Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7 MS:CVE-2026-21253

Mailslot File System Elevation of Privilege Vulnerability_MS:CVE-2026-21253

Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7 MS:CVE-2026-21517

Windows App for Mac Installer Elevation of Privilege Vulnerability_MS:CVE-2026-21517

Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-21259

Microsoft Excel Elevation of Privilege Vulnerability_MS:CVE-2026-21259

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally.

N/A N/A MSCVE
CRITICAL 9.8 MS:CVE-2026-21531

Azure SDK for Python Remote Code Execution Vulnerability_MS:CVE-2026-21531

Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.

N/A N/A MSCVE
HIGH 8 MS:CVE-2026-21523

GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability_MS:CVE-2026-21523

Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.

N/A N/A MSCVE
MEDIUM 6.5 MS:CVE-2026-21528

Azure IoT Explorer Information Disclosure Vulnerability_MS:CVE-2026-21528

Binding to an unrestricted ip address in Azure IoT SDK allows an unauthorized attacker to disclose information over a network.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-21239

Windows Kernel Elevation of Privilege Vulnerability_MS:CVE-2026-21239

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-1862

Chromium: CVE-2026-1862 Type Confusion in V8_MS:CVE-2026-1862

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
CRITICAL 9.8 MS:CVE-2026-24300

Azure Front Door Elevation of Privilege Vulnerability_MS:CVE-2026-24300

{“lastseen”:”2026-02-05T23:38:03″,”description”:””,”published”:”2026-02-05T08:00:...

N/A N/A MSCVE
MEDIUM 6.5 MS:CVE-2026-0391

Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability_MS:CVE-2026-0391

User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing ove...

N/A N/A MSCVE