Microsoft Makers of the Windows Operating System and hundreds of products that run on it.
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Microsoft product.
RSS Feeds for Microsoft security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Microsoft products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Microsoft Sorted by Most Security Vulnerabilities since 2018
Recent Microsoft Security Advisories
| Advisory | Title | Published |
|---|---|---|
| CVE-2026-50012 | CVE-2026-50012 Squid: Memory corruption in cache_digest reply handling | July 18, 2026 |
| CVE-2026-47729 | CVE-2026-47729 Squid: Memory disclosure in FTP gateway | July 18, 2026 |
| CVE-2026-62299 | CVE-2026-62299 CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record | July 18, 2026 |
| CVE-2026-62309 | CVE-2026-62309 CoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — single 28-byte packet remote DoS | July 18, 2026 |
| CVE-2026-15905 | Chromium: CVE-2026-15905 Use after free in Aura | July 18, 2026 |
| CVE-2026-15904 | Chromium: CVE-2026-15904 Use after free in Ozone | July 18, 2026 |
| CVE-2026-15903 | Chromium: CVE-2026-15903 Out of bounds read and write in V8 | July 18, 2026 |
| CVE-2026-15902 | Chromium: CVE-2026-15902 Use after free in Cast | July 18, 2026 |
| CVE-2026-15901 | Chromium: CVE-2026-15901 Use after free in Network | July 18, 2026 |
| CVE-2026-15900 | Chromium: CVE-2026-15900 Use after free in GPU | July 18, 2026 |
Known Exploited Microsoft Vulnerabilities
The following Microsoft vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Microsoft SharePoint Deserialization of Untrusted Data Vulnerability |
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. CVE-2026-58644 |
July 16, 2026 |
| Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerabil |
Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally. CVE-2026-56155 |
July 14, 2026 |
| Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability |
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network. CVE-2026-56164 |
July 14, 2026 |
| Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability |
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network. CVE-2026-45659 Exploit Probability: 1.7% |
July 1, 2026 |
| Microsoft Internet Explorer Use-After-Free Vulnerability |
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CVE-2010-0249 Exploit Probability: 91.9% |
May 20, 2026 |
| Microsoft Windows Buffer Overflow Vulnerability |
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization. CVE-2008-4250 Exploit Probability: 98.8% |
May 20, 2026 |
| Microsoft Defender Denial of Service Vulnerability |
Microsoft Defender contains an unspecified vulnerability that allows for denial of service. CVE-2026-45498 Exploit Probability: 2.5% |
May 20, 2026 |
| Microsoft DirectX NULL Byte Overwrite Vulnerability |
Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file. CVE-2009-1537 Exploit Probability: 51.2% |
May 20, 2026 |
| Microsoft Internet Explorer Use-After-Free Vulnerability |
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CVE-2010-0806 Exploit Probability: 82.2% |
May 20, 2026 |
| Microsoft Defender Link Following Vulnerability |
Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally. CVE-2026-41091 Exploit Probability: 1.2% |
May 20, 2026 |
| Microsoft Exchange Server Cross-Site Scripting Vulnerability |
Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context. CVE-2026-42897 Exploit Probability: 2.5% |
May 15, 2026 |
| Microsoft Windows Protection Mechanism Failure Vulnerability |
Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network. CVE-2026-32202 Exploit Probability: 20.0% |
April 28, 2026 |
| Microsoft Defender Insufficient Granularity of Access Control Vulnerability |
Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally. CVE-2026-33825 Exploit Probability: 6.2% |
April 22, 2026 |
| Microsoft Office Remote Code Execution |
Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object. CVE-2009-0238 Exploit Probability: 43.1% |
April 14, 2026 |
| Microsoft SharePoint Server Improper Input Validation Vulnerability |
Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. CVE-2026-32201 Exploit Probability: 24.2% |
April 14, 2026 |
| Microsoft Windows Link Following Vulnerability |
Microsoft Windows contains a link following vulnerability that allows for privilege escalation CVE-2025-60710 Exploit Probability: 4.7% |
April 13, 2026 |
| Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability |
Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. CVE-2023-21529 Exploit Probability: 62.1% |
April 13, 2026 |
| Microsoft Windows Out-of-Bounds Read Vulnerability |
Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation CVE-2023-36424 Exploit Probability: 12.2% |
April 13, 2026 |
| Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability |
Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution. CVE-2012-1854 Exploit Probability: 21.0% |
April 13, 2026 |
| Microsoft SharePoint Deserialization of Untrusted Data Vulnerability |
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. CVE-2026-20963 Exploit Probability: 31.1% |
March 18, 2026 |
Of the known exploited vulnerabilities above, 4 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 7 known exploited Microsoft vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
Top 10 Riskiest Microsoft Vulnerabilities
Based on the current exploit probability, these Microsoft vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.
| Rank | CVE | EPSS | Vulnerability |
|---|---|---|---|
| 1 | CVE-2021-34473 | 100.0% | Microsoft Exchange Server Remote Code Execution Vulnerability |
| 2 | CVE-2021-26855 | 100.0% | Microsoft OWA Exchange Control Panel (ECP) Exploit Chain |
| 3 | CVE-2019-0708 | 100.0% | "BlueKeep" Microsoft Windows Remote Desktop Remote Code Execution Vulnerability |
| 4 | CVE-2015-1635 | 100.0% | Microsoft HTTP.sys Remote Code Execution Vulnerability |
| 5 | CVE-2021-34523 | 100.0% | Microsoft Exchange Server Privilege Escalation Vulnerability |
| 6 | CVE-2025-53770 | 100.0% | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability |
| 7 | CVE-2022-41082 | 100.0% | Microsoft Exchange Server Remote Code Execution Vulnerability |
| 8 | CVE-2012-0158 | 100.0% | Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability |
| 9 | CVE-2020-0688 | 100.0% | Microsoft Exchange Server Key Validation Vulnerability |
| 10 | CVE-2025-59287 | 100.0% | Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability |
By the Year
In 2026 there have been 4471 vulnerabilities in Microsoft with an average score of 7.2 out of ten. Last year, in 2025 Microsoft had 2750 security vulnerabilities published. That is, 1721 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.16.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 4471 | 7.24 |
| 2025 | 2750 | 7.08 |
| 2024 | 2182 | 7.33 |
| 2023 | 1695 | 7.22 |
| 2022 | 1389 | 7.43 |
| 2021 | 1153 | 7.44 |
| 2020 | 1253 | 7.20 |
| 2019 | 831 | 7.08 |
| 2018 | 661 | 7.03 |
It may take a day or so for new Microsoft vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Microsoft Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-56171 | Jul 17, 2026 |
Jul 2026: Windows Remote Desktop Protocol (RDP) Information Disclosure VulnerabilityExposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
| CVE-2026-57980 | Jul 17, 2026 |
Jul 2026: Microsoft Edge (Chromium-based) Tampering VulnerabilityAuthentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. |
|
| CVE-2026-62826 | Jul 16, 2026 |
Jul 2026: Microsoft SharePoint Server Spoofing VulnerabilityImproper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |
And others... |
| CVE-2026-58643 | Jul 16, 2026 |
Jul 2026: Windows Admin Center Spoofing VulnerabilityImproper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network. |
|
| CVE-2026-58598 | Jul 16, 2026 |
Jul 2026: Windows Backup Service Elevation of Privilege VulnerabilityConcurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally. |
And others... |
| CVE-2026-59117 | Jul 16, 2026 |
Jul 2026: Windows Terminal Remote Code Execution VulnerabilityInteger overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network. |
|
| CVE-2026-62299 | Jul 16, 2026 |
CoreDNS 1.x DoS via REWRITE plugin Nil OPT deref - <1.14.5CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an optional revert flag, and two response rules, edns0SetResponseRule and edns0ReplaceResponseRule[T] in plugin/rewrite/edns0.go, call res.IsEdns0() and immediately dereference the returned *dns.OPT without a nil check when a downstream plugin returns a response with no OPT record. A remote, unauthenticated client can send a single ordinary DNS query matching a rewrite edns0 <local|nsid|subnet> <set|append|replace> ... revert rule, causing ResponseReverter in plugin/rewrite/reverter.go to panic, return SERVFAIL, and degrade availability, or crash the CoreDNS process if the debug directive disables recovery. This issue is fixed in version 1.14.5. |
|
| CVE-2026-62309 | Jul 16, 2026 |
CoreDNS 1.14.4 Crash on 28byte UDP via proxyproto (pre1.14.4)CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin is enabled because plugin/pkg/proxyproto/proxyproto.go PacketConn.ReadFrom handles a PROXY v2 header with non-UDP transport such as family byte 0x11, reassigns addr from a nil readFrom result after parseProxyProtocol errors, and calls addr.String() in the warning log before ServeDNS recovery applies. This issue is fixed in version 1.14.4. |
|
| CVE-2026-47729 | Jul 16, 2026 |
Squid <7.6 OOB Read via FTP GatewaySquid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6. |
|
| CVE-2026-50012 | Jul 16, 2026 |
Squid<7.6 Heap BOverflow via CacheDigest (peerDigestSwapInMask)Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest's on-the-wire size may be larger than the mask_size declared within the digest, so a trusted peer sending a maliciously crafted reply to a cache_digest request message can trigger the overflow. This attack is limited to Squid instances compiled with the --enable-cache-digests option and configured with cache_peer entries. This issue is fixed in version 7.6. |
|
| CVE-2026-55440 | Jul 16, 2026 |
Jul 2026: Microsoft UFO: COMMAND_RESULTS handler creates unowned sessions, allowing authenticated seMicrosoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/server/ws/handler.py called get_or_create_session in ufo/server/services/session_manager.py without owner_client_id, allowing an authenticated client to create an unowned attacker-chosen session_id such as constellation_task_id = f"{task_name}@{task_id}" and deny the legitimate owner or exhaust memory with phantom sessions. This issue is fixed in version 3.0.7. |
|
| CVE-2026-54568 | Jul 16, 2026 |
Jul 2026: Microsoft UFO: Missing Authorization in DEVICE_INFO_REQUEST Allows a DEVICE Client to ReadMicrosoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a client connected to the UFO WebSocket server as a DEVICE could call DEVICE_INFO_REQUEST with another device's target_id and receive that device's server-side system_info through ufo/server/ws/handler.py, because handle_device_info_request and get_device_info did not enforce the constellation-only role or object-level authorization boundary. This issue is fixed in version 3.0.6. |
|
| CVE-2026-57206 | Jul 16, 2026 |
Jul 2026: SimpleChat plugin validation endpoints missing authentication and authorizationSimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin validation routes in application/single_app/plugin_validation_endpoint.py, including `POST /api/admin/plugins/test-instantiation`, `GET /api/admin/plugins/health-check/<plugin_name>`, `POST /api/admin/plugins/repair/<plugin_name>`, and `POST /api/plugins/validate`, relied on @swagger_route(security=get_auth_security()) documentation without enforcing @login_required, @user_required, or @admin_required at runtime, allowing unauthenticated or unauthorized clients to invoke plugin validation, health, and repair behavior. This issue is fixed in version 0.241.206. |
|
| CVE-2026-57205 | Jul 16, 2026 |
Jul 2026: SimpleChat: Authenticated users can access other users' profile metadata through user IDORSimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> endpoints in application/single_app/route_backend_users.py accepted a caller-supplied user_id and read the matching Cosmos DB user-settings document without object-level authorization, allowing a low-privilege authenticated user to retrieve another user's email address, display name, and profile image. This issue is fixed in version 0.241.203. |
|
| CVE-2026-53598 | Jul 16, 2026 |
Jul 2026: Prompty: Arbitrary File Read via ${file:path} Reference ExpansionPrompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that resolved paths stayed within the prompt directory or allowed roots, allowing an attacker-controlled prompt file to read local files through absolute paths, .. traversal, or symlink escapes. This issue is fixed in versions 2.0.0-beta.2. |
|
| CVE-2026-53597 | Jul 16, 2026 |
Jul 2026: Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loaderPrompty is a markdown file format (.prompty) for LLM prompts. From 2.0.0-alpha.1 until 2.0.0-beta.3, the @prompty/core TypeScript loader in runtime/typescript/packages/core/src/core/loader.ts used gray-matter without overriding executable js and javascript frontmatter engines, allowing an attacker-controlled .prompty file with ---js frontmatter to execute arbitrary JavaScript during prompt loading. This issue is fixed in version 2.0.0-beta.3. |
|
| CVE-2026-54733 | Jul 16, 2026 |
Jul 2026: moodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpoinThe Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn claim without verifying the JWT signature, allowing an unauthenticated attacker to forge a token and obtain a Moodle session as an O365-authenticated user. This issue is fixed in versions 4.5.6, 5.0.5, and 5.1.1. |
|
| CVE-2026-59867 | Jul 16, 2026 |
Jul 2026: Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $refKiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local absolute or out-of-tree file paths, allowing `kiota generate` on an attacker-controlled or attacker-influenced description to perform build-time SSRF, remote file inclusion, and local file inclusion by inlining external schemas such as REMOTE_KIOTA_PROP or Leaked into generated clients. This issue is fixed in version 1.32.5 by AllowedExternalOriginsStreamLoader and the --allowed-external-origins option. |
|
| CVE-2026-59866 | Jul 16, 2026 |
Jul 2026: Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clienKiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as both generated client class or namespace names and generated output path components when `kiota generate` ran without -c/--class-name, allowing an attacker-controlled or compromised OpenAPI description to write generated source outside the -o output directory and inject arbitrary text into generated class or namespace declarations. This issue is fixed in version 1.32.5 by GenerationConfiguration.SanitizeClientClassName and SanitizeClientNamespaceName. |
|
| CVE-2026-59864 | Jul 16, 2026 |
Jul 2026: Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensionsKiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_template.file values from x-ai-adaptive-card and x-ai-capabilities into generated Microsoft 365 Copilot and Teams plugin manifests without path validation, allowing ../, absolute, rooted, UNC, Windows drive, or URI paths in response_semantics.static_template.file to cause path traversal or out-of-package file inclusion when the generated plugin was deployed. This issue is fixed in version 1.32.5. |
|
| CVE-2026-59865 | Jul 16, 2026 |
Jul 2026: Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota iKiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version values from an OpenAPI description and presented the spec-supplied command as Kiota's recommended install command, allowing an attacker-controlled or compromised description to cause command injection when the suggested command was run manually or through the Kiota VS Code extension's kiota info --json dependency-install flow. This issue is fixed in version 1.32.5. |
|
| CVE-2026-59863 | Jul 16, 2026 |
Jul 2026: Kiota: Workspace-config poisoning: out-of-repo file write + generation-time SSRFKiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota honored a poisoned .kiota/workspace.json workspace configuration without validating per-client or per-plugin outputPath values during kiota client generate and kiota plugin generate, allowing a malicious repository or pull request to use absolute paths, rooted POSIX / paths, UNC \\ or // paths, Windows drive X:\ paths, or .. traversal segments to write generated client files outside the workspace root on a developer or CI host. This issue is fixed in version 1.32.5. |
|
| CVE-2026-59859 | Jul 16, 2026 |
Jul 2026: Kiota: Code Generation Literal Injection in the PHP GeneratorKiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-derived strings into PHP double-quoted literals through SanitizeDoubleQuote() in Writers/StringExtensions.cs without escaping $, allowing attacker-controlled ${...}, $var, or {$obj->prop} interpolation constructs to inject arbitrary PHP code into generated model and request-builder classes. This issue is fixed in version 1.32.4. |
|
| CVE-2026-59862 | Jul 16, 2026 |
Jul 2026: Kiota: Code Generation Literal Injection in the Python GeneratorKiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Python generator let attacker-controlled enum value descriptions from x-ms-enum.values[].description flow through KiotaBuilder.SetEnumOptions into Documentation.DescriptionTemplate and PythonConventionService.RemoveInvalidDescriptionCharacters without newline sanitization, allowing generated inline comments to split and execute attacker-controlled Python code at module scope when generated modules were imported. This issue is fixed in version 1.32.0. |
|
| CVE-2026-59861 | Jul 16, 2026 |
Jul 2026: Kiota: Code Generation Literal Injection in Kiota Ruby GeneratorKiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Ruby generator embedded OpenAPI default fields, property names, and other schema-derived strings through CodeMethodWriter.cs and SanitizeForQuotedLiteral() in Writers/StringExtensions.cs into Ruby double-quoted literals without escaping #, allowing attacker-controlled #{expr}, #$var, or #@var interpolation markers to inject arbitrary Ruby code into generated model classes. This issue is fixed in version 1.32.0. |
|
| CVE-2026-59860 | Jul 16, 2026 |
Jul 2026: Kiota: XML Doc-Comment Newline Breakout Code InjectionKiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.3, Kiota is affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the description, externalDocs label, and externalDocs link fields emitted as /// comments). When text from an OpenAPI description is written into single-line XML doc comments without stripping newline and Unicode line-terminator characters, an attacker can break out of the /// comment line and inject additional code into generated C# clients. This issue is fixed in version 1.32.3. |
|
| CVE-2026-53366 | Jul 16, 2026 |
CVE-2026-53366: Linux IPv4 Paged Alloc Frag Size Miscalc BugIn the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation path In __ip_append_data(), when the paged-allocation branch is taken, alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap, but the fraggap bytes carried over from the previous skb are copied into the new skb's linear area at offset transhdrlen by the subsequent skb_copy_and_csum_bits(). The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount. The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does. Bring the paged branch in line by adding fraggap to alloclen and subtracting it from pagedlen. After this adjustment, copy no longer collapses to -fraggap on the paged path, so remove the stale comment describing that old arithmetic. |
|
| CVE-2026-48863 | Jul 16, 2026 |
libsolv PGP EdDSA Buffer Overflow (CVE-2026-48863)A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows. |
|
| CVE-2026-15714 | Jul 14, 2026 |
libsoup OOB Read in multipart boundary parsingAn out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_multipart_input_stream_read_headers() function inside soup-multipart-input-stream.c, which does not adequately restrict or validate the size of incoming multipart boundary strings. When processing a crafted HTTP response containing a malformed or oversized boundary parameter, the internal stream reader reads past the allocated buffer bounds. A remote, unauthenticated attacker can exploit this behavior to cause a service denial (DoS) through application failure or potentially read fragments of unauthorized memory metadata. |
|
| CVE-2026-15713 | Jul 14, 2026 |
libsoup HTTP/2 Memory Leak Causing OOM DoS by Remote PeerA vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory context blocks under specific stream termination conditions, such as when an HTTP/2 connection encounters window exhaustion or explicit stream resets. A remote, unauthenticated attacker acting as a malicious network peer can trick the connection engine into allocating stream states that are subsequently leaked during cleanup. Over a sustained period, this flaw allows the remote attacker to consume the system's heap allocations incrementally, triggering a denial of service (DoS) through an ultimate Out-of-Memory (OOM) application crash. |
|
| CVE-2026-15711 | Jul 14, 2026 |
libsoup WebSocket Frame Length Validation DoSA vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a payload of 125 bytes or less. A remote, unauthenticated attacker can exploit this by sending a non-compliant, oversized control frame. Because the parser handles this protocol violation improperly instead of throwing an immediate connection termination error, it triggers a internal processing crash, resulting in a remote denial of service (DoS) for applications utilizing libsoup WebSockets. |
|
| CVE-2026-15709 | Jul 14, 2026 |
libsoup WebSocket permessage-deflate OOM DoS via decompression bombA flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compressed frame size via max_incoming_payload_size, it fails to track or limit memory allocation during decompression. A separate check for decompressed size (max_total_message_size) exists but executes only after inflation is complete, and it is entirely disabled by default for client connections. A remote, unauthenticated attacker can exploit this by sending a small, highly compressed payload (a decompression bomb), causing unbounded memory allocation that triggers an Out-of-Memory (OOM) crash and a Denial of Service (DoS). |
|
| CVE-2026-50659 | Jul 14, 2026 |
Jul 2026: .NET Spoofing VulnerabilityImproper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. |
And others... |
| CVE-2026-50651 | Jul 14, 2026 |
Jul 2026: .NET Denial of Service VulnerabilityAllocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. |
And others... |
| CVE-2026-50650 | Jul 14, 2026 |
Jul 2026: .NET Framework Elevation of Privilege VulnerabilityImproper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally. |
And others... |
| CVE-2026-50649 | Jul 14, 2026 |
Jul 2026: .NET Remote Code Execution VulnerabilityDeserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. |
And others... |
| CVE-2026-50648 | Jul 14, 2026 |
Jul 2026: .NET Framework Denial of Service VulnerabilityAllocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. |
And others... |
| CVE-2026-50646 | Jul 14, 2026 |
Jul 2026: .NET Framework Remote Code Execution VulnerabilityProtection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. |
And others... |
| CVE-2026-50528 | Jul 14, 2026 |
Jul 2026: .NET Security Feature Bypass VulnerabilityIncorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. |
And others... |
| CVE-2026-50527 | Jul 14, 2026 |
Jul 2026: .NET Framework Denial of Service VulnerabilityStack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. |
And others... |
| CVE-2026-50526 | Jul 14, 2026 |
Jul 2026: .NET Tampering VulnerabilityImproper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally. |
And others... |
| CVE-2026-50525 | Jul 14, 2026 |
Jul 2026: .NET Denial of Service VulnerabilityAllocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. |
And others... |
| CVE-2026-50524 | Jul 14, 2026 |
Jul 2026: .NET Framework Denial of Service VulnerabilityImproper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network. |
And others... |
| CVE-2026-47305 | Jul 14, 2026 |
Jul 2026: Visual Studio Remote Code Execution VulnerabilityProtection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally. |
|
| CVE-2026-47304 | Jul 14, 2026 |
Jul 2026: .NET Security Feature Bypass VulnerabilityImproper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. |
And others... |
| CVE-2026-47303 | Jul 14, 2026 |
Jul 2026: ASP.NET Core Elevation of Privilege VulnerabilityAuthentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. |
And others... |
| CVE-2026-47302 | Jul 14, 2026 |
Jul 2026: .NET Denial of Service VulnerabilityAllocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. |
And others... |
| CVE-2026-47301 | Jul 14, 2026 |
Jul 2026: Configuration Manager Elevation of Privilege VulnerabilityImproper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network. |
And others... |
| CVE-2026-47300 | Jul 14, 2026 |
Jul 2026: ASP.NET Core Elevation of Privilege VulnerabilityIncorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. |
And others... |
| CVE-2026-15712 | Jul 14, 2026 |
libsoup HTTP/2 GOAWAY Frame Heap Buffer Overread (CVE-2026-15712)A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tracking framework. When the library processes an HTTP/2 GOAWAY frame, it improperly handles the "Additional Debug Data" payload by assuming the data stream is a safely NUL-terminated C-string. Because the parser lacks strict length-boundary verification before reading this data, a remote, unauthenticated attacker can intentionally send a malformed GOAWAY frame missing the appropriate null delimiter. This causes the library to read past the end of the allocated buffer, triggering an application crash that results in a denial of service (DoS), or potentially exposing fragments of memory contents. |