Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 46 min 25 sec ago

Chromium: CVE-2026-13025 Insufficient validation of untrusted input in DevTools

Sat, 06/27/2026 - 00:46
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Chromium: CVE-2026-13024 Insufficient validation of untrusted input in Navigation

Sat, 06/27/2026 - 00:46
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Chromium: CVE-2026-13023 Uninitialized Use in GPU

Sat, 06/27/2026 - 00:46
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Chromium: CVE-2026-13022 Inappropriate implementation in Autofill

Sat, 06/27/2026 - 00:46
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Chromium: CVE-2026-13021 Inappropriate implementation in DeviceBoundSessionCredentials

Sat, 06/27/2026 - 00:46
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

CVE-2026-45930 net: mctp: ensure our nlmsg responses are initialised

Fri, 06/26/2026 - 08:40
Information published.
Categories: Microsoft

CVE-2026-45850 ipvs: skip ipv6 extension headers for csum checks

Fri, 06/26/2026 - 08:40
Information published.
Categories: Microsoft

CVE-2025-68736 landlock: Fix handling of disconnected directories

Fri, 06/26/2026 - 08:39
Information published.
Categories: Microsoft

CVE-2025-68296 drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup

Fri, 06/26/2026 - 08:39
Information published.
Categories: Microsoft

CVE-2026-41086 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability

Thu, 06/25/2026 - 14:00
Updated an acknowledgement. This is an informational change only.
Categories: Microsoft

CVE-2026-11816 Path Traversal in keras-team/keras

Thu, 06/25/2026 - 08:03
Information published.
Categories: Microsoft

CVE-2026-46140 Bluetooth: btmtk: validate WMT event SKB length before struct access

Thu, 06/25/2026 - 08:03
Information published.
Categories: Microsoft

CVE-2026-33840 Win32k Elevation of Privilege Vulnerability

Tue, 06/23/2026 - 14:00
Updated an acknowledgement. This is an informational change only.
Categories: Microsoft

CVE-2026-46331 net/sched: fix pedit partial COW leading to page cache corruption

Sat, 06/20/2026 - 08:43
Information published.
Categories: Microsoft

CVE-2025-5791 Users: `root` appended to group listings

Sat, 06/20/2026 - 08:40
Information published.
Categories: Microsoft

CVE-2025-4574 Crossbeam-channel: crossbeam-channel vulnerable to double free on drop

Sat, 06/20/2026 - 08:39
Information published.
Categories: Microsoft

CVE-2026-12466 Heap buffer overflow in WebRTC

Fri, 06/19/2026 - 20:52
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

CVE-2026-12461 Out of bounds read in WebRTC

Fri, 06/19/2026 - 20:52
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

CVE-2026-12449 Use after free in Chromoting

Fri, 06/19/2026 - 20:52
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Pages