Chromium: CVE-2026-15899 Use after free in CameraCapture
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft
CVE-2026-59886 pyasn1: Uncontrolled resource consumption when converting decoded REAL values
Information published.
Categories: Microsoft
CVE-2026-59884 pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
Information published.
Categories: Microsoft
CVE-2026-59885 pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
Information published.
Categories: Microsoft
CVE-2026-60081 DBI::ProfileData versions before 1.651 for Perl do not limit the path index
Information published.
Categories: Microsoft
CVE-2026-15392 DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location
Information published.
Categories: Microsoft
CVE-2026-60082 DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row
Information published.
Categories: Microsoft
CVE-2026-15043 DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text
Information published.
Categories: Microsoft
CVE-2026-57433 Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record
Information published.
Categories: Microsoft
CVE-2026-15709 Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of service
Information published.
Categories: Microsoft
CVE-2026-15712 Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over-read via invalid nul-termination assumption
Information published.
Categories: Microsoft
CVE-2026-15714 Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary string
Information published.
Categories: Microsoft
CVE-2026-15713 Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via memory leak
Information published.
Categories: Microsoft
CVE-2026-15711 Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol violation
Information published.
Categories: Microsoft
CVE-2026-53366 ipv4: account for fraggap on the paged allocation path
Information published.
Categories: Microsoft
CVE-2026-48863 Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service
Information published.
Categories: Microsoft
CVE-2026-59117 Windows Terminal Remote Code Execution Vulnerability
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-58643 Windows Admin Center Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-58598 Windows Backup Service Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-56171 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
Categories: Microsoft


