Chromium: CVE-2026-16805 Use after free in Blink
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft
Chromium: CVE-2026-16804 Use after free in Input
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft
CVE-2026-64600 xfs: resample the data fork mapping after cycling ILOCK
Information published.
Categories: Microsoft
CVE-2026-59677 Process Kill Attack Vector in killall() in seunshare
Information published.
Categories: Microsoft
CVE-2026-59676 Local File Deletion Attack Vector in rm_rf() in seunshare
Information published.
Categories: Microsoft
CVE-2026-56167 Azure AI Search Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-56163 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-56165 Microsoft Account Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-54120 Microsoft Surface Remote Code Execution Vulnerability
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-56160 Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-35425 Azure API Management (APIM) Remote Code Execution Vulnerability
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-49159 Microsoft Graph Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
Categories: Microsoft
CVE-2026-50517 Microsoft M365 Copilot Remote Code Execution Vulnerability
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-56191 Microsoft Exchange Online Tampering Vulnerability
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
Categories: Microsoft
CVE-2026-57106 Data Quality Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-62825 Azure Key Vault Elevation of Privilege Vulnerability
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-58630 Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-58275 Azure DNS Elevation of Privilege Vulnerability
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-62835 Online Services Information Disclosure Vulnerability
Improper authorization in Online Services allows an unauthorized attacker to disclose information over a network.
Categories: Microsoft
CVE-2026-54171 Excon: redact additional sensitive/risky headers when following redirects
Information published.
Categories: Microsoft


