Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-26162

Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 22H3, Windows Server 2012, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows Server 2022, Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows 11 version 26H1, Windows 10 Version 1607, Windows Server 2012 R2, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2025, Windows Server 2022, 23H2 Edition (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-26161

Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019, Windows 11 Version 25H2, Windows 11 version 26H1, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows Server 2025, Windows 11 version 22H3, Windows Server 2022, Windows 10 Version 21H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-26160

Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2019, Windows Server 2025, Windows Server 2012 (Server Core installation), Windows Server 2022, Windows Server 2012, Windows 10 Version 1809, Windows 10 Version 1607, Windows 11 Version 23H2, Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 11 version 22H3, Windows 10 Version 21H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012 R2, Windows 10 Version 22H2, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-2616

A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface. The manipulation leads to hard-coded credentials. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. It is advisable to modify the configuration settings. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Beetel
Product
777VR1
Provider severity
HIGH
Conflicts
2

CVE-2026-26159

Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2012 R2, Windows Server 2022, Windows 11 Version 23H2, Windows Server 2012, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 24H2, Windows Server 2025, Windows 11 version 26H1, Windows Server 2019, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2016, Windows 10 Version 22H2, Windows 11 Version 25H2, Windows 10 Version 1607, Windows 10 Version 1809, Windows 11 version 22H3, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-26158

A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is extracted with elevated privileges, this flaw can lead to privilege escalation, enabling an attacker to gain unauthorized access to critical system files.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Siemens
Product
Red Hat Enterprise Linux 6, Red Hat Hardened Images, Red Hat Hardened Images, Red Hat Enterprise Linux 6, RUGGEDCOM RST2428P
Provider severity
HIGH
Conflicts
1

CVE-2026-26157

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially enabling code execution through the modification of sensitive system files.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Siemens, Red Hat
Product
Red Hat Hardened Images, Red Hat Hardened Images, Red Hat Enterprise Linux 6, RUGGEDCOM RST2428P, Red Hat Enterprise Linux 6
Provider severity
HIGH
Conflicts
1

CVE-2026-26156

Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2025, Windows 11 version 26H1, Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 version 22H3, Windows 10 Version 1809, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 1607, Windows 11 Version 25H2, Windows Server 2019, Windows 11 Version 24H2, Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows Server 2016
Provider severity
HIGH
Conflicts
2

CVE-2026-26155

Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 Version 24H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1809, Windows 10 Version 22H2, Windows 11 version 22H3, Windows Server 2016, Windows 10 Version 1607, Windows 10 Version 21H2, Windows Server 2022, Windows Server 2016 (Server Core installation), Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows Server 2019, Windows 11 Version 23H2, Windows Server 2019 (Server Core installation), Windows 11 version 26H1
Provider severity
MEDIUM
Conflicts
1

CVE-2026-26154

Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 (Server Core installation), Windows Server 2016, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows Server 2016 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2022, Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2012, Windows Server 2025 (Server Core installation), Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-26153

Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows 11 Version 25H2, Windows 11 Version 23H2, Windows Server 2019, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows 10 Version 1809, Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows Server 2022, Windows 11 version 22H3, Windows Server 2019 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-26152

Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1607, Windows 11 version 26H1, Windows Server 2012, Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 Version 24H2, Windows 11 Version 23H2, Windows 10 Version 21H2, Windows 11 version 22H3, Windows 11 Version 25H2, Windows 10 Version 1809, Windows Server 2016, Windows Server 2012 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2019, Windows Server 2025, Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-26151

Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 11 version 26H1, Windows Server 2016, Windows 11 Version 24H2, Windows 10 Version 1607, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2019, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 25H2, Windows Server 2022, Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 R2, Windows Server 2019 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-26150

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Purview eDiscovery
Provider severity
HIGH
Conflicts
0

CVE-2026-2615

A flaw has been found in Wavlink WL-NU516U1 up to 20251208. The affected element is the function singlePortForwardDelete of the file /cgi-bin/firewall.cgi. Executing a manipulation of the argument del_flag can lead to command injection. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Wavlink
Product
WL-NU516U1
Provider severity
HIGH
Conflicts
2

CVE-2026-26149

Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Power Apps Desktop Client
Provider severity
CRITICAL
Conflicts
0

CVE-2026-26148

External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Azure AD SSH Login extension for Linux
Provider severity
HIGH
Conflicts
0

CVE-2026-26147

Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Stack HCI
Provider severity
HIGH
Conflicts
0

CVE-2026-26145

Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Synapse
Provider severity
MEDIUM
Conflicts
0

CVE-2026-26144

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
Provider severity
HIGH
Conflicts
0

CVE-2026-26143

Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft
Product
PowerShell 7.5, PowerShell 7.4
Provider severity
HIGH
Conflicts
1

CVE-2026-26142

Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Nuance PowerScribe 360 version 4.0.8, Nuance PowerScribe One version 2019.7, Nuance PowerScribe 360 version 4.0.5, Nuance PowerScribe 360 version 4.0.6, Nuance PowerScribe 360 version 4.0.9, Nuance PowerScribe One version 2019.4, PowerScribe One version 2023.1 SP3 Patch 6, PowerScribe One version 2023.1 SP2 Patch 11, Nuance PowerScribe 360 version 4.0.3, Nuance PowerScribe 360 version 4.0.1, Nuance PowerScribe One version 2019.6, Nuance PowerScribe One version 2019.10, Nuance PowerScribe One version 2019.3, Nuance PowerScribe One version 2019.8, Nuance PowerScribe One version 2019.5, Nuance PowerScribe 360 4.0, Nuance PowerScribe 360 version 4.0.4, Nuance PowerScribe One version 2019.9, Nuance PowerScribe One version 2019.1, Nuance PowerScribe 360 version 4.0.7, Nuance PowerScribe 360 version 4.0.2, Nuance PowerScribe One version 2019.2
Provider severity
CRITICAL
Conflicts
1

CVE-2026-26141

Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Azure Automation Hybrid Worker Windows Extension
Provider severity
HIGH
Conflicts
0

CVE-2026-2614

A flaw was found in mlflow. An unauthenticated remote attacker can exploit a vulnerability in the `_create_model_version()` handler by including a specific tag, `mlflow.prompt.is_prompt`, in a `CreateModelVersion` request. This bypasses source path validation, allowing the attacker to specify an arbitrary local filesystem path as the model version source. Subsequently, the `get_model_version_artifact_handler()` function serves files from this unverified source, leading to the disclosure of arbit

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, mlflow, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.4, Red Hat OpenShift AI (RHOAI), mlflow/mlflow, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.4, Red Hat OpenShift AI 3.4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI)
Provider severity
HIGH
Conflicts
3

CVE-2026-26139

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Purview
Provider severity
HIGH
Conflicts
0

CVE-2026-26138

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Purview
Provider severity
HIGH
Conflicts
0

CVE-2026-26137

Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Exchange Online
Provider severity
CRITICAL
Conflicts
0

CVE-2026-26136

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Copilot
Provider severity
MEDIUM
Conflicts
0

CVE-2026-26135

Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Custom Locations Resource Provider
Provider severity
CRITICAL
Conflicts
0

CVE-2026-26134

Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Office for Android
Provider severity
HIGH
Conflicts
1

CVE-2026-26133

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Teams for Android, Microsoft Loop for iOS, Microsoft Word for Android, Microsoft Outlook for Mac, Microsoft Teams for iOS, Microsoft Outlook for iOS, Microsoft Word for iOS, Microsoft OneNote for Android, Microsoft Edge for Android, Microsoft PowerPoint for iOS, Microsoft Outlook for Android, Microsoft PowerPoint for Android, Microsoft Excel for iOS, Microsoft Edge for iOS, Microsoft PowerBI for Android, Microsoft PowerBI for iOS, Microsoft 365 Copilot for Android, Microsoft OneNote, Microsoft Excel for Android, Microsoft 365 Copilot for iOS
Provider severity
HIGH
Conflicts
1

CVE-2026-26132

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 21H2, Windows 11 version 22H3, Windows Server 2025, Windows 11 Version 23H2, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 11 version 26H1, Windows 11 Version 24H2, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-26131

Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
.NET 10.0
Provider severity
HIGH
Conflicts
0

CVE-2026-26130

A flaw was found in ASP.NET Core. This vulnerability allows an unauthorized attacker to perform a Denial of Service (DoS) attack over a network by allocating resources without limits or throttling. This can lead to the unavailability of the service for legitimate users.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Microsoft, Microsoft, Red Hat, Red Hat, Red Hat, Microsoft, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.4 Extended Update Support, ASP.NET Core 10.0, ASP.NET Core 8.0, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, ASP.NET Core 9.0, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.6 Extended Update Support
Provider severity
HIGH
Conflicts
3

CVE-2026-26129

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft 365 Copilot's Business Chat
Provider severity
HIGH
Conflicts
0

CVE-2026-26128

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows 11 Version 24H2, Windows Server 2019, Windows Server 2012, Windows Server 2022, Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2016, Windows 11 version 22H3, Windows 11 version 26H1, Windows 11 Version 25H2, Windows 10 Version 1607, Windows 10 Version 21H2, Windows Server 2025, Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1809, Windows 11 Version 23H2, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-26127

Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft.Bcl.Memory, Microsoft.Bcl.Memory, .NET 9.0, .NET 10.0
Provider severity
HIGH
Conflicts
1

CVE-2026-26125

Payment Orchestrator Service Elevation of Privilege Vulnerability

PUBLISHED
Vendor
Microsoft
Product
Payment Orchestrator Service
Provider severity
HIGH
Conflicts
0

CVE-2026-26124

'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft ACI Confidential Containers
Provider severity
MEDIUM
Conflicts
0

CVE-2026-26123

Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft
Product
Microsoft Authenticator for IOS, Microsoft Authenticator for Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-26122

Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft ACI Confidential Containers
Provider severity
MEDIUM
Conflicts
0

CVE-2026-26121

Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure IoT Explorer
Provider severity
HIGH
Conflicts
1

CVE-2026-26120

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Bing
Provider severity
MEDIUM
Conflicts
0

CVE-2026-26119

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Windows Admin Center
Provider severity
HIGH
Conflicts
0

CVE-2026-26118

Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Azure MCP Server Tools 2.0.0 (PyPi), Azure MCP Server Tools 1.0.0 (npm), Azure MCP Server Tools 2.0.0 (npm), Azure MCP Server Tools 2.0.0 (NuGet), Azure MCP Server Tools 1.0.0 (NuGet)
Provider severity
HIGH
Conflicts
1

CVE-2026-26117

Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Arc Enabled Servers - Azure Connected Machine Agent
Provider severity
HIGH
Conflicts
0

CVE-2026-26116

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft
Product
Microsoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2025 (CU 2)
Provider severity
HIGH
Conflicts
1

CVE-2026-26115

Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft SQL Server 2019 (CU 32), Microsoft SQL Server 2019 (GDR), Microsoft SQL Server 2022 for x64-based Systems (CU 23), Microsoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2017 (CU 31), Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack, Microsoft SQL Server 2025 (CU 2), Microsoft SQL Server 2016 Service Pack 3 (GDR), Microsoft SQL Server 2022 (GDR), Microsoft SQL Server 2017 (GDR)
Provider severity
HIGH
Conflicts
1

CVE-2026-26114

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft
Product
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019
Provider severity
HIGH
Conflicts
1

CVE-2026-26113

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 2016, Microsoft Office LTSC 2021, Microsoft Office 2019, Microsoft Office LTSC for Mac 2024, Microsoft SharePoint Enterprise Server 2016, Microsoft Office LTSC for Mac 2021, Microsoft SharePoint Server Subscription Edition, Microsoft Office LTSC 2024, Microsoft 365 Apps for Enterprise, Microsoft SharePoint Server 2019
Provider severity
HIGH
Conflicts
1