Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 MS:CVE-2026-9123

Chromium: CVE-2026-9122 Out of bounds read in GPU_MS:CVE-2026-9123

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
MEDIUM 6.8 MS:CVE-2026-45585

Windows BitLocker Security Feature Bypass Vulnerability_MS:CVE-2026-45585

Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnera...

N/A N/A MSCVE
NONE MS:CVE-2026-42834

Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability_MS:CVE-2026-42834

Improper link resolution before file access ('link following') in Azure Portal Windows Admin Center allows an authorized attacker to elevate privil...

N/A N/A MSCVE
NONE MS:CVE-2026-45584

Microsoft Defender Remote Code Execution Vulnerability_MS:CVE-2026-45584

Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.

N/A N/A MSCVE
NONE MS:CVE-2026-41091

Microsoft Defender Elevation of Privilege Vulnerability_MS:CVE-2026-41091

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
NONE MS:CVE-2026-45498

Microsoft Defender Denial of Service Vulnerability_MS:CVE-2026-45498

{“lastseen”:”2026-05-20T01:15:30″,”description”:””,”published”:”2026-05-19T14:00:...

N/A N/A MSCVE
NONE MS:CVE-2026-42822

Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability_MS:CVE-2026-42822

Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.

N/A N/A MSCVE
MEDIUM 6.5 MS:CVE-2026-6478

PostgreSQL discloses MD5-hashed passwords via covert timing channel_MS:CVE-2026-6478

{“lastseen”:”2026-05-18T09:15:25″,”description”:””,”published”:”2026-05-16T08:03:...

N/A N/A MSCVE
LOW 3.7 MS:CVE-2026-6638

PostgreSQL REFRESH PUBLICATION allows SQL injection via table name_MS:CVE-2026-6638

{“lastseen”:”2026-05-18T09:15:25″,”description”:””,”published”:”2026-05-16T08:04:...

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-6473

PostgreSQL server undersizes allocations, via integer wraparound_MS:CVE-2026-6473

{“lastseen”:”2026-05-18T09:15:25″,”description”:””,”published”:”2026-05-16T08:04:...

N/A N/A MSCVE