High · CVSS 8.8
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 8.8
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Published Feb 17, 2026 · Updated May 11, 2026
High · CVSS 7.5
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.
Published Feb 10, 2026 · Updated May 11, 2026
Medium · CVSS 5.5
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 8.1
Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7.8
Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7.8
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7.8
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7.8
Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7.5
Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7.3
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7.8
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
Published Feb 10, 2026 · Updated May 11, 2026
Low · CVSS 3.3
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7.8
Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7.8
Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7
Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 8.8
Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 8.8
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 8
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker to elevate privileges over a network.
Published Feb 10, 2026 · Updated May 11, 2026
Medium · CVSS 5.5
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7
Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7.5
Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 8.8
Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network.
Published Feb 10, 2026 · Updated May 11, 2026
Medium · CVSS 6.2 · CISA KEV
Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7.8 · CISA KEV
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
Published Feb 10, 2026 · Updated May 11, 2026
Medium · CVSS 5.7
Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 8.8
Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 8.8 · CISA KEV
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
Published Feb 10, 2026 · Updated May 11, 2026
Critical · CVSS 9.8
Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.
Published Feb 10, 2026 · Updated May 11, 2026
Medium · CVSS 6.5
Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
Published Feb 10, 2026 · Updated May 11, 2026
Medium · CVSS 6.5
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 8.2
Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.
Published Feb 19, 2026 · Updated May 11, 2026
Low · CVSS 3.1
Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data such as addresses, email, or phone number metadata.
Published Feb 17, 2026 · Updated May 11, 2026
Medium · CVSS 6.7
Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 8.2
Azure Function Information Disclosure Vulnerability
Published Feb 5, 2026 · Updated May 11, 2026
Critical · CVSS 9.8
Azure Front Door Elevation of Privilege Vulnerability
Published Feb 5, 2026 · Updated May 11, 2026
Medium · CVSS 6.5
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.
Published Feb 5, 2026 · Updated May 11, 2026
High · CVSS 8.8 · CISA KEV
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7.8 · CISA KEV
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 8
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
Published Feb 10, 2026 · Updated May 11, 2026
Medium · CVSS 6.5
Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7.5
Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7.8
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7.3
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7
Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
Published Feb 10, 2026 · Updated May 11, 2026
High · CVSS 7.3
Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.
Published Feb 10, 2026 · Updated May 11, 2026