Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 MS:CVE-2026-21519

Desktop Window Manager Elevation of Privilege Vulnerability_MS:CVE-2026-21519

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-21260

Microsoft Outlook Spoofing Vulnerability_MS:CVE-2026-21260

Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a n...

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-21218

.NET Spoofing Vulnerability_MS:CVE-2026-21218

Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-21513

MSHTML Framework Security Feature Bypass Vulnerability_MS:CVE-2026-21513

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-21510

Windows Shell Security Feature Bypass Vulnerability_MS:CVE-2026-21510

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-21250

Windows HTTP.sys Elevation of Privilege Vulnerability_MS:CVE-2026-21250

Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
MEDIUM 6.2 MS:CVE-2026-21525

Windows Remote Access Connection Manager Denial of Service Vulnerability_MS:CVE-2026-21525

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

N/A N/A MSCVE
HIGH 8 MS:CVE-2026-21229

Power BI Remote Code Execution Vulnerability_MS:CVE-2026-21229

Improper input validation in Power BI allows an authorized attacker to execute code over a network.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-21255

Windows Hyper-V Security Feature Bypass Vulnerability_MS:CVE-2026-21255

Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-21511

Microsoft Outlook Spoofing Vulnerability_MS:CVE-2026-21511

Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

N/A N/A MSCVE