Windows update
-
CVE-2026-54128 Windows DHCP Client Remote Code Execution Vulnerability
Updated an acknowledgement. This is an informational change only. -
CVE-2026-55129 Microsoft Office Remote Code Execution Vulnerability
Acknowledgement Updated -
CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution Vulnerability
Updated an acknowledgement. This is an informational change only. -
CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. -
CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability
Informational Change. CVE ID stays the same. -
CVE-2026-24304 Azure Cosmos DB Remote Code Execution Vulnerability
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. -
CVE-2026-50422 Windows NTFS Elevation of Privilege Vulnerability
Updated an acknowledgement. This is an informational change only. -
CVE-2026-47301 Configuration Manager Elevation of Privilege Vulnerability
Corrected Build Number in the Security Updates table. This is an informational change only. -
CVE-2026-59117 Windows Terminal Remote Code Execution Vulnerability
Change the name of the affected software from **Microsoft Power Apps** to **Microsoft Power Apps Desktop Client**. This is an informational change only. -
Chromium: CVE-2026-13032 Use after free in WebGL
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. -
Chromium: CVE-2026-13028 Use after free in WebGL
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. -
Chromium: CVE-2026-13030 Uninitialized Use in GPU
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. -
Chromium: CVE-2026-13037 Use after free in WebView
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. -
CVE-2026-50333 Windows Spaceport.sys Elevation of Privilege Vulnerability
Updated an acknowledgement. This is an informational change only. -
CVE-2026-50697 Windows Common Log File System Driver Elevation of Privilege Vulnerability
Updated an acknowledgement. This is an informational change only. -
CVE-2026-50343 Microsoft Install Service Elevation of Privilege Vulnerability
Updated an acknowledgement. This is an informational change only. -
CVE-2026-56159 DHCP Server Service Remote Code Execution Vulnerability
Updated an acknowledgement. This is an informational change only. -
CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()
Information published. -
CVE-2024-14040 net: nexthop: Increase weight to u16
Information published. -
CVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
Information published. -
CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting
Information published. -
CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()
Information published. -
Chromium: CVE-2026-16804 Use after free in Input
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. -
Chromium: CVE-2026-16805 Use after free in Blink
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. -
Chromium: CVE-2026-16806 Use after free in WebMCP
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. -
Chromium: CVE-2026-16807 Out of bounds write in Codecs
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. -
CVE-2026-62835 Azure Portal Information Disclosure Vulnerability
Corrected the CVE description and title. This is an informational change only. -
CVE-2026-48561 Microsoft Edge Copilot Remote Code Execution Vulnerability
Corrected the CVE description and title. This is an informational change only. -
CVE-2026-59676 Local File Deletion Attack Vector in rm_rf() in seunshare
Information published. -
CVE-2026-59677 Process Kill Attack Vector in killall() in seunshare
Information published. -
CVE-2026-64600 xfs: resample the data fork mapping after cycling ILOCK
Information published. -
CVE-2026-56167 Azure AI Search Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. -
CVE-2026-56163 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. -
CVE-2026-56165 Microsoft Account Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. -
CVE-2026-54120 Microsoft Surface Remote Code Execution Vulnerability
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. -
CVE-2026-56160 Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. -
CVE-2026-35425 Azure API Management (APIM) Remote Code Execution Vulnerability
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. -
CVE-2026-49159 Microsoft Graph Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. -
CVE-2026-50517 Microsoft M365 Copilot Remote Code Execution Vulnerability
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. -
CVE-2026-56191 Microsoft Exchange Online Tampering Vulnerability
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. -
CVE-2026-57106 Data Quality Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. -
CVE-2026-62825 Azure Key Vault Elevation of Privilege Vulnerability
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. -
CVE-2026-58630 Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. -
CVE-2026-58275 Azure DNS Elevation of Privilege Vulnerability
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. -
CVE-2026-62835 Online Services Information Disclosure Vulnerability
Improper authorization in Online Services allows an unauthorized attacker to disclose information over a network. -
CVE-2026-47729 Squid: Memory disclosure in FTP gateway
Information published. -
CVE-2026-56145 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Information published. -
CVE-2026-63140 Reachable Assertion in Elasticsearch Leading to Denial of Service
Information published. -
CVE-2026-63136 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Information published. -
CVE-2026-53910 Heap-based Buffer Overflow in GNU diffutils
Information published.
Приглашаю на лучшие дистанционные курсы повышения квалификации, курсы профессиональной переподготовки и курсы по специальностям на проверенной образовательной платформе «Знанио».
Воспользуйтесь моим купоном «9954514» при оформлении заказа, чтобы получить скидку -50% на https://znanio.ru на все курсы и другие услуги портала.
