CVE-2026-46285 mtd: docg3: fix use-after-free in docg3_release() Microsoft Security 24 Juni 2026 om 11:43 Information published.
CVE-2026-45504 Microsoft Exchange Server Elevation of Privilege Vulnerability Microsoft Security 23 Juni 2026 om 16:00 Acknowledgement added. This is an informational change only.
CVE-2026-33840 Win32k Elevation of Privilege Vulnerability Microsoft Security 23 Juni 2026 om 16:00 Updated an acknowledgement. This is an informational change only.
CVE-2026-42915 Microsoft Windows VMSwitch Denial of Service Vulnerability Microsoft Security 23 Juni 2026 om 16:00 Updated an acknowledgement. This is an informational change only.
CVE-2026-44967 opentelemetry-cpp: OTLP HTTP exporters read unbounded HTTP response Microsoft Security 20 Juni 2026 om 10:43 Information published.
CVE-2026-46331 net/sched: fix pedit partial COW leading to page cache corruption Microsoft Security 20 Juni 2026 om 10:43 Information published.
CVE-2026-34180 Heap Buffer Over-read in ASN.1 Content Parsing Microsoft Security 20 Juni 2026 om 10:43 Information published.
CVE-2026-7383 Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion Microsoft Security 20 Juni 2026 om 10:43 Information published.
CVE-2026-42767 NULL Pointer Dereference in CRMF EncryptedValue Decryption Microsoft Security 20 Juni 2026 om 10:43 Information published.
CVE-2026-42766 Possible NULL Dereference in Password-Based CMS Decryption Microsoft Security 20 Juni 2026 om 10:42 Information published.
CVE-2026-45446 Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes Microsoft Security 20 Juni 2026 om 10:42 Information published.
CVE-2026-9076 Out-of-Bounds Read in CMS Password-Based Decryption Microsoft Security 20 Juni 2026 om 10:42 Information published.
CVE-2026-42768 Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() Microsoft Security 20 Juni 2026 om 10:41 Information published.
CVE-2026-34183 Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler Microsoft Security 20 Juni 2026 om 10:41 Information published.
CVE-2026-45445 AES-OCB IV Ignored on EVP_Cipher() Path Microsoft Security 20 Juni 2026 om 10:40 Information published.
CVE-2025-5791 Users: `root` appended to group listings Microsoft Security 20 Juni 2026 om 10:40 Information published.
CVE-2025-4574 Crossbeam-channel: crossbeam-channel vulnerable to double free on drop Microsoft Security 20 Juni 2026 om 10:39 Information published.
Chromium: CVE-2026-12439 Use after free in Digital Credentials Microsoft Security 19 Juni 2026 om 16:00 Corrected CVE title. This is an informational change only.
Chromium: CVE-2026-12440 Use after free in DigitalCredentials Microsoft Security 19 Juni 2026 om 16:00 Corrected CVE title. This is an informational change only.
Chromium: CVE-2026-12445 Use after free in Extensions Microsoft Security 19 Juni 2026 om 16:00 Corrected CVE title. This is an informational change only.
Chromium: CVE-2026-12446 Insufficient data validation in Passwords Microsoft Security 19 Juni 2026 om 16:00 Corrected CVE title. This is an informational change only.
Chromium: CVE-2026-12451 Use after free in DigitalCredentials Microsoft Security 19 Juni 2026 om 16:00 Corrected CVE title. This is an informational change only.
Chromium: CVE-2026-12441 Use after free in File Input Microsoft Security 19 Juni 2026 om 16:00 Corrected CVE title. This is an informational change only.
Chromium: CVE-2026-12447 Heap buffer overflow in WebRTC Microsoft Security 19 Juni 2026 om 16:00 Corrected CVE title. This is an informational change only.
Chromium: CVE-2026-12443 Use after free in Web Authentication Microsoft Security 19 Juni 2026 om 16:00 Corrected CVE title. This is an informational change only.
Chromium: CVE-2026-12452 Use after free in Downloads Microsoft Security 19 Juni 2026 om 16:00 Corrected CVE title. This is an informational change only.
Chromium: CVE-2026-12453 Insufficient validation of untrusted input in Input Microsoft Security 19 Juni 2026 om 16:00 Corrected CVE title. This is an informational change only.
Chromium: CVE-2026-12455 Use after free in Tab Strip Microsoft Security 19 Juni 2026 om 16:00 Corrected CVE title. This is an informational change only.
Chromium: CVE-2026-12456 Insufficient validation of untrusted input in Extensions Microsoft Security 19 Juni 2026 om 16:00 Corrected CVE title. This is an informational change only.
Chromium: CVE-2026-12458 Incorrect security UI in Passwords Microsoft Security 19 Juni 2026 om 16:00 Corrected CVE title. This is an informational change only.