Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-57217

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.11, and 4.2.6.

PUBLISHED
Vendor
rabbitmq
Product
rabbitmq-server
Provider severity
HIGH
Conflicts
0

CVE-2026-57216

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted through a trusted PROXY-protocol path and the backend listener is loopback-bound because the loopback check uses the listener-side socket address instead of the real client source. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.

PUBLISHED
Vendor
rabbitmq
Product
rabbitmq-server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57215

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations because volatile direct-reply-to queues can be accepted at bind and route time but are missing from Khepri-backed deletion checks, leaving persistent route entries after unbind. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.

PUBLISHED
Vendor
rabbitmq
Product
rabbitmq-server
Provider severity
HIGH
Conflicts
0

CVE-2026-57214

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.

PUBLISHED
Vendor
rabbitmq
Product
rabbitmq-server
Provider severity
HIGH
Conflicts
0

CVE-2026-57213

RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_management plugin renders the consumer_tag field on the Federation Status page without HTML escaping, allowing a user who can configure a federation upstream or policy to execute JavaScript in the browser of a user viewing that page. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.

PUBLISHED
Vendor
rabbitmq
Product
rabbitmq-server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57212

RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid JSON bodies on with_decode and direct_request paths because read_complete_body checks the accumulated size before the final chunk but not the final combined size. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.

PUBLISHED
Vendor
rabbitmq
Product
rabbitmq-server
Provider severity
HIGH
Conflicts
0

CVE-2026-57211

RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extension plugins are enabled, causing outbound DNS and SMB requests to attacker-controlled UNC paths. This issue is fixed in versions 4.1.11 and 4.2.6.

PUBLISHED
Vendor
rabbitmq
Product
rabbitmq-server
Provider severity
MEDIUM
Conflicts
1

CVE-2026-5721

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.5.0.4. This is due to insufficient input sanitization and output escaping in the prepareCellOutput() method of the LinkWDTColumn, ImageWDTColumn, and EmailWDTColumn classes. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an in

PUBLISHED
Vendor
wpdatatables
Product
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57206

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin validation routes in application/single_app/plugin_validation_endpoint.py, including `POST /api/admin/plugins/test-instantiation`, `GET /api/admin/plugins/health-check/<plugin_name>`, `POST /api/admin/plugins/repair/<plugin_name>`, and `POST /api/plugins/validate`, relied on @swagger_route(security=get_auth_security()) documentation without

PUBLISHED
Vendor
microsoft
Product
simplechat
Provider severity
HIGH
Conflicts
1

CVE-2026-57205

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> endpoints in application/single_app/route_backend_users.py accepted a caller-supplied user_id and read the matching Cosmos DB user-settings document without object-level authorization, allowing a low-privilege authenticated user to retrieve another user's email address

PUBLISHED
Vendor
microsoft
Product
simplechat
Provider severity
MEDIUM
Conflicts
1

CVE-2026-57204

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerability can craft a PDF which leads to large memory usage, as MAX_DECLARED_STREAM_LENGTH is sometimes ignored. This requires parsing a content stream without a /Length value. This issue has been fixed in version 6.13.3.

PUBLISHED
Vendor
py-pdf
Product
pypdf
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5720

miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote. Attackers can trigger an out-of-bounds memory read by exploiting improper length validation in ParseHttpHeaders(), where the parsed length underflows to a large unsigned value when passed to memchr(), causing the process to scan memory far beyond the allocated HTTP reque

PUBLISHED
Vendor
miniupnp project
Product
miniupnpd
Provider severity
HIGH
Conflicts
1

CVE-2026-5719

A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /borrowedtool.php. Executing a manipulation of the argument code can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Construction Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-5718

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.3.9.7. This is due to insufficient file type validation that occurs when custom blacklist types are configured, which replaces the default dangerous extension denylist instead of merging with it, and the wpcf7_antiscript_file_name() sanitization function being bypassed for filenames containing non-ASCII characters. This makes it possible for un

PUBLISHED
Vendor
glenwpcoder
Product
Drag and Drop Multiple File Upload for Contact Form 7
Provider severity
HIGH
Conflicts
0

CVE-2026-57172

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded default share link signature key, allowing an attacker who can obtain a passwordless share for a resource and user to use the known key link-pwd-fit2cloud to forge linkToken JWTs, bypass TokenFilter verification, and access backend resources as the share creator even if the original share has been revoked. This issue is fixed in version 2.10.24.

PUBLISHED
Vendor
dataease
Product
dataease
Provider severity
HIGH
Conflicts
1

CVE-2026-5717

The VI: Include Post By plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_container' attribute of the 'include-post-by-cat' shortcode in all versions up to, and including, 0.4.200706 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
knighthawk
Product
VI: Include Post By
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57167

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, server-side-rendered video watch pages embed a schema.org JSON-LD block by JSON.stringify-ing video metadata without escaping less-than, greater-than, or slash characters, allowing a value containing the byte sequence that closes a script element to inject arbitrary HTML or JavaScript that executes in the instance origin for visitors to the attacker's videos. This issue is fixed in version 8.2.2.

PUBLISHED
Vendor
Chocobozzz
Product
PeerTube
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57158

FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only in libfreerdp/codec/planar.c, allowing a malicious RDP server to send a truncated RDPGFX_CMDID_WIRETOSURFACE_1 planar payload that reads one byte past the input buffer. This issue is fixed in version 3.28.0.

PUBLISHED
Vendor
FreeRDP
Product
FreeRDP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57157

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, FreeRDP server implementations with the MS-RDPECAM camera device enumerator channel enabled scan attacker-supplied DeviceName and VirtualChannelName fields for a NUL terminator in channels/rdpecam/server/camera_device_enumerator_main.c and then dereference once past the scan bound, allowing a malicious RDP client to trigger a 1- to 2-byte out-of-bounds heap read. This issue is fixed in version 3.28.0.

PUBLISHED
Vendor
FreeRDP
Product
FreeRDP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57156

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfreerdp/core/orders.c when multiplying an attacker-controlled point count by sizeof(DELTA_POINT), allowing a malicious RDP peer to allocate an undersized heap buffer and then write beyond it during initialization. This issue is fixed in version 3.28.0.

PUBLISHED
Vendor
FreeRDP
Product
FreeRDP
Provider severity
HIGH
Conflicts
1

CVE-2026-5715

The Voyage Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the 'post-content' shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
scui2
Product
Voyage Plus
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5714

The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘location_dir’ parameter in all versions up to, and including, 4.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
shortpixel
Product
Enable Media Replace
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5713

The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used to read and write addresses in a privileged process if that process connected to a malicious or "infected" Python process via the remote debugging feature. This vulnerability requires persistently and repeatedly connecting to the process to be exploited, even after the connecting process crashes with high likelihood due to A

PUBLISHED
Vendor
Python Software Foundation
Product
CPython
Provider severity
MEDIUM
Conflicts
1

CVE-2026-5712

This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing.

PUBLISHED
Vendor
SailPoint Technologies
Product
IdentityIQ
Provider severity
HIGH
Conflicts
0

CVE-2026-57111

Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows a remote attacker controlling a web page visited by an authorized user to read responses from and issue cross-origin requests to administrative REST endpoints via a cross-origin request from an arbitrary origin, since the filter unconditionally returns Access-Control-Allow-Origin: * together with Access-Control-Allow-C

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Helix REST
Provider severity
HIGH
Conflicts
0

CVE-2026-5711

The Post Blocks & Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliderStyle' block attribute in the Posts Slider block in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
pubudu-malalasekara
Product
Post Blocks & Tools
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57108

Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
.NET 10.0, .NET 8.0, .NET 9.0
Provider severity
HIGH
Conflicts
1

CVE-2026-57107

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Windows Admin Center
Provider severity
HIGH
Conflicts
0

CVE-2026-57106

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Purview Data Governance
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57102

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

PUBLISHED
Vendor
Microsoft
Product
Visual Studio Code
Provider severity
HIGH
Conflicts
1

CVE-2026-57101

Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft
Product
Visual Studio Code
Provider severity
HIGH
Conflicts
0

CVE-2026-57100

Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Entra Provisioning Service
Provider severity
CRITICAL
Conflicts
0

CVE-2026-5710

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versions up to and including 1.3.9.6. This is due to the plugin using client-supplied mfile[] POST values as the source of truth for email attachment selection without performing any server-side upload provenance check, path canonicalization, or directory containment boundary enforcement. In dnd_wpcf7_posted_data(), each user-submitted filename is direc

PUBLISHED
Vendor
glenwpcoder
Product
Drag and Drop Multiple File Upload for Contact Form 7
Provider severity
HIGH
Conflicts
0

CVE-2026-57097

Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2, Windows Server 2016, Windows Server 2025 (Server Core installation), Windows Server 2019, Windows 10 Version 1607, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 21H2, Windows 11 Version 24H2, Windows Server 2025, Windows Server 2012 (Server Core installation), Windows 10 Version 1809, Windows 11 Version 25H2, Windows 11 version 26H1, Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows Server 2022, Windows Server 2019 (Server Core installation), Windows Server 2012
Provider severity
MEDIUM
Conflicts
1

CVE-2026-57096

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2 (Server Core installation), Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows Server 2022, Windows Server 2012 R2, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows 10 Version 1607, Windows Server 2019, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows 11 version 26H1, Windows Server 2025, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-57095

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows Server 2016 (Server Core installation), Windows 11 Version 24H2, Windows Server 2012, Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2012 R2, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows Server 2016, Windows Server 2012 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 1809, Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1607, Windows Server 2019, Windows Server 2019 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-57094

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2022, Windows 10 Version 22H2, Windows Server 2016, Windows 11 Version 24H2, Windows 10 Version 1607, Windows Server 2019, Windows Server 2025
Provider severity
HIGH
Conflicts
2

CVE-2026-57093

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2, Windows Server 2012, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 26H1, Windows 11 Version 25H2, Windows 10 Version 1809, Windows Server 2022, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2025, Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-57092

Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2012 R2, Windows 11 Version 25H2, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2025, Windows 10 Version 1607, Windows Server 2012 (Server Core installation), Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows Server 2016, Windows Server 2012, Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation)
Provider severity
CRITICAL
Conflicts
1

CVE-2026-57091

Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows Server 2025, Windows Server 2019, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2016, Windows 10 Version 1607, Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2026-57090

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2019, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows 10 Version 21H2, Windows Server 2016, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-5709

Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via crafted input when using the FileBrowser functionality. To remediate this issue, users are advised to upgrade to RES version 2026.03 or apply the corresponding mitigation patch to their existing environment.

PUBLISHED
Vendor
AWS
Product
Research and Engineering Studio (RES)
Provider severity
HIGH
Conflicts
1

CVE-2026-57089

Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2025, Windows Server 2012 R2, Windows 11 version 26H1, Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2012 (Server Core installation), Windows Server 2019, Windows Server 2022, Windows Server 2016 (Server Core installation), Windows 10 Version 1607, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-57088

Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows Server 2022, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows Server 2019
Provider severity
HIGH
Conflicts
1

CVE-2026-57087

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2016 (Server Core installation), Windows 11 Version 24H2, Windows Server 2025, Windows 10 Version 21H2, Windows 10 Version 1607, Windows Server 2016, Windows 11 version 26H1, Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 25H2, Windows Server 2022
Provider severity
HIGH
Conflicts
1

CVE-2026-57085

Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2016, Windows Server 2025, Windows Server 2012 R2, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2012 R2 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 1607, Windows Server 2012, Windows 11 Version 25H2, Windows Server 2022, Windows 10 Version 22H2, Windows 10 Version 21H2, Windows Server 2012 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-57084

Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2 (Server Core installation), Windows 11 Version 25H2, Windows Server 2022, Windows Server 2012 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 10 Version 21H2, Windows Server 2019, Windows 11 version 26H1, Windows 11 Version 24H2, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2019 (Server Core installation), Windows Server 2012, Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows Server 2016, Windows 10 Version 1809
Provider severity
MEDIUM
Conflicts
1

CVE-2026-57083

Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012, Windows Server 2016, Windows 10 Version 1607, Windows Server 2012 (Server Core installation), Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2022, Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 21H2, Windows Server 2019, Windows 11 version 26H1, Windows Server 2025, Windows 10 Version 1809
Provider severity
MEDIUM
Conflicts
1

CVE-2026-57082

Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG. The MSE (Message Stream Encryption) handshake derives its 160-bit Diffie-Hellman private key from Perl's rand(), a non-cryptographic drand48-class generator seeded once per process, in KeyExchange.pm. The shared secret and the RC4 keys derived from it (the SHA-1 of "keyA" or "keyB", the shared secret, and the infohash) therefore depend entirely on a predictable PRNG. The sam

PUBLISHED
Vendor
SANKO
Product
Net::BitTorrent
Provider severity
MEDIUM
Conflicts
1

CVE-2026-57081

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested list or dictionary level with no depth cap, and each recursive call receives the remaining buffer by value while the list and dictionary branches capture the whole remainder, so every live recursion frame keeps its own copy of the shrinking buffer (O(N^2) bytes for an N-deep input). The decoder runs on every untrusted bencode source: .torrent files, B

PUBLISHED
Vendor
SANKO
Product
Net::BitTorrent
Provider severity
HIGH
Conflicts
1