Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 MS:CVE-2026-40420

Microsoft Office Click-To-Run Elevation of Privilege Vulnerability_MS:CVE-2026-40420

Improper access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-32204

Azure Monitor Agent Elevation of Privilege Vulnerability_MS:CVE-2026-32204

External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-40405

Windows TCP/IP Denial of Service Vulnerability_MS:CVE-2026-40405

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-40406

Windows TCP/IP Information Disclosure Vulnerability_MS:CVE-2026-40406

Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-35424

Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability_MS:CVE-2026-35424

Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service ...

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-34336

Windows DWM Core Library Information Disclosure Vulnerability_MS:CVE-2026-34336

Buffer over-read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-40417

Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability_MS:CVE-2026-40417

Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
CRITICAL 9.9 MS:CVE-2026-42898

Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability_MS:CVE-2026-42898

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code ove...

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-33110

Microsoft SharePoint Server Remote Code Execution Vulnerability_MS:CVE-2026-33110

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

N/A N/A MSCVE
HIGH 7.3 MS:CVE-2026-32177

.NET Elevation of Privilege Vulnerability_MS:CVE-2026-32177

Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.

N/A N/A MSCVE