Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 MS:CVE-2026-26143

Microsoft PowerShell Security Feature Bypass Vulnerability_MS:CVE-2026-26143

Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-21637

HackerOne: CVE-2026-21637 TLS PSK/ALPN Callback Exceptions Bypass Error Handlers_MS:CVE-2026-21637

CVE-2026-21637 is regarding a vulnerability in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server whe...

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-23657

Microsoft Word Remote Code Execution Vulnerability_MS:CVE-2026-23657

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

N/A N/A MSCVE
HIGH 7 MS:CVE-2026-33100

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability_MS:CVE-2026-33100

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7 MS:CVE-2026-33099

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability_MS:CVE-2026-33099

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
MEDIUM 5.5 MS:CVE-2026-33103

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability_MS:CVE-2026-33103

Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-26171

.NET Denial of Service Vulnerability_MS:CVE-2026-26171

Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.

N/A N/A MSCVE
MEDIUM 5.5 MS:CVE-2026-32214

Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability_MS:CVE-2026-32214

Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-32225

Windows Shell Security Feature Bypass Vulnerability_MS:CVE-2026-32225

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

N/A N/A MSCVE
HIGH 7 MS:CVE-2026-33104

Win32k Elevation of Privilege Vulnerability_MS:CVE-2026-33104

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker ...

N/A N/A MSCVE