Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 MS:CVE-2026-21232

Windows HTTP.sys Elevation of Privilege Vulnerability_MS:CVE-2026-21232

Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-21243

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability_MS:CVE-2026-21243

Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

N/A N/A MSCVE
MEDIUM 6.5 MS:CVE-2026-21512

Azure DevOps Server Cross-Site Scripting Vulnerability_MS:CVE-2026-21512

Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network.

N/A N/A MSCVE
HIGH 7 MS:CVE-2026-21242

Windows Subsystem for Linux Elevation of Privilege Vulnerability_MS:CVE-2026-21242

Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.3 MS:CVE-2026-21235

Windows Graphics Component Elevation of Privilege Vulnerability_MS:CVE-2026-21235

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-21537

Microsoft Defender for Endpoint Linux Extension Remote Code Execution Vulnerability_MS:CVE-2026-21537

Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an a...

N/A N/A MSCVE
HIGH 7 MS:CVE-2026-21237

Windows Subsystem for Linux Elevation of Privilege Vulnerability_MS:CVE-2026-21237

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized att...

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-21519

Desktop Window Manager Elevation of Privilege Vulnerability_MS:CVE-2026-21519

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-21260

Microsoft Outlook Spoofing Vulnerability_MS:CVE-2026-21260

Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a n...

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-21218

.NET Spoofing Vulnerability_MS:CVE-2026-21218

Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.

N/A N/A MSCVE