Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.9
CVE-2026-42823
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
Azure Logic Apps
Mitigation only
CRITICAL 9.1
CVE-2026-42833
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over …
Dynamics 365
9.1.45.11+
CRITICAL 9.8
CVE-2026-41096
Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.
Windows 11 23h2
10.0.22631.7079 / 10.0.25398.2330+
CRITICAL 9.1
CVE-2026-41103EPSS 5%
Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate pri…
Confluence Saml Sso
1.3.3 / 7.4.0+
CRITICAL 9.8
CVE-2026-41089EPSS 80%
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
Windows Server 2012
10.0.14393.9140 / 10.0.17763.8755+
CRITICAL 9.3
CVE-2026-40402
Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.
Windows 11 23h2
10.0.20348.5074 / 10.0.22631.7079+
CRITICAL 9.9
CVE-2026-33821
Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.
Dynamics 365 Customer Insights
Mitigation only
CRITICAL 9.1
CVE-2026-33117
The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag com…
Azure Sdk For Java
4.10.6+
CRITICAL 10.0
CVE-2026-35435
Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Foundry
Mitigation only
CRITICAL 9.9
CVE-2026-33109
Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
Azure Managed Instance For Apache Cassandra
Mitigation only
CRITICAL 9.6
CVE-2026-35428
Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform s…
Azure Cloud Shell
Mitigation only
CRITICAL 9.0
CVE-2026-33844
Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
Azure Managed Instance For Apache Cassandra
Mitigation only
CRITICAL 9.9
CVE-2026-21515
Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.
Azure Iot Central
No fix yet
CRITICAL 10.0
CVE-2026-35431
Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.
Entra Id
Mitigation only
CRITICAL 9.8
CVE-2026-33819
Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.
Bing
Mitigation only
CRITICAL 9.3
CVE-2026-33102
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
365 Copilot
Mitigation only
CRITICAL 10.0
CVE-2026-26150
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
Purview Ediscovery
Mitigation only
CRITICAL 9.6
CVE-2026-24303
Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
Partner Center
No fix yet
CRITICAL 9.1
CVE-2026-40372EPSS 11%
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
Asp.net Core
10.0.7+
CRITICAL 9.8
CVE-2026-33824 KEVEPSS 78%
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9060 / 10.0.17763.8644+
CRITICAL 9.0
CVE-2026-26149
Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a networ…
Power Apps
3.26032.10.0+
CRITICAL 9.8
CVE-2026-32186
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.
Bing
No fix yet
CRITICAL 9.8
CVE-2026-33105
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
Azure Kubernetes Service
Mitigation only
CRITICAL 9.8
CVE-2026-33107
Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
Azure Databricks
Mitigation only
CRITICAL 9.8
CVE-2026-32213
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Foundry
Mitigation only
CRITICAL 9.8
CVE-2026-32194
Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execu…
Bing Images
No fix yet
CRITICAL 9.8
CVE-2026-32169
Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.
Azure Cloud Shell
Mitigation only
CRITICAL 9.8
CVE-2026-32191
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker t…
Bing Images
Mitigation only
CRITICAL 10.0
CVE-2026-26138
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
Purview
Mitigation only
CRITICAL 9.9
CVE-2026-26137
Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.
365 Copilot Chat
No fix yet