LiveActive security incident?Get immediate response
CVE archive

February 2026

Browse CVE records published in February 2026, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 3072 matching CVEs · Page 10 of 62.

Medium · CVSS 5.7

CVE-2026-21529: Azure HDInsight Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network.

Published Feb 10, 2026 · Updated May 11, 2026

Low · CVSS 3.1

CVE-2026-0102: Microsoft Edge (Chromium-based) Defense in Depth Vulnerability

Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data such as addresses, email, or phone number metadata.

Published Feb 17, 2026 · Updated May 11, 2026

High · CVSS 7.5

CVE-2026-21218: .NET Spoofing Vulnerability

Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.

Published Feb 10, 2026 · Updated May 11, 2026