CVE-2026-52935 xfrm: espintcp: do not reuse an in-progress partial send
Information published.
Categories: Microsoft
CVE-2026-53130 fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START
Information published.
Categories: Microsoft
CVE-2026-53357 Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()
Information published.
Categories: Microsoft
CVE-2026-53048 gfs2: prevent NULL pointer dereference during unmount
Information published.
Categories: Microsoft
CVE-2026-56149 Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service
Information published.
Categories: Microsoft
CVE-2026-49090 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Information published.
Categories: Microsoft
CVE-2026-52992 fs/adfs: validate nzones in adfs_validate_bblk()
Information published.
Categories: Microsoft
CVE-2026-50521 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Added Edge software to the Security Updates table. Customers that are running supported version of Edge are encouraged to update to the indicated version to be protected from this vulnerability.
Categories: Microsoft
CVE-2026-57100 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-45499 Azure OpenAI Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-26145 Microsoft Azure Synapse Elevation of Privilege Vulnerability
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-41106 Microsoft 365 Copilot Elevation of Privilege Vulnerability
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-54998 Microsoft Exchange Online Elevation of Privilege Vulnerability
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-57062 CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.
Information published.
Categories: Microsoft
CVE-2026-13595 Util-linux: util-linux: heap use-after-free in libblkid nested partition probing
Information published.
Categories: Microsoft
CVE-2026-11625 Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes
Information published.
Categories: Microsoft
CVE-2026-7531 Use-after-free in PQC hybrid key-share handling
Information published.
Categories: Microsoft
CVE-2026-6412 Continued acceptance of SHA-1/MD5 digests in certificate processing
Information published.
Categories: Microsoft
CVE-2026-6092 Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configured
Information published.
Categories: Microsoft
CVE-2026-11310 X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring
Information published.
Categories: Microsoft


