Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.7 MS:CVE-2026-41097

Secure Boot Security Feature Bypass Vulnerability_MS:CVE-2026-41097

Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-40403

Windows Graphics Component Remote Code Execution Vulnerability_MS:CVE-2026-40403

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.

N/A N/A MSCVE
CRITICAL 9.1 MS:CVE-2026-42833

Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability_MS:CVE-2026-42833

Execution with unnecessary privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-40370

SQL Server Remote Code Execution Vulnerability_MS:CVE-2026-40370

External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-40365

Microsoft SharePoint Server Remote Code Execution Vulnerability_MS:CVE-2026-40365

Insufficient granularity of access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2026-40398

Windows Remote Desktop Services Elevation of Privilege Vulnerability_MS:CVE-2026-40398

Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
CRITICAL 9.3 MS:CVE-2026-40402

Windows Hyper-V Elevation of Privilege Vulnerability_MS:CVE-2026-40402

Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.4 MS:CVE-2026-40413

Windows TCP/IP Denial of Service Vulnerability_MS:CVE-2026-40413

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an adjacent network.

N/A N/A MSCVE
NONE MS:CVE-2026-42823

Azure Logic Apps Elevation of Privilege Vulnerability_MS:CVE-2026-42823

Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

N/A N/A MSCVE
NONE MS:CVE-2026-42832

Microsoft Office Spoofing Vulnerability_MS:CVE-2026-42832

Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.

N/A N/A MSCVE