Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 MS:CVE-2026-40403

Windows Graphics Component Remote Code Execution Vulnerability_MS:CVE-2026-40403

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-40365

Microsoft SharePoint Server Remote Code Execution Vulnerability_MS:CVE-2026-40365

Insufficient granularity of access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-40398

Windows Remote Desktop Services Elevation of Privilege Vulnerability_MS:CVE-2026-40398

Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
CRITICAL 9.3 MS:CVE-2026-40402

Windows Hyper-V Elevation of Privilege Vulnerability_MS:CVE-2026-40402

Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.4 MS:CVE-2026-40413

Windows TCP/IP Denial of Service Vulnerability_MS:CVE-2026-40413

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an adjacent network.

N/A N/A MSCVE
NONE MS:CVE-2026-42823

Azure Logic Apps Elevation of Privilege Vulnerability_MS:CVE-2026-42823

Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

N/A N/A MSCVE
NONE MS:CVE-2026-42832

Microsoft Office Spoofing Vulnerability_MS:CVE-2026-42832

Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.

N/A N/A MSCVE
NONE MS:CVE-2026-42893

Microsoft Outlook for iOS Tampering Vulnerability_MS:CVE-2026-42893

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tamp...

N/A N/A MSCVE
NONE MS:CVE-2026-42830

Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability_MS:CVE-2026-42830

Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
NONE MS:CVE-2026-41613

Visual Studio Code Elevation of Privilege Vulnerability_MS:CVE-2026-41613

Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

N/A N/A MSCVE