CVE-2026-52911 ksmbd: scope conn->binding slowpath to bound sessions only
Information published.
Categories: Microsoft
CVE-2026-14164 Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack()
Information published.
Categories: Microsoft
CVE-2026-53052 ASoC: qcom: qdsp6: topology: check widget type before accessing data
Information published.
Categories: Microsoft
CVE-2026-14258 Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling
Information published.
Categories: Microsoft
CVE-2026-53043 ocfs2/dlm: validate qr_numregions in dlm_match_regions()
Information published.
Categories: Microsoft
CVE-2026-53195 USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()
Information published.
Categories: Microsoft
CVE-2026-52944 ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE
Information published.
Categories: Microsoft
CVE-2026-52935 xfrm: espintcp: do not reuse an in-progress partial send
Information published.
Categories: Microsoft
CVE-2026-53130 fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START
Information published.
Categories: Microsoft
CVE-2026-53357 Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()
Information published.
Categories: Microsoft
CVE-2026-53048 gfs2: prevent NULL pointer dereference during unmount
Information published.
Categories: Microsoft
CVE-2026-56149 Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service
Information published.
Categories: Microsoft
CVE-2026-49090 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Information published.
Categories: Microsoft
CVE-2026-52992 fs/adfs: validate nzones in adfs_validate_bblk()
Information published.
Categories: Microsoft
CVE-2026-50521 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Added Edge software to the Security Updates table. Customers that are running supported version of Edge are encouraged to update to the indicated version to be protected from this vulnerability.
Categories: Microsoft
CVE-2026-57100 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-45499 Azure OpenAI Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-26145 Microsoft Azure Synapse Elevation of Privilege Vulnerability
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-41106 Microsoft 365 Copilot Elevation of Privilege Vulnerability
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-54998 Microsoft Exchange Online Elevation of Privilege Vulnerability
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft


