Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.2 MS:CVE-2026-33833

Azure Machine Learning Notebook Spoofing Vulnerability_MS:CVE-2026-33833

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized...

N/A N/A MSCVE
HIGH 8.4 MS:CVE-2026-40366

Microsoft Word Remote Code Execution Vulnerability_MS:CVE-2026-40366

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

N/A N/A MSCVE
MEDIUM 5.5 MS:CVE-2026-35440

Microsoft Word Information Disclosure Vulnerability_MS:CVE-2026-35440

Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-33841

Windows Kernel Elevation of Privilege Vulnerability_MS:CVE-2026-33841

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-42899

ASP.NET Core Denial of Service Vulnerability_MS:CVE-2026-42899

Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-35439

Microsoft SharePoint Server Remote Code Execution Vulnerability_MS:CVE-2026-35439

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-33834

Windows Event Logging Service Elevation of Privilege Vulnerability_MS:CVE-2026-33834

Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-33840

Win32k Elevation of Privilege Vulnerability_MS:CVE-2026-33840

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-40420

Microsoft Office Click-To-Run Elevation of Privilege Vulnerability_MS:CVE-2026-40420

Improper access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-32204

Azure Monitor Agent Elevation of Privilege Vulnerability_MS:CVE-2026-32204

External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE