Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.3 MS:CVE-2026-40402

Windows Hyper-V Elevation of Privilege Vulnerability_MS:CVE-2026-40402

Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.4 MS:CVE-2026-40413

Windows TCP/IP Denial of Service Vulnerability_MS:CVE-2026-40413

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an adjacent network.

N/A N/A MSCVE
NONE MS:CVE-2026-42823

Azure Logic Apps Elevation of Privilege Vulnerability_MS:CVE-2026-42823

Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

N/A N/A MSCVE
NONE MS:CVE-2026-42832

Microsoft Office Spoofing Vulnerability_MS:CVE-2026-42832

Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.

N/A N/A MSCVE
NONE MS:CVE-2026-42893

Microsoft Outlook for iOS Tampering Vulnerability_MS:CVE-2026-42893

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tamp...

N/A N/A MSCVE
NONE MS:CVE-2026-42830

Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability_MS:CVE-2026-42830

Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
NONE MS:CVE-2026-41613

Visual Studio Code Elevation of Privilege Vulnerability_MS:CVE-2026-41613

Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

N/A N/A MSCVE
NONE MS:CVE-2025-54518

AMD: CVE-2025-54518 CPU OP Cache Corruption_MS:CVE-2025-54518

This vulnerability was found and addressed by AMD. We are documenting it in the Security Update Guide to encourage customers to install the May 202...

N/A N/A MSCVE
MEDIUM 4.3 MS:CVE-2026-7915

Chromium: CVE-2026-7915 Insufficient data validation in DevTools_MS:CVE-2026-7915

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
HIGH 8.3 MS:CVE-2026-7905

Chromium: CVE-2026-7905 Insufficient validation of untrusted input in Media_MS:CVE-2026-7905

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE