CVE-2026-15709 Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of service
Information published.
Categories: Microsoft
CVE-2026-15712 Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over-read via invalid nul-termination assumption
Information published.
Categories: Microsoft
CVE-2026-15714 Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary string
Information published.
Categories: Microsoft
CVE-2026-15713 Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via memory leak
Information published.
Categories: Microsoft
CVE-2026-15711 Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol violation
Information published.
Categories: Microsoft
CVE-2026-53366 ipv4: account for fraggap on the paged allocation path
Information published.
Categories: Microsoft
CVE-2026-48863 Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service
Information published.
Categories: Microsoft
CVE-2026-59117 Windows Terminal Remote Code Execution Vulnerability
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-58643 Windows Admin Center Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-58598 Windows Backup Service Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-56171 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
Categories: Microsoft
CVE-2025-44904 hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.
Information published.
Categories: Microsoft
CVE-2026-57215 RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom
Information published.
Categories: Microsoft
CVE-2026-57211 RabbitMQ: UNC SSRF affecting the management UI on Windows
Information published.
Categories: Microsoft
CVE-2026-57216 RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks
Information published.
Categories: Microsoft
CVE-2026-57213 RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering
Information published.
Categories: Microsoft
CVE-2026-57217 RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass
Information published.
Categories: Microsoft
CVE-2026-57220 RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS
Information published.
Categories: Microsoft
CVE-2026-57219 RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations
Information published.
Categories: Microsoft
CVE-2026-59831 GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace
Information published.
Categories: Microsoft


