Recent Advisories

Severity ID Title Vendor Product Date Type
NONE MS:CVE-2026-41615

Microsoft Authenticator Information Disclosure Vulnerability_MS:CVE-2026-41615

Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over ...

N/A N/A MSCVE
NONE MS:CVE-2026-42897

Microsoft Exchange Server Spoofing Vulnerability_MS:CVE-2026-42897

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker t...

N/A N/A MSCVE
HIGH 8 MS:CVE-2026-34332

Windows Kernel-Mode Driver Remote Code Execution Vulnerability_MS:CVE-2026-34332

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-40360

Microsoft Excel Information Disclosure Vulnerability_MS:CVE-2026-40360

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

N/A N/A MSCVE
MEDIUM 6.7 MS:CVE-2026-32170

Windows Rich Text Edit Elevation of Privilege Vulnerability_MS:CVE-2026-32170

Double free in Windows Rich Text Edit Control allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 8.4 MS:CVE-2026-40367

Microsoft Word Remote Code Execution Vulnerability_MS:CVE-2026-40367

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-33112

Microsoft SharePoint Server Remote Code Execution Vulnerability_MS:CVE-2026-33112

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-40357

Microsoft SharePoint Server Remote Code Execution Vulnerability_MS:CVE-2026-40357

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-40377

Microsoft Cryptographic Services Elevation of Privilege Vulnerability_MS:CVE-2026-40377

Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-33837

Windows TCP/IP Local Elevation of Privilege Vulnerability_MS:CVE-2026-33837

Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE