CVE-2026-12439 Use after free in Digital Credentials
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft
CVE-2026-24289 Windows Kernel Elevation of Privilege Vulnerability
Acknowledgement added. This is an informational change only.
Categories: Microsoft
CVE-2025-6965 Integer Truncation on SQLite
Added Visual Studio software to the Security Updates table. Customers that are running supported version of Visual Studio are encouraged to update to the indicated version to be protected from this vulnerability.
Categories: Microsoft
CVE-2026-48914 Qemu-kvm: heap buffer overflow in virtio-blk scsi request handling
Information published.
Categories: Microsoft
CVE-2026-10275 OpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer overflow
Information published.
Categories: Microsoft
CVE-2026-8376 Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
Information published.
Categories: Microsoft
CVE-2026-43966 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2
Information published.
Categories: Microsoft
CVE-2026-9669 bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow
Information published.
Categories: Microsoft
CVE-2026-12087 Socket versions before 2.041 for Perl have an out-of-bounds heap read
Information published.
Categories: Microsoft
CVE-2026-42014 Gnutls: fix use-after-free in gnutls_pkcs11_token_set_pin
Information published.
Categories: Microsoft
CVE-2026-44967 opentelemetry-cpp: OTLP HTTP exporters read unbounded HTTP response
Information published.
Categories: Microsoft
CVE-2026-47633 Microsoft Cost Management Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network.
Categories: Microsoft
CVE-2026-32208 Microsoft Edge (Chromium-based) Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-32174 Azure Bot Service Elevation of Privilege Vulnerability
Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-45480 Azure Active Directory Elevation of Privilege Vulnerability
Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-42895 Microsoft Copilot Tampering Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
Categories: Microsoft
CVE-2026-54130 M365 Copilot Information Disclosure Vulnerability
Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Categories: Microsoft
CVE-2026-47647 Dynamics 365 Elevation of Privilege Vulnerability
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-48584 Microsoft Azure Synapse Elevation of Privilege Vulnerability
Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft


