惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

A
About on SuperTechFans
Cyberwarzone
Cyberwarzone
博客园 - Franky
V
V2EX
人人都是产品经理
人人都是产品经理
爱范儿
爱范儿
Martin Fowler
Martin Fowler
The Cloudflare Blog
Security Archives - TechRepublic
Security Archives - TechRepublic
Vercel News
Vercel News
Blog — PlanetScale
Blog — PlanetScale
Webroot Blog
Webroot Blog
Hacker News: Ask HN
Hacker News: Ask HN
Forbes - Security
Forbes - Security
D
Docker
C
CXSECURITY Database RSS Feed - CXSecurity.com
Project Zero
Project Zero
大猫的无限游戏
大猫的无限游戏
云风的 BLOG
云风的 BLOG
C
Cyber Attacks, Cyber Crime and Cyber Security
Recent Announcements
Recent Announcements
L
LINUX DO - 热门话题
小众软件
小众软件
Stack Overflow Blog
Stack Overflow Blog
G
Google Developers Blog
S
Security @ Cisco Blogs
T
Threat Research - Cisco Blogs
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
The Register - Security
The Register - Security
O
OpenAI News
雷峰网
雷峰网
P
Proofpoint News Feed
宝玉的分享
宝玉的分享
Scott Helme
Scott Helme
Google DeepMind News
Google DeepMind News
博客园 - 司徒正美
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Help Net Security
Help Net Security
F
Full Disclosure
Engineering at Meta
Engineering at Meta
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
T
Tailwind CSS Blog
Google DeepMind News
Google DeepMind News
博客园 - 三生石上(FineUI控件)
Apple Machine Learning Research
Apple Machine Learning Research
Attack and Defense Labs
Attack and Defense Labs
T
Tenable Blog
AI
AI
Spread Privacy
Spread Privacy

SANS Internet Storm Center, InfoCON: green

From a VHDX File to a Remcos RAT - SANS Internet Storm Center ISC Stormcast For Tuesday, June 16th, 2026 https://isc.sans.edu/podcastdetail/9974 Evil MSI Background: BASE64 Statistical Analysis - SANS ISC ISC Stormcast For Monday, June 15th, 2026 https://isc.sans.edu/podcastdetail/9972 ISC Stormcast For Friday, June 12th, 2026 https://isc.sans.edu/podcastdetail/9970 ISC Stormcast For Thursday, June 11th, 2026 https://isc.sans.edu/podcastdetail/9968 How has use of framing protection security headers changed in the past 3 years? ISC Stormcast For Wednesday, June 10th, 2026 https://isc.sans.edu/podcastdetail/9966 Microsoft June 2026 Patch Tuesday - SANS Internet Storm Center ISC Stormcast For Tuesday, June 9th, 2026 https://isc.sans.edu/podcastdetail/9964 TeamPCP Supply Chain Campaign: Activity Through 2026-06-07 ISC Stormcast For Monday, June 8th, 2026 https://isc.sans.edu/podcastdetail/9962 The Evil MSI Background is Back! - SANS Internet Storm Center ISC Stormcast For Friday, June 5th, 2026 https://isc.sans.edu/podcastdetail/9960 Microsoft's Coreutils for Windows - SANS Internet Storm Center ISC Stormcast For Thursday, June 4th, 2026 https://isc.sans.edu/podcastdetail/9958 Continuing Scans for swagger.json - SANS Internet Storm Center ISC Stormcast For Wednesday, June 3rd, 2026 https://isc.sans.edu/podcastdetail/9956 New Wave Of Phishing Emails with SVG Files - SANS ISC ISC Stormcast For Tuesday, June 2nd, 2026 https://isc.sans.edu/podcastdetail/9954 ISC Stormcast For Monday, June 1st, 2026 https://isc.sans.edu/podcastdetail/9952 Unidentified RAT pushes NetSupport RAT - SANS ISC YARA-X 1.17.0 Release - SANS Internet Storm Center ISC Stormcast For Friday, May 29th, 2026 https://isc.sans.edu/podcastdetail/9950 Analysis of a Year of Files Uploaded to DShield Sensors ISC Stormcast For Thursday, May 28th, 2026 https://isc.sans.edu/podcastdetail/9948 Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs ISC Stormcast For Wednesday, May 27th, 2026 https://isc.sans.edu/podcastdetail/9946 ISC Stormcast For Tuesday, May 26th, 2026 https://isc.sans.edu/podcastdetail/9944 Possible ACR Stealer From Page Impersonating Claude Microsoft Access VBA - SANS Internet Storm Center Wireshark 4.6.6 Released - SANS Internet Storm Center An Example of Stack String in High Level Language - SANS ISC Cross-Platform NPM Stealer - SANS Internet Storm Center ISC Stormcast For Friday, May 22nd, 2026 https://isc.sans.edu/podcastdetail/9942 Selective HTTP Proxying in Linux - SANS Internet Storm Center ISC Stormcast For Thursday, May 21st, 2026 https://isc.sans.edu/podcastdetail/9940 ISC Stormcast For Wednesday, May 20th, 2026 https://isc.sans.edu/podcastdetail/9938 ISC Stormcast For Tuesday, May 19th, 2026 https://isc.sans.edu/podcastdetail/9936 TeamPCP Supply Chain Campaign: Activity Through 2026-05-17 [Guest Diary] New Malware Libraries means New Signatures ISC Stormcast For Friday, May 15th, 2026 https://isc.sans.edu/podcastdetail/9934 Simple bypass of the link preview function in Outlook Junk folder ISC Stormcast For Thursday, May 14th, 2026 https://isc.sans.edu/podcastdetail/9932 [GUEST DIARY] Tearing apart website fraud to see how it works. ISC Stormcast For Wednesday, May 13th, 2026 https://isc.sans.edu/podcastdetail/9930 Proxying the Unproxyable? Sending EXE traffic to a Proxy ISC Stormcast For Tuesday, May 12th, 2026 https://isc.sans.edu/podcastdetail/9928 Apple Patches Everything - SANS Internet Storm Center Why we use CAPTCHAs - SANS Internet Storm Center ISC Stormcast For Monday, May 11th, 2026 https://isc.sans.edu/podcastdetail/9926 YARA-X 1.16.0 Release - SANS Internet Storm Center Another Universal Linux Local Privilege Escalation (LPE) Vulnerability: Dirty Frag ISC Stormcast For Friday, May 8th, 2026 https://isc.sans.edu/podcastdetail/9924 ISC Stormcast For Wednesday, May 6th, 2026 https://isc.sans.edu/podcastdetail/9920 Cleartext Passwords in MS Edge? In 2026? - SANS ISC SSL.com rotates their root certificate today - SANS ISC ISC Stormcast For Tuesday, May 5th, 2026 https://isc.sans.edu/podcastdetail/9918 TeamPCP Weekly Analysis: 2026-W18 (2026-04-27 through 2026-05-03) DShield Honeypot Update - SANS Internet Storm Center ISC Stormcast For Monday, May 4th, 2026 https://isc.sans.edu/podcastdetail/9916 Wireshark 4.6.5 Released - SANS Internet Storm Center Malicious Ad for Homebrew Leads to MacSync Stealer ISC Stormcast For Friday, May 1st, 2026 https://isc.sans.edu/podcastdetail/9914 ISC Stormcast For Thursday, April 30th, 2026 https://isc.sans.edu/podcastdetail/9912 Danger of Libredtail [Guest Diary] - SANS Internet Storm Center Today's Odd Web Requests - SANS Internet Storm Center ISC Stormcast For Wednesday, April 29th, 2026 https://isc.sans.edu/podcastdetail/9910 HTTP Requests with X-Vercel-Set-Bypass-Cookie Header ISC Stormcast For Tuesday, April 28th, 2026 https://isc.sans.edu/podcastdetail/9908 TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns ISC Stormcast For Friday, April 24th, 2026 https://isc.sans.edu/podcastdetail/9906 Apple Patches Exploited Notification Flaw - SANS ISC ISC Stormcast For Thursday, April 23rd, 2026 https://isc.sans.edu/podcastdetail/9904 ISC Stormcast For Wednesday, April 22nd, 2026 https://isc.sans.edu/podcastdetail/9902 [Guest Diary] Beyond Cryptojacking: Telegram tdata as a Credential Harvesting Vector, Lessons from a Honeypot Incident, (Wed, Apr 22nd) A .WAV With A Payload - SANS Internet Storm Center ISC Stormcast For Tuesday, April 21st, 2026 https://isc.sans.edu/podcastdetail/9900 Handling the CVE Flood With EPSS - SANS Internet Storm Center ISC Stormcast For Monday, April 20th, 2026 https://isc.sans.edu/podcastdetail/9898 ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896 Lumma Stealer infection with Sectop RAT (ArechClient2) ISC Stormcast For Thursday, April 16th, 2026 https://isc.sans.edu/podcastdetail/9894 [Guest Diary] Compromised DVRs and Finding Them in the Wild ISC Stormcast For Wednesday, April 15th, 2026 https://isc.sans.edu/podcastdetail/9892 Scanning for AI Models - SANS Internet Storm Center Microsoft Patch Tuesday April 2026. - SANS ISC ISC Stormcast For Tuesday, April 14th, 2026 https://isc.sans.edu/podcastdetail/9890 Scans for EncystPHP Webshell - SANS Internet Storm Center ISC Stormcast For Monday, April 13th, 2026 https://isc.sans.edu/podcastdetail/9888 Obfuscated JavaScript or Nothing - SANS Internet Storm Center ISC Stormcast For Thursday, April 9th, 2026 https://isc.sans.edu/podcastdetail/9886 Number Usage in Passwords: Take Two - SANS ISC TeamPCP Supply Chain Campaign: Update 007 - Cisco Source Code Stolen via Trivy-Linked Breach, Google GTIG Tracks TeamPCP as UNC6780, and CISA KEV Deadline Arrives with No Standalone Advisory More Honeypot Fingerprinting Scans - SANS Internet Storm Center ISC Stormcast For Wednesday, April 8th, 2026 https://isc.sans.edu/podcastdetail/9884 A Little Bit Pivoting: What Web Shells are Attackers Looking for? ISC Stormcast For Tuesday, April 7th, 2026 https://isc.sans.edu/podcastdetail/9882 How often are redirects used in phishing in 2026? - SANS ISC ISC Stormcast For Monday, April 6th, 2026 https://isc.sans.edu/podcastdetail/9880
Microsoft May 2026 Patch Tuesday - SANS Internet Storm Center
2026-05-13 · via SANS Internet Storm Center, InfoCON: green

Today's Microsoft patch Tuesday fixes 137 different vulnerabilities. In addition, the update addresses 137 Chromium-related issues affecting Microsoft Edge.

There are no already disclosed or already exploited vulnerabilities included in today's patches. I removed the Chromium issues from the table below and included only the 137 Microsoft issues to make it more readable.

Note that issues related to Microsoft Azure are labeled as "no customer action required. 

Significant Vulnerabilities of interest:

CVE-2026-41103: This vulnerability affects the Microsoft SSO Plugin for Jira & Confluence. Exploitation could lead to an elevation of privileges. With ongoing supply chain attacks, development and CI/CD tools like Jira and Confluence are popular targets. 

CVE-2026-41089: A preauthentication remote code execution vulnerability in the Netlogon service will always be a juicy target, worth some AI tokens to write an exploit for.

Other critical vulnerabilities include the usual Word and Microsoft Office issues.

Description
CVE Disclosed Exploited Exploitability (old versions) current version Severity CVSS Base (AVG) CVSS Temporal (AVG)
.NET Core Tampering Vulnerability
CVE-2026-32175 No No - - Important 4.3 3.8
.NET Elevation of Privilege Vulnerability
CVE-2026-32177 No No - - Important 7.3 6.4
CVE-2026-35433 No No - - Important 7.3 6.4
ASP.NET Core Denial of Service Vulnerability
CVE-2026-42899 No No - - Important 7.5 6.5
Azure AI Foundry Elevation of Privilege Vulnerability
(no customer action required)
CVE-2026-35435 No No - - Critical 8.6 7.5
Azure Cloud Shell Spoofing Vulnerability
(no customer action required)
CVE-2026-35428 No No - - Critical 9.6 8.3
Azure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2026-40381 No No - - Important 7.8 6.8
Azure DevOps Information Disclosure Vulnerability
(no customer action required)
CVE-2026-42826 No No - - Critical 10.0 8.7
Azure Logic Apps Elevation of Privilege Vulnerability
CVE-2026-42823 No No - - Important 9.9 8.6
Azure Machine Learning Notebook Spoofing Vulnerability
(no customer action required)
CVE-2026-32207 No No - - Critical 8.8 7.7
CVE-2026-33833 No No - - Important 8.2 7.1
Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
(no customer action required)
CVE-2026-33109 No No - - Critical 9.9 8.6
CVE-2026-33844 No No - - Critical 9.0 7.8
Azure Monitor Action Group Notification System Elevation of Privilege Vulnerability
(no customer action required)
CVE-2026-41105 No No - - Critical 8.1 7.1
Azure Monitor Agent Elevation of Privilege Vulnerability
CVE-2026-32204 No No - - Important 7.8 6.8
Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability
CVE-2026-42830 No No - - Important 6.5 5.7
Azure SDK for Java Security Feature Bypass Vulnerability
CVE-2026-33117 No No - - Important 9.1 7.9
Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
(no customer action required)
CVE-2026-33111 No No - - Critical 7.5 6.5
Data Deduplication Elevation of Privilege Vulnerability
CVE-2026-41095 No No - - Important 7.8 6.8
GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-41109 No No - - Important 8.8 7.7
Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability
CVE-2026-35424 No No - - Important 7.5 6.5
M365 Copilot Information Disclosure Vulnerability
(no customer action required)
CVE-2026-26129 No No - - Critical 7.5 6.5
CVE-2026-26164 No No - - Critical 7.5 6.5
M365 Copilot for Desktop Spoofing Vulnerability
CVE-2026-41614 No No - - Important 6.2 5.4
Microsoft 365 Copilot for Android Spoofing Vulnerability
CVE-2026-41100 No No - - Important 4.4 3.9
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
CVE-2026-40377 No No - - Important 7.8 6.8
Microsoft Data Formulator Remote Code Execution Vulnerability
CVE-2026-41094 No No - - Important 8.8 7.7
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
CVE-2026-40417 No No - - Important 7.8 6.8
Microsoft Dynamics 365 Customer Insights Elevation of Privilege Vulnerability
(no customer action required)
CVE-2026-33821 No No - - Critical 7.7 6.7
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
CVE-2026-42898 No No - - Critical 9.9 8.6
CVE-2026-42833 No No - - Important 9.1 7.9
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2026-42838 No No - - Important 5.4 4.7
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-41107 No No - - Moderate 7.4 6.4
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2026-42891 No No - - Moderate 6.5 5.7
CVE-2026-35429 No No - - Moderate 4.3 3.9
CVE-2026-40416 No No - - Low 4.3 3.8
Microsoft Enterprise Security Token Service (ESTS) Spoofing Vulnerability
(no customer action required)
CVE-2026-40379 No No - - Critical 9.3 8.1
Microsoft Excel Information Disclosure Vulnerability
CVE-2026-40360 No No - - Important 7.8 6.8
Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-40359 No No - - Important 7.8 6.8
CVE-2026-40362 No No - - Important 7.8 6.8
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2026-34329 No No - - Important 8.8 7.7
Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
CVE-2026-40419 No No - - Important 7.8 6.8
CVE-2026-40418 No No - - Important 7.8 6.8
CVE-2026-35436 No No - - Important 8.8 7.7
CVE-2026-40420 No No - - Important 8.8 7.7
Microsoft Office Remote Code Execution Vulnerability
CVE-2026-40363 No No - - Critical 8.4 7.3
CVE-2026-42831 No No - - Critical 7.8 6.8
CVE-2026-40358 No No - - Critical 8.4 7.3
Microsoft Office Spoofing Vulnerability
CVE-2026-42832 No No - - Important 7.7 6.7
Microsoft Outlook for iOS Tampering Vulnerability
CVE-2026-42893 No No - - Important 7.4 6.4
Microsoft Partner Center Spoofing Vulnerability
(no customer action required)
CVE-2026-34327 No No - - Critical 8.2 7.1
Microsoft Power Automate Desktop Information Disclosure Vulnerability
CVE-2026-40374 No No - - Important 6.5 5.7
Microsoft PowerPoint for Android Spoofing Vulnerability
CVE-2026-41102 No No - - Important 7.1 6.2
Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability
CVE-2026-41103 No No - - Critical 9.1 7.9
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-35439 No No - - Important 8.8 7.7
CVE-2026-40368 No No - - Important 8.0 7.0
CVE-2026-33110 No No - - Important 8.8 7.7
CVE-2026-33112 No No - - Important 8.8 7.7
CVE-2026-40357 No No - - Important 8.8 7.7
CVE-2026-40365 No No - - Critical 8.8 7.7
Microsoft Team Events Portal Information Disclosure Vulnerability
(no customer action required)
CVE-2026-33823 No No - - Critical 9.6 8.3
Microsoft Teams Spoofing Vulnerability
CVE-2026-32185 No No - - Important 5.5 4.8
Microsoft Word Information Disclosure Vulnerability
CVE-2026-35440 No No - - Important 5.5 4.8
CVE-2026-40421 No No - - Important 4.3 3.8
Microsoft Word Remote Code Execution Vulnerability
CVE-2026-40364 No No - - Critical 8.4 7.3
CVE-2026-40366 No No - - Critical 8.4 7.3
CVE-2026-40361 No No - - Critical 8.4 7.3
CVE-2026-40367 No No - - Critical 8.4 7.3
Microsoft Word for Android Spoofing Vulnerability
CVE-2026-41101 No No - - Important 7.1 6.2
SQL Server Remote Code Execution Vulnerability
CVE-2026-40370 No No - - Important 8.8 7.7
Secure Boot Security Feature Bypass Vulnerability
CVE-2026-41097 No No - - Important 6.7 5.8
Visual Studio Code Elevation of Privilege Vulnerability
CVE-2026-41613 No No - - Important 8.8 7.7
Visual Studio Code Information Disclosure Vulnerability
CVE-2026-41612 No No - - Important 5.5 4.8
Visual Studio Code Remote Code Execution Vulnerability
CVE-2026-41611 No No - - Important 7.8 6.8
Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-41610 No No - - Important 6.3 5.5
Win32k Elevation of Privilege Vulnerability
CVE-2026-33839 No No - - Important 7.0 6.1
CVE-2026-33840 No No - - Important 7.8 6.8
CVE-2026-34330 No No - - Important 7.8 6.8
CVE-2026-34331 No No - - Important 7.0 6.1
Windows 11 Telnet Client Information Disclosure Vulnerability
CVE-2026-35423 No No - - Important 5.4 4.7
Windows Admin Center Elevation of Privilege Vulnerability
CVE-2026-35438 No No - - Important 8.3 7.2
Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability
CVE-2026-41086 No No - - Important 8.8 7.7
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-34344 No No - - Important 7.8 6.8
CVE-2026-34345 No No - - Important 7.0 6.1
CVE-2026-35416 No No - - Important 7.0 6.1
CVE-2026-41088 No No - - Important 7.8 6.8
Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability
CVE-2026-34343 No No - - Important 7.8 6.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-35418 No No - - Important 7.8 6.8
CVE-2026-33835 No No - - Important 7.8 6.8
CVE-2026-34337 No No - - Important 7.8 6.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2026-40407 No No - - Important 7.8 6.8
CVE-2026-40397 No No - - Important 7.8 6.8
Windows DNS Client Remote Code Execution Vulnerability
CVE-2026-41096 No No - - Critical 9.8 8.5
Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-42896 No No - - Important 7.8 6.8
Windows DWM Core Library Information Disclosure Vulnerability
CVE-2026-35419 No No - - Important 5.5 4.8
CVE-2026-34336 No No - - Important 7.8 6.8
Windows Event Logging Service Elevation of Privilege Vulnerability
CVE-2026-33834 No No - - Important 7.8 6.8
Windows Filtering Platform (WFP) Security Feature Bypass Vulnerability
CVE-2026-32209 No No - - Important 4.4 3.9
Windows GDI Remote Code Execution Vulnerability
CVE-2026-35421 No No - - Critical 7.8 6.8
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-40403 No No - - Critical 8.8 7.7
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2026-40402 No No - - Critical 9.3 8.1
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-33841 No No - - Important 7.8 6.8
CVE-2026-35420 No No - - Important 7.8 6.8
CVE-2026-40369 No No - - Important 7.8 6.8
Windows Kernel-Mode Driver Remote Code Execution Vulnerability
CVE-2026-34332 No No - - Important 8.0 7.0
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
CVE-2026-34339 No No - - Important 5.5 4.8
Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege Vulnerability
CVE-2026-34341 No No - - Important 7.0 6.1
Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability
CVE-2026-33838 No No - - Important 7.8 6.8
Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability
CVE-2026-32161 No No - - Critical 7.5 6.5
Windows Netlogon Remote Code Execution Vulnerability
CVE-2026-41089 No No - - Critical 9.8 8.5
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2026-34342 No No - - Important 7.0 6.1
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-34340 No No - - Important 7.0 6.1
Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVE-2026-40398 No No - - Important 7.8 6.8
Windows Rich Text Edit Elevation of Privilege Vulnerability
CVE-2026-21530 No No - - Important 6.7 5.8
CVE-2026-32170 No No - - Important 6.7 5.8
Windows SMB Client Elevation of Privilege Vulnerability
CVE-2026-40410 No No - - Important 7.0 6.1
Windows Storage Spaces Controller Elevation of Privilege Vulnerability
CVE-2026-35415 No No - - Important 7.8 6.8
Windows Storport Miniport Driver Denial of Service Vulnerability
CVE-2026-34350 No No - - Important 6.5 5.7
Windows TCP/IP Denial of Service Vulnerability
CVE-2026-40405 No No - - Important 7.5 6.5
CVE-2026-40414 No No - - Important 7.4 6.4
CVE-2026-40401 No No - - Important 7.1 6.2
CVE-2026-40413 No No - - Important 7.4 6.4
Windows TCP/IP Driver Security Feature Bypass Vulnerability
CVE-2026-35422 No No - - Important 6.5 5.7
Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-34351 No No - - Important 7.8 6.8
CVE-2026-40399 No No - - Important 7.8 6.8
CVE-2026-34334 No No - - Important 7.8 6.8
Windows TCP/IP Information Disclosure Vulnerability
CVE-2026-40406 No No - - Important 7.5 6.5
Windows TCP/IP Local Elevation of Privilege Vulnerability
CVE-2026-33837 No No - - Important 7.8 6.8
Windows TCP/IP Remote Code Execution Vulnerability
CVE-2026-40415 No No - - Important 8.1 7.1
Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-42825 No No - - Important 7.0 6.1
CVE-2026-34338 No No - - Important 7.8 6.8
CVE-2026-40382 No No - - Important 7.8 6.8
Windows Volume Manager Extension Driver Remote Code Execution Vulnerability
CVE-2026-40380 No No - - Important 6.2 5.4
Windows WAN ARP Driver Elevation of Privilege Vulnerability
CVE-2026-40408 No No - - Important 7.8 6.8
Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-34333 No No - - Important 7.8 6.8
CVE-2026-34347 No No - - Important 7.0 6.1
CVE-2026-35417 No No - - Important 7.8 6.8

--
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
Twitter|