CVE-2026-58637 Windows Client-Side Caching Elevation of Privilege Vulnerability
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-58638 Windows Boot Loader Security Feature Bypass Vulnerability
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
Categories: Microsoft
CVE-2026-56181 Windows Network Address Translation (NAT) Spoofing Vulnerability
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
Categories: Microsoft
CVE-2026-55121 Microsoft Office Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Categories: Microsoft
CVE-2026-58529 Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability
Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.
Categories: Microsoft
CVE-2026-55008 Microsoft Exchange Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-59874 node-tar: Negative tar entry size causes infinite loop in archive replace
Information published.
Categories: Microsoft
CVE-2026-59873 node-tar: Decompression/parse DoS via unlimited input
Information published.
Categories: Microsoft
CVE-2026-59871 node-tar: Process crash via PAX numeric path type confusion
Information published.
Categories: Microsoft
CVE-2026-15308 Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
Information published.
Categories: Microsoft
Chromium: CVE-2026-14428 Insufficient validation of untrusted input in Dawn
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft
Chromium: CVE-2026-14382 Insufficient validation of untrusted input in ANGLE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft
Chromium: CVE-2026-14126 Incorrect security UI in UI
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft
Chromium: CVE-2026-14114 Inappropriate implementation in WebAppInstalls
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft
Chromium: CVE-2026-14096 Object lifecycle issue in Input
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft
Chromium: CVE-2026-14005 Use after free in Omnibox
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft


