Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 MS:CVE-2026-42899

ASP.NET Core Denial of Service Vulnerability_MS:CVE-2026-42899

Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-35439

Microsoft SharePoint Server Remote Code Execution Vulnerability_MS:CVE-2026-35439

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-33834

Windows Event Logging Service Elevation of Privilege Vulnerability_MS:CVE-2026-33834

Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-33840

Win32k Elevation of Privilege Vulnerability_MS:CVE-2026-33840

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-40420

Microsoft Office Click-To-Run Elevation of Privilege Vulnerability_MS:CVE-2026-40420

Improper access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-32204

Azure Monitor Agent Elevation of Privilege Vulnerability_MS:CVE-2026-32204

External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-35424

Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability_MS:CVE-2026-35424

Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service ...

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-40405

Windows TCP/IP Denial of Service Vulnerability_MS:CVE-2026-40405

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-40406

Windows TCP/IP Information Disclosure Vulnerability_MS:CVE-2026-40406

Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-34336

Windows DWM Core Library Information Disclosure Vulnerability_MS:CVE-2026-34336

Buffer over-read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

N/A N/A MSCVE