CVE-2026-40401 Windows TCP/IP Denial of Service Vulnerability
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service locally. Continue reading CVE-2026-40401 Windows TCP/IP Denial of Service Vulnerability
Opinions, tips, and news orbiting Microsoft
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service locally. Continue reading CVE-2026-40401 Windows TCP/IP Denial of Service Vulnerability
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. Continue reading CVE-2026-42823 Azure Logic Apps Elevation of Privilege Vulnerability
Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. Continue reading CVE-2026-41097 Secure Boot Security Feature Bypass Vulnerability
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Continue reading CVE-2026-40361 Microsoft Word Remote Code Execution Vulnerability
This vulnerability was found and addressed by AMD. We are documenting it in the Security Update Guide to encourage customers to install the May 2026 version of Windows as soon as possible.
The vulnerability assigned to this CVE is in certain processo… Continue reading CVE-2025-54518 AMD: CVE-2025-54518 CPU OP Cache Corruption
Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. Continue reading CVE-2026-32177 .NET Elevation of Privilege Vulnerability
Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally. Continue reading CVE-2026-41612 Visual Studio Code Information Disclosure Vulnerability
Improper neutralization of input during web page generation (‘cross-site scripting’) in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. Continue reading CVE-2026-41610 Visual Studio Code Security Feature Bypass Vulnerability