Microsoft Makers of the Windows Operating System and hundreds of products that run on it.
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Microsoft product.
RSS Feeds for Microsoft security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Microsoft products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Microsoft Sorted by Most Security Vulnerabilities since 2018
Recent Microsoft Security Advisories
| Advisory | Title | Published |
|---|---|---|
| CVE-2026-66803 | CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability | July 30, 2026 |
| CVE-2026-13037 | Chromium: CVE-2026-13037 Use after free in WebView | July 28, 2026 |
| CVE-2026-13032 | Chromium: CVE-2026-13032 Use after free in WebGL | July 28, 2026 |
| CVE-2026-13030 | Chromium: CVE-2026-13030 Uninitialized Use in GPU | July 28, 2026 |
| CVE-2026-13028 | Chromium: CVE-2026-13028 Use after free in WebGL | July 28, 2026 |
| CVE-2026-16461 | CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting | July 27, 2026 |
| CVE-2026-8450 | CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file() | July 27, 2026 |
| CVE-2026-64530 | CVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle | July 27, 2026 |
| CVE-2026-16807 | Chromium: CVE-2026-16807 Out of bounds write in Codecs | July 25, 2026 |
| CVE-2026-16806 | Chromium: CVE-2026-16806 Use after free in WebMCP | July 25, 2026 |
Known Exploited Microsoft Vulnerabilities
The following Microsoft vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Microsoft SharePoint Deserialization of Untrusted Data Vulnerability |
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. CVE-2026-50522 Exploit Probability: 57.1% |
July 22, 2026 |
| Microsoft SharePoint Deserialization of Untrusted Data Vulnerability |
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. CVE-2026-58644 |
July 16, 2026 |
| Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerabil |
Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally. CVE-2026-56155 Exploit Probability: 2.3% |
July 14, 2026 |
| Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability |
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network. CVE-2026-56164 Exploit Probability: 18.4% |
July 14, 2026 |
| Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability |
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network. CVE-2026-45659 Exploit Probability: 9.1% |
July 1, 2026 |
| Microsoft Internet Explorer Use-After-Free Vulnerability |
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CVE-2010-0249 Exploit Probability: 91.9% |
May 20, 2026 |
| Microsoft Windows Buffer Overflow Vulnerability |
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization. CVE-2008-4250 Exploit Probability: 98.8% |
May 20, 2026 |
| Microsoft Defender Denial of Service Vulnerability |
Microsoft Defender contains an unspecified vulnerability that allows for denial of service. CVE-2026-45498 Exploit Probability: 63.1% |
May 20, 2026 |
| Microsoft DirectX NULL Byte Overwrite Vulnerability |
Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file. CVE-2009-1537 Exploit Probability: 51.2% |
May 20, 2026 |
| Microsoft Internet Explorer Use-After-Free Vulnerability |
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CVE-2010-0806 Exploit Probability: 82.2% |
May 20, 2026 |
| Microsoft Defender Link Following Vulnerability |
Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally. CVE-2026-41091 Exploit Probability: 9.6% |
May 20, 2026 |
| Microsoft Exchange Server Cross-Site Scripting Vulnerability |
Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context. CVE-2026-42897 Exploit Probability: 5.6% |
May 15, 2026 |
| Microsoft Windows Protection Mechanism Failure Vulnerability |
Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network. CVE-2026-32202 Exploit Probability: 63.7% |
April 28, 2026 |
| Microsoft Defender Insufficient Granularity of Access Control Vulnerability |
Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally. CVE-2026-33825 Exploit Probability: 6.7% |
April 22, 2026 |
| Microsoft Office Remote Code Execution |
Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object. CVE-2009-0238 Exploit Probability: 43.1% |
April 14, 2026 |
| Microsoft SharePoint Server Improper Input Validation Vulnerability |
Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. CVE-2026-32201 Exploit Probability: 21.5% |
April 14, 2026 |
| Microsoft Windows Link Following Vulnerability |
Microsoft Windows contains a link following vulnerability that allows for privilege escalation CVE-2025-60710 Exploit Probability: 4.7% |
April 13, 2026 |
| Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability |
Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. CVE-2023-21529 Exploit Probability: 62.1% |
April 13, 2026 |
| Microsoft Windows Out-of-Bounds Read Vulnerability |
Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation CVE-2023-36424 Exploit Probability: 12.2% |
April 13, 2026 |
| Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability |
Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution. CVE-2012-1854 Exploit Probability: 21.0% |
April 13, 2026 |
Of the known exploited vulnerabilities above, 6 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 7 known exploited Microsoft vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
Top 10 Riskiest Microsoft Vulnerabilities
Based on the current exploit probability, these Microsoft vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.
| Rank | CVE | EPSS | Vulnerability |
|---|---|---|---|
| 1 | CVE-2021-34473 | 100.0% | Microsoft Exchange Server Remote Code Execution Vulnerability |
| 2 | CVE-2021-26855 | 100.0% | Microsoft OWA Exchange Control Panel (ECP) Exploit Chain |
| 3 | CVE-2019-0708 | 100.0% | "BlueKeep" Microsoft Windows Remote Desktop Remote Code Execution Vulnerability |
| 4 | CVE-2015-1635 | 100.0% | Microsoft HTTP.sys Remote Code Execution Vulnerability |
| 5 | CVE-2021-34523 | 100.0% | Microsoft Exchange Server Privilege Escalation Vulnerability |
| 6 | CVE-2022-41082 | 100.0% | Microsoft Exchange Server Remote Code Execution Vulnerability |
| 7 | CVE-2012-0158 | 100.0% | Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability |
| 8 | CVE-2020-0688 | 100.0% | Microsoft Exchange Server Key Validation Vulnerability |
| 9 | CVE-2022-41040 | 100.0% | Microsoft Exchange Server Server-Side Request Forgery Vulnerability |
| 10 | CVE-2021-27065 | 99.9% | Microsoft OWA Exchange Control Panel (ECP) Exploit Chain |
By the Year
In 2026 there have been 4680 vulnerabilities in Microsoft with an average score of 7.3 out of ten. Last year, in 2025 Microsoft had 2750 security vulnerabilities published. That is, 1930 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.05.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 4680 | 7.27 |
| 2025 | 2750 | 7.22 |
| 2024 | 2182 | 7.33 |
| 2023 | 1695 | 7.21 |
| 2022 | 1389 | 7.43 |
| 2021 | 1153 | 7.44 |
| 2020 | 1253 | 7.20 |
| 2019 | 831 | 7.08 |
| 2018 | 661 | 7.03 |
It may take a day or so for new Microsoft vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Microsoft Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-66803 | Jul 30, 2026 |
Jul 2026: Azure Cosmos DB Remote Code Execution VulnerabilityImproper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. |
|
| CVE-2026-62828 | Jul 28, 2026 |
Jul 2026: Microsoft Edge for Android (Chromium-based) Tampering VulnerabilityImproper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network. |
|
| CVE-2026-57990 | Jul 26, 2026 |
Jul 2026: Microsoft Edge (Chromium-based) Information Disclosure VulnerabilityFiles or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. |
|
| CVE-2026-57989 | Jul 26, 2026 |
Jul 2026: Microsoft Edge (Chromium-based) Information Disclosure VulnerabilityOrigin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. |
|
| CVE-2026-57978 | Jul 26, 2026 |
Jul 2026: Microsoft Edge (Chromium-based) Spoofing VulnerabilityOrigin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
|
| CVE-2026-64530 | Jul 26, 2026 |
Linux Kernel: Handle TC_ACT_CONSUMED in tcf_qevent_handle Prevents SKB UAFIn the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the defragmentation engine (e.g. act_ct on out-of-order fragments). When that happens the skb is no longer owned by the caller and must not be touched again. tcf_qevent_handle() did not handle TC_ACT_CONSUMED: it fell through the switch and returned the skb to the caller as if classification had passed. The only qdisc that wires up qevents today is RED, via three call sites (qe_mark on RED_PROB_MARK/HARD_MARK, qe_early_drop on congestion_drop) red_enqueue() was continuing to operate on an skb it no longer owns in this case -- enqueueing it, dropping it, or updating statistics. Resulting in a UAF. tc qdisc add dev eth0 root handle 1: red ... qevent early_drop block 10 tc filter add block 10 ... action ct (with ct defrag enabled and traffic that produces out-of-order fragments, e.g. a fragmented UDP stream) Handle TC_ACT_CONSUMED in tcf_qevent_handle() the same way the ingress and egress fast paths do: treat it as stolen and return NULL without touching the skb. Unlike the TC_ACT_STOLEN case, the skb must not be dropped/freed here, as it is no longer owned by us. |
|
| CVE-2026-62835 | Jul 24, 2026 |
Jul 2026: Azure Portal Information Disclosure VulnerabilityImproper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. |
|
| CVE-2026-56163 | Jul 24, 2026 |
Jul 2026: Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityMissing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. |
|
| CVE-2026-58630 | Jul 24, 2026 |
Jul 2026: Azure App Service on Azure Stack Hub Elevation of Privilege VulnerabilityImproper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. |
|
| CVE-2026-57106 | Jul 24, 2026 |
Jul 2026: Data Quality Elevation of Privilege VulnerabilityServer-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. |
|
| CVE-2026-58275 | Jul 24, 2026 |
Jul 2026: Azure DNS Elevation of Privilege VulnerabilityMissing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. |
|
| CVE-2026-62825 | Jul 24, 2026 |
Jul 2026: Azure Key Vault Elevation of Privilege VulnerabilityImproper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. |
|
| CVE-2026-50517 | Jul 24, 2026 |
Jul 2026: Microsoft M365 Copilot Remote Code Execution VulnerabilityDeserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. |
|
| CVE-2026-56191 | Jul 24, 2026 |
Jul 2026: Microsoft Exchange Online Tampering VulnerabilityImproper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. |
|
| CVE-2026-35425 | Jul 24, 2026 |
Jul 2026: Azure API Management (APIM) Remote Code Execution VulnerabilityImproper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. |
|
| CVE-2026-49159 | Jul 24, 2026 |
Jul 2026: Microsoft Graph Information Disclosure VulnerabilityExposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. |
|
| CVE-2026-56160 | Jul 23, 2026 |
Jul 2026: Azure Red Hat OpenShift (ARO) Elevation of Privilege VulnerabilityImproper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. |
|
| CVE-2026-54120 | Jul 23, 2026 |
Jul 2026: Microsoft Surface Remote Code Execution VulnerabilityImproper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. |
|
| CVE-2026-56165 | Jul 23, 2026 |
Jul 2026: Microsoft Account Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. |
|
| CVE-2026-56167 | Jul 23, 2026 |
Jul 2026: Azure AI Search Elevation of Privilege VulnerabilityServer-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. |
|
| CVE-2026-16804 | Jul 23, 2026 |
Use after free in Input in Google Chrome <150.0.7871.186Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-16806 | Jul 23, 2026 |
Use-after-Free in Chrome WebMCP before 150.0.7871.186 (Remote code execution)Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-16805 | Jul 23, 2026 |
Use after free in Blink (Chrome <150.0.7871.186) Enables Remote Code ExecutionUse after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-16807 | Jul 23, 2026 |
Out-of-bounds write in Codecs in Chrome 150.0.7871.186 Caused Sandbox EscapeOut of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-59677 | Jul 23, 2026 |
SELinux Policycoreutils 3.10 Unconfined Kill Auth BypassA Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10. |
|
| CVE-2026-59676 | Jul 23, 2026 |
seunshare TOCTOU Race in Selinux Policycoreutils 3.10 Arbitrary File DeletionA Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils through 3.10. |
|
| CVE-2026-64600 | Jul 23, 2026 |
Linux Kernel XFS: Stale Data Mappings Post ILOCK Reacquire Causing DirectIO RaceIn the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. Currently we refresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but we don't refresh the data fork mapping beforehand, which means that the xfs_bmap_trim_cow in that function queries the refcount btree about the wrong physical blocks and returns an inaccurate value in *shared. If *shared is now false, the directio write proceeds with a stale data fork mapping. Fix this by querying the data fork mapping if the sequence counter changes across the ILOCK cycle. |
|
| CVE-2026-53910 | Jul 22, 2026 |
Diffutils diff3 Heap Buffer Overflow via Signed Integer Overflowsdiff3 tool from GNU diffutils is vulnerable to a heapbased buffer overflow due to multiple signed integer overflows in linemapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds. When processing crafted diff output, these overflows may cause the application to allocate insufficient memory and subsequently perform outofbounds writes during internal processing. An attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, resulting in a crash and potentially remote code execution depending on the environment. This issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815 NOTE: The project maintainers claim that this is not a security issue. They state that the worst outcome this issue can cause is a crash of diff and that it cannot be used to escalate privileges. |
|
| CVE-2026-56444 | Jul 22, 2026 |
Unbound 1.201.25.1: Serve-Expired Branch Causes Silent Client DropsIn NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values), the discard-timeout branch during the serve expired logic drops an aged client reply without performing the correct accounting for the number of reply addresses for the query. Other identical branches outside of serve expired perform the correct decrement. Since the counter is never decremented in such scenario, it can reach the maximum limit and new clients for duplicate in-flight queries are silently dropped resulting in degradation of resolution service. A malicious actor can exploit the vulnerability by querying the resolver for a client-controlled slow-on-demand authoritative zone that can drive the counter past the threshold. Shipped defaults for 'serve-expired-client-timeout: 1800' and 'discard-timeout: 1900' make the branch unreachable. |
|
| CVE-2026-56416 | Jul 22, 2026 |
Unbound 1.25.1 Vulnerable RRSIG + PX RP MINFO SOA Leads to Heap Buffer OverflowIn NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker who runs a DNSSEC-signed authoritative server can deliver a record with an absent second domain name (e.g. SOA record) and cause 'query_dname_tolower()' to walk label-by-label through stale bytes in the per-worker 'env->scratch_buffer', past the end of that heap allocation if 'msg-buffer-size' has been lowered from the default. This leads to heap buffer overflow and on a release build the outcome relies heavily on the contents of the buffer tail and the adjacent heap chunk. |
|
| CVE-2026-55991 | Jul 22, 2026 |
Unbound 1.22-1.25.1 DoQ crash via libngtcp2 assertionIn NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate the entire Unbound process using a single DNS-over-QUIC (DoQ) connection and one normal DNS query. This is caused by an erroneous error value passed to libngtcp2. When 'ngtcp2_conn_writev_stream()' returns 'NGTCP2_ERR_STREAM_DATA_BLOCKED', Unbound continues to call 'ngtcp2_ccerr_set_application_error()' with a '-1' error value. The 'int' literal '-1' is implicitly converted to the function's 'uint64_t error_code' parameter as '0xFFFFFFFFFFFFFFFF'. The follow-on 'ngtcp2_conn_write_connection_close()' serialises that value as a QUIC variable-length integer; because '2^64-1' exceeds the 62-bit varint ceiling, 'ngtcp2_put_uvarintlen()' fails 'assert(n < 4611686018427387904ULL)' and the whole resolver process aborts. A remote, unauthenticated DoQ client can trigger this deterministically with a single QUIC connection by advertising 'initial_max_stream_data_bidi_local = 1' in its transport parameters and sending one DoQ query without ever reading the stream. |
|
| CVE-2026-55990 | Jul 22, 2026 |
Unbound 1.7.0-1.25.1 DNSCrypt Config Buffer UnderflowIn NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with '0xdb' bytes. Any unauthenticated client that sends one UDP datagram of 68 bytes whose first 8 bytes are '0xdb' to 'dnscrypt-port' will use that garbage entry which leads to a garbage dereference killing the server. This is a silent faulty configuration that goes unnoticed until triggered with the right client query. Unbound needs to be compiled with DNSCrypt support ('--enable-dnscrypt'). |
|
| CVE-2026-55973 | Jul 22, 2026 |
Unbound 1.23.0-1.25.1 EDNS Report-Channel Stack Overflow via Malformed Agent DomainIn NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic '_er.' report query name. That query name is later used in the iterator via a subquery to send out the DNS Error Report and when Unbound tries to walk that query name during 'find_closest_of_type()', it strips labels using the query name length rather than stopping at the embedded root, walks one byte past it, and feeds the first garbage byte to 'dname_query_hash()' as a label length writing over the stack variable 'labuf'. One ordinary upstream response from a delegated zone the attacker controls is sufficient to terminate the daemon. |
|
| CVE-2026-55717 | Jul 22, 2026 |
Unbound 1.10.0-1.25.1 serve-expired-client-timeout Null Ptr Crash via response-ipIn NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: <net> redirect' /'response-ip-data: <net> CNAME <target>' rule (or the RPZ 'rpz-cname-override' equivalent), a remote client who controls any delegated domain can crash the daemon. The serve-expired-client-timeout callback runs a two-pass loop to chase the respip-generated CNAME alias; on the second pass it resets 'alias_rrset' but not 'partial_rep'. Later, this inconsistency leads to a NULL pointer dereference and an eventual crash. A malicious actor can exploit the vulnerability by controlling any zone that replies with an A/AAAA record that falls inside the configured response-ip/rpz subnet. By delaying the answer when the previous record has expired, the vulnerable path of 'serve-expired-client-timeout' is taken leading to denial of service via the server crash. |
|
| CVE-2026-55708 | Jul 22, 2026 |
Unbound 1.6.0-1.25.1 unsafely omits default zones via unbound-controlIn NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones (e.g., RFC 1918 reverse, AS112 zones, .onion, .localhost). Once the local zone tree exists without the defaults, every query for a default-protected name from a client mapped to that view escapes to the public DNS via the iterator instead of being answered locally, bypassing local policy expectations. |
|
| CVE-2026-54478 | Jul 22, 2026 |
Unbound 1.18.0-1.25.1 Proxy-Protocol Cookie Replay (RFC9018)In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with 'answer-cookie: yes', the RFC 9018 server-cookie SipHash is computed over the proxy's wire address instead of the PROXYv2-declared client. One server cookie obtained through a given proxy node therefore validates for every PROXYv2-declared source behind that node. On a UDP+proxy-protocol front, an off-path attacker can harvest one cookie with a single legitimate query, then replay it under any spoofed source and pass DNS Cookie checks that were deployed to defeat this in the first place. |
|
| CVE-2026-52863 | Jul 22, 2026 |
Unbound 1.25.0-1.25.1 MemCorrupt via respip/dns64 shallow copyIn NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is jostled out when Unbound is under pressure. Unbound needs to be configured with one of 'respip'/'rpz' modules, together with a module that can attach subqueries (respip CNAME redirection, dns64, subnetcache) and a configured 'access-control-view' while Unbound is under pressure so that joslte logic kicks in and starts dropping slow queries. The subquery is getting a shallow copy of the view name and if the super query which owns the view name is jostled out, memory corruption can occur. Likelihood of a crash is low, since it relies heavily on the underlying memory allocator and the memory layout. Debug memory builds (e.g., ASAN) that catch the free terminate the server. |
|
| CVE-2026-50252 | Jul 22, 2026 |
Unbound 1.4.221.25.1 UDP SrcPort Randomization Flaw Enables Cache PoisoningIn NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port while their outcome is revealed this secrecy is undermined. The vulnerability arises when the load balancing policy is consistent with respect to the incoming source UDP port and IP address while heavily depending on the incoming source UDP port as a randomization source. When the SO_REUSEPORT configuration option is enabled ('so-reuseport: yes') in Unbound (by default), it meets these conditions, making it vulnerable for DNS cache poisoning attacks. Upon startup, Unbound randomly partitions the available UDP source port space into disjoint subsets of (almost) equal size, assigning each subset to a specific worker thread. When an incoming DNS query is received, the kernels SO_REUSEPORT load balancing mechanism deterministically assigns the query to a socket associated with a particular thread. All outgoing DNS queries generated during the resolution of that request use source ports selected exclusively from the port subset assigned to the corresponding thread. Since these port subsets are disjoint across threads, the source port observed in a resolvers outgoing query to an authoritative name server serves as a reliable indicator of the worker thread that processed the original client query. A malicious actor can acquire the mapping between incoming UDP source ports (for a given fixed source IP address) and Unbound worker threads and leverage it to conduct DNS cache poisoning attacks by effectively lowering the random port population per thread. |
|
| CVE-2026-50251 | Jul 22, 2026 |
Unbound 0.0.0.0/::0 Glue Loop Triggers Cache FlushIn NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS queries and receiving seemingly unwanted replies since the remote IP does not match the original source IP of 0.0.0.0/::0. This behavior keeps on looping for the glue records and pushing the counter to the configured 'unwanted-reply-threshold' that triggers a defensive cache clear. A malicious actor who controls a delegation that returns in-bailiwick glue of 0.0.0.0/::0 can drive the counter to the limit of 'unwanted-reply-threshold' to the threshold and trigger a cache clean of the message and rrset caches; at will, indefinitely, without sending a single spoofed packet. The iterator uses the 0.0.0.0/::0 glue, and a system that can route this (e.g., Linux kernel routes the datagram over loopback), Unbound's own listener answers from 127.0.0.1. Because of the mismatch of 0.0.0.0 and 127.0.0.1, in this example, Unbound accounts the reply as an unwanted (probably spoofed) answer. The counter resets to zero on every cache flush, so the attack loops forever. |
|
| CVE-2026-50248 | Jul 22, 2026 |
Unbound 1.7.0-1.25.1 BOGUS A/AAAA Spoofing Enables Unauth XFRIn NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostname's A/AAAA record (no valid RRSIG required) becomes the zone's XFR primary and can replaces the entire zone/the resolver's entire response policy. |
|
| CVE-2026-50243 | Jul 22, 2026 |
Unbound 1.6.21.25.1: respip rewrites BOGUS DNSSEC answers as INSECUREIn NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect rule or an RPZ file with an RPZ-IP trigger, the rewriting handler does not check the security status of the upstream answer and can instead rewrite a BOGUS A/AAAA answer to point to an operator's configured IP. If the validator finds an expired or otherwise invalid RRSIG on an answer whose A record falls within a 'response-ip'/RPZ configuration, the answer is still rewritten and given a hard coded security level of INSECURE. This results in the client receiving an INSECURE NOERROR reply rewritten by the operator's configured IP. A malicious actor can exploit the possible poisonous effect by spoofing a BOGUS A/AAAA answer that falls inside the operator's configured subnet rewrites. Such DNSSEC protected answers are then insecurely redirected to the operator's configured target. |
|
| CVE-2026-50046 | Jul 22, 2026 |
Unbound DoT TLS Server Name Deref Crash before v1.25.2In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind the referenced string and if the TLS stream then errors out, it dereferences the freed pointer. The dereference is read-only and the practical impact is a daemon crash resulting in denial of service. A malicious actor that knows a DoT forwarding/stub Unbound's configuration could exploit the vulnerability by quering records in the appropriate zone while keeping Unbound uder pressure so that the jostle logic kicks in. If answers for the vulnerable zone are slow, the likelihood of jostling such queries is higher, although the timing of the jostle needs to be precise. Requirements for a vulnerable Unbound is the existence of a stub/forward zone configured for DoT together with a configured '#authname' suffix on the server identification. The connectivity to the server needs to exhibit a transient failure at the correct time in order to kick off the vulnerable error path. |
|
| CVE-2026-50045 | Jul 22, 2026 |
DNSSEC Amplification Bypass in Unbound <=1.25.1 via Excessive Upstream PacketsIn NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the configured 'max-global-quota'. This effectively bypasses a security configuration that limits upstream amplification traffic. |
|
| CVE-2026-46582 | Jul 22, 2026 |
Unbound DNSSEC Wildcard Replay Cache Poisoning CVE-2026-46582 1.25.1In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before later validation treats it as bogus based on NSEC validation. When the resolving thread puts secure on the rrset, and another thread that is on the serve expired path then picks up the updated rrset contents with the secure status for a reply, it can be used to change a specific record, next to a wildcard that could be covered by the wildcard, into the wildcard. A malicious actor can exploit the possible poisonous effect by having any DNSSEC-singed domain (irrelevant to the victim domain) and a CNAME wrapper record that points to a record next to a wildcard (that could be covered by the wildcard). Then quering Unbound for the wildcard sibling record would seed the secure message. A later (after expiry) query for the CNAME wrapper would need to resolve the target sibling record. If the wildcard replay is injected into the response, the wildcard rrset will update the expired sibling record with a secure status before completing proper wildcard validation with NSEC records and eventually treating the CNAME wrapper answer as bogus. The updated poisoned rrset is now secure and points to the wildcard. This vulnerability is explicit for the serve expired path and needs injection of the signed wildcard rrset without the NSEC accompanying rrset. |
|
| CVE-2026-44690 | Jul 22, 2026 |
Unbound 1.7.01.25.1 RRSIG.Labels Poisoning via NSEC Aggressive CacheIn NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. This allows the malicious actor to inject insecure wildcard records for those delegations. |
|
| CVE-2026-44687 | Jul 22, 2026 |
Unbound 1.13.21.25.1: hardenbelownxdomain NXDOMAIN bypassIn NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate labed below a DNSSEC signed zone could be shadowed by the intermediate label's secure NXDOMAIN answer from the parent. This is caused by an off-by-one error in 'harden-below-nxdomain' logic; enabled by default. It effectively bypasses the configuration and the configured stub/forward zone is never contacted. 'harden-below-nxdomain' does an upward DNS cache walk together with a delegation point guard that does not allow NXDOMAIN synthesis above stub/forward zones. The guard tests the domain name but before stripping a label. This results in an iteration where the domain name equals the configured stub/forward zone apex that passes the guard, strips one more label, and probes the cache at the apex's immediate public parent. If that parent has a cached DNSSEC-secure NXDOMAIN, which it will for any private namespace nested two or more labels under a signed public name, the walk returns it and the configured stub/forward upstream is never contacted. This can only be triggered by the query for the intermediate label (between the stub/forward apex and the DNSSEC parent zone). |
|
| CVE-2026-44621 | Jul 22, 2026 |
Unbound 1.25.1 libunbound crash via UnwantedReplyThresholdWith NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold', could eventually be abruptly terminated if the threshold is reached and libunbound needs to call 'libworker_alloc_cleanup' since the function is absent from the function call allow list. When an application using libunbound sets 'unwanted-reply-threshold' to any non-zero value and the iterator queries an authoritative that replies with enough wrong-transaction-ID UDP datagrams to cross the threshold, the 'libworker_alloc_cleanup' will eventually be called. Since the function is absent from the function call allow list, this leads to a fatal exit of libunbound and eventual termination of the embedding application.Unbound itself is not affected since its relevant function 'worker_alloc_cleanup' is registed in the allow list and proceeds to perform the documented cache flush. |
|
| CVE-2026-42955 | Jul 22, 2026 |
Unbound 1.16.21.25.1 Ghost Domain TTL Extension VulnerabilityIn NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client A/AAAA query can cause Unbound to overwrite the cached expired parent-side glue rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client query is required since Unbound implicitly performs that query. This is a variant of CVE-2026-40622 which only addressed the NS query. |
|
| CVE-2026-41637 | Jul 22, 2026 |
Unbound 1.22.0-1.25.1 DoQ Query Counter DoS via Dropped StreamsIn NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queries are not accounted properly by Unbound resulting in low-cost inflation of the waiting number of replies for already in-flight resolution queries. This results in degradation of resolution service for new clients for already in-flight queries. A malicious actor can exploit the vulnerability by issuing DoQ queries for query names that need resolution and proceeding on immediately terminating the query by one of STOP_SENDING/RESET_STREAM/CONNECTION_CLOSE QUIC frames. Those terminated DoQ queries are not properly counted for and keep inflating the number of waiting replies for in-flight queries. When the maximum is reached, it results in silent query drops for new clients needing resolution for already in-flight queries. This vulnerability needs Unbound to be compiled with DoQ support ('--with-libngtcp2') and the 'quic-port' to be configured for the listening interfaces. Additionally, a malicious actor needs access to multiple source IPs to bypass the by-default configured 'wait-limit' option. |
|
| CVE-2026-40691 | Jul 22, 2026 |
Unbound 1.9.01.25.1 DNSCrypt TCP DoSIn Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound the reply length against the destination buffer size. The size clamp that protects the UDP path is not applied on the TCP path, so a reply larger than 65504 bytes is shifted forward by 48 bytes inside a buffer of capacity equal to 'msg-buffer-size', writing past the end of the heap allocation. A single malicious encrypted query crashes the resolver and lead to denial of service. This vulnerability needs Unbound to be compiled with DNSCrypt support ('--enable-dnscrypt') and the 'dnscrypt:' clause to be configured and enabled for the listening interfaces. |