CVE-2026-45638 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Microsoft Security 7 Juli 2026 om 16:00 Updated an acknowledgement. This is an informational change only.
CVE-2026-9080 UAF after pause in socket callback Microsoft Security 7 Juli 2026 om 10:43 Information published.
CVE-2026-8926 password leak with netrc and user in URL Microsoft Security 7 Juli 2026 om 10:43 Information published.
CVE-2026-10536 HTTP/2 stream-dependency tree UAF Microsoft Security 7 Juli 2026 om 10:42 Information published.
CVE-2026-8286 wrong STARTTLS connection reuse Microsoft Security 7 Juli 2026 om 10:42 Information published.
CVE-2026-8458 wrong reuse for different services Microsoft Security 7 Juli 2026 om 10:42 Information published.
CVE-2026-8924 trailing dot domain super cookie Microsoft Security 7 Juli 2026 om 10:41 Information published.
CVE-2026-8932 incomplete mTLS config matching in conn reuse Microsoft Security 7 Juli 2026 om 10:41 Information published.
CVE-2026-9545 exposing HTTP/3 early data Microsoft Security 7 Juli 2026 om 10:41 Information published.
CVE-2026-39827 Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh Microsoft Security 7 Juli 2026 om 10:40 Information published.
CVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html Microsoft Security 7 Juli 2026 om 10:40 Information published.
CVE-2026-14647 onnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-bounds Microsoft Security 7 Juli 2026 om 10:01 Information published.
CVE-2026-12480 Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/keras Microsoft Security 7 Juli 2026 om 10:01 Information published.
CVE-2026-54891 Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl Microsoft Security 7 Juli 2026 om 10:01 Information published.
CVE-2026-54886 SSH SFTP server denial of service via extended channel data infinite loop Microsoft Security 7 Juli 2026 om 10:01 Information published.
CVE-2026-55952 TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension Microsoft Security 7 Juli 2026 om 10:01 Information published.