Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 MS:CVE-2026-21513

MSHTML Framework Security Feature Bypass Vulnerability_MS:CVE-2026-21513

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-21510

Windows Shell Security Feature Bypass Vulnerability_MS:CVE-2026-21510

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-21250

Windows HTTP.sys Elevation of Privilege Vulnerability_MS:CVE-2026-21250

Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
MEDIUM 6.2 MS:CVE-2026-21525

Windows Remote Access Connection Manager Denial of Service Vulnerability_MS:CVE-2026-21525

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

N/A N/A MSCVE
HIGH 8 MS:CVE-2026-21229

Power BI Remote Code Execution Vulnerability_MS:CVE-2026-21229

Improper input validation in Power BI allows an authorized attacker to execute code over a network.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-21255

Windows Hyper-V Security Feature Bypass Vulnerability_MS:CVE-2026-21255

Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-21511

Microsoft Outlook Spoofing Vulnerability_MS:CVE-2026-21511

Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

N/A N/A MSCVE
LOW 3.3 MS:CVE-2026-21249

Windows NTLM Spoofing Vulnerability_MS:CVE-2026-21249

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.

N/A N/A MSCVE
MEDIUM 5.7 MS:CVE-2026-21529

Azure HDInsight Spoofing Vulnerability_MS:CVE-2026-21529

Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform s...

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-21238

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability_MS:CVE-2026-21238

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE