CVE-2026-66306 Skype for Business Information Disclosure Vulnerability
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
CVE-2026-66308 Skype for Business and Lync Denial of Service Vulnerability
Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
CVE-2026-62895 Azure Arc SQL Server Extension Elevation of Privilege Vulnerability
Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69341 Windows Image Acquisition Elevation of Privilege Vulnerability
Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.
CVE-2026-69522 .NET and Visual Studio Remote Code Execution Vulnerability
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2026-70091 Windows DNS Denial of Service Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network.
CVE-2026-69782 Windows DNS Server Remote Code Execution Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.
CVE-2026-83941 Entra ID Elevation of Privilege Vulnerability
Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.
CVE-2026-85360 Windows Kernel Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-77482 Microsoft SQL Server Remote Code Execution Vulnerability
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-57098 Microsoft Remote Desktop App for Windows Information Disclosure Vulnerability
Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-62801 Microsoft PowerShell Security Feature Bypass Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-55007 Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2026-50349 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-67368 Microsoft SQL Server Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-67370 Microsoft SQL Server Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-67373 Microsoft SQL Server Remote Code Execution Vulnerability
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-67629 Microsoft SQL Server Information Disclosure Vulnerability
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67630 Microsoft SQL Server Information Disclosure Vulnerability
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.


