CVE-2026-53366 ipv4: account for fraggap on the paged allocation path
Information published. Continue reading CVE-2026-53366 ipv4: account for fraggap on the paged allocation path
CVE-2026-56171 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network. Continue reading CVE-2026-56171 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-58643 Windows Admin Center Spoofing Vulnerability
Improper neutralization of input during web page generation (‘cross-site scripting’) in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network. Continue reading CVE-2026-58643 Windows Admin Center Spoofing Vulnerability
CVE-2026-58598 Windows Backup Service Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Backup Engine allows an authorized attacker to elevate privileges locally. Continue reading CVE-2026-58598 Windows Backup Service Elevation of Privilege Vulnerability
CVE-2026-59831 GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace
CVE-2026-58644 Microsoft SharePoint Remote Code Execution Vulnerability
Corrected the Exploitability Index, Exploited flag and CVSS vector which was incorrect at the time of publication on 7/14/2026. This is an informational change only. Continue reading CVE-2026-58644 Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2026-50375 DirectX Graphics Kernel Elevation of Privilege Vulnerability
Updated acknowledgment. This is an informational change only. Continue reading CVE-2026-50375 DirectX Graphics Kernel Elevation of Privilege Vulnerability
