Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.3 MS:CVE-2026-21249

Windows NTLM Spoofing Vulnerability_MS:CVE-2026-21249

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.

N/A N/A MSCVE
MEDIUM 5.7 MS:CVE-2026-21529

Azure HDInsight Spoofing Vulnerability_MS:CVE-2026-21529

Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform s...

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-21238

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability_MS:CVE-2026-21238

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
MEDIUM 5.5 MS:CVE-2026-21222

Windows Kernel Information Disclosure Vulnerability_MS:CVE-2026-21222

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-21251

Cluster Client Failover (CCF) Elevation of Privilege Vulnerability_MS:CVE-2026-21251

Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-21514

Microsoft Word Security Feature Bypass Vulnerability_MS:CVE-2026-21514

Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-21245

Windows Kernel Elevation of Privilege Vulnerability_MS:CVE-2026-21245

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
MEDIUM 6.5 MS:CVE-2023-2804

Red Hat, Inc. CVE-2023-2804: Heap Based Overflow libjpeg-turbo_MS:CVE-2023-2804

A heap‑based buffer overflow exists in libjpeg‑turbo’s h2v2_merged_upsample_internal() function when processing 12‑bit lossless JPEG images. An att...

N/A N/A MSCVE
HIGH 7 MS:CVE-2026-21253

Mailslot File System Elevation of Privilege Vulnerability_MS:CVE-2026-21253

Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7 MS:CVE-2026-21517

Windows App for Mac Installer Elevation of Privilege Vulnerability_MS:CVE-2026-21517

Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE