Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 MS:CVE-2026-21514

Microsoft Word Security Feature Bypass Vulnerability_MS:CVE-2026-21514

Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-21245

Windows Kernel Elevation of Privilege Vulnerability_MS:CVE-2026-21245

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
MEDIUM 6.5 MS:CVE-2023-2804

Red Hat, Inc. CVE-2023-2804: Heap Based Overflow libjpeg-turbo_MS:CVE-2023-2804

A heap‑based buffer overflow exists in libjpeg‑turbo’s h2v2_merged_upsample_internal() function when processing 12‑bit lossless JPEG images. An att...

N/A N/A MSCVE
HIGH 7 MS:CVE-2026-21253

Mailslot File System Elevation of Privilege Vulnerability_MS:CVE-2026-21253

Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7 MS:CVE-2026-21517

Windows App for Mac Installer Elevation of Privilege Vulnerability_MS:CVE-2026-21517

Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-21259

Microsoft Excel Elevation of Privilege Vulnerability_MS:CVE-2026-21259

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally.

N/A N/A MSCVE
CRITICAL 9.8 MS:CVE-2026-21531

Azure SDK for Python Remote Code Execution Vulnerability_MS:CVE-2026-21531

Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.

N/A N/A MSCVE
HIGH 8 MS:CVE-2026-21523

GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability_MS:CVE-2026-21523

Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.

N/A N/A MSCVE
MEDIUM 6.5 MS:CVE-2026-21528

Azure IoT Explorer Information Disclosure Vulnerability_MS:CVE-2026-21528

Binding to an unrestricted ip address in Azure IoT SDK allows an unauthorized attacker to disclose information over a network.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-21239

Windows Kernel Elevation of Privilege Vulnerability_MS:CVE-2026-21239

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE