Microsoft Microsoft Makers of the Windows Operating System and hundreds of products that run on it.

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Microsoft product.

RSS Feeds for Microsoft security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Microsoft products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Microsoft Sorted by Most Security Vulnerabilities since 2018

Microsoft Windows 105047 vulnerabilities

Microsoft Windows Server 20194791 vulnerabilities

Microsoft Windows Server 20164715 vulnerabilities

Microsoft Windows Server 20123545 vulnerabilities

Microsoft Windows Server 20223142 vulnerabilities

Microsoft Windows Server 20082820 vulnerabilities

Microsoft Windows 112280 vulnerabilities

Microsoft Windows 71810 vulnerabilities

Microsoft Windows 11 24h21735 vulnerabilities

Microsoft Windows 8.11712 vulnerabilities

Microsoft Windows Server 20251705 vulnerabilities

Microsoft Windows 11 23h21683 vulnerabilities

Microsoft Windows Rt 8 11592 vulnerabilities

Microsoft Windows 10 15071453 vulnerabilities

Microsoft Windows Server 2012 R21433 vulnerabilities

Microsoft Windows Server 23h21356 vulnerabilities

Microsoft Windows931 vulnerabilities

Microsoft Windows 11 25h2893 vulnerabilities

Microsoft Windows 11 26h1742 vulnerabilities

Microsoft Windows Server655 vulnerabilities

Microsoft Office597 vulnerabilities

Microsoft 365 Apps571 vulnerabilities

Microsoft Internet Explorer (IE)528 vulnerabilities
Popular web browser for windows

Microsoft Sharepoint Server490 vulnerabilities

Microsoft Edge Browser412 vulnerabilities
Web Browser based on Chromium

Microsoft Windows Vista382 vulnerabilities

Microsoft Windows XP326 vulnerabilities

Microsoft Office 2024307 vulnerabilities

Microsoft Office 2021297 vulnerabilities

Microsoft Office 2019285 vulnerabilities

Microsoft Edge Chromium278 vulnerabilities

Microsoft Windows 10 1803275 vulnerabilities

Microsoft Windows 10 1909274 vulnerabilities

Microsoft Windows Server 2003262 vulnerabilities

Microsoft Office Macos 2024259 vulnerabilities

Microsoft Office Macos 2021257 vulnerabilities

Microsoft Windows Server 2004245 vulnerabilities

Microsoft Windows Server 1903240 vulnerabilities

Microsoft Windows Server 1909223 vulnerabilities

Microsoft Windows Server 20h2208 vulnerabilities

Microsoft Excel192 vulnerabilities
Spreadsheet Software

Microsoft Windows 2003 Server162 vulnerabilities

Microsoft Sql Server 2019140 vulnerabilities

Microsoft Visual Studio 2022140 vulnerabilities

Microsoft Office Online Server135 vulnerabilities

Microsoft Exchange Server132 vulnerabilities

Microsoft Visual Studio 2019124 vulnerabilities

Microsoft Net123 vulnerabilities

Microsoft Excel 2016118 vulnerabilities

Microsoft Sql Server 2022112 vulnerabilities

Microsoft Windows 2000112 vulnerabilities

Microsoft Windows 11 2h2110 vulnerabilities

Microsoft Office 365107 vulnerabilities

Microsoft Word104 vulnerabilities

Microsoft Dynamics 365101 vulnerabilities

Microsoft Windows Server 1803101 vulnerabilities

Microsoft Sql Server 201799 vulnerabilities

Microsoft SQL Server98 vulnerabilities
Database Server

Microsoft Windows 10 21h198 vulnerabilities

Microsoft Sql Server 201697 vulnerabilities

Microsoft Visual Studio 201796 vulnerabilities

Microsoft Visual Studio94 vulnerabilities
Developer IDE

Microsoft Office 201689 vulnerabilities

Microsoft Office 365 Proplus87 vulnerabilities

Microsoft Outlook86 vulnerabilities

Microsoft Visual Studio Code78 vulnerabilities
VSCode Developer IDE

Microsoft Windows 861 vulnerabilities

Microsoft Windows Nt57 vulnerabilities

Microsoft Office Web Apps55 vulnerabilities

Microsoft Azure Site Recovery53 vulnerabilities

Microsoft Windows Rt46 vulnerabilities

Microsoft Powershell45 vulnerabilities

Microsoft Word 201644 vulnerabilities

Microsoft Http Server41 vulnerabilities

Microsoft Windows 10 170940 vulnerabilities

Microsoft Azure Devops Server40 vulnerabilities

Microsoft 39 vulnerabilities

Microsoft ASP.NET Core37 vulnerabilities

Microsoft Mysql36 vulnerabilities

Microsoft .NET Core35 vulnerabilities

Microsoft Remote Desktop34 vulnerabilities

Microsoft Excel Viewer34 vulnerabilities

Microsoft Windows 10 170331 vulnerabilities

Microsoft Exchange Server 201629 vulnerabilities

Microsoft Exchange Server 201928 vulnerabilities

Microsoft Teams27 vulnerabilities

Microsoft Windows 10 190326 vulnerabilities

Microsoft Windows 10 200426 vulnerabilities

Recent Microsoft Security Advisories

Advisory Title Published
CVE-2026-50012 CVE-2026-50012 Squid: Memory corruption in cache_digest reply handling July 18, 2026
CVE-2026-47729 CVE-2026-47729 Squid: Memory disclosure in FTP gateway July 18, 2026
CVE-2026-62299 CVE-2026-62299 CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record July 18, 2026
CVE-2026-62309 CVE-2026-62309 CoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — single 28-byte packet remote DoS July 18, 2026
CVE-2026-15905 Chromium: CVE-2026-15905 Use after free in Aura July 18, 2026
CVE-2026-15904 Chromium: CVE-2026-15904 Use after free in Ozone July 18, 2026
CVE-2026-15903 Chromium: CVE-2026-15903 Out of bounds read and write in V8 July 18, 2026
CVE-2026-15902 Chromium: CVE-2026-15902 Use after free in Cast July 18, 2026
CVE-2026-15901 Chromium: CVE-2026-15901 Use after free in Network July 18, 2026
CVE-2026-15900 Chromium: CVE-2026-15900 Use after free in GPU July 18, 2026

Known Exploited Microsoft Vulnerabilities

The following Microsoft vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
CVE-2026-58644
July 16, 2026
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerabil Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2026-56155
July 14, 2026
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56164
July 14, 2026
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
CVE-2026-45659 Exploit Probability: 1.7%
July 1, 2026
Microsoft Internet Explorer Use-After-Free Vulnerability Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2010-0249 Exploit Probability: 91.9%
May 20, 2026
Microsoft Windows Buffer Overflow Vulnerability Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
CVE-2008-4250 Exploit Probability: 98.8%
May 20, 2026
Microsoft Defender Denial of Service Vulnerability Microsoft Defender contains an unspecified vulnerability that allows for denial of service.
CVE-2026-45498 Exploit Probability: 2.5%
May 20, 2026
Microsoft DirectX NULL Byte Overwrite Vulnerability Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.
CVE-2009-1537 Exploit Probability: 51.2%
May 20, 2026
Microsoft Internet Explorer Use-After-Free Vulnerability Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2010-0806 Exploit Probability: 82.2%
May 20, 2026
Microsoft Defender Link Following Vulnerability Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2026-41091 Exploit Probability: 1.2%
May 20, 2026
Microsoft Exchange Server Cross-Site Scripting Vulnerability Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.
CVE-2026-42897 Exploit Probability: 2.5%
May 15, 2026
Microsoft Windows Protection Mechanism Failure Vulnerability Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-32202 Exploit Probability: 20.0%
April 28, 2026
Microsoft Defender Insufficient Granularity of Access Control Vulnerability Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
CVE-2026-33825 Exploit Probability: 6.2%
April 22, 2026
Microsoft Office Remote Code Execution Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.
CVE-2009-0238 Exploit Probability: 43.1%
April 14, 2026
Microsoft SharePoint Server Improper Input Validation Vulnerability Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-32201 Exploit Probability: 24.2%
April 14, 2026
Microsoft Windows Link Following Vulnerability Microsoft Windows contains a link following vulnerability that allows for privilege escalation
CVE-2025-60710 Exploit Probability: 4.7%
April 13, 2026
Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.
CVE-2023-21529 Exploit Probability: 62.1%
April 13, 2026
Microsoft Windows Out-of-Bounds Read Vulnerability Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation
CVE-2023-36424 Exploit Probability: 12.2%
April 13, 2026
Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.
CVE-2012-1854 Exploit Probability: 21.0%
April 13, 2026
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
CVE-2026-20963 Exploit Probability: 31.1%
March 18, 2026

Of the known exploited vulnerabilities above, 4 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 7 known exploited Microsoft vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.

Top 10 Riskiest Microsoft Vulnerabilities

Based on the current exploit probability, these Microsoft vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.

Rank CVE EPSS Vulnerability
1 CVE-2021-34473 100.0% Microsoft Exchange Server Remote Code Execution Vulnerability
2 CVE-2021-26855 100.0% Microsoft OWA Exchange Control Panel (ECP) Exploit Chain
3 CVE-2019-0708 100.0% "BlueKeep" Microsoft Windows Remote Desktop Remote Code Execution Vulnerability
4 CVE-2015-1635 100.0% Microsoft HTTP.sys Remote Code Execution Vulnerability
5 CVE-2021-34523 100.0% Microsoft Exchange Server Privilege Escalation Vulnerability
6 CVE-2025-53770 100.0% Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
7 CVE-2022-41082 100.0% Microsoft Exchange Server Remote Code Execution Vulnerability
8 CVE-2012-0158 100.0% Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
9 CVE-2020-0688 100.0% Microsoft Exchange Server Key Validation Vulnerability
10 CVE-2025-59287 100.0% Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability

By the Year

In 2026 there have been 4471 vulnerabilities in Microsoft with an average score of 7.2 out of ten. Last year, in 2025 Microsoft had 2750 security vulnerabilities published. That is, 1721 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.16.




Year Vulnerabilities Average Score
2026 4471 7.24
2025 2750 7.08
2024 2182 7.33
2023 1695 7.22
2022 1389 7.43
2021 1153 7.44
2020 1253 7.20
2019 831 7.08
2018 661 7.03

It may take a day or so for new Microsoft vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-56171 Jul 17, 2026
Jul 2026: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
Windows Admin Center
Remote Desktop Web Client
CVE-2026-57980 Jul 17, 2026
Jul 2026: Microsoft Edge (Chromium-based) Tampering Vulnerability Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.
Edge Chromium
CVE-2026-62826 Jul 16, 2026
Jul 2026: Microsoft SharePoint Server Spoofing Vulnerability Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Sharepoint Server 2016
Sharepoint Server 2019
Sharepoint Server
And others...
CVE-2026-58643 Jul 16, 2026
Jul 2026: Windows Admin Center Spoofing Vulnerability Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
Windows Admin Center
CVE-2026-58598 Jul 16, 2026
Jul 2026: Windows Backup Service Elevation of Privilege Vulnerability Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
Windows 10
Windows 11 25h2
Windows 11 24h2
And others...
CVE-2026-59117 Jul 16, 2026
Jul 2026: Windows Terminal Remote Code Execution Vulnerability Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.
Terminal
CVE-2026-62299 Jul 16, 2026
CoreDNS 1.x DoS via REWRITE plugin Nil OPT deref - <1.14.5 CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an optional revert flag, and two response rules, edns0SetResponseRule and edns0ReplaceResponseRule[T] in plugin/rewrite/edns0.go, call res.IsEdns0() and immediately dereference the returned *dns.OPT without a nil check when a downstream plugin returns a response with no OPT record. A remote, unauthenticated client can send a single ordinary DNS query matching a rewrite edns0 <local|nsid|subnet> <set|append|replace> ... revert rule, causing ResponseReverter in plugin/rewrite/reverter.go to panic, return SERVFAIL, and degrade availability, or crash the CoreDNS process if the debug directive disables recovery. This issue is fixed in version 1.14.5.
CVE-2026-62309 Jul 16, 2026
CoreDNS 1.14.4 Crash on 28byte UDP via proxyproto (pre1.14.4) CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin is enabled because plugin/pkg/proxyproto/proxyproto.go PacketConn.ReadFrom handles a PROXY v2 header with non-UDP transport such as family byte 0x11, reassigns addr from a nil readFrom result after parseProxyProtocol errors, and calls addr.String() in the warning log before ServeDNS recovery applies. This issue is fixed in version 1.14.4.
CVE-2026-47729 Jul 16, 2026
Squid <7.6 OOB Read via FTP Gateway Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.
CVE-2026-50012 Jul 16, 2026
Squid<7.6 Heap BOverflow via CacheDigest (peerDigestSwapInMask) Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest's on-the-wire size may be larger than the mask_size declared within the digest, so a trusted peer sending a maliciously crafted reply to a cache_digest request message can trigger the overflow. This attack is limited to Squid instances compiled with the --enable-cache-digests option and configured with cache_peer entries. This issue is fixed in version 7.6.
CVE-2026-55440 Jul 16, 2026
Jul 2026: Microsoft UFO: COMMAND_RESULTS handler creates unowned sessions, allowing authenticated se Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/server/ws/handler.py called get_or_create_session in ufo/server/services/session_manager.py without owner_client_id, allowing an authenticated client to create an unowned attacker-chosen session_id such as constellation_task_id = f"{task_name}@{task_id}" and deny the legitimate owner or exhaust memory with phantom sessions. This issue is fixed in version 3.0.7.
CVE-2026-54568 Jul 16, 2026
Jul 2026: Microsoft UFO: Missing Authorization in DEVICE_INFO_REQUEST Allows a DEVICE Client to Read Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a client connected to the UFO WebSocket server as a DEVICE could call DEVICE_INFO_REQUEST with another device's target_id and receive that device's server-side system_info through ufo/server/ws/handler.py, because handle_device_info_request and get_device_info did not enforce the constellation-only role or object-level authorization boundary. This issue is fixed in version 3.0.6.
CVE-2026-57206 Jul 16, 2026
Jul 2026: SimpleChat plugin validation endpoints missing authentication and authorization SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin validation routes in application/single_app/plugin_validation_endpoint.py, including `POST /api/admin/plugins/test-instantiation`, `GET /api/admin/plugins/health-check/<plugin_name>`, `POST /api/admin/plugins/repair/<plugin_name>`, and `POST /api/plugins/validate`, relied on @swagger_route(security=get_auth_security()) documentation without enforcing @login_required, @user_required, or @admin_required at runtime, allowing unauthenticated or unauthorized clients to invoke plugin validation, health, and repair behavior. This issue is fixed in version 0.241.206.
CVE-2026-57205 Jul 16, 2026
Jul 2026: SimpleChat: Authenticated users can access other users' profile metadata through user IDOR SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> endpoints in application/single_app/route_backend_users.py accepted a caller-supplied user_id and read the matching Cosmos DB user-settings document without object-level authorization, allowing a low-privilege authenticated user to retrieve another user's email address, display name, and profile image. This issue is fixed in version 0.241.203.
CVE-2026-53598 Jul 16, 2026
Jul 2026: Prompty: Arbitrary File Read via ${file:path} Reference Expansion Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that resolved paths stayed within the prompt directory or allowed roots, allowing an attacker-controlled prompt file to read local files through absolute paths, .. traversal, or symlink escapes. This issue is fixed in versions 2.0.0-beta.2.
CVE-2026-53597 Jul 16, 2026
Jul 2026: Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader Prompty is a markdown file format (.prompty) for LLM prompts. From 2.0.0-alpha.1 until 2.0.0-beta.3, the @prompty/core TypeScript loader in runtime/typescript/packages/core/src/core/loader.ts used gray-matter without overriding executable js and javascript frontmatter engines, allowing an attacker-controlled .prompty file with ---js frontmatter to execute arbitrary JavaScript during prompt loading. This issue is fixed in version 2.0.0-beta.3.
CVE-2026-54733 Jul 16, 2026
Jul 2026: moodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpoin The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn claim without verifying the JWT signature, allowing an unauthenticated attacker to forge a token and obtain a Moodle session as an O365-authenticated user. This issue is fixed in versions 4.5.6, 5.0.5, and 5.1.1.
CVE-2026-59867 Jul 16, 2026
Jul 2026: Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local absolute or out-of-tree file paths, allowing `kiota generate` on an attacker-controlled or attacker-influenced description to perform build-time SSRF, remote file inclusion, and local file inclusion by inlining external schemas such as REMOTE_KIOTA_PROP or Leaked into generated clients. This issue is fixed in version 1.32.5 by AllowedExternalOriginsStreamLoader and the --allowed-external-origins option.
CVE-2026-59866 Jul 16, 2026
Jul 2026: Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clien Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as both generated client class or namespace names and generated output path components when `kiota generate` ran without -c/--class-name, allowing an attacker-controlled or compromised OpenAPI description to write generated source outside the -o output directory and inject arbitrary text into generated class or namespace declarations. This issue is fixed in version 1.32.5 by GenerationConfiguration.SanitizeClientClassName and SanitizeClientNamespaceName.
CVE-2026-59864 Jul 16, 2026
Jul 2026: Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_template.file values from x-ai-adaptive-card and x-ai-capabilities into generated Microsoft 365 Copilot and Teams plugin manifests without path validation, allowing ../, absolute, rooted, UNC, Windows drive, or URI paths in response_semantics.static_template.file to cause path traversal or out-of-package file inclusion when the generated plugin was deployed. This issue is fixed in version 1.32.5.
CVE-2026-59865 Jul 16, 2026
Jul 2026: Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota i Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version values from an OpenAPI description and presented the spec-supplied command as Kiota's recommended install command, allowing an attacker-controlled or compromised description to cause command injection when the suggested command was run manually or through the Kiota VS Code extension's kiota info --json dependency-install flow. This issue is fixed in version 1.32.5.
CVE-2026-59863 Jul 16, 2026
Jul 2026: Kiota: Workspace-config poisoning: out-of-repo file write + generation-time SSRF Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota honored a poisoned .kiota/workspace.json workspace configuration without validating per-client or per-plugin outputPath values during kiota client generate and kiota plugin generate, allowing a malicious repository or pull request to use absolute paths, rooted POSIX / paths, UNC \\ or // paths, Windows drive X:\ paths, or .. traversal segments to write generated client files outside the workspace root on a developer or CI host. This issue is fixed in version 1.32.5.
CVE-2026-59859 Jul 16, 2026
Jul 2026: Kiota: Code Generation Literal Injection in the PHP Generator Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-derived strings into PHP double-quoted literals through SanitizeDoubleQuote() in Writers/StringExtensions.cs without escaping $, allowing attacker-controlled ${...}, $var, or {$obj->prop} interpolation constructs to inject arbitrary PHP code into generated model and request-builder classes. This issue is fixed in version 1.32.4.
CVE-2026-59862 Jul 16, 2026
Jul 2026: Kiota: Code Generation Literal Injection in the Python Generator Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Python generator let attacker-controlled enum value descriptions from x-ms-enum.values[].description flow through KiotaBuilder.SetEnumOptions into Documentation.DescriptionTemplate and PythonConventionService.RemoveInvalidDescriptionCharacters without newline sanitization, allowing generated inline comments to split and execute attacker-controlled Python code at module scope when generated modules were imported. This issue is fixed in version 1.32.0.
CVE-2026-59861 Jul 16, 2026
Jul 2026: Kiota: Code Generation Literal Injection in Kiota Ruby Generator Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Ruby generator embedded OpenAPI default fields, property names, and other schema-derived strings through CodeMethodWriter.cs and SanitizeForQuotedLiteral() in Writers/StringExtensions.cs into Ruby double-quoted literals without escaping #, allowing attacker-controlled #{expr}, #$var, or #@var interpolation markers to inject arbitrary Ruby code into generated model classes. This issue is fixed in version 1.32.0.
CVE-2026-59860 Jul 16, 2026
Jul 2026: Kiota: XML Doc-Comment Newline Breakout Code Injection Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.3, Kiota is affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the description, externalDocs label, and externalDocs link fields emitted as /// comments). When text from an OpenAPI description is written into single-line XML doc comments without stripping newline and Unicode line-terminator characters, an attacker can break out of the /// comment line and inject additional code into generated C# clients. This issue is fixed in version 1.32.3.
CVE-2026-53366 Jul 16, 2026
CVE-2026-53366: Linux IPv4 Paged Alloc Frag Size Miscalc Bug In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation path In __ip_append_data(), when the paged-allocation branch is taken, alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap, but the fraggap bytes carried over from the previous skb are copied into the new skb's linear area at offset transhdrlen by the subsequent skb_copy_and_csum_bits(). The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount. The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does. Bring the paged branch in line by adding fraggap to alloclen and subtracting it from pagedlen. After this adjustment, copy no longer collapses to -fraggap on the paged path, so remove the stale comment describing that old arithmetic.
CVE-2026-48863 Jul 16, 2026
libsolv PGP EdDSA Buffer Overflow (CVE-2026-48863) A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.
CVE-2026-15714 Jul 14, 2026
libsoup OOB Read in multipart boundary parsing An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_multipart_input_stream_read_headers() function inside soup-multipart-input-stream.c, which does not adequately restrict or validate the size of incoming multipart boundary strings. When processing a crafted HTTP response containing a malformed or oversized boundary parameter, the internal stream reader reads past the allocated buffer bounds. A remote, unauthenticated attacker can exploit this behavior to cause a service denial (DoS) through application failure or potentially read fragments of unauthorized memory metadata.
CVE-2026-15713 Jul 14, 2026
libsoup HTTP/2 Memory Leak Causing OOM DoS by Remote Peer A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory context blocks under specific stream termination conditions, such as when an HTTP/2 connection encounters window exhaustion or explicit stream resets. A remote, unauthenticated attacker acting as a malicious network peer can trick the connection engine into allocating stream states that are subsequently leaked during cleanup. Over a sustained period, this flaw allows the remote attacker to consume the system's heap allocations incrementally, triggering a denial of service (DoS) through an ultimate Out-of-Memory (OOM) application crash.
CVE-2026-15711 Jul 14, 2026
libsoup WebSocket Frame Length Validation DoS A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a payload of 125 bytes or less. A remote, unauthenticated attacker can exploit this by sending a non-compliant, oversized control frame. Because the parser handles this protocol violation improperly instead of throwing an immediate connection termination error, it triggers a internal processing crash, resulting in a remote denial of service (DoS) for applications utilizing libsoup WebSockets.
CVE-2026-15709 Jul 14, 2026
libsoup WebSocket permessage-deflate OOM DoS via decompression bomb A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compressed frame size via max_incoming_payload_size, it fails to track or limit memory allocation during decompression. A separate check for decompressed size (max_total_message_size) exists but executes only after inflation is complete, and it is entirely disabled by default for client connections. A remote, unauthenticated attacker can exploit this by sending a small, highly compressed payload (a decompression bomb), causing unbounded memory allocation that triggers an Out-of-Memory (OOM) crash and a Denial of Service (DoS).
CVE-2026-50659 Jul 14, 2026
Jul 2026: .NET Spoofing Vulnerability Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
Visual Studio 2022
Net
Visual Studio 2026
And others...
CVE-2026-50651 Jul 14, 2026
Jul 2026: .NET Denial of Service Vulnerability Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Net
Visual Studio 2022
Visual Studio 2026
And others...
CVE-2026-50650 Jul 14, 2026
Jul 2026: .NET Framework Elevation of Privilege Vulnerability Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
Net
Visual Studio 2026
Visual Studio 2022
And others...
CVE-2026-50649 Jul 14, 2026
Jul 2026: .NET Remote Code Execution Vulnerability Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
Visual Studio 2022
Net
Visual Studio 2026
And others...
CVE-2026-50648 Jul 14, 2026
Jul 2026: .NET Framework Denial of Service Vulnerability Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
Net
Visual Studio 2022
Visual Studio 2026
And others...
CVE-2026-50646 Jul 14, 2026
Jul 2026: .NET Framework Remote Code Execution Vulnerability Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
Net
Visual Studio 2026
Visual Studio 2022
And others...
CVE-2026-50528 Jul 14, 2026
Jul 2026: .NET Security Feature Bypass Vulnerability Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
Visual Studio 2022
Net
Visual Studio 2026
And others...
CVE-2026-50527 Jul 14, 2026
Jul 2026: .NET Framework Denial of Service Vulnerability Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
Net
Visual Studio 2026
Visual Studio 2022
And others...
CVE-2026-50526 Jul 14, 2026
Jul 2026: .NET Tampering Vulnerability Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
Visual Studio 2022
Net
Visual Studio 2026
And others...
CVE-2026-50525 Jul 14, 2026
Jul 2026: .NET Denial of Service Vulnerability Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Visual Studio 2022
Net
Visual Studio 2026
And others...
CVE-2026-50524 Jul 14, 2026
Jul 2026: .NET Framework Denial of Service Vulnerability Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
Visual Studio 2026
Net
Visual Studio 2022
And others...
CVE-2026-47305 Jul 14, 2026
Jul 2026: Visual Studio Remote Code Execution Vulnerability Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.
Visual Studio 2026
Visual Studio 2022
CVE-2026-47304 Jul 14, 2026
Jul 2026: .NET Security Feature Bypass Vulnerability Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
Visual Studio 2022
Visual Studio 2026
Net
And others...
CVE-2026-47303 Jul 14, 2026
Jul 2026: ASP.NET Core Elevation of Privilege Vulnerability Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Net
Visual Studio 2022
Visual Studio 2026
And others...
CVE-2026-47302 Jul 14, 2026
Jul 2026: .NET Denial of Service Vulnerability Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Net
Visual Studio 2026
Visual Studio 2022
And others...
CVE-2026-47301 Jul 14, 2026
Jul 2026: Configuration Manager Elevation of Privilege Vulnerability Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.
Configuration Manager 2509
Configuration Manager 2603
Configuration Manager 2503
And others...
CVE-2026-47300 Jul 14, 2026
Jul 2026: ASP.NET Core Elevation of Privilege Vulnerability Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Net
Visual Studio 2022
Visual Studio 2026
And others...
CVE-2026-15712 Jul 14, 2026
libsoup HTTP/2 GOAWAY Frame Heap Buffer Overread (CVE-2026-15712) A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tracking framework. When the library processes an HTTP/2 GOAWAY frame, it improperly handles the "Additional Debug Data" payload by assuming the data stream is a safely NUL-terminated C-string. Because the parser lacks strict length-boundary verification before reading this data, a remote, unauthenticated attacker can intentionally send a malformed GOAWAY frame missing the appropriate null delimiter. This causes the library to read past the end of the allocated buffer, triggering an application crash that results in a denial of service (DoS), or potentially exposing fragments of memory contents.
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.