Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.3 MS:CVE-2026-2323

Chromium: CVE-2026-2323 Inappropriate implementation in Downloads_MS:CVE-2026-2323

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-2441

Chromium: CVE-2026-2441 Use after free in CSS_MS:CVE-2026-2441

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-21246

Windows Graphics Component Elevation of Privilege Vulnerability_MS:CVE-2026-21246

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-21232

Windows HTTP.sys Elevation of Privilege Vulnerability_MS:CVE-2026-21232

Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-21243

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability_MS:CVE-2026-21243

Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

N/A N/A MSCVE
MEDIUM 6.5 MS:CVE-2026-21512

Azure DevOps Server Cross-Site Scripting Vulnerability_MS:CVE-2026-21512

Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network.

N/A N/A MSCVE
HIGH 7 MS:CVE-2026-21242

Windows Subsystem for Linux Elevation of Privilege Vulnerability_MS:CVE-2026-21242

Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.3 MS:CVE-2026-21235

Windows Graphics Component Elevation of Privilege Vulnerability_MS:CVE-2026-21235

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-21537

Microsoft Defender for Endpoint Linux Extension Remote Code Execution Vulnerability_MS:CVE-2026-21537

Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an a...

N/A N/A MSCVE
HIGH 7 MS:CVE-2026-21237

Windows Subsystem for Linux Elevation of Privilege Vulnerability_MS:CVE-2026-21237

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized att...

N/A N/A MSCVE