Microsoft Microsoft Makers of the Windows Operating System and hundreds of products that run on it.

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Microsoft product.

RSS Feeds for Microsoft security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Microsoft products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Microsoft Sorted by Most Security Vulnerabilities since 2018

Microsoft Windows 105047 vulnerabilities

Microsoft Windows Server 20194791 vulnerabilities

Microsoft Windows Server 20164715 vulnerabilities

Microsoft Windows Server 20123545 vulnerabilities

Microsoft Windows Server 20223142 vulnerabilities

Microsoft Windows Server 20082820 vulnerabilities

Microsoft Windows 112280 vulnerabilities

Microsoft Windows 71810 vulnerabilities

Microsoft Windows 11 24h21735 vulnerabilities

Microsoft Windows 8.11712 vulnerabilities

Microsoft Windows Server 20251705 vulnerabilities

Microsoft Windows 11 23h21683 vulnerabilities

Microsoft Windows Rt 8 11592 vulnerabilities

Microsoft Windows 10 15071453 vulnerabilities

Microsoft Windows Server 2012 R21433 vulnerabilities

Microsoft Windows Server 23h21356 vulnerabilities

Microsoft Windows931 vulnerabilities

Microsoft Windows 11 25h2897 vulnerabilities

Microsoft Windows 11 26h1742 vulnerabilities

Microsoft Windows Server655 vulnerabilities

Microsoft Office597 vulnerabilities

Microsoft 365 Apps571 vulnerabilities

Microsoft Internet Explorer (IE)528 vulnerabilities
Popular web browser for windows

Microsoft Sharepoint Server490 vulnerabilities

Microsoft Edge Browser413 vulnerabilities
Web Browser based on Chromium

Microsoft Windows Vista382 vulnerabilities

Microsoft Windows XP326 vulnerabilities

Microsoft Office 2024307 vulnerabilities

Microsoft Office 2021297 vulnerabilities

Microsoft Office 2019285 vulnerabilities

Microsoft Edge Chromium281 vulnerabilities

Microsoft Windows 10 1803275 vulnerabilities

Microsoft Windows 10 1909274 vulnerabilities

Microsoft Windows Server 2003262 vulnerabilities

Microsoft Office Macos 2024259 vulnerabilities

Microsoft Office Macos 2021257 vulnerabilities

Microsoft Windows Server 2004245 vulnerabilities

Microsoft Windows Server 1903240 vulnerabilities

Microsoft Windows Server 1909223 vulnerabilities

Microsoft Windows Server 20h2208 vulnerabilities

Microsoft Excel192 vulnerabilities
Spreadsheet Software

Microsoft Windows 2003 Server162 vulnerabilities

Microsoft Visual Studio 2022140 vulnerabilities

Microsoft Sql Server 2019140 vulnerabilities

Microsoft Office Online Server135 vulnerabilities

Microsoft Exchange Server132 vulnerabilities

Microsoft Visual Studio 2019125 vulnerabilities

Microsoft Net123 vulnerabilities

Microsoft Excel 2016118 vulnerabilities

Microsoft Windows 2000112 vulnerabilities

Microsoft Sql Server 2022112 vulnerabilities

Microsoft Windows 11 2h2110 vulnerabilities

Microsoft Office 365107 vulnerabilities

Microsoft Word104 vulnerabilities

Microsoft Windows Server 1803101 vulnerabilities

Microsoft Dynamics 365101 vulnerabilities

Microsoft Sql Server 201799 vulnerabilities

Microsoft Windows 10 21h198 vulnerabilities

Microsoft SQL Server98 vulnerabilities
Database Server

Microsoft Sql Server 201697 vulnerabilities

Microsoft Visual Studio 201797 vulnerabilities

Microsoft Visual Studio94 vulnerabilities
Developer IDE

Microsoft Office 201689 vulnerabilities

Microsoft Office 365 Proplus87 vulnerabilities

Microsoft Outlook86 vulnerabilities

Microsoft Visual Studio Code78 vulnerabilities
VSCode Developer IDE

Microsoft Windows 861 vulnerabilities

Microsoft Windows Nt57 vulnerabilities

Microsoft Office Web Apps55 vulnerabilities

Microsoft Azure Site Recovery53 vulnerabilities

Microsoft Windows Rt46 vulnerabilities

Microsoft Powershell45 vulnerabilities

Microsoft Word 201644 vulnerabilities

Microsoft Http Server41 vulnerabilities

Microsoft Windows 10 170940 vulnerabilities

Microsoft Azure Devops Server40 vulnerabilities

Microsoft 39 vulnerabilities

Microsoft ASP.NET Core37 vulnerabilities

Microsoft .NET Framework37 vulnerabilities

Microsoft Mysql36 vulnerabilities

Microsoft .NET Core35 vulnerabilities

Microsoft Remote Desktop34 vulnerabilities

Microsoft Excel Viewer34 vulnerabilities

Microsoft Windows 10 170331 vulnerabilities

Microsoft Exchange Server 201629 vulnerabilities

Microsoft Exchange Server 201928 vulnerabilities

Microsoft Teams27 vulnerabilities

Microsoft Windows 10 190326 vulnerabilities

Recent Microsoft Security Advisories

Advisory Title Published
CVE-2026-66803 CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability July 30, 2026
CVE-2026-13037 Chromium: CVE-2026-13037 Use after free in WebView July 28, 2026
CVE-2026-13032 Chromium: CVE-2026-13032 Use after free in WebGL July 28, 2026
CVE-2026-13030 Chromium: CVE-2026-13030 Uninitialized Use in GPU July 28, 2026
CVE-2026-13028 Chromium: CVE-2026-13028 Use after free in WebGL July 28, 2026
CVE-2026-16461 CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting July 27, 2026
CVE-2026-8450 CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file() July 27, 2026
CVE-2026-64530 CVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle July 27, 2026
CVE-2026-16807 Chromium: CVE-2026-16807 Out of bounds write in Codecs July 25, 2026
CVE-2026-16806 Chromium: CVE-2026-16806 Use after free in WebMCP July 25, 2026

Known Exploited Microsoft Vulnerabilities

The following Microsoft vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
CVE-2026-50522 Exploit Probability: 57.1%
July 22, 2026
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
CVE-2026-58644
July 16, 2026
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerabil Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2026-56155 Exploit Probability: 2.3%
July 14, 2026
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56164 Exploit Probability: 18.4%
July 14, 2026
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
CVE-2026-45659 Exploit Probability: 9.1%
July 1, 2026
Microsoft Internet Explorer Use-After-Free Vulnerability Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2010-0249 Exploit Probability: 91.9%
May 20, 2026
Microsoft Windows Buffer Overflow Vulnerability Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
CVE-2008-4250 Exploit Probability: 98.8%
May 20, 2026
Microsoft Defender Denial of Service Vulnerability Microsoft Defender contains an unspecified vulnerability that allows for denial of service.
CVE-2026-45498 Exploit Probability: 63.1%
May 20, 2026
Microsoft DirectX NULL Byte Overwrite Vulnerability Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.
CVE-2009-1537 Exploit Probability: 51.2%
May 20, 2026
Microsoft Internet Explorer Use-After-Free Vulnerability Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2010-0806 Exploit Probability: 82.2%
May 20, 2026
Microsoft Defender Link Following Vulnerability Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2026-41091 Exploit Probability: 9.6%
May 20, 2026
Microsoft Exchange Server Cross-Site Scripting Vulnerability Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.
CVE-2026-42897 Exploit Probability: 5.6%
May 15, 2026
Microsoft Windows Protection Mechanism Failure Vulnerability Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-32202 Exploit Probability: 63.7%
April 28, 2026
Microsoft Defender Insufficient Granularity of Access Control Vulnerability Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
CVE-2026-33825 Exploit Probability: 6.7%
April 22, 2026
Microsoft Office Remote Code Execution Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.
CVE-2009-0238 Exploit Probability: 43.1%
April 14, 2026
Microsoft SharePoint Server Improper Input Validation Vulnerability Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-32201 Exploit Probability: 21.5%
April 14, 2026
Microsoft Windows Link Following Vulnerability Microsoft Windows contains a link following vulnerability that allows for privilege escalation
CVE-2025-60710 Exploit Probability: 4.7%
April 13, 2026
Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.
CVE-2023-21529 Exploit Probability: 62.1%
April 13, 2026
Microsoft Windows Out-of-Bounds Read Vulnerability Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation
CVE-2023-36424 Exploit Probability: 12.2%
April 13, 2026
Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.
CVE-2012-1854 Exploit Probability: 21.0%
April 13, 2026

Of the known exploited vulnerabilities above, 6 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 7 known exploited Microsoft vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.

Top 10 Riskiest Microsoft Vulnerabilities

Based on the current exploit probability, these Microsoft vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.

Rank CVE EPSS Vulnerability
1 CVE-2021-34473 100.0% Microsoft Exchange Server Remote Code Execution Vulnerability
2 CVE-2021-26855 100.0% Microsoft OWA Exchange Control Panel (ECP) Exploit Chain
3 CVE-2019-0708 100.0% "BlueKeep" Microsoft Windows Remote Desktop Remote Code Execution Vulnerability
4 CVE-2015-1635 100.0% Microsoft HTTP.sys Remote Code Execution Vulnerability
5 CVE-2021-34523 100.0% Microsoft Exchange Server Privilege Escalation Vulnerability
6 CVE-2022-41082 100.0% Microsoft Exchange Server Remote Code Execution Vulnerability
7 CVE-2012-0158 100.0% Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
8 CVE-2020-0688 100.0% Microsoft Exchange Server Key Validation Vulnerability
9 CVE-2022-41040 100.0% Microsoft Exchange Server Server-Side Request Forgery Vulnerability
10 CVE-2021-27065 99.9% Microsoft OWA Exchange Control Panel (ECP) Exploit Chain

By the Year

In 2026 there have been 4680 vulnerabilities in Microsoft with an average score of 7.3 out of ten. Last year, in 2025 Microsoft had 2750 security vulnerabilities published. That is, 1930 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.05.




Year Vulnerabilities Average Score
2026 4680 7.27
2025 2750 7.22
2024 2182 7.33
2023 1695 7.21
2022 1389 7.43
2021 1153 7.44
2020 1253 7.20
2019 831 7.08
2018 661 7.03

It may take a day or so for new Microsoft vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-66803 Jul 30, 2026
Jul 2026: Azure Cosmos DB Remote Code Execution Vulnerability Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
Cosmos Db
CVE-2026-62828 Jul 28, 2026
Jul 2026: Microsoft Edge for Android (Chromium-based) Tampering Vulnerability Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network.
Edge Browser
CVE-2026-57990 Jul 26, 2026
Jul 2026: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Edge Chromium
CVE-2026-57989 Jul 26, 2026
Jul 2026: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Edge Chromium
CVE-2026-57978 Jul 26, 2026
Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Edge Chromium
CVE-2026-64530 Jul 26, 2026
Linux Kernel: Handle TC_ACT_CONSUMED in tcf_qevent_handle Prevents SKB UAF In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the defragmentation engine (e.g. act_ct on out-of-order fragments). When that happens the skb is no longer owned by the caller and must not be touched again. tcf_qevent_handle() did not handle TC_ACT_CONSUMED: it fell through the switch and returned the skb to the caller as if classification had passed. The only qdisc that wires up qevents today is RED, via three call sites (qe_mark on RED_PROB_MARK/HARD_MARK, qe_early_drop on congestion_drop) red_enqueue() was continuing to operate on an skb it no longer owns in this case -- enqueueing it, dropping it, or updating statistics. Resulting in a UAF. tc qdisc add dev eth0 root handle 1: red ... qevent early_drop block 10 tc filter add block 10 ... action ct (with ct defrag enabled and traffic that produces out-of-order fragments, e.g. a fragmented UDP stream) Handle TC_ACT_CONSUMED in tcf_qevent_handle() the same way the ingress and egress fast paths do: treat it as stolen and return NULL without touching the skb. Unlike the TC_ACT_STOLEN case, the skb must not be dropped/freed here, as it is no longer owned by us.
CVE-2026-62835 Jul 24, 2026
Jul 2026: Azure Portal Information Disclosure Vulnerability Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
Azure Portal
CVE-2026-56163 Jul 24, 2026
Jul 2026: Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
Azure Kubernetes Service
CVE-2026-58630 Jul 24, 2026
Jul 2026: Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
Azure App Service
CVE-2026-57106 Jul 24, 2026
Jul 2026: Data Quality Elevation of Privilege Vulnerability Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
Office Purview Data Governance
CVE-2026-58275 Jul 24, 2026
Jul 2026: Azure DNS Elevation of Privilege Vulnerability Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
Azure Dns
CVE-2026-62825 Jul 24, 2026
Jul 2026: Azure Key Vault Elevation of Privilege Vulnerability Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
Azure Key Vault
CVE-2026-50517 Jul 24, 2026
Jul 2026: Microsoft M365 Copilot Remote Code Execution Vulnerability Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
365 Copilot
CVE-2026-56191 Jul 24, 2026
Jul 2026: Microsoft Exchange Online Tampering Vulnerability Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
Exchange Online
CVE-2026-35425 Jul 24, 2026
Jul 2026: Azure API Management (APIM) Remote Code Execution Vulnerability Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
Azure Api Management
CVE-2026-49159 Jul 24, 2026
Jul 2026: Microsoft Graph Information Disclosure Vulnerability Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
Graph
CVE-2026-56160 Jul 23, 2026
Jul 2026: Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
Azure Red Hat Openshift
CVE-2026-54120 Jul 23, 2026
Jul 2026: Microsoft Surface Remote Code Execution Vulnerability Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
Surface Management Services
CVE-2026-56165 Jul 23, 2026
Jul 2026: Microsoft Account Remote Code Execution Vulnerability Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
Microsoft Account
CVE-2026-56167 Jul 23, 2026
Jul 2026: Azure AI Search Elevation of Privilege Vulnerability Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
Azure Ai Search
CVE-2026-16804 Jul 23, 2026
Use after free in Input in Google Chrome <150.0.7871.186 Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-16806 Jul 23, 2026
Use-after-Free in Chrome WebMCP before 150.0.7871.186 (Remote code execution) Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-16805 Jul 23, 2026
Use after free in Blink (Chrome <150.0.7871.186) Enables Remote Code Execution Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-16807 Jul 23, 2026
Out-of-bounds write in Codecs in Chrome 150.0.7871.186 Caused Sandbox Escape Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-59677 Jul 23, 2026
SELinux Policycoreutils 3.10 Unconfined Kill Auth Bypass A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10.
CVE-2026-59676 Jul 23, 2026
seunshare TOCTOU Race in Selinux Policycoreutils 3.10 Arbitrary File Deletion A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils through 3.10.
CVE-2026-64600 Jul 23, 2026
Linux Kernel XFS: Stale Data Mappings Post ILOCK Reacquire Causing DirectIO Race In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. Currently we refresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but we don't refresh the data fork mapping beforehand, which means that the xfs_bmap_trim_cow in that function queries the refcount btree about the wrong physical blocks and returns an inaccurate value in *shared. If *shared is now false, the directio write proceeds with a stale data fork mapping. Fix this by querying the data fork mapping if the sequence counter changes across the ILOCK cycle.
CVE-2026-53910 Jul 22, 2026
Diffutils diff3 Heap Buffer Overflow via Signed Integer Overflows diff3 tool from GNU diffutils is vulnerable to a heapbased buffer overflow due to multiple signed integer overflows in linemapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds. When processing crafted diff output, these overflows may cause the application to allocate insufficient memory and subsequently perform outofbounds writes during internal processing.  An attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, resulting in a crash and potentially remote code execution depending on the environment. This issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815  NOTE: The project maintainers claim that this is not a security issue. They state that the worst outcome this issue can cause is a crash of diff and that it cannot be used to escalate privileges.
CVE-2026-56444 Jul 22, 2026
Unbound 1.201.25.1: Serve-Expired Branch Causes Silent Client Drops In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values), the discard-timeout branch during the serve expired logic drops an aged client reply without performing the correct accounting for the number of reply addresses for the query. Other identical branches outside of serve expired perform the correct decrement. Since the counter is never decremented in such scenario, it can reach the maximum limit and new clients for duplicate in-flight queries are silently dropped resulting in degradation of resolution service. A malicious actor can exploit the vulnerability by querying the resolver for a client-controlled slow-on-demand authoritative zone that can drive the counter past the threshold. Shipped defaults for 'serve-expired-client-timeout: 1800' and 'discard-timeout: 1900' make the branch unreachable.
CVE-2026-56416 Jul 22, 2026
Unbound 1.25.1 Vulnerable RRSIG + PX RP MINFO SOA Leads to Heap Buffer Overflow In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker who runs a DNSSEC-signed authoritative server can deliver a record with an absent second domain name (e.g. SOA record) and cause 'query_dname_tolower()' to walk label-by-label through stale bytes in the per-worker 'env->scratch_buffer', past the end of that heap allocation if 'msg-buffer-size' has been lowered from the default. This leads to heap buffer overflow and on a release build the outcome relies heavily on the contents of the buffer tail and the adjacent heap chunk.
CVE-2026-55991 Jul 22, 2026
Unbound 1.22-1.25.1 DoQ crash via libngtcp2 assertion In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate the entire Unbound process using a single DNS-over-QUIC (DoQ) connection and one normal DNS query. This is caused by an erroneous error value passed to libngtcp2. When 'ngtcp2_conn_writev_stream()' returns 'NGTCP2_ERR_STREAM_DATA_BLOCKED', Unbound continues to call 'ngtcp2_ccerr_set_application_error()' with a '-1' error value. The 'int' literal '-1' is implicitly converted to the function's 'uint64_t error_code' parameter as '0xFFFFFFFFFFFFFFFF'. The follow-on 'ngtcp2_conn_write_connection_close()' serialises that value as a QUIC variable-length integer; because '2^64-1' exceeds the 62-bit varint ceiling, 'ngtcp2_put_uvarintlen()' fails 'assert(n < 4611686018427387904ULL)' and the whole resolver process aborts. A remote, unauthenticated DoQ client can trigger this deterministically with a single QUIC connection by advertising 'initial_max_stream_data_bidi_local = 1' in its transport parameters and sending one DoQ query without ever reading the stream.
CVE-2026-55990 Jul 22, 2026
Unbound 1.7.0-1.25.1 DNSCrypt Config Buffer Underflow In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with '0xdb' bytes. Any unauthenticated client that sends one UDP datagram of 68 bytes whose first 8 bytes are '0xdb' to 'dnscrypt-port' will use that garbage entry which leads to a garbage dereference killing the server. This is a silent faulty configuration that goes unnoticed until triggered with the right client query. Unbound needs to be compiled with DNSCrypt support ('--enable-dnscrypt').
CVE-2026-55973 Jul 22, 2026
Unbound 1.23.0-1.25.1 EDNS Report-Channel Stack Overflow via Malformed Agent Domain In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic '_er.' report query name. That query name is later used in the iterator via a subquery to send out the DNS Error Report and when Unbound tries to walk that query name during 'find_closest_of_type()', it strips labels using the query name length rather than stopping at the embedded root, walks one byte past it, and feeds the first garbage byte to 'dname_query_hash()' as a label length writing over the stack variable 'labuf'. One ordinary upstream response from a delegated zone the attacker controls is sufficient to terminate the daemon.
CVE-2026-55717 Jul 22, 2026
Unbound 1.10.0-1.25.1 serve-expired-client-timeout Null Ptr Crash via response-ip In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: <net> redirect' /'response-ip-data: <net> CNAME <target>' rule (or the RPZ 'rpz-cname-override' equivalent), a remote client who controls any delegated domain can crash the daemon. The serve-expired-client-timeout callback runs a two-pass loop to chase the respip-generated CNAME alias; on the second pass it resets 'alias_rrset' but not 'partial_rep'. Later, this inconsistency leads to a NULL pointer dereference and an eventual crash. A malicious actor can exploit the vulnerability by controlling any zone that replies with an A/AAAA record that falls inside the configured response-ip/rpz subnet. By delaying the answer when the previous record has expired, the vulnerable path of 'serve-expired-client-timeout' is taken leading to denial of service via the server crash.
CVE-2026-55708 Jul 22, 2026
Unbound 1.6.0-1.25.1 unsafely omits default zones via unbound-control In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones (e.g., RFC 1918 reverse, AS112 zones, .onion, .localhost). Once the local zone tree exists without the defaults, every query for a default-protected name from a client mapped to that view escapes to the public DNS via the iterator instead of being answered locally, bypassing local policy expectations.
CVE-2026-54478 Jul 22, 2026
Unbound 1.18.0-1.25.1 Proxy-Protocol Cookie Replay (RFC9018) In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with 'answer-cookie: yes', the RFC 9018 server-cookie SipHash is computed over the proxy's wire address instead of the PROXYv2-declared client. One server cookie obtained through a given proxy node therefore validates for every PROXYv2-declared source behind that node. On a UDP+proxy-protocol front, an off-path attacker can harvest one cookie with a single legitimate query, then replay it under any spoofed source and pass DNS Cookie checks that were deployed to defeat this in the first place.
CVE-2026-52863 Jul 22, 2026
Unbound 1.25.0-1.25.1 MemCorrupt via respip/dns64 shallow copy In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is jostled out when Unbound is under pressure. Unbound needs to be configured with one of 'respip'/'rpz' modules, together with a module that can attach subqueries (respip CNAME redirection, dns64, subnetcache) and a configured 'access-control-view' while Unbound is under pressure so that joslte logic kicks in and starts dropping slow queries. The subquery is getting a shallow copy of the view name and if the super query which owns the view name is jostled out, memory corruption can occur. Likelihood of a crash is low, since it relies heavily on the underlying memory allocator and the memory layout. Debug memory builds (e.g., ASAN) that catch the free terminate the server.
CVE-2026-50252 Jul 22, 2026
Unbound 1.4.221.25.1 UDP SrcPort Randomization Flaw Enables Cache Poisoning In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port while their outcome is revealed this secrecy is undermined. The vulnerability arises when the load balancing policy is consistent with respect to the incoming source UDP port and IP address while heavily depending on the incoming source UDP port as a randomization source. When the SO_REUSEPORT configuration option is enabled ('so-reuseport: yes') in Unbound (by default), it meets these conditions, making it vulnerable for DNS cache poisoning attacks. Upon startup, Unbound randomly partitions the available UDP source port space into disjoint subsets of (almost) equal size, assigning each subset to a specific worker thread. When an incoming DNS query is received, the kernels SO_REUSEPORT load balancing mechanism deterministically assigns the query to a socket associated with a particular thread. All outgoing DNS queries generated during the resolution of that request use source ports selected exclusively from the port subset assigned to the corresponding thread. Since these port subsets are disjoint across threads, the source port observed in a resolvers outgoing query to an authoritative name server serves as a reliable indicator of the worker thread that processed the original client query. A malicious actor can acquire the mapping between incoming UDP source ports (for a given fixed source IP address) and Unbound worker threads and leverage it to conduct DNS cache poisoning attacks by effectively lowering the random port population per thread.
CVE-2026-50251 Jul 22, 2026
Unbound 0.0.0.0/::0 Glue Loop Triggers Cache Flush In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS queries and receiving seemingly unwanted replies since the remote IP does not match the original source IP of 0.0.0.0/::0. This behavior keeps on looping for the glue records and pushing the counter to the configured 'unwanted-reply-threshold' that triggers a defensive cache clear. A malicious actor who controls a delegation that returns in-bailiwick glue of 0.0.0.0/::0 can drive the counter to the limit of 'unwanted-reply-threshold' to the threshold and trigger a cache clean of the message and rrset caches; at will, indefinitely, without sending a single spoofed packet. The iterator uses the 0.0.0.0/::0 glue, and a system that can route this (e.g., Linux kernel routes the datagram over loopback), Unbound's own listener answers from 127.0.0.1. Because of the mismatch of 0.0.0.0 and 127.0.0.1, in this example, Unbound accounts the reply as an unwanted (probably spoofed) answer. The counter resets to zero on every cache flush, so the attack loops forever.
CVE-2026-50248 Jul 22, 2026
Unbound 1.7.0-1.25.1 BOGUS A/AAAA Spoofing Enables Unauth XFR In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostname's A/AAAA record (no valid RRSIG required) becomes the zone's XFR primary and can replaces the entire zone/the resolver's entire response policy.
CVE-2026-50243 Jul 22, 2026
Unbound 1.6.21.25.1: respip rewrites BOGUS DNSSEC answers as INSECURE In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect rule or an RPZ file with an RPZ-IP trigger, the rewriting handler does not check the security status of the upstream answer and can instead rewrite a BOGUS A/AAAA answer to point to an operator's configured IP. If the validator finds an expired or otherwise invalid RRSIG on an answer whose A record falls within a 'response-ip'/RPZ configuration, the answer is still rewritten and given a hard coded security level of INSECURE. This results in the client receiving an INSECURE NOERROR reply rewritten by the operator's configured IP. A malicious actor can exploit the possible poisonous effect by spoofing a BOGUS A/AAAA answer that falls inside the operator's configured subnet rewrites. Such DNSSEC protected answers are then insecurely redirected to the operator's configured target.
CVE-2026-50046 Jul 22, 2026
Unbound DoT TLS Server Name Deref Crash before v1.25.2 In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind the referenced string and if the TLS stream then errors out, it dereferences the freed pointer. The dereference is read-only and the practical impact is a daemon crash resulting in denial of service. A malicious actor that knows a DoT forwarding/stub Unbound's configuration could exploit the vulnerability by quering records in the appropriate zone while keeping Unbound uder pressure so that the jostle logic kicks in. If answers for the vulnerable zone are slow, the likelihood of jostling such queries is higher, although the timing of the jostle needs to be precise. Requirements for a vulnerable Unbound is the existence of a stub/forward zone configured for DoT together with a configured '#authname' suffix on the server identification. The connectivity to the server needs to exhibit a transient failure at the correct time in order to kick off the vulnerable error path.
CVE-2026-50045 Jul 22, 2026
DNSSEC Amplification Bypass in Unbound <=1.25.1 via Excessive Upstream Packets In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the configured 'max-global-quota'. This effectively bypasses a security configuration that limits upstream amplification traffic.
CVE-2026-46582 Jul 22, 2026
Unbound DNSSEC Wildcard Replay Cache Poisoning CVE-2026-46582 1.25.1 In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before later validation treats it as bogus based on NSEC validation. When the resolving thread puts secure on the rrset, and another thread that is on the serve expired path then picks up the updated rrset contents with the secure status for a reply, it can be used to change a specific record, next to a wildcard that could be covered by the wildcard, into the wildcard. A malicious actor can exploit the possible poisonous effect by having any DNSSEC-singed domain (irrelevant to the victim domain) and a CNAME wrapper record that points to a record next to a wildcard (that could be covered by the wildcard). Then quering Unbound for the wildcard sibling record would seed the secure message. A later (after expiry) query for the CNAME wrapper would need to resolve the target sibling record. If the wildcard replay is injected into the response, the wildcard rrset will update the expired sibling record with a secure status before completing proper wildcard validation with NSEC records and eventually treating the CNAME wrapper answer as bogus. The updated poisoned rrset is now secure and points to the wildcard. This vulnerability is explicit for the serve expired path and needs injection of the signed wildcard rrset without the NSEC accompanying rrset.
CVE-2026-44690 Jul 22, 2026
Unbound 1.7.01.25.1 RRSIG.Labels Poisoning via NSEC Aggressive Cache In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. This allows the malicious actor to inject insecure wildcard records for those delegations.
CVE-2026-44687 Jul 22, 2026
Unbound 1.13.21.25.1: hardenbelownxdomain NXDOMAIN bypass In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate labed below a DNSSEC signed zone could be shadowed by the intermediate label's secure NXDOMAIN answer from the parent. This is caused by an off-by-one error in 'harden-below-nxdomain' logic; enabled by default. It effectively bypasses the configuration and the configured stub/forward zone is never contacted. 'harden-below-nxdomain' does an upward DNS cache walk together with a delegation point guard that does not allow NXDOMAIN synthesis above stub/forward zones. The guard tests the domain name but before stripping a label. This results in an iteration where the domain name equals the configured stub/forward zone apex that passes the guard, strips one more label, and probes the cache at the apex's immediate public parent. If that parent has a cached DNSSEC-secure NXDOMAIN, which it will for any private namespace nested two or more labels under a signed public name, the walk returns it and the configured stub/forward upstream is never contacted. This can only be triggered by the query for the intermediate label (between the stub/forward apex and the DNSSEC parent zone).
CVE-2026-44621 Jul 22, 2026
Unbound 1.25.1 libunbound crash via UnwantedReplyThreshold With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold', could eventually be abruptly terminated if the threshold is reached and libunbound needs to call 'libworker_alloc_cleanup' since the function is absent from the function call allow list. When an application using libunbound sets 'unwanted-reply-threshold' to any non-zero value and the iterator queries an authoritative that replies with enough wrong-transaction-ID UDP datagrams to cross the threshold, the 'libworker_alloc_cleanup' will eventually be called. Since the function is absent from the function call allow list, this leads to a fatal exit of libunbound and eventual termination of the embedding application.Unbound itself is not affected since its relevant function 'worker_alloc_cleanup' is registed in the allow list and proceeds to perform the documented cache flush.
CVE-2026-42955 Jul 22, 2026
Unbound 1.16.21.25.1 Ghost Domain TTL Extension Vulnerability In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client A/AAAA query can cause Unbound to overwrite the cached expired parent-side glue rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client query is required since Unbound implicitly performs that query. This is a variant of CVE-2026-40622 which only addressed the NS query.
CVE-2026-41637 Jul 22, 2026
Unbound 1.22.0-1.25.1 DoQ Query Counter DoS via Dropped Streams In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queries are not accounted properly by Unbound resulting in low-cost inflation of the waiting number of replies for already in-flight resolution queries. This results in degradation of resolution service for new clients for already in-flight queries. A malicious actor can exploit the vulnerability by issuing DoQ queries for query names that need resolution and proceeding on immediately terminating the query by one of STOP_SENDING/RESET_STREAM/CONNECTION_CLOSE QUIC frames. Those terminated DoQ queries are not properly counted for and keep inflating the number of waiting replies for in-flight queries. When the maximum is reached, it results in silent query drops for new clients needing resolution for already in-flight queries. This vulnerability needs Unbound to be compiled with DoQ support ('--with-libngtcp2') and the 'quic-port' to be configured for the listening interfaces. Additionally, a malicious actor needs access to multiple source IPs to bypass the by-default configured 'wait-limit' option.
CVE-2026-40691 Jul 22, 2026
Unbound 1.9.01.25.1 DNSCrypt TCP DoS In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound the reply length against the destination buffer size. The size clamp that protects the UDP path is not applied on the TCP path, so a reply larger than 65504 bytes is shifted forward by 48 bytes inside a buffer of capacity equal to 'msg-buffer-size', writing past the end of the heap allocation. A single malicious encrypted query crashes the resolver and lead to denial of service. This vulnerability needs Unbound to be compiled with DNSCrypt support ('--enable-dnscrypt') and the 'dnscrypt:' clause to be configured and enabled for the listening interfaces.
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.