⚡ TL;DR | Go Straight to the August 2026 Patch Tuesday Audit Report
Patch Tuesday is once again upon us. As always, our team has put together the monthly Patch Tuesday Report to help you manage your update progress. The audit report gives you a quick and clear overview of your Windows machines and their patching status. The August 2026 edition of Patch Tuesday brings us 669 fixes, with 82 rated as critical. We’ve listed the most important changes below.
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerabilities
CVE-2026-68820, CVE-2026-61348, and CVE-2026-70307 all hit the same component this month: the Ancillary Function Driver (AFD) for WinSock, the kernel-mode driver that handles socket operations for just about every networked Windows process. All three are local elevation of privilege bugs rated Important with a CVSS score of 7.0, requiring low privileges and high attack complexity but no user interaction.
What makes this trio worth your attention is CVE-2026-68820: Microsoft confirms it is already being exploited in the wild. An attacker who already has a foothold on a machine, even a low-privileged one, can use this flaw to escalate to SYSTEM. The other two land in the exact same driver in the same release, so if you’re running exposed workstations or terminal servers where users can execute untrusted code, get this one out first.
Patch status aside, seeing three AFD vulnerabilities fixed together is a good reminder that this driver has quietly become one of the more consistent privilege escalation targets in Windows.
Microsoft SharePoint Server Remote Code Execution and Elevation of Privilege Vulnerabilities
CVE-2026-63520, CVE-2026-65665, and CVE-2026-70355 round out another month of SharePoint Server fixes. CVE-2026-65665 is the standout: a Critical, network-exploitable remote code execution vulnerability with a CVSS score of 8.8, requiring only low privileges and no user interaction. CVE-2026-63520 is a related RCE rated 8.1, though it needs high attack complexity to pull off. CVE-2026-70355 is an elevation of privilege issue reachable over the network, rated 7.3, that does require some user interaction.
None of the three are flagged as exploited yet, but Microsoft’s exploitability assessment marks them as exploitation more likely. That’s worth taking seriously given last month’s SharePoint RCE was actively used to steal machine keys from on-premises servers. If you’re running SharePoint Server on-premises or in a hybrid setup, treat this batch as a priority.
Microsoft High Performance Computing (HPC) Pack Remote Code Execution and Elevation of Privilege Vulnerabilities
CVE-2026-59124 is the highest CVSS score in this month’s release: a 9.8, network-exploitable, no privileges or user interaction required. It’s paired with CVE-2026-59133, an elevation of privilege bug in the same product rated 8.8. Both affect Microsoft HPC Pack, the clustering and job-scheduling software used to manage compute clusters.
Run the Patch Tuesday August 2026 Audit
To help manage your update progress, we’ve created the Patch Tuesday Audit that checks if the assets in your network are on the latest patch updates. The report has been color-coded to see which machines are up-to-date and which ones still need to be updated. As always, system administrators are urged to update their environment as soon as possible to ensure all endpoints are secured.
The Lansweeper Patch Tuesday dashboard is available in our marketplace and is automatically kept up-to-date. Lansweeper Sites is included in all our licenses without any additional cost and allows you to federate all your installations into one single view so all you need to do is look at one dashboard, automatically updated.
Patch Tuesday August 2026 CVE Codes & Titles
| CVE ID | Title |
| CVE-2026-15534 | Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch |
| CVE-2026-20337 | ClamAV ZIP File Format Processing Memory Corruption Vulnerability |
| CVE-2026-20338 | ClamAV ZIP File Format Processing Memory Corruption Vulnerability |
| CVE-2026-20339 | ClamAV PESpin File Format Processing Integer Overflow Vulnerability |
| CVE-2026-20345 | ClamAV GPT File Format Processing Memory Corruption Vulnerability |
| CVE-2026-20346 | ClamAV PDF File Format Processing Memory Corruption Vulnerability |
| CVE-2026-20347 | ClamAV Mach-O File Format Processing Memory Corruption Vulnerability |
| CVE-2026-20348 | ClamAV XAR File Format Processing Memory Corruption Vulnerability |
| CVE-2026-40375 | Microsoft Dynamics Business Central Information Disclosure Vulnerability |
| CVE-2026-42976 | Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability |
| CVE-2026-47285 | Visual Studio Code Information Disclosure Vulnerability |
| CVE-2026-47299 | Azure Monitor Agent Elevation of Privilege Vulnerability |
| CVE-2026-49179 | Windows Active Directory Domain Services Remote Code Execution Vulnerability |
| CVE-2026-50472 | Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-54113 | Remote Procedure Call Denial of Service Vulnerability |
| CVE-2026-54123 | Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability |
| CVE-2026-54981 | Visual Studio Code Python Extension Security Feature Bypass Vulnerability |
| CVE-2026-54984 | Windows Imaging Component Remote Code Execution Vulnerability |
| CVE-2026-56174 | Windows Narrator Braille Elevation of Privilege Vulnerability |
| CVE-2026-56179 | Windows Network Address Translation (NAT) Spoofing Vulnerability |
| CVE-2026-57104 | Azure Storage Explorer Elevation of Privilege Vulnerability |
| CVE-2026-57105 | Microsoft Office SharePoint Spoofing Vulnerability |
| CVE-2026-58612 | PowerShell Information Disclosure Vulnerability |
| CVE-2026-58639 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-58641 | .NET Elevation of Privilege Vulnerability |
| CVE-2026-58650 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-58651 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-59113 | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-59119 | PowerShell Elevation of Privilege Vulnerability |
| CVE-2026-59122 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-59124 | Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability |
| CVE-2026-59125 | Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability |
| CVE-2026-59126 | Windows Event Logging Service Elevation of Privilege Vulnerability |
| CVE-2026-59127 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-59128 | Windows Encrypting File System (EFS) Information Disclosure Vulnerability |
| CVE-2026-59130 | AMD Zen Information Disclosure Vulnerability |
| CVE-2026-59131 | AMD Zen Information Disclosure Vulnerability |
| CVE-2026-59132 | Windows TCP/IP Denial of Service Vulnerability |
| CVE-2026-59133 | Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability |
| CVE-2026-59134 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-59135 | Microsoft Windows Search Component Information Disclosure Vulnerability |
| CVE-2026-59136 | Microsoft COM for Windows Information Disclosure Vulnerability |
| CVE-2026-59137 | Windows Event Logging Service Information Disclosure Vulnerability |
| CVE-2026-59138 | Microsoft Remote Registry Service Denial of Service Vulnerability |
| CVE-2026-61345 | Microsoft Remote Registry Service Denial of Service Vulnerability |
| CVE-2026-61346 | Windows Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-61347 | Windows Event Logging Service Information Disclosure Vulnerability |
| CVE-2026-61348 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-61349 | Windows Work Folder Service Elevation of Privilege Vulnerability |
| CVE-2026-61350 | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-61352 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-61353 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-61355 | Windows Sensor Data Service Elevation of Privilege Vulnerability |
| CVE-2026-61356 | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2026-61357 | Application Information Services Elevation of Privilege Vulnerability |
| CVE-2026-61358 | Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability |
| CVE-2026-61359 | Windows Storage Elevation of Privilege Vulnerability |
| CVE-2026-61360 | Windows GDI Information Disclosure Vulnerability |
| CVE-2026-61361 | Windows DHCP Client Remote Code Execution Vulnerability |
| CVE-2026-61363 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-61364 | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2026-61365 | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2026-61366 | Windows Network Connection Broker Elevation of Privilege Vulnerability |
| CVE-2026-61367 | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2026-61368 | Windows Hyper-V Information Disclosure Vulnerability |
| CVE-2026-61477 | Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection |
| CVE-2026-61918 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-61920 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-61921 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-61923 | Windows Display Enhancement Service Elevation of Privilege Vulnerability |
| CVE-2026-61924 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-61925 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-61926 | Windows USB Driver Elevation of Privilege Vulnerability |
| CVE-2026-61927 | Windows Bind Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-61928 | Windows Hello Tampering Vulnerability |
| CVE-2026-61929 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-61930 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-61932 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-61933 | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-61934 | Windows Bind Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-61936 | Windows Defender Firewall Service Security Feature Bypass Vulnerability |
| CVE-2026-61937 | Windows HTTP.sys Elevation of Privilege Vulnerability |
| CVE-2026-61938 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-61939 | Winlogon Elevation of Privilege Vulnerability |
| CVE-2026-62688 | Windows MIDI Service Module Elevation of Privileges Vulnerability |
| CVE-2026-62690 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-62692 | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2026-62693 | Windows MIDI Service Module Elevation of Privileges Vulnerability |
| CVE-2026-62695 | Windows Storage Elevation of Privilege Vulnerability |
| CVE-2026-62696 | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability |
| CVE-2026-62698 | Microsoft Digest Authentication Elevation of Privilege Vulnerability |
| CVE-2026-62699 | Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability |
| CVE-2026-62700 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-62701 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62702 | Windows Graphics Kernel Denial of Service Vulnerability |
| CVE-2026-62703 | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-62705 | Windows Bind Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-62707 | Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability |
| CVE-2026-62708 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-62709 | Windows GDI+ Information Disclosure Vulnerability |
| CVE-2026-62710 | Windows Device Association Service Elevation of Privilege Vulnerability |
| CVE-2026-62711 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-62712 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-62713 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-62714 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62715 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62716 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62717 | Windows Message Queuing Elevation of Privilege Vulnerability |
| CVE-2026-62718 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62719 | Windows Message Queuing Elevation of Privilege Vulnerability |
| CVE-2026-62720 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62721 | Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability |
| CVE-2026-62722 | Windows Bind Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-62723 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62724 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62725 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62726 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62728 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2026-62729 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62730 | Windows Wired AutoConfig Service Information Disclosure Vulnerability |
| CVE-2026-62732 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62733 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-62734 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62735 | Windows HTTP.sys Elevation of Privilege Vulnerability |
| CVE-2026-62736 | Windows DHCP Client Elevation of Privilege Vulnerability |
| CVE-2026-62737 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-62738 | Windows Management Instrumentation Information Disclosure Vulnerability |
| CVE-2026-62739 | Windows HTTP.sys Elevation of Privilege Vulnerability |
| CVE-2026-62740 | Windows Imaging Component Information Disclosure Vulnerability |
| CVE-2026-62741 | Windows HTTP.sys Elevation of Privilege Vulnerability |
| CVE-2026-62742 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62743 | Win32k Information Disclosure Vulnerability |
| CVE-2026-62745 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62746 | Win32k Information Disclosure Vulnerability |
| CVE-2026-62747 | Windows Device Association Service Elevation of Privilege Vulnerability |
| CVE-2026-62748 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62749 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-62750 | Windows HTTP Protocol Stack Tampering Vulnerability |
| CVE-2026-62751 | Windows Projected File System Elevation of Privilege Vulnerability |
| CVE-2026-62752 | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2026-62753 | Windows HTTP.sys Elevation of Privilege Vulnerability |
| CVE-2026-62754 | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2026-62755 | Windows DHCP Client Elevation of Privilege Vulnerability |
| CVE-2026-62757 | Windows Schannel Security Feature Bypass Vulnerability |
| CVE-2026-62758 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
| CVE-2026-62761 | Windows DHCP Server Elevation of Privilege Vulnerability |
| CVE-2026-62766 | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2026-62768 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-62769 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-62770 | Windows Shell Elevation of Privilege Vulnerability |
| CVE-2026-62771 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-62772 | Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege Vulnerability |
| CVE-2026-62773 | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2026-62774 | Windows Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-62775 | Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability |
| CVE-2026-62776 | Windows DHCP Server Elevation of Privilege Vulnerability |
| CVE-2026-62777 | Windows License Manager Elevation of Privilege Vulnerability |
| CVE-2026-62778 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-62779 | Windows Schannel Elevation of Privilege Vulnerability |
| CVE-2026-62780 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-62781 | RPC Runtime Library Remote Code Execution Vulnerability |
| CVE-2026-62782 | Windows SMB Client Information Disclosure Vulnerability |
| CVE-2026-62783 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
| CVE-2026-62784 | Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability |
| CVE-2026-62785 | Windows LDAP – Lightweight Directory Access Protocol Remote Code Execution Vulnerability |
| CVE-2026-62786 | Win32k Information Disclosure Vulnerability |
| CVE-2026-62787 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-62788 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-62790 | Windows SMBv3 Server Remote Code Execution Vulnerability |
| CVE-2026-62792 | Windows TCP/IP Remote Code Execution Vulnerability |
| CVE-2026-62793 | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-62795 | Windows LDAP – Lightweight Directory Access Protocol Remote Code Execution Vulnerability |
| CVE-2026-62796 | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-62797 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-62798 | Win32k Information Disclosure Vulnerability |
| CVE-2026-62799 | Windows SMB Client Elevation of Privilege Vulnerability |
| CVE-2026-62800 | Windows SMBv3 Server Remote Code Execution Vulnerability |
| CVE-2026-62803 | Windows DHCP Server Elevation of Privilege Vulnerability |
| CVE-2026-62807 | Windows DHCP Server Elevation of Privilege Vulnerability |
| CVE-2026-62811 | Windows HTTP.sys Elevation of Privilege Vulnerability |
| CVE-2026-62812 | Windows DHCP Server Elevation of Privilege Vulnerability |
| CVE-2026-62814 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62815 | Microsoft QUIC Remote Code Execution Vulnerability |
| CVE-2026-62816 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability |
| CVE-2026-62817 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-62818 | Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability |
| CVE-2026-62819 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
| CVE-2026-62820 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-62822 | Windows GDI+ Remote Code Execution Vulnerability |
| CVE-2026-62823 | Windows DHCP Server Remote Code Execution Vulnerability |
| CVE-2026-62824 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-62827 | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2026-62829 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-62832 | Windows User Profile Service Elevation of Privilege Vulnerability |
| CVE-2026-62837 | Microsoft SharePoint Server Information Disclosure Vulnerability |
| CVE-2026-62839 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-62842 | Microsoft Office Graphics Component Information Disclosure Vulnerability |
| CVE-2026-62871 | .NET Elevation of Privilege Vulnerability |
| CVE-2026-62872 | .NET Framework Elevation of Privilege Vulnerability |
| CVE-2026-62876 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-62877 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-62878 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-62880 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-62881 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-62882 | Microsoft Outlook Spoofing Vulnerability |
| CVE-2026-62883 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-62885 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-62886 | .NET Elevation of Privilege Vulnerability |
| CVE-2026-62887 | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-62888 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-62889 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability |
| CVE-2026-62890 | Windows GDI+ Elevation of Privilege Vulnerability |
| CVE-2026-62892 | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability |
| CVE-2026-62893 | Windows Deployment Services TFTP Server Remote Code Execution Vulnerability |
| CVE-2026-62894 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-62897 | .NET Framework Remote Code Execution Vulnerability |
| CVE-2026-62898 | Microsoft QUIC Information Disclosure Vulnerability |
| CVE-2026-62899 | .NET Security Feature Bypass Vulnerability |
| CVE-2026-62900 | .NET Information Disclosure Vulnerability |
| CVE-2026-62901 | .NET Denial of Service Vulnerability |
| CVE-2026-62902 | .NET Information Disclosure Vulnerability |
| CVE-2026-62908 | Windows Backup Engine Elevation of Privilege Vulnerability |
| CVE-2026-62909 | .NET Elevation of Privilege Vulnerability |
| CVE-2026-62910 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-62911 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-62912 | Microsoft Exchange Server Denial of Service Vulnerability |
| CVE-2026-62913 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2026-62914 | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-62915 | Microsoft Exchange Server Security Feature Bypass Vulnerability |
| CVE-2026-62917 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-63512 | Microsoft SharePoint Server Tampering Vulnerability |
| CVE-2026-63513 | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-63514 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-63515 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-63516 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-63517 | Microsoft Office Graphics Component Information Disclosure Vulnerability |
| CVE-2026-63518 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-63519 | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-63520 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-63521 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-63524 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-63525 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-63526 | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-63527 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-63528 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-63529 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-63530 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-63531 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-63532 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-63533 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64563 | rhashtable: clear stale iter->p on table restart |
| CVE-2026-64581 | xfrm: fix sk_dst_cache double-free in xfrm_user_policy() |
| CVE-2026-64652 | GitHub CLI: Partial token disclosure in `gh auth status` output |
| CVE-2026-64653 | GitHub CLI: Unescaped variable components in request URLs could allow path traversal |
| CVE-2026-64654 | GitHub CLI: Terminal escape sequence injection in multiple `gh` commands |
| CVE-2026-64655 | GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching |
| CVE-2026-64897 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-64898 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64899 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-64900 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-64901 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-64902 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-64903 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64904 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64905 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-64906 | Microsoft Access Remote Code Execution Vulnerability |
| CVE-2026-64907 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-64908 | Microsoft Access Remote Code Execution Vulnerability |
| CVE-2026-64909 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64910 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64911 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64912 | Microsoft Access Remote Code Execution Vulnerability |
| CVE-2026-64914 | Microsoft Access Remote Code Execution Vulnerability |
| CVE-2026-64915 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-64916 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-64917 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-64919 | Microsoft Access Remote Code Execution Vulnerability |
| CVE-2026-64920 | Microsoft Access Remote Code Execution Vulnerability |
| CVE-2026-64921 | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2026-64922 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-65656 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-65657 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-65658 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-65660 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-65661 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-65662 | Windows GDI Information Disclosure Vulnerability |
| CVE-2026-65663 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-65664 | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-65665 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-65671 | Remote Access API Elevation of Privilege Vulnerability |
| CVE-2026-65672 | Remote Access API Elevation of Privilege Vulnerability |
| CVE-2026-65673 | Microsoft Entra Connect Elevation of Privilege Vulnerability |
| CVE-2026-65675 | CoPilot Chat Security Feature Bypass Vulnerability |
| CVE-2026-65678 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-65679 | Windows iSCSI Target Service Remote Code Execution Vulnerability |
| CVE-2026-65680 | Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability |
| CVE-2026-65681 | Windows iSCSI Target Service Denial of Service Vulnerability |
| CVE-2026-65767 | Microsoft Teams for Android and iOS Spoofing Vulnerability |
| CVE-2026-65768 | Microsoft Teams Remote Code Execution Vulnerability |
| CVE-2026-65769 | Microsoft Teams iOS Information Disclosure Vulnerability |
| CVE-2026-65773 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-65774 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-65775 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-65776 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-65777 | Active Directory Security Feature Bypass Vulnerability |
| CVE-2026-65778 | Windows Autopilot Elevation of Privilege Vulnerability |
| CVE-2026-65779 | Windows Autopilot Elevation of Privilege Vulnerability |
| CVE-2026-65780 | Windows Autopilot Elevation of Privilege Vulnerability |
| CVE-2026-65781 | Windows Autopilot Elevation of Privilege Vulnerability |
| CVE-2026-65782 | Windows Autopilot Elevation of Privilege Vulnerability |
| CVE-2026-65783 | Windows Autopilot Elevation of Privilege Vulnerability |
| CVE-2026-65784 | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-65785 | Windows DHCP Client Denial of Service Vulnerability |
| CVE-2026-65786 | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-65787 | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-65788 | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-65789 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-65790 | Windows Message Queuing Elevation of Privilege Vulnerability |
| CVE-2026-65791 | Windows iSCSI Target Service Remote Code Execution Vulnerability |
| CVE-2026-65794 | Windows SMB Client Information Disclosure Vulnerability |
| CVE-2026-65795 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-65796 | Windows iSCSI Target Service Denial of Service Vulnerability |
| CVE-2026-65797 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-65798 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-65799 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-65806 | Azure CycleCloud Information Disclosure Vulnerability |
| CVE-2026-65807 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-65810 | .NET Framework Elevation of Privilege Vulnerability |
| CVE-2026-65811 | Power BI Remote Code Execution Vulnerability |
| CVE-2026-65813 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-65814 | Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability |
| CVE-2026-65815 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability |
| CVE-2026-65819 | gopacket: Multiple layer decoders panic on crafted packets (out-of-bounds/underflow) enabling unauthenticated remote DoS via DecodingLayerParser |
| CVE-2026-66301 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability |
| CVE-2026-66484 | Path Traversal in GNU cpio |
| CVE-2026-66485 | Uncontrolled Memory Allocation in GNU cpio |
| CVE-2026-66486 | Improper Output Encoding in GNU cpio |
| CVE-2026-66799 | Windows Key Guard Elevation of Privilege Vulnerability |
| CVE-2026-66802 | Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability |
| CVE-2026-66804 | Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability |
| CVE-2026-66805 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-66806 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-66807 | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-66808 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-66809 | Microsoft Office Graphics Component Information Disclosure Vulnerability |
| CVE-2026-66810 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-6726 | MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot Reuse |
| CVE-2026-6727 | MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability |
| CVE-2026-68083 | ksmbd: fix path resolution in ksmbd_vfs_kern_path_create |
| CVE-2026-68084 | staging: vme_user: fix location monitor leak in tsi148 bridge |
| CVE-2026-68085 | Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled |
| CVE-2026-68086 | mm/khugepaged: write all dirty file folios when collapsing |
| CVE-2026-68088 | usb: gadget: function: rndis: add length check to response query |
| CVE-2026-68090 | debugobjects: Plug race against a concurrent OOM disable |
| CVE-2026-68091 | HID: wacom: stop hardware after post-start probe failures |
| CVE-2026-68093 | KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug |
| CVE-2026-68096 | audit: fix recursive locking deadlock in audit_dupe_exe() |
| CVE-2026-68097 | ksmbd: validate ACE size against SID sub-authorities |
| CVE-2026-68098 | ksmbd: bound DACL dedup walk to copied ACEs |
| CVE-2026-68099 | ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL |
| CVE-2026-68100 | ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl |
| CVE-2026-68102 | drm/amdgpu: fix aperture mapping leak |
| CVE-2026-68103 | drm/amdgpu: reject mapping a reserved doorbell to a new queue |
| CVE-2026-68104 | drm/amdgpu: invoke pm_genpd_remove() before freeing genpd |
| CVE-2026-68105 | drm/amdgpu: Fix kernel panic during driver load failure |
| CVE-2026-68106 | drm/amdgpu: fix division by zero with invalid uvd dimensions |
| CVE-2026-68107 | drm/amdgpu/vcn4: avoid rereading IB param length |
| CVE-2026-68108 | drm/amdgpu/vce: fix integer overflow in image size |
| CVE-2026-68109 | drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON() |
| CVE-2026-68110 | drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() |
| CVE-2026-68111 | drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() |
| CVE-2026-68112 | drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() |
| CVE-2026-68113 | drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() |
| CVE-2026-68114 | drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON() |
| CVE-2026-68115 | drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() |
| CVE-2026-68116 | vxlan: mdb: Fix source list corruption on a failed replace |
| CVE-2026-68117 | tipc: clear sock->sk on the failed-insert path in tipc_sk_create() |
| CVE-2026-68118 | tcp: challenge ACK for non-exact RST in SYN-RECEIVED |
| CVE-2026-68121 | pppoe: reload header pointer after dev_hard_header() |
| CVE-2026-68123 | openvswitch: fix GSO userspace truncation underflow |
| CVE-2026-68124 | mctp: serial: handle zero-length frames to prevent rx buffer overflow |
| CVE-2026-68125 | mac802154: llsec: reject frames shorter than the authentication tag |
| CVE-2026-68126 | mac802154: hold an interface reference across the scan worker |
| CVE-2026-68127 | ila: reload IPv6 header after pskb_may_pull in checksum adjust |
| CVE-2026-68129 | gve: fix Rx queue stall on alloc failure |
| CVE-2026-68130 | ksmbd: defer destroy_previous_session() until after NTLM authentication |
| CVE-2026-68131 | rbd: Reset positive result codes to zero in object map update path |
| CVE-2026-68132 | super: fix emergency thaw deadlock on frozen block devices |
| CVE-2026-68135 | net: hip04: fix RX buffer leak on build_skb failure |
| CVE-2026-68136 | net: gro: fix double aggregation of flush-marked skbs |
| CVE-2026-68137 | net/x25: fix use-after-free in x25_kill_by_neigh() |
| CVE-2026-68138 | net/sched: serialize qdisc_rtab_list against concurrent get/put |
| CVE-2026-68140 | net/iucv: fix use-after-free of a severed iucv_path |
| CVE-2026-68141 | net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() |
| CVE-2026-68142 | geneve: require CAP_NET_ADMIN in the device netns for changelink |
| CVE-2026-68143 | net: slip: serialize receive against buffer reallocation |
| CVE-2026-68144 | phonet: pep: fix use-after-free in pep_get_sb() |
| CVE-2026-68145 | iomap: fix out-of-bounds bitmap_set() with zero-length range |
| CVE-2026-68146 | ftrace: Add global mutex to serialize trace_parser access |
| CVE-2026-68147 | fscrypt: Avoid dynamic allocation in fscrypt_get_devices() |
| CVE-2026-68148 | fscrypt: Add missing superblock check in find_or_insert_direct_key() |
| CVE-2026-68149 | fs: preserve ACL_DONT_CACHE state in forget_cached_acl() |
| CVE-2026-68151 | binfmt_elf_fdpic: only honour the first PT_INTERP |
| CVE-2026-68152 | amt: fix use-after-free in AMT delayed works |
| CVE-2026-68153 | libceph: remove debugfs files before client teardown |
| CVE-2026-68154 | libceph: reject zero bucket types in crush_decode |
| CVE-2026-68155 | libceph: Reject monmaps advertising zero monitors |
| CVE-2026-68156 | libceph: refresh auth->authorizer_buf{,_len} after authorizer update |
| CVE-2026-68157 | libceph: guard missing CRUSH type name lookup |
| CVE-2026-68158 | libceph: Fix multiplication overflow in decode_new_up_state_weight() |
| CVE-2026-68159 | libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE |
| CVE-2026-68160 | ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() |
| CVE-2026-68161 | sctp: close UDP tunnel sockets during netns teardown |
| CVE-2026-68162 | sctp: avoid auth_enable sysctl UAF during netns teardown |
| CVE-2026-68164 | mm/damon/core: disallow overlapping input ranges for damon_set_regions() |
| CVE-2026-68165 | mm/damon/core: validate ranges in damon_set_regions() |
| CVE-2026-68166 | userfaultfd: prevent registration of special VMAs |
| CVE-2026-68169 | mptcp: pm: userspace: fix use-after-free in get_local_id |
| CVE-2026-68171 | arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates |
| CVE-2026-68175 | tracing: Fix resource leak on mmiotrace trace_pipe close |
| CVE-2026-68176 | tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev |
| CVE-2026-68180 | intel_th: fix MSC output device reference leak |
| CVE-2026-68181 | mei: bus: access mei_device under device_lock on cleanup |
| CVE-2026-68182 | comedi: comedi_parport: deal with premature interrupt |
| CVE-2026-68183 | firmware: stratix10-svc: fix memory leaks and list corruption bugs |
| CVE-2026-68184 | cdrom: fix stack out-of-bounds read in CDROMVOLCTRL |
| CVE-2026-68185 | LoongArch: Move jump_label_init() before parse_early_param() |
| CVE-2026-68186 | binfmt_misc: set have_execfd only once the interpreter is opened |
| CVE-2026-68187 | exec: fix unsigned loop counter wrap in transfer_args_to_stack() |
| CVE-2026-68188 | Bluetooth: RFCOMM: Fix session UAF in set_termios |
| CVE-2026-68189 | Bluetooth: hci_sync: Protect UUID list traversal |
| CVE-2026-68190 | staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() |
| CVE-2026-68192 | wifi: brcmfmac: make release_scratchbuffers idempotent |
| CVE-2026-68194 | wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses |
| CVE-2026-68195 | wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses |
| CVE-2026-68196 | wifi: wilc1000: validate assoc response length before subtracting header |
| CVE-2026-68197 | wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper |
| CVE-2026-68198 | wifi: ath6kl: fix use-after-free in aggr_reset_state() |
| CVE-2026-68199 | wifi: ath6kl: fix OOB access from firmware ADDBA window size |
| CVE-2026-68202 | ALSA: seq: close a re-opened queue timer in the destructor |
| CVE-2026-68203 | media: vivid: fix cleanup bugs in vivid_init() |
| CVE-2026-68204 | media: vivid: check for vb2_is_busy() when toggling caps |
| CVE-2026-68205 | media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() |
| CVE-2026-68206 | media: v4l2-ctrls: validate HEVC active reference counts |
| CVE-2026-68207 | media: ti: vpe: unwind v4l2 device registration on probe error |
| CVE-2026-68209 | media: sun4i-csi: Return queued buffers on start_streaming() failure |
| CVE-2026-68210 | media: stm32: dcmi: unregister notifier on probe failure |
| CVE-2026-68212 | media: saa7134: Fix a possible memory leak in saa7134_video_init1 |
| CVE-2026-68214 | media: rtl2832: fix use-after-free in rtl2832_remove() |
| CVE-2026-68215 | media: radio-si476x: Unregister v4l2_device on probe failure |
| CVE-2026-68216 | media: pwc: Return queued buffers on start_streaming() failure |
| CVE-2026-68217 | media: pwc: Drain fill_buf on start_streaming() failure |
| CVE-2026-68218 | media: pci: dm1105: Free allocated workqueue |
| CVE-2026-68219 | media: nxp: imx8-isi: Fix potential out-of-bounds issues |
| CVE-2026-68220 | media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe |
| CVE-2026-68222 | media: msi2500: Return queued buffers on start_streaming() failure |
| CVE-2026-68223 | media: meson: vdec: Fix memory leak in error path of vdec_open |
| CVE-2026-68226 | media: cx23885: add ioremap return check and cleanup |
| CVE-2026-68229 | media: cedrus: skip invalid H.264 reference list entries |
| CVE-2026-68231 | media: airspy: Return queued buffers on start_streaming() failure |
| CVE-2026-68233 | drm/vc4: Shut down BO cache timer before teardown |
| CVE-2026-68234 | drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved |
| CVE-2026-68235 | drm/amd/display: dce100: skip non-DP stream encoders for DP MST |
| CVE-2026-68236 | drm/amd/display: set new_stream to NULL after release |
| CVE-2026-68238 | drm/amdgpu: Release VFCT ACPI table reference |
| CVE-2026-68241 | drm/i915/mst: limit DP MST ESI service loop |
| CVE-2026-68242 | drm/i915/gt: Fix NULL deref on sched_engine alloc failure |
| CVE-2026-68243 | drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU |
| CVE-2026-68244 | drm/i915/gem: Do not leak siblings[] on proto context error |
| CVE-2026-68245 | drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() |
| CVE-2026-68246 | drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() |
| CVE-2026-68247 | drm/i915/bios: range check LFP Data Block panel_type2 |
| CVE-2026-68248 | drm/i915: Return NULL on error in active_instance |
| CVE-2026-68249 | drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() |
| CVE-2026-68250 | drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() |
| CVE-2026-68251 | drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() |
| CVE-2026-68252 | drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() |
| CVE-2026-68253 | drm/i915/hdcp: check streams[] bounds before overflow |
| CVE-2026-68254 | drm/i915/vrr: require valid min/max vfreq for VRR |
| CVE-2026-68255 | drm/virtio: bound EDID block reads to the response buffer |
| CVE-2026-68256 | drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference |
| CVE-2026-68257 | drm/amdkfd: fix 32-bit overflow in CWSR total size calculation |
| CVE-2026-68258 | drm/amdkfd: Check bounds on CRIU restore queue type and mqd size |
| CVE-2026-68259 | drm/amdkfd: Check bounds in allocate_event_notification_slot |
| CVE-2026-68269 | drm/i915/gem: Add missing nospec on parallel submit slot |
| CVE-2026-68271 | drm/nouveau: fix reversed error cleanup order in ucopy functions |
| CVE-2026-68272 | drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 |
| CVE-2026-68273 | drm/amdgpu: Fix context pstate override handling |
| CVE-2026-68277 | drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers |
| CVE-2026-68278 | drm/dp/mst: fix buffer overflows in sideband chunk accumulation |
| CVE-2026-68279 | drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers |
| CVE-2026-68280 | drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() |
| CVE-2026-68284 | bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() |
| CVE-2026-68286 | drop_monitor: perform u64_stats updates under IRQ-disabled section |
| CVE-2026-68287 | drop_monitor: fix size calculations for 64-bit attributes |
| CVE-2026-68288 | net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD |
| CVE-2026-68289 | tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() |
| CVE-2026-68293 | net/mlx5: Fix MCIA register buffer overflow on 32 dword reads |
| CVE-2026-68294 | net: qrtr: restrict socket creation to the initial network namespace |
| CVE-2026-68297 | tipc: fix u16 MTU truncation in media and bearer MTU validation |
| CVE-2026-68299 | vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets |
| CVE-2026-68300 | sctp: auth: verify auth requirement when auth_chunk is NULL |
| CVE-2026-68301 | net: hsr: fix memory leak on slave unregistration by removing synced VLANs |
| CVE-2026-68302 | amt: re-read skb header pointers after every pull |
| CVE-2026-68303 | drm/vc4: hvs/v3d: Fix null dereference in unbind |
| CVE-2026-68304 | wifi: brcmfmac: fix 802.1X-SHA256 call trace warning |
| CVE-2026-68306 | wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() |
| CVE-2026-68308 | wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() |
| CVE-2026-68309 | wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() |
| CVE-2026-68310 | wifi: mt76: mt7915: guard HE capability lookups |
| CVE-2026-68312 | cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths |
| CVE-2026-68313 | tipc: fix infinite loop in __tipc_nl_compat_dumpit |
| CVE-2026-68315 | sctp: validate stream count in sctp_process_strreset_inreq() |
| CVE-2026-68317 | pds_core: fix auxiliary device add/del races |
| CVE-2026-68318 | pds_core: fix use-after-free on workqueue during remove |
| CVE-2026-68320 | sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid |
| CVE-2026-68322 | rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled |
| CVE-2026-68323 | tipc: serialize udp bearer replicast list updates |
| CVE-2026-68324 | iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() |
| CVE-2026-68325 | iommu/amd: Bound the early ACPI HID map |
| CVE-2026-68326 | wifi: mwifiex: bound uAP association event IEs to the event buffer |
| CVE-2026-68327 | wan: wanxl: Only reset hardware after BAR mapping |
| CVE-2026-68328 | nfp: Check resource mutex allocation |
| CVE-2026-68329 | iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() |
| CVE-2026-68331 | dpaa2-eth: put MAC endpoint device on disconnect |
| CVE-2026-68333 | dpaa2-switch: put MAC endpoint device on disconnect |
| CVE-2026-68335 | rds: drop incoming messages that cross network namespace boundaries |
| CVE-2026-68336 | bonding: fix devconf_all NULL dereference when IPv6 is disabled |
| CVE-2026-68337 | bpf: Reject redirect helpers without a bpf_net_context |
| CVE-2026-68338 | net/packet: avoid fanout hook re-registration after unregister |
| CVE-2026-68339 | Bluetooth: btusb: validate Realtek vendor event length |
| CVE-2026-68340 | hwmon: occ: validate poll response sensor blocks |
| CVE-2026-68343 | smb: client: validate DFS referral PathConsumed |
| CVE-2026-68348 | ASoC: tas2781: bound firmware description string parsing |
| CVE-2026-68349 | wifi: carl9170: fix buffer overflow in rx_stream failover path |
| CVE-2026-68350 | wifi: carl9170: fix OOB read from off-by-two in TX status handler |
| CVE-2026-68351 | wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read |
| CVE-2026-68352 | wifi: ath6kl: fix OOB read from firmware IE lengths in connect event |
| CVE-2026-68353 | wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler |
| CVE-2026-68354 | firewire: net: Fix fragmented datagram reassembly |
| CVE-2026-68355 | wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() |
| CVE-2026-68357 | watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() |
| CVE-2026-68359 | hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop |
| CVE-2026-68360 | hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop |
| CVE-2026-68361 | hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop |
| CVE-2026-68362 | wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin |
| CVE-2026-68363 | wifi: ath9k: hif_usb: don’t dereference hif_dev after re-arming firmware request |
| CVE-2026-68364 | drm/amd/display: Fix ISM dc_lock deadlock during suspend |
| CVE-2026-68365 | USB: serial: io_edgeport: cap received transmit credits |
| CVE-2026-68366 | usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer |
| CVE-2026-68367 | usb: gadget: f_tcm: synchronize delayed set_alt with teardown |
| CVE-2026-68368 | usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() |
| CVE-2026-68369 | usb: gadget: printer: fix infinite loop in printer_read() |
| CVE-2026-68370 | usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback |
| CVE-2026-68371 | usb: musb: omap2430: Do not put borrowed of_node in probe |
| CVE-2026-68373 | wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() |
| CVE-2026-68374 | usb: core: sysfs: add lock to bos_descriptors_read() |
| CVE-2026-68376 | sctp: fix auth_hmacs array size in struct sctp_cookie |
| CVE-2026-68377 | net/sched: act_tunnel_key: Defer dst_release to RCU callback |
| CVE-2026-68381 | ksmbd: pin conn during async oplock break notification |
| CVE-2026-68386 | bpf, sockmap: Reject unhashed UDP sockets on sockmap update |
| CVE-2026-68388 | smb/client: handle overlapping allocated ranges in fallocate |
| CVE-2026-68389 | Bluetooth: hci_qca: Clear memdump state on invalid dump size |
| CVE-2026-68391 | Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds |
| CVE-2026-68392 | Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync |
| CVE-2026-68395 | ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered |
| CVE-2026-68396 | scsi: core: wake eh reliably when using scsi_schedule_eh |
| CVE-2026-68397 | net/iucv: take a reference on the socket found in afiucv_hs_rcv() |
| CVE-2026-68398 | ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF |
| CVE-2026-68399 | bpf: Fix UAF in sock clone early bailouts |
| CVE-2026-68401 | firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit() |
| CVE-2026-68402 | wifi: cfg80211: bound element ID read when checking non-inheritance |
| CVE-2026-68403 | wifi: brcmfmac: initialize SDIO data work before cleanup |
| CVE-2026-68404 | wifi: cfg80211: use wiphy work for socket owner autodisconnect |
| CVE-2026-68405 | wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock |
| CVE-2026-68406 | wifi: cfg80211: validate PMSR FTM preamble range |
| CVE-2026-68407 | wifi: nl80211: free RNR data on MBSSID mismatch |
| CVE-2026-68408 | wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock |
| CVE-2026-68409 | wifi: mac80211: defer link RX stats percpu free to RCU |
| CVE-2026-68410 | wifi: libertas: fix memory leak in helper_firmware_cb() |
| CVE-2026-68411 | wifi: mac80211_hwsim: clamp virtio RX length before skb_put |
| CVE-2026-68412 | wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan() |
| CVE-2026-68413 | wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() |
| CVE-2026-68414 | wifi: cfg80211: cancel sched scan results work on unregister |
| CVE-2026-68416 | mtd: fix double free and WARN_ON in add_mtd_device() error paths |
| CVE-2026-68417 | RDMA/siw: publish QP after initialization |
| CVE-2026-68418 | RDMA/irdma: Prevent user-triggered null deref on QP create |
| CVE-2026-68419 | RDMA/irdma: Prevent rereg_mr for non-mem regions |
| CVE-2026-68422 | btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() |
| CVE-2026-68425 | IB/mad: Drop unmatched RMPP responses before reassembly |
| CVE-2026-68426 | xfrm: fix stale skb->prev after async crypto steals a GSO segment |
| CVE-2026-68427 | gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings |
| CVE-2026-68428 | KVM: x86/mmu: Fix use-after-free on vendor module reload |
| CVE-2026-68792 | Microsoft Office Elevation of Privilege Vulnerability |
| CVE-2026-68793 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68794 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68795 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68796 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68797 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-68798 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68799 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-68800 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68801 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68802 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-68803 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68804 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68805 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68806 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68807 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68808 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-68809 | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-68810 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68811 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68812 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68813 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-68814 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68815 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68816 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68817 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68819 | Windows Network File System Denial of Service Vulnerability |
| CVE-2026-68820 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-68821 | Windows Package Manager Elevation of Privilege Vulnerability |
| CVE-2026-69278 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-69306 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-69320 | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-70130 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-70304 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-70306 | Microsoft Office SharePoint Spoofing Vulnerability |
| CVE-2026-70307 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-70310 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-70311 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-70312 | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-70313 | Microsoft PowerPoint Remote Code Execution Vulnerability |
| CVE-2026-70314 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-70315 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-70316 | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-70317 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-70318 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-70319 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-70320 | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-70321 | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2026-70322 | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-70323 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-70324 | Microsoft SharePoint Elevation of Privilege Vulnerability |
| CVE-2026-70325 | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-70326 | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2026-70327 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-70328 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-70329 | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2026-70330 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-70335 | GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability |
| CVE-2026-70336 | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-70337 | Microsoft PowerShell Remote Code Execution Vulnerability |
| CVE-2026-70338 | Microsoft PowerShell Security Feature Bypass Vulnerability |
| CVE-2026-70340 | Azure CycleCloud Elevation of Privilege Vulnerability |
| CVE-2026-70344 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-70345 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-70346 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-70347 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-70348 | Windows Management Services Denial of Service Vulnerability |
| CVE-2026-70354 | .NET Core Remote Code Execution Vulnerability |
| CVE-2026-70355 | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2026-71331 | Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability |
| CVE-2026-71497 | jsoup: Cleaner may expose markup with custom raw-text elements |
| CVE-2026-71556 | go-git: Worktree operations may follow symlinks |
| CVE-2026-71557 | go-git: Malicious reference names may modify files outside the reference storage |
| CVE-2026-72522 | libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions. |
| CVE-2026-72568 | Redis – Heap Out-of-Bounds Read in Cluster Bus PING Message Handler |
| CVE-2026-72971 | Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability |