Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-27960

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability that can be exploited by unauthenticated attackers to query the API as any existing user, including the default admin account. This issue has been fixed in version 6.9.13. As a workaround, the default admin can be disabled using the `APP__ADMIN__EXTERNALLY_MANAGED` configuration.

PUBLISHED
Vendor
OpenCTI-Platform
Product
opencti
Provider severity
CRITICAL
Conflicts
0

CVE-2026-2796

A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: JIT miscompilation in the JavaScript: WebAssembly component

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Mozilla, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Mozilla
Product
Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Thunderbird, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 7, Firefox
Provider severity
CRITICAL, HIGH
Conflicts
2

CVE-2026-27959

Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa's `ctx.hostname` API performs naive parsing of the HTTP Host header, extracting everything before the first colon without validating the input conforms to RFC 3986 hostname syntax. When a malformed Host header containing a `@` symbol is received, `ctx.hostname` returns `evil[.]com` - an attacker-controlled value. Applications using `ctx.hostname` for URL generation, password reset links, email ver

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, koajs, Red Hat
Product
Red Hat OpenShift Dev Spaces, Self-service automation portal 2, Red Hat OpenShift AI (RHOAI), Red Hat Developer Hub, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI 2.25, koa, Red Hat OpenShift Container Platform 4.19
Provider severity
HIGH
Conflicts
3

CVE-2026-27957

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, an authenticated command injection vulnerability in the CA Certificate management feature allows any authenticated user to execute arbitrary commands as the configured SSH user on the managed server host. As the SSH user typically would have to either be root or part of the docker group for Coolify to function as intended, this provides complete compromise of the managed s

PUBLISHED
Vendor
coollabsio
Product
coolify
Provider severity
HIGH
Conflicts
0

CVE-2026-27956

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, `GET /api/v1/servers/{server_uuid}/domains?uuid={app_uuid}` bypasses team scoping when the optional uuid query parameter is provided. Any authenticated API user can enumerate domain names (FQDNs) of applications belonging to other teams. This vulnerability is fixed in 4.0.0-beta.464.

PUBLISHED
Vendor
coollabsio
Product
coolify
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27955

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the executeInDocker() helper wraps commands in bash -c '{$command}' without escaping single quotes. User-controlled docker_compose_custom_build_command and docker_compose_custom_start_command fields are interpolated directly, allowing a single quote to break out of the bash -c argument and execute commands on the managed server host (outside the intended Docker container c

PUBLISHED
Vendor
coollabsio
Product
coolify
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27954

Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52, three chat action endpoints (holdaction.php, blockuser.php, and transferchat.php) load chat objects by ID without calling `erLhcoreClassChat::hasAccessToRead()`, allowing operators to act on chats in departments they are not assigned to. Operators with the relevant role permissions (holduse, allowblockusers, allowtransfer) can hold, block users from, or transfer chats in depa

PUBLISHED
Vendor
LiveHelperChat
Product
livehelperchat
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27953

ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the model constructor, allowing any unauthenticated user to skip all field validation by injecting "__pk_only__": true into a JSON request body. By injecting "__pk_only__": true into a JSON request body, an unauthenticated attacker can skip all field validation and persist unvalidated data directly to the database. A secondary __excluded__ parameter injection uses the same pattern

PUBLISHED
Vendor
ormar-orm
Product
ormar
Provider severity
HIGH
Conflicts
1

CVE-2026-27952

Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability existed in Agenta's custom code evaluator. Agenta used RestrictedPython as a sandboxing mechanism for user-supplied evaluator code, but incorrectly whitelisted the `numpy` package as safe within the sandbox. This allowed authenticated users to bypass the sandbox and achieve arbitrary code execution on the API server. The escape path was through `numpy.ma.core.inspect`, which exp

PUBLISHED
Vendor
Agenta-AI
Product
agenta-api
Provider severity
HIGH
Conflicts
0

CVE-2026-27951

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the function `Stream_EnsureCapacity` can create an endless blocking loop. This may affect all client and server implementations using `FreeRDP`. For practical exploitation this will only work on 32bit systems where the available physical memory is `>= SIZE_MAX`. Version 3.23.0 contains a patch. No known workarounds are available.

PUBLISHED
Vendor
FreeRDP
Product
FreeRDP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27950

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the fix for the heap-use-after-free described in CVE-2026-24680 is incomplete. While the vulnerable execution flow referenced in the advisory exists in the SDL2 implementation, the fix appears to have been applied only to the SDL3 code path. In the SDL2 implementation, the pointer is not nulled after free. This creates a situation where the advisory suggests the vulnerability is fully resolved, while builds

PUBLISHED
Vendor
FreeRDP
Product
FreeRDP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2795

A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue: Use-after-free in the JavaScript: GC component

PUBLISHED
Vendor
Mozilla, Mozilla, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Thunderbird, Firefox, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10
Provider severity
HIGH
Conflicts
2

CVE-2026-27949

Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentication flow where a user's email address is included as a query parameter in the URL during error handling (e.g., when an invalid magic code is submitted). Transmitting personally identifiable information (PII) via GET request query strings is classified as an insecure design practice. The affected code path is located in the authentication utility module (packages/utils/src/auth

PUBLISHED
Vendor
makeplane
Product
plane
Provider severity
LOW
Conflicts
1

CVE-2026-27948

Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-parameter `?setck=...`. Version 1.20.9 fixes the issue.

PUBLISHED
Vendor
9001
Product
copyparty
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27947

Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.9, 25.0.87, and 6.8.154 have an authenticated Remote Code Execution vulnerability in the TNEF attachment processing flow. The vulnerable path extracts attacker-controlled files from `winmail.dat` and then invokes `zip` with a shell wildcard (`*`). Because extracted filenames are attacker-controlled, they can be interpreted as `zip` options and lead to arbitrary command execution. Versions 26

PUBLISHED
Vendor
Intermesh
Product
groupoffice
Provider severity
CRITICAL
Conflicts
1

CVE-2026-27946

ZITADEL is an open source identity management platform. Prior to versions 4.11.1 and 3.4.7, a vulnerability in Zitadel's self-management capability allowed users to mark their email and phone as verified without going through an actual verification process. The patch in versions 4.11.1 and 3.4.7 resolves the issue by requiring the correct permission in case the verification flag is provided and only allows self-management of the email address and/or phone number itself. If an upgrade is not poss

PUBLISHED
Vendor
zitadel
Product
zitadel
Provider severity
HIGH
Conflicts
0

CVE-2026-27945

ZITADEL is an open source identity management platform. Zitadel Action V2 (introduced as early preview in 2.59.0, beta in 3.0.0 and GA in 4.0.0) is a webhook based approach to allow developers act on API request to Zitadel and customize flows such the issue of a token. Zitadel's Action target URLs can point to local hosts, potentially allowing adversaries to gather internal network information and connect to internal services. When the URL points to a local host / IP address, an adversary might

PUBLISHED
Vendor
zitadel
Product
zitadel
Provider severity
LOW
Conflicts
0

CVE-2026-27944

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately. This issue has been patched in version 2.3.3.

PUBLISHED
Vendor
0xJacky
Product
nginx-ui
Provider severity
CRITICAL
Conflicts
1

CVE-2026-27943

OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the eye exam (eye_mag) view loads data by `form_id` (or equivalent) without verifying that the form belongs to the current user’s patient/encounter context. An authenticated user can access or edit any patient’s eye exam by supplying another form ID; in some flows the session’s active patient may also be switched. A fix is available on the `main` branch

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27942

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML builder with `preserveOrder:true`. Version 5.3.8 fixes the issue. As a workaround, use XML builder with `preserveOrder:false` or check the input data before passing to builder.

PUBLISHED
Vendor
NaturalIntelligence
Product
fast-xml-parser
Provider severity
LOW
Conflicts
0

CVE-2026-27941

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_target` event while checking out and executing untrusted code from forked pull requests. These workflows run with the security context of the base repository, including a write-privileged `GITHUB_TOKEN` and numerous sensitive secrets (API keys, database/vector store tokens, and a Google Cloud service account key). Version 1.37.1 con

PUBLISHED
Vendor
openlit
Product
openlit
Provider severity
CRITICAL
Conflicts
0

CVE-2026-27940

llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is vulnerable to an Integer overflow, leading to an undersized heap allocation. Using the subsequent fread() writes 528+ bytes of attacker-controlled data past the buffer boundary. This is a bypass of a similar bug in the same file - CVE-2025-53630, but the fix overlooked some areas. This vulnerability is fixed in b8146.

PUBLISHED
Vendor
ggml-org
Product
llama.cpp
Provider severity
HIGH
Conflicts
1

CVE-2026-2794

A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue: Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Mozilla
Product
Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Firefox
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-27939

Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may under certain conditions obtain elevated privileges without completing the intended verification step. This can allow access to sensitive operations and, depending on the user’s existing permissions, may lead to privilege escalation. This has been fixed in 6.4.0.

PUBLISHED
Vendor
statamic
Product
cms
Provider severity
HIGH
Conflicts
0

CVE-2026-27938

WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.9.1, the `wp-graphql/wp-graphql` repository contains a GitHub Actions workflow (`release.yml`) vulnerable to OS command injection through direct use of `${{ github.event.pull_request.body }}` inside a `run:` shell block. When a pull request from `develop` to `master` is merged, the PR body is injected verbatim into a shell command, allowing arbitrary command execution on the Actions runner. Version 2.9.1 contains a fix for

PUBLISHED
Vendor
wp-graphql
Product
wp-graphql
Provider severity
HIGH
Conflicts
0

CVE-2026-27937

October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, a reflected Cross-Site Scripting (XSS) vulnerability was identified in the backend DataTable widget where a query parameter was rendered without proper output escaping. This vulnerability is fixed in 3.7.16 and 4.1.16.

PUBLISHED
Vendor
octobercms
Product
october
Provider severity
LOW
Conflicts
0

CVE-2026-27936

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a restriction bypass allows restricted post action counts to be disclosed to non-privileged users through a carefully crafted request. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.

PUBLISHED
Vendor
discourse
Product
discourse
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27935

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a vulnerability in an API endpoint that discloses private topic metadata of admin users to moderator users even if the moderators do not have access to the private topics. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.

PUBLISHED
Vendor
discourse
Product
discourse
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27934

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a lack of visibility checks with a user action API endpoint that results in disclosure of the title and post excerpt to unauthorized users, leading to information disclosure. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.

PUBLISHED
Vendor
discourse
Product
discourse
Provider severity
HIGH
Conflicts
0

CVE-2026-27933

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Versions prior to 0.133.0 are vulnerable to session hijack via cookie leakage in proxy caches. Version 0.133.0 fixes the issue.

PUBLISHED
Vendor
manyfold3d
Product
manyfold
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27932

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In 1.6.2 and earlier, a resource exhaustion vulnerability in joserfc allows an unauthenticated attacker to cause a Denial of Service (DoS) via CPU exhaustion. When the library decrypts a JSON Web Encryption (JWE) token using Password-Based Encryption (PBES2) algorithms, it reads the p2c (PBES2 Count) parameter directly from the token's protected header. This parameter defin

PUBLISHED
Vendor
authlib
Product
joserfc
Provider severity
HIGH
Conflicts
0

CVE-2026-27931

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 22H3, Windows 10 Version 22H2, Windows Server 2025, Windows 11 Version 24H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2022, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows 11 Version 25H2, Windows 10 Version 21H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-27930

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 23H2, Windows Server 2025 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016 (Server Core installation), Windows 10 Version 1607, Windows Server 2012 R2 (Server Core installation), Windows 11 version 26H1, Windows 11 Version 25H2, Windows 11 version 22H3, Windows Server 2012 (Server Core installation), Windows 11 Version 24H2, Windows Server 2012, Windows Server 2022, Windows 10 Version 1809, Windows Server 2012 R2, Windows Server 2016, Windows 10 Version 21H2, Windows Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-2793

Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Mozilla, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Mozilla, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Thunderbird, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 10, Firefox, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9.4 Extended Update Support
Provider severity
CRITICAL, HIGH
Conflicts
2

CVE-2026-27929

Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 (Server Core installation), Windows 11 Version 23H2, Windows Server 2025 (Server Core installation), Windows Server 2019, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2016, Windows Server 2012, Windows 11 version 22H3, Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows Server 2012 R2, Windows 11 version 26H1, Windows Server 2016 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2022, Windows Server 2025, Windows 10 Version 1607, Windows 10 Version 1809
Provider severity
HIGH
Conflicts
1

CVE-2026-27928

Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2022, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows Server 2016, Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-27927

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Projected File System allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 11 Version 24H2, Windows Server 2025, Windows 11 version 26H1, Windows Server 2019, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows 11 version 22H3, Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 21H2, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
2

CVE-2026-27926

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows 11 Version 23H2, Windows 11 version 22H3, Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2019, Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025
Provider severity
HIGH
Conflicts
2

CVE-2026-27925

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 10 Version 22H2, Windows 11 Version 23H2, Windows Server 2016, Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows Server 2019, Windows Server 2012 (Server Core installation), Windows 10 Version 1607, Windows Server 2025, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows 11 version 22H3, Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows 11 Version 24H2, Windows Server 2012, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2022
Provider severity
MEDIUM
Conflicts
1

CVE-2026-27924

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022
Provider severity
HIGH
Conflicts
1

CVE-2026-27923

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows Server 2019, Windows 10 Version 1809, Windows 10 Version 1607, Windows 11 version 22H3, Windows Server 2012 R2 (Server Core installation), Windows 11 version 26H1, Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 21H2, Windows Server 2012 (Server Core installation), Windows Server 2012, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows Server 2022, Windows Server 2025, Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-27922

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows 11 version 22H3, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows Server 2025, Windows Server 2016, Windows 10 Version 1607, Windows 10 Version 22H2, Windows 11 Version 25H2, Windows 11 Version 23H2, Windows 11 version 26H1, Windows Server 2019, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2026-27921

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 (Server Core installation), Windows Server 2025, Windows Server 2012 R2 (Server Core installation), Windows 11 version 26H1, Windows Server 2016, Windows 10 Version 22H2, Windows Server 2012 R2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 10 Version 1607, Windows Server 2022, Windows 10 Version 21H2, Windows Server 2012, Windows 11 version 22H3, Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 10 Version 1809
Provider severity
HIGH
Conflicts
2

CVE-2026-27920

Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 22H2, Windows Server 2019, Windows 11 Version 23H2, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows Server 2025 (Server Core installation), Windows Server 2012 R2, Windows Server 2025, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 11 version 22H3, Windows 10 Version 21H2, Windows Server 2022, Windows 10 Version 1607, Windows 11 Version 25H2, Windows Server 2016, Windows 10 Version 1809, Windows Server 2012 (Server Core installation), Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-2792

A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Mozilla, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Mozilla, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Thunderbird, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Firefox, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.2 Advanced Update Support
Provider severity
CRITICAL, HIGH
Conflicts
2

CVE-2026-27919

Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows 11 Version 23H2, Windows Server 2025, Windows Server 2012, Windows 11 version 22H3, Windows 10 Version 21H2, Windows 11 Version 24H2, Windows Server 2012 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2016, Windows Server 2022, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2012 R2, Windows 11 Version 25H2, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-27918

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1809, Windows 10 Version 22H2, Windows Server 2025, Windows Server 2019, Windows 11 Version 24H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-27917

Use after free in Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows 11 Version 24H2, Windows 10 Version 21H2, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows 11 Version 25H2, Windows Server 2016, Windows Server 2019 (Server Core installation), Windows 11 version 22H3, Windows Server 2022, Windows Server 2012 R2, Windows Server 2016 (Server Core installation), Windows Server 2025, Windows 10 Version 1809, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1607
Provider severity
HIGH
Conflicts
1

CVE-2026-27916

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 10 Version 1809, Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 11 Version 23H2, Windows 11 version 22H3, Windows 10 Version 1607, Windows 10 Version 21H2, Windows Server 2016, Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Windows 10 Version 22H2, Windows Server 2012, Windows Server 2012 R2, Windows 11 version 26H1, Windows Server 2016 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-27915

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 (Server Core installation), Windows 11 Version 23H2, Windows Server 2019 (Server Core installation), Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows Server 2022, Windows 10 Version 22H2, Windows Server 2012, Windows 11 version 22H3, Windows 10 Version 1809, Windows 11 version 26H1, Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Windows Server 2025, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 25H2, Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows Server 2016, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1