Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-42965

A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allows the router to proxy requests to the cloud metadata endpoint, leading to the disclosure of instance credentials and other sensitive metadata. This bypasses previous security measures for validating IP addresses.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4
Provider severity
HIGH
Conflicts
1

CVE-2026-42961

ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked to do unintended operations.

PUBLISHED
Vendor
ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD.
Product
WAB-BE36-S, WAB-BE187-M, WAB-BE72-M, WAB-BE36-M
Provider severity
MEDIUM
Conflicts
2

CVE-2026-42960

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such records in a reply (i.e., spoofed packet, fragmentation attack) he would be able to poison Unbound's cache. A malicious actor can exploit the possible poisonous effect by injecting RRSets other than NS tha

PUBLISHED
Vendor
NLnet Labs
Product
Unbound
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4296

An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth redirect URI validation. An attacker with knowledge of a first-party OAuth application's registered callback URL could craft a malicious authorization link that, when clicked by a victim, would redirect the OAuth authorization code to an attacker-controlled domain. This could allow the attacker to gain unauthorized access to the victim's account with the scopes grante

PUBLISHED
Vendor
GitHub
Product
Enterprise Server
Provider severity
HIGH
Conflicts
0

CVE-2026-42959

A flaw was found in Unbound's DNSSEC validator when constructing chase-reply messages for validation. The code uses the wrong counter to calculate write offsets for ADDITIONAL section resource record sets. When a DNAME chain is combined with authority filtering, an uninitialized array slot is created that the validator later dereferences, causing an immediate process crash. Any application or infrastructure relying on Unbound for DNS resolution could be forced to exit unexpectedly, resulting in

PUBLISHED
Vendor
Red Hat, Red Hat, NLnet Labs, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Hardened Images, Red Hat OpenShift Container Platform 4, Unbound, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7
Provider severity
HIGH
Conflicts
3

CVE-2026-42958

The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing specially crafted files. This could allow an attacker to execute arbitrary code in the context of the current process.

PUBLISHED
Vendor
Labcenter
Product
Proteus
Provider severity
HIGH
Conflicts
1

CVE-2026-42955

In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client A/AAAA query can cause Unbound to overwrite the cached expired parent-

PUBLISHED
Vendor
NLnet Labs
Product
Unbound
Provider severity
LOW
Conflicts
0

CVE-2026-42953

The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program to write data past the end of an allocated memory buffer. This can lead to arbitrary code execution.

PUBLISHED
Vendor
Labcenter
Product
Proteus
Provider severity
HIGH
Conflicts
0

CVE-2026-42952

Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could allow an attacker to execute a denial-of-service attack.

PUBLISHED
Vendor
Hydro-Québec
Product
Le Circuit Electrique charging station backend
Provider severity
HIGH
Conflicts
1

CVE-2026-42951

An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes.

PUBLISHED
Vendor
Danelec
Product
MacGregor Voyage Data Recorder (VDR) G4e
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42950

ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a malicious page while logged in, the admin page on the user's web browser may become broken.

PUBLISHED
Vendor
ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD.
Product
WAB-BE187-M, WAB-BE36-S, WAB-BE36-M, WAB-BE72-M
Provider severity
MEDIUM
Conflicts
2

CVE-2026-4295

Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote unauthenticated threat actor to execute arbitrary code via maliciously crafted project directory files that bypass workspace trust protections when a local user opens the directory. To remediate this issue, users should upgrade to version 0.8.0 or higher.

PUBLISHED
Vendor
AWS
Product
Kiro IDE
Provider severity
HIGH
Conflicts
1

CVE-2026-42948

Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another administrative user's web browser.

PUBLISHED
Vendor
ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD.
Product
WAB-BE36-M, WAB-BE36-S, WAB-BE72-M, WAB-BE187-M
Provider severity
MEDIUM
Conflicts
2

CVE-2026-42947

A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbitrary account. Because the affected endpoints validate request signatures but do not confirm legitimate ownership, an attacker with any account can take over a device without user interaction while the device remains online and unaware.

PUBLISHED
Vendor
Naxclow, Naxclow, Naxclow, Naxclow
Product
Smart Doorbell X3, ix cam, X Smart Home, V720
Provider severity
HIGH
Conflicts
2

CVE-2026-42946

A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to read the memory of the NGINX worker process or restart it.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5, F5
Product
NGINX Plus, NGINX Open Source
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-42945

A flaw was found in NGINX, specifically within the ngx_http_rewrite_module. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests under specific rewrite configurations. This can lead to a heap buffer overflow in the NGINX worker process, which may result in arbitrary code execution if Address Space Layout Randomization (ASLR), a security technique to prevent exploitation, is disabled. Otherwise, this flaw causes a denial of service due to a restart of the NG

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, F5, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, F5, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.15, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.14, Red Hat Satellite 6.19, Red Hat Openshift Data Foundation 4.14, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.15, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.14, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Openshift Data Foundation 4.21, Red Hat Openshift Data Foundation 4.16, Red Hat Openshift Data Foundation 4.16, Red Hat Openshift Data Foundation 4.16, Red Hat Openshift Data Foundation 4.17, Red Hat Enterprise Linux 9, Red Hat Satellite 6.18, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 10, Red Hat 3scale API Management Platform 2, Red Hat Openshift Data Foundation 4.19, Red Hat Lightspeed proxy 1, Red Hat Openshift Data Foundation 4.21, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.21, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.15, Red Hat Update Infrastructure 5, NGINX Open Source, Red Hat Openshift Data Foundation 4.2, Red Hat Enterprise Linux 9, Red Hat Openshift Data Foundation 4.17, Red Hat Openshift Data Foundation 4.18, Red Hat Enterprise Linux 9.6 Extended Update Support, NGINX Plus, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Hardened Images, Red Hat Openshift Data Foundation 4.17
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-42944

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be enabled for the vulnerability to be exploited. An adversary who can query Unbound can exploit the vulnerability by attaching multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options to the query.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, NLnet Labs, Red Hat, Red Hat
Product
Red Hat Hardened Images, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Unbound, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8
Provider severity
HIGH
Conflicts
3

CVE-2026-42941

The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change.

PUBLISHED
Vendor
Danelec
Product
MacGregor Voyage Data Recorder (VDR) G4e
Provider severity
HIGH
Conflicts
1

CVE-2026-42937

Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view adjacent network information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5, F5
Product
BIG-IP, BIG-IQ
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-42936

The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privilege of the user invoking the installer.

PUBLISHED
Vendor
SBI SECURITIES Co.,Ltd.
Product
HYPER SBI 2
Provider severity
HIGH
Conflicts
1

CVE-2026-42934

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.  Note: Software versions which have reached End of Technical Support (EoT

PUBLISHED
Vendor
F5, F5
Product
NGINX Plus, NGINX Open Source
Provider severity
MEDIUM
Conflicts
2

CVE-2026-42933

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.

PUBLISHED
Vendor
Pronetiqs
Product
Panduit Intravue
Provider severity
CRITICAL
Conflicts
1

CVE-2026-42932

Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predictable and enumerable identifier space. Because the platform also exposes an endpoint that reveals the current identifier high-water mark, the active fleet can be enumerated.

PUBLISHED
Vendor
Naxclow, Naxclow, Naxclow, Naxclow
Product
Smart Doorbell X3, ix cam, V720, X Smart Home
Provider severity
MEDIUM
Conflicts
2

CVE-2026-42930

When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
BIG-IP
Provider severity
HIGH
Conflicts
1

CVE-2026-4293

The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's browser, which allows the attacker to control the browser.

PUBLISHED
Vendor
Kieback & Peter, Kieback & Peter, Kieback & Peter, Kieback & Peter, Kieback & Peter, Kieback & Peter, Kieback & Peter, Kieback & Peter, Kieback & Peter, Kieback & Peter, Kieback & Peter
Product
DDC4002e, DDC4100, DDC520, DDC4040e, DDC4002, DDC4020e, DDC4200-L, DDC4400e, DDC4200, DDC4400, DDC4200e
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42929

Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.

PUBLISHED
Vendor
Danelec
Product
MacGregor Voyage Data Recorder (VDR) G4e
Provider severity
HIGH
Conflicts
1

CVE-2026-42926

When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
NGINX Open Source
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42924

An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting in privilege escalation.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
BIG-IP
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-42923

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to consult the negative cache for DS records does not take into account the limit on NSEC3 hash calculations introduced in 1.19.1. This leads to degradation of service during the attack. An adversary that controls a DNSSEC signed zone can exploit this by signing NSEC3 records with acceptably high iterations for child delegations and querying a vulnerable Unbound. Unbound will kee

PUBLISHED
Vendor
NLnet Labs
Product
Unbound
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42920

When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
BIG-IP
Provider severity
HIGH
Conflicts
1

CVE-2026-4292

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `ModelAdmin.list_editable` incorrectly allowed new instances to be created via forged `POST` data. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.

PUBLISHED
Vendor
djangoproject
Product
Django
Provider severity
LOW
Conflicts
0

CVE-2026-42919

A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrative access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
BIG-IP
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-42916

Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 23H2, Windows Server 2016 (Server Core installation), Windows 11 Version 23H2, Windows 10 Version 1809, Windows Server 2019, Windows Server 2012 R2, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2025, Windows Server 2016, Windows Server 2012, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 Version 24H2, Windows Server 2012 (Server Core installation), Windows 10 Version 21H2, Windows 10 Version 1607, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-42915

Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows Server 2022, Windows 10 Version 21H2, Windows Server 2025, Windows 11 version 26H1, Windows 11 Version 23H2, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 23H2, Windows 11 Version 25H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42914

Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows 10 Version 22H2, Windows 11 Version 24H2, Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2012 (Server Core installation), Windows 11 version 23H2, Windows 10 Version 1809, Windows Server 2012 R2 (Server Core installation), Windows Server 2022, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows Server 2012, Windows Server 2019 (Server Core installation), Windows 10 Version 1607, Windows 10 Version 21H2, Windows 11 Version 25H2, Windows Server 2025, Windows Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42913

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 version 23H2, Windows 11 Version 23H2, Remote Desktop client for Windows Desktop, Windows Server 2022, Windows Server 2025, Windows 11 Version 25H2, Windows 11 version 26H1, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
2

CVE-2026-42912

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 11 Version 23H2, Windows 11 Version 25H2, Windows 10 Version 1809, Windows Server 2012 R2, Windows 11 Version 24H2, Windows Server 2022, Windows Server 2019, Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2016, Windows Server 2012 (Server Core installation), Windows Server 2025, Windows 10 Version 1607, Windows 11 version 23H2, Windows Server 2012, Windows 10 Version 22H2
Provider severity
HIGH
Conflicts
1

CVE-2026-42911

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows 11 Version 23H2, Windows Server 2022, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows 11 version 23H2, Windows Server 2016 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 1809, Windows Server 2012 R2, Windows Server 2025, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 21H2, Windows 10 Version 1607, Windows 10 Version 22H2, Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-42910

Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 Version 24H2, Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-42909

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows 11 version 23H2, Windows Server 2012 R2, Windows Server 2016, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 1607, Windows 11 Version 24H2, Windows 10 Version 22H2, Windows 11 version 26H1, Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Remote Desktop client for Windows Desktop, Windows Server 2019, Windows Server 2012, Windows Server 2022, Windows 10 Version 21H2, Windows Server 2012 (Server Core installation), Windows App Client for Windows Desktop, Windows Server 2019 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-42908

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows 10 Version 21H2, Windows 10 Version 1607, Windows App Client for Windows Desktop, Windows 11 Version 24H2, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2025, Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 11 version 23H2, Windows 10 Version 1809, Windows 11 version 26H1, Windows Server 2012 R2 (Server Core installation), Windows Server 2012, Windows Server 2022
Provider severity
HIGH
Conflicts
1

CVE-2026-42907

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows Server 2022, Windows 10 Version 21H2, Windows Server 2025, Windows 11 Version 24H2, Windows Server 2019, Windows 11 version 23H2, Windows 10 Version 22H2, Windows 11 Version 23H2, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42906

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows 11 Version 25H2, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows 11 version 26H1, Windows 11 Version 24H2, Windows 11 version 23H2, Windows 11 Version 23H2, Windows Server 2022
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42905

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Windows 11 version 26H1, Windows Server 2025, Windows Server 2022, Windows 10 Version 22H2, Windows 11 Version 23H2, Windows Server 2016, Windows Server 2012 (Server Core installation), Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 version 23H2, Windows 11 Version 25H2, Windows 10 Version 1809, Windows Server 2012, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows Server 2012 R2
Provider severity
HIGH
Conflicts
1

CVE-2026-42904

Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 11 Version 23H2, Windows Server 2022, Windows 11 version 23H2, Windows 11 version 26H1, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows Server 2025
Provider severity
CRITICAL
Conflicts
1

CVE-2026-42903

Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows 11 Version 25H2, Windows Server 2012, Windows Server 2012 R2, Windows Server 2025, Windows Server 2022, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 1809, Windows Server 2016, Windows 10 Version 1607, Windows Server 2012 R2 (Server Core installation), Windows 11 version 26H1, Windows Server 2012 (Server Core installation), Windows 11 version 23H2, Windows 11 Version 24H2, Windows Server 2019, Windows 11 Version 23H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42902

Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft PowerToys
Provider severity
HIGH
Conflicts
0

CVE-2026-42901

Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Entra
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42900

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows Server 2025, Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2016, Windows 10 Version 21H2, Windows 11 version 26H1, Windows Server 2016 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-4290

The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and including, 10.6.0. This is due to the check_permission() callback unconditionally returning true and the Database::delete() method passing the user ID directly to wp_delete_user() without any role validation. This makes it possible for unauthenticated attackers to delete arbitrary user accounts, including those of admini

PUBLISHED
Vendor
WPTravel
Product
WP Travel Pro
Provider severity
CRITICAL
Conflicts
0