Chromium CVE-2026-85048: Use after free in Compositing
Chromium CVE-2026-85045: Race condition in V8
Chromium CVE-2026-85043: Incomplete cleanup in Network
Chromium CVE-2026-85042: Use after free in DevTools
Chromium: CVE-2026-84333 Use after free in Dawn
Chromium: CVE-2026-84330 UI misrepresentation in FullScreen
Chromium: CVE-2026-84352 Use after free in WebGL
CVE-2026-85892 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
CVE-2026-77490 Microsoft Edge (Chromium-based) Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Chromium: CVE-2026-85046 Type confusion in V8
CVE-2026-62706 Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
CVE-2026-62694 Windows Installer Elevation of Privilege Vulnerability
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-62744 Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
CVE-2026-66304 Skype for Business Information Disclosure Vulnerability
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
CVE-2026-66302 Skype for Business Remote Code Execution Vulnerability
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
CVE-2026-66306 Skype for Business Information Disclosure Vulnerability
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
CVE-2026-66308 Skype for Business and Lync Denial of Service Vulnerability
Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
CVE-2026-62895 Azure Arc SQL Server Extension Elevation of Privilege Vulnerability
Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.


