CVE-2026-58630 Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-58275 Azure DNS Elevation of Privilege Vulnerability
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-62835 Online Services Information Disclosure Vulnerability
Improper authorization in Online Services allows an unauthorized attacker to disclose information over a network.
Categories: Microsoft
CVE-2026-54171 Excon: redact additional sensitive/risky headers when following redirects
Information published.
Categories: Microsoft
CVE-2026-44508 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate.
Information published.
Categories: Microsoft
CVE-2026-44510 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate.
Information published.
Categories: Microsoft
CVE-2026-44509 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate.
Information published.
Categories: Microsoft
CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()
Information published.
Categories: Microsoft
CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys
Information published.
Categories: Microsoft
CVE-2026-15788 WCOW cache mount source selector resolves NTFS junctions outside of cache root
Information published.
Categories: Microsoft
CVE-2026-26081 HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.
Information published.
Categories: Microsoft
CVE-2026-26080 HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.
Information published.
Categories: Microsoft
CVE-2026-15588 Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering
Information published.
Categories: Microsoft
CVE-2026-63308 Helm Files.Lines Denial of Service via Empty Chart Files
Information published.
Categories: Microsoft
CVE-2026-50243 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL
Information published.
Categories: Microsoft
CVE-2026-41637 Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries
Information published.
Categories: Microsoft
CVE-2026-50252 Possible cache poisoning attack by mapping source port population per thread
Information published.
Categories: Microsoft
CVE-2026-50251 Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush
Information published.
Categories: Microsoft
CVE-2026-55991 Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
Information published.
Categories: Microsoft
CVE-2026-55990 Packet of death for a DNSCrypt misconfigured Unbound
Information published.
Categories: Microsoft


