CVE-2026-8328 FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address Microsoft Security 17 Mei 2026 om 10:01 Information published.
CVE-2026-8368 LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects Microsoft Security 17 Mei 2026 om 10:01 Information published.
CVE-2026-7210 The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection Microsoft Security 17 Mei 2026 om 10:01 Information published.
CVE-2026-44283 etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks Microsoft Security 17 Mei 2026 om 10:01 Information published.
CVE-2026-46483 Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag Microsoft Security 17 Mei 2026 om 10:01 Information published.