CVE-2026-43010 bpf: Reject sleepable kprobe_multi programs at attach time
Information published.
Categories: Microsoft
CVE-2026-53345 KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying
Information published.
Categories: Microsoft
CVE-2026-53354 arm64: errata: Mitigate TLBI errata on various Arm CPUs
Information published.
Categories: Microsoft
CVE-2026-47241 Net::IMAP: Denial of Service via incomplete raw argument validation
Information published.
Categories: Microsoft
CVE-2026-54908 Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
Information published.
Categories: Microsoft
CVE-2026-38969 ruby webrick through v1.9.2 WEBrick reparses trailer Content-Length into canonical request state, enabling request smuggling.
Information published.
Categories: Microsoft
CVE-2026-38968 ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh...
Information published.
Categories: Microsoft
CVE-2026-14191 WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader
Information published.
Categories: Microsoft
CVE-2026-53269 netfilter: synproxy: add mutex to guard hook reference counting
Information published.
Categories: Microsoft
CVE-2026-56000 xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()
Information published.
Categories: Microsoft
CVE-2026-55999 xorg-server / xwayland glamor font atlas Heap Buffer Overflow
Information published.
Categories: Microsoft
CVE-2026-56002 libXfont2 PCF Font Parsing Heap Buffer Overflow
Information published.
Categories: Microsoft
CVE-2026-56003 libXfont2 computeProps Property Buffer Heap Buffer Overflow
Information published.
Categories: Microsoft
CVE-2026-56001 libXfont2 BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow
Information published.
Categories: Microsoft
CVE-2026-60002 ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
Information published.
Categories: Microsoft
CVE-2026-59999 In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
Information published.
Categories: Microsoft
CVE-2026-60000 sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.
Information published.
Categories: Microsoft
CVE-2026-60001 sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
Information published.
Categories: Microsoft
CVE-2026-59995 sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
Information published.
Categories: Microsoft
CVE-2026-59996 scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
Information published.
Categories: Microsoft


