linux / other | drm/i915/gem: Add missing nospec on parallel submit slot |
| CVE-2026-68403 | Normal | 2.5 | Low | — | Other / general Windows | Linux / other | wifi: brcmfmac: initialize SDIO data work before cleanup |
| CVE-2026-68226 | Normal | 2.5 | Low | — | Other / general Windows | Linux / other | media: cx23885: add ioremap return check and cleanup |
| CVE-2026-68107 | Normal | 2.5 | Low | — | Other / general Windows | Linux / other | drm/amdgpu/vcn4: avoid rereading IB param length |
| CVE-2026-68279 | Normal | 2.4 | Low | — | Other / general Windows | Linux / other | drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers |
| CVE-2026-61477 | Normal | 2.3 | — | — | Network / infra servers | Linux / other | Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection |
| CVE-2026-18839 | Normal | 2.2 | Low | — | Other / general Windows | Linux / other | Popt-devel: popt-static: size_t underflow in singleoptionhelp |
| CVE-2026-68363 | Normal | 2.0 | Low | — | Other / general Windows | Linux / other | wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request |
| CVE-2026-68171 | Normal | 1.9 | Low | — | Other / general Windows | Linux / other | arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates |
| CVE-2026-19137 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19137 Use after free in WebGL |
| CVE-2026-19140 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19140 Use after free in GPU |
| CVE-2026-19138 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19138 Heap buffer overflow in CrashReporting |
| CVE-2026-19139 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19139 Race in CredentialProvider |
| CVE-2026-19145 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19145 Use after free in Translate |
| CVE-2026-19142 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19142 Use after free in Views |
| CVE-2026-19144 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19144 Use after free in HTML |
| CVE-2026-19146 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19146 Uninitialized Use in GPU |
| CVE-2026-19147 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19147 Use after free in Aura |
| CVE-2026-19149 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19149 Use after free in Aura |
| CVE-2026-19148 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19148 Out of bounds write in GPU |
| CVE-2026-19151 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19151 Use after free in V8 |
| CVE-2026-19153 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19153 Insufficient validation of untrusted input in Workers |
| CVE-2026-19152 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19152 Inappropriate implementation in Navigation |
| CVE-2026-19155 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19155 Use after free in Payments |
| CVE-2026-19158 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19158 Use after free in Views |
| CVE-2026-19157 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19157 Out of bounds write in ANGLE |
| CVE-2026-19156 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19156 Heap buffer overflow in Base |
| CVE-2026-19150 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19150 Inappropriate implementation in V8 |
| CVE-2026-19161 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19161 Uninitialized Use in Skia |
| CVE-2026-19162 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19162 Out of bounds write in V8 |
| CVE-2026-19160 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19160 Uninitialized Use in Skia |
| CVE-2026-19163 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19163 Use after free in Media |
| CVE-2026-19159 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19159 Use after free in Views |
| CVE-2026-19164 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19164 Insufficient validation of untrusted input in Codecs |
| CVE-2026-19165 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19165 Use after free in Extensions |
| CVE-2026-19167 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19167 Integer overflow in GPU |
| CVE-2026-19166 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19166 Use after free in Web Authentication |
| CVE-2026-19170 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19170 Use after free in WebGL |
| CVE-2026-19169 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19169 Insufficient validation of untrusted input in Contextual Tasks |
| CVE-2026-19173 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19173 Out of bounds write in Skia |
| CVE-2026-19172 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19172 Use after free in Views |
| CVE-2026-19168 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19168 Inappropriate implementation in V8 |
| CVE-2026-19174 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19174 Integer overflow in V8 |
| CVE-2026-19176 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19176 Use after free in Skia |
| CVE-2026-19171 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19171 Use after free in Media |
| CVE-2026-19175 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19175 Use after free in Payments |
| CVE-2026-19177 | Normal | — | — | — | Other / general Windows | Linux / other | CVE-2026-19177 Insufficient validation of untrusted input in UI |
| CVE-2024-26464 | Normal | — | — | — | Other / general Windows | Linux / other | |
| CVE-2024-31745 | Normal | — | — | — | Other / general Windows | Linux / other | |
| CVE-2026-19025 | Normal | — | Moderate | — | Other / general Windows | Linux / other | HDF5 divide-by-zero (SIGFPE) via mismatched chunk-layout dimensionality and dataspace rank on dataset open |
| CVE-2026-19027 | Normal | — | Moderate | — | Other / general Windows | Linux / other | HDF5 out-of-bounds heap read in N-Bit filter decompression |
| CVE-2026-19026 | Normal | — | Moderate | — | Other / general Windows | Linux / other | Nbit filter NULL/short parameter-array dereference |
| CVE-2026-19024 | Normal | — | Important | — | Other / general Windows | Linux / other | HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message |
| CVE-2026-67319 | Normal | — | Moderate | — | Other / general Windows | Linux / other | axios before 0.33.0 Prototype Pollution via nested option objects |
| CVE-2026-69248 | Normal | — | Moderate | — | Network / infra servers | Linux / other | python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees |
| CVE-2026-64653 | Normal | — | Moderate | — | Other / general Windows | Linux / other | GitHub CLI: Unescaped variable components in request URLs could allow path traversal |
| CVE-2026-66486 | Normal | — | Moderate | — | Other / general Windows | Linux / other | Improper Output Encoding in GNU cpio |
| CVE-2026-66484 | Normal | — | Moderate | — | Other / general Windows | Linux / other | Path Traversal in GNU cpio |
| CVE-2026-68413 | Normal | — | — | — | Other / general Windows | Linux / other | wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() |
| CVE-2026-68428 | Normal | — | — | — | Other / general Windows | Linux / other | KVM: x86/mmu: Fix use-after-free on vendor module reload |
| CVE-2026-64654 | Normal | — | Moderate | — | Other / general Windows | Linux / other | GitHub CLI: Terminal escape sequence injection in multiple `gh` commands |
| CVE-2026-19023 | Normal | — | Low | — | Other / general Windows | Linux / other | HDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length String Datasets |
| CVE-2026-19028 | Normal | — | Moderate | — | Other / general Windows | Linux / other | HDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds read |
| CVE-2026-69249 | Normal | — | Important | — | Other / general Windows | Linux / other | python-cryptography: Duplicate self-signed intermediates can cause exponential path-building |
| CVE-2026-64655 | Normal | — | — | — | Other / general Windows | Linux / other | GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching |
| CVE-2026-66485 | Normal | — | Moderate | — | Other / general Windows | Linux / other | Uncontrolled Memory Allocation in GNU cpio |
| CVE-2026-68398 | Normal | — | — | — | Other / general Windows | Linux / other | ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF |