Windows update
-
Chromium: CVE-2026-16804 Use after free in Input
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. -
Chromium: CVE-2026-16805 Use after free in Blink
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. -
Chromium: CVE-2026-16806 Use after free in WebMCP
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. -
Chromium: CVE-2026-16807 Out of bounds write in Codecs
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. -
CVE-2026-62835 Azure Portal Information Disclosure Vulnerability
Corrected the CVE description and title. This is an informational change only. -
CVE-2026-48561 Microsoft Edge Copilot Remote Code Execution Vulnerability
Corrected the CVE description and title. This is an informational change only. -
CVE-2026-59676 Local File Deletion Attack Vector in rm_rf() in seunshare
Information published. -
CVE-2026-59677 Process Kill Attack Vector in killall() in seunshare
Information published. -
CVE-2026-64600 xfs: resample the data fork mapping after cycling ILOCK
Information published. -
CVE-2026-56167 Azure AI Search Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. -
CVE-2026-56163 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. -
CVE-2026-56165 Microsoft Account Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. -
CVE-2026-54120 Microsoft Surface Remote Code Execution Vulnerability
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. -
CVE-2026-56160 Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. -
CVE-2026-35425 Azure API Management (APIM) Remote Code Execution Vulnerability
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. -
CVE-2026-49159 Microsoft Graph Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. -
CVE-2026-50517 Microsoft M365 Copilot Remote Code Execution Vulnerability
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. -
CVE-2026-56191 Microsoft Exchange Online Tampering Vulnerability
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. -
CVE-2026-57106 Data Quality Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. -
CVE-2026-62825 Azure Key Vault Elevation of Privilege Vulnerability
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. -
CVE-2026-58630 Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. -
CVE-2026-58275 Azure DNS Elevation of Privilege Vulnerability
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. -
CVE-2026-62835 Online Services Information Disclosure Vulnerability
Improper authorization in Online Services allows an unauthorized attacker to disclose information over a network. -
CVE-2026-47729 Squid: Memory disclosure in FTP gateway
Information published. -
CVE-2026-56145 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Information published. -
CVE-2026-63140 Reachable Assertion in Elasticsearch Leading to Denial of Service
Information published. -
CVE-2026-63136 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Information published. -
CVE-2026-53910 Heap-based Buffer Overflow in GNU diffutils
Information published. -
CVE-2026-55973 'dns-error-reporting: yes' leads to stack buffer overflow
Information published. -
CVE-2026-44687 Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN
Information published. -
CVE-2026-50248 BOGUS configured primary hostname accepted for XFR in auth/rpz zones
Information published. -
CVE-2026-55708 Privacy/configuration issue when adding local data in views through 'unbound-control'
Information published. -
CVE-2026-44621 Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated
Information published. -
CVE-2026-55717 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash
Information published. -
CVE-2026-40691 Packet of death for DNSCrypt over TCP
Information published. -
CVE-2026-32665 Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass
Information published. -
CVE-2026-46582 A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path
Information published. -
CVE-2026-42955 Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records
Information published. -
CVE-2026-50046 Possible heap use-after-free in an error path when a DoT forwarded query is jostled out
Information published. -
CVE-2026-55990 Packet of death for a DNSCrypt misconfigured Unbound
Information published. -
CVE-2026-55991 Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
Information published. -
CVE-2026-50251 Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush
Information published. -
CVE-2026-50252 Possible cache poisoning attack by mapping source port population per thread
Information published. -
CVE-2026-50243 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL
Information published. -
CVE-2026-63308 Helm Files.Lines Denial of Service via Empty Chart Files
Information published. -
CVE-2026-15588 Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering
Information published. -
CVE-2026-26080 HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.
Information published. -
CVE-2026-26081 HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.
Information published. -
CVE-2026-15788 WCOW cache mount source selector resolves NTFS junctions outside of cache root
Information published. -
CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys
Information published.
Приглашаю на лучшие дистанционные курсы повышения квалификации, курсы профессиональной переподготовки и курсы по специальностям на проверенной образовательной платформе «Знанио».
Воспользуйтесь моим купоном «9954514» при оформлении заказа, чтобы получить скидку -50% на https://znanio.ru на все курсы и другие услуги портала.
