Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2026-23652
Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execu…
Power Pages
Mitigation only
HIGH 7.7
CVE-2026-26147
Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
Azure Stack Hci
Mitigation only
HIGH 7.5
CVE-2026-23663
Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.
Global Secure Access
No fix yet
HIGH 8.1
CVE-2026-45584
Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
Malware Protection Engine
1.1.26040.8+
HIGH 7.5
CVE-2026-45498 KEVEPSS 63%
Microsoft Defender Denial of Service Vulnerability
Defender Antimalware Platform
4.18.26040.7+
HIGH 7.8
CVE-2026-42834
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Windows Admin Center
0.72.0.0+
HIGH 7.8
CVE-2026-41091 KEVEPSS 10%
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
Malware Protection Engine
1.1.26040.8+
MEDIUM 6.8
CVE-2026-45585
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this…
Windows 11 24h2
No fix yet
CRITICAL 9.8
CVE-2026-45495
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Edge Chromium
148.0.3967.70+
MEDIUM 6.1
CVE-2026-45494
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Edge Chromium
148.0.3967.70+
MEDIUM 5.4
CVE-2026-45492
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
Edge Chromium
148.0.3967.70+
CRITICAL 10.0
CVE-2026-42822
Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.
Azure Local
2604.2.25645+
MEDIUM 6.1
CVE-2026-42897 KEVEPSS 70%
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to …
Exchange Server
15.02.2562.043+
HIGH 7.4
CVE-2026-41615
Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a …
Authenticator
6.8.47 / 6.2605.2973+
CRITICAL 9.9
CVE-2026-42898
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over …
Dynamics 365
9.1.45.11+
HIGH 7.8
CVE-2026-42896
Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.26100.8457 / 10.0.26100.32860+
HIGH 7.5
CVE-2026-42893
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tamper…
Outlook
5.2617.1+
HIGH 7.5
CVE-2026-42899
Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.
.net
8.0.27 / 9.0.16+
MEDIUM 6.5
CVE-2026-42891
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing …
Edge Chromium
148.0.3967.55+
MEDIUM 5.4
CVE-2026-42838
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unaut…
Edge Chromium
148.0.3967.55+
CRITICAL 9.9
CVE-2026-42823
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
Azure Logic Apps
Mitigation only
CRITICAL 9.1
CVE-2026-42833
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over …
Dynamics 365
9.1.45.11+
HIGH 7.8
CVE-2026-42831
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Copilot
16.0.19822.20190+
HIGH 7.0
CVE-2026-42825
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9140 / 10.0.17763.8755+
MEDIUM 6.5
CVE-2026-42830
Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
Azure Monitor Agent
1.42.0+
MEDIUM 5.5
CVE-2026-42832
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
Excel
16.0.19822.20190+
HIGH 8.8
CVE-2026-41613
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Visual Studio Code
1.119.1+
MEDIUM 6.2
CVE-2026-41614
Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.
365 Copilot
19.2604.43111.0+
MEDIUM 5.5
CVE-2026-41612
Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.
Live Preview
0.4.19+
HIGH 8.8
CVE-2026-41109
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unau…
Visual Studio Code
1.119.1+