Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2026-24299
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor…
365 Copilot
Mitigation only
HIGH 7.5
CVE-2026-23659
Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a netwo…
Azure Data Factory
No fix yet
CRITICAL 9.8
CVE-2026-23658
Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
Azure Devops
No fix yet
HIGH 7.5
CVE-2026-25667
ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by se…
.net
8.0.22 / 9.0.11+
HIGH 7.1
CVE-2026-26133
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
365 Copilot
2.2.260210.21290750 / 2.106+
MEDIUM 5.0
CVE-2026-0385
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
Edge Chromium
146.0.3856.59+
MEDIUM 5.5
CVE-2026-26123
Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.
Authenticator
6.8.40 / 6.2511.7533+
HIGH 8.1
CVE-2026-26148
External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.
Azure Ad Ssh Login Extension For Linux
1.0.033370002+
HIGH 7.8
CVE-2026-26131
Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.
.net
10.0.4+
HIGH 7.8
CVE-2026-26132
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Windows 10 21h2
10.0.19044.7058 / 10.0.19045.7058+
HIGH 7.8
CVE-2026-26134
Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.
365 Copilot
16.0.19822.20000+
HIGH 7.8
CVE-2026-26141
Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.
Azure Automation Hybrid Worker Windows Extension
1.3.74+
HIGH 7.5
CVE-2026-26130
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Asp.net Core
8.0.25 / 9.0.14+
HIGH 8.8
CVE-2026-26118
Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.
Azure Mcp Server
2.0.0+
HIGH 7.8
CVE-2026-26117
Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges l…
Arc Enabled Servers Azure Connected Machine Agent
1.61+
HIGH 7.8
CVE-2026-26128
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
HIGH 7.5
CVE-2026-26121
Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network.
Azure Iot Explorer
0.15.14+
HIGH 7.5
CVE-2026-26127
Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.
.net
9.0.14 / 10.0.4+
HIGH 8.8
CVE-2026-26114
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Server
Mitigation only
HIGH 8.8
CVE-2026-26115
Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.
Sql Server 2016
13.0.6480.4 / 13.0.7075.5+
HIGH 8.8
CVE-2026-26116
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…
Sql Server 2016
13.0.6480.4 / 13.0.7075.5+
HIGH 7.8
CVE-2026-26113
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
16.0.19725.20076+
HIGH 8.0
CVE-2026-26111
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
Windows Server 2012
6.2.9200.25973 / 10.0.14393.8957+
HIGH 7.8
CVE-2026-26108
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20102+
HIGH 7.8
CVE-2026-26109
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20102+
HIGH 7.8
CVE-2026-26110
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
16.0.19822.20000+
HIGH 7.8
CVE-2026-26112
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20102+
CRITICAL 9.3
CVE-2026-26105
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…
Sharepoint Server
16.0.19725.20076+
HIGH 8.8
CVE-2026-26106
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Server
16.0.19725.20076+
HIGH 7.8
CVE-2026-26107
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20102+