Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2026-33837
Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9140 / 10.0.17763.8755+
HIGH 7.8
CVE-2026-33838
Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9140 / 10.0.17763.8755+
CRITICAL 9.9
CVE-2026-33821
Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.
Dynamics 365 Customer Insights
Mitigation only
CRITICAL 9.1
CVE-2026-33117
The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag com…
Azure Sdk For Java
4.10.6+
HIGH 8.8
CVE-2026-33110
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Server
16.0.19725.20280+
HIGH 8.8
CVE-2026-33112
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Server
16.0.19725.20280+
HIGH 7.8
CVE-2026-32204
External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
Azure Monitor Agent
1.14.0+
MEDIUM 5.5
CVE-2026-32185
Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.
Teams
1.0.0.2026092103+
HIGH 7.3
CVE-2026-32177
Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
Visual Studio 2022
8.0.27 / 9.0.16+
MEDIUM 6.7
CVE-2026-32170
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9140 / 10.0.17763.8755+
HIGH 7.5
CVE-2026-32161
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthor…
Windows 10 1607
10.0.14393.9140 / 10.0.17763.8755+
MEDIUM 6.7
CVE-2026-21530
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9140 / 10.0.17763.8755+
HIGH 8.1
CVE-2026-41105
Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network.
Azure Monitor Action Group Notification System
Mitigation only
HIGH 7.5
CVE-2026-42826
Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.
Azure Devops
No fix yet
CRITICAL 10.0
CVE-2026-35435
Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Foundry
Mitigation only
CRITICAL 9.9
CVE-2026-33109
Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
Azure Managed Instance For Apache Cassandra
Mitigation only
CRITICAL 9.6
CVE-2026-35428
Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform s…
Azure Cloud Shell
Mitigation only
CRITICAL 9.0
CVE-2026-33844
Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
Azure Managed Instance For Apache Cassandra
Mitigation only
HIGH 8.2
CVE-2026-34327
Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over …
Partner Center
Mitigation only
HIGH 7.5
CVE-2026-33111
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker …
Copilot Chat
Mitigation only
MEDIUM 6.5
CVE-2026-33823
Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
Teams
No fix yet
HIGH 7.5
CVE-2026-26129
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor…
365 Copilot Chat
No fix yet
HIGH 7.5
CVE-2026-26164
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor…
365 Copilot Chat
No fix yet
MEDIUM 6.1
CVE-2026-32207
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to per…
Azure Machine Learning
Mitigation only
CRITICAL 9.9
CVE-2026-21515
Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.
Azure Iot Central
No fix yet
HIGH 7.5
CVE-2026-32952
go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can caus…
Go Ntlmssp
0.1.1+
CRITICAL 10.0
CVE-2026-35431
Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.
Entra Id
Mitigation only
CRITICAL 9.8
CVE-2026-33819
Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.
Bing
Mitigation only
CRITICAL 9.3
CVE-2026-33102
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
365 Copilot
Mitigation only
HIGH 7.5
CVE-2026-32210
Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.
Dynamics 365
Mitigation only