Microsoft Security Response Center
Monthly Patch Tuesday advisories covering Windows, Azure, Office, and the wider Microsoft platform.
10,246 advisories tracked · showing 100
- Sep 11, 2026CVE-2026-86141LowCVSS 2.9CVE-2026-86141
xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.
- Sep 11, 2026CVE-2026-86139MediumCVSS 6.9CVE-2026-86139
In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
- Sep 11, 2026CVE-2026-85396HighCVSS 7.5CVE-2026-85396
rubyzip before 3.4.0 Path Traversal in Zip::Entry#extract via Sibling-Directory Prefix
- Sep 11, 2026CVE-2026-85393HighCVSS 7.5CVE-2026-85393
node-forge through 1.4.0 RSA PKCS#1 v1.5 Signature Forgery via Nested DigestAlgorithm Padding
- Sep 11, 2026CVE-2026-85062MediumCVE-2026-85062
Colord: Slow rejection of oversized malformed color strings
- Sep 11, 2026CVE-2026-84303MediumCVE-2026-84303
gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion
- Sep 11, 2026CVE-2026-83619HighCVE-2026-83619
xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser
- Sep 11, 2026CVE-2026-83616HighCVE-2026-83616
xmldom: Processing Instruction Target Injection Bypasses requireWellFormed
- Sep 11, 2026CVE-2026-83615HighCVE-2026-83615
xmldom: Quadratic-memory consumption
- Sep 11, 2026CVE-2026-83614HighCVE-2026-83614
xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge
- Sep 11, 2026CVE-2026-83613HighCVE-2026-83613
xmldom: Quadratic-time attribute deduplication
- Sep 11, 2026CVE-2026-83611MediumCVE-2026-83611
xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content
- Sep 11, 2026CVE-2026-83610MediumCVE-2026-83610
xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization
- Sep 11, 2026CVE-2026-83608HighCVE-2026-83608
xmldom: DocType `name` Injection Bypasses requireWellFormed
- Sep 11, 2026CVE-2026-83607HighCVE-2026-83607
xmldom: Element name injection via createElement() bypasses requireWellFormed
- Sep 11, 2026CVE-2026-83605HighCVE-2026-83605
xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed
- Sep 11, 2026CVE-2026-82208HighCVSS 7.4CVE-2026-82208
wolfSSL CA-cache hit overrides callback
- Sep 11, 2026CVE-2026-80910LowCVSS 3.3CVE-2026-80910
ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses
- Sep 11, 2026CVE-2026-80892LowCVSS 3.3CVE-2026-80892
erofs: cap LZMA stream pool size
- Sep 11, 2026CVE-2026-80891MediumCVSS 5.9CVE-2026-80891
KVM: s390: pci: Validate AIBV and AISB before pinning guest pages
- Sep 11, 2026CVE-2026-80889LowCVSS 2.5CVE-2026-80889
can: isotp: fix timer drain order, wakeup handling and tx_gen ordering
- Sep 11, 2026CVE-2026-80872MediumCVSS 4.1CVE-2026-80872
ALSA: hda/tas2781: Cancel async firmware request at unbind
- Sep 11, 2026CVE-2026-80854MediumCVSS 5.7CVE-2026-80854
usb: gadget: f_tcm: keep port count until LUN teardown completes
- Sep 11, 2026CVE-2026-80851MediumCVSS 5.7CVE-2026-80851
gtp: serialize PDP context updates
- Sep 11, 2026CVE-2026-80848MediumCVSS 5.9CVE-2026-80848
xfrm: espintcp: fix UAF during close
- Sep 11, 2026CVE-2026-80846MediumCVSS 5.9CVE-2026-80846
xfrm: drop ESP-in-TCP packets with no ingress device
- Sep 11, 2026CVE-2026-80834MediumCVSS 4.7CVE-2026-80834
crypto: sun8i-ce - Remove crypto_rng interface
- Sep 11, 2026CVE-2026-80833MediumCVSS 4.7CVE-2026-80833
crypto: sun8i-ss - Remove crypto_rng interface
- Sep 11, 2026CVE-2026-80832MediumCVSS 5.5CVE-2026-80832
crypto: qce - fix CCM AAD buffer underallocation
- Sep 11, 2026CVE-2026-80823HighCVSS 8.1CVE-2026-80823
nfc: st21nfca: validate ATR_REQ length against the received frame
- Sep 11, 2026CVE-2026-80820MediumCVSS 4.1CVE-2026-80820
xfs: don't livelock in scrub on a circular unlinked list
- Sep 11, 2026CVE-2026-80809MediumCVSS 4.7CVE-2026-80809
ocfs2: fix missing metadata reservation for large xattrs
- Sep 11, 2026CVE-2026-80807MediumCVSS 6.0CVE-2026-80807
nilfs2: reject invalid block index in GC ioctl
- Sep 11, 2026CVE-2026-80803HighCVSS 8.1CVE-2026-80803
nfc: digital: clamp SENSF_RES length to the destination buffer
- Sep 11, 2026CVE-2026-80802MediumCVSS 5.9CVE-2026-80802
nfc: fdp: bound the device-reported read length and fix an skb leak
- Sep 11, 2026CVE-2026-80801MediumCVSS 4.3CVE-2026-80801
nfc: microread: validate target discovery payload lengths
- Sep 11, 2026CVE-2026-80800HighCVSS 8.1CVE-2026-80800
nfc: llcp: bound the connect_sn TLV walk to the skb
- Sep 11, 2026CVE-2026-80799HighCVSS 8.1CVE-2026-80799
nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers
- Sep 11, 2026CVE-2026-80798HighCVSS 8.1CVE-2026-80798
nfc: llcp: reject PDUs shorter than the LLCP header
- Sep 11, 2026CVE-2026-80797LowCVSS 1.9CVE-2026-80797
nfc: pn533: purge fragmented skbs during cleanup
- Sep 11, 2026CVE-2026-80796MediumCVSS 4.3CVE-2026-80796
nfc: nci: add data_len bound checks to activation parameter extractors
- Sep 11, 2026CVE-2026-80794MediumCVSS 4.3CVE-2026-80794
nfc: nci: fix uninit-value in the RF discover/activated NTF handlers
- Sep 11, 2026CVE-2026-80791HighCVSS 7.5CVE-2026-80791
nvmet-auth: zero the AUTH_RECEIVE response buffer
- Sep 11, 2026CVE-2026-80790MediumCVSS 5.7CVE-2026-80790
nvmet-fc: fix invalid free in LS IOD error path
- Sep 11, 2026CVE-2026-80780MediumCVSS 5.9CVE-2026-80780
HID: pidff: fix OOB write when hid->inputs is empty
- Sep 11, 2026CVE-2026-80772MediumCVSS 4.3CVE-2026-80772
HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()
- Sep 11, 2026CVE-2026-80771MediumCVSS 4.7CVE-2026-80771
HID: nintendo: register input device after capabilities are set
- Sep 11, 2026CVE-2026-80770MediumCVSS 4.0CVE-2026-80770
HID: nintendo: stop device IO before hid_hw_stop on probe failure
- Sep 11, 2026CVE-2026-80768MediumCVSS 5.6CVE-2026-80768
HID: ft260: fix stack-use-after-return write in I2C read race
- Sep 11, 2026CVE-2026-78607MediumCVSS 5.4CVE-2026-78607
Missing Authorization in Elasticsearch Leading to Information Disclosure
- Sep 11, 2026CVE-2026-72649HighCVSS 8.8CVE-2026-72649
Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution
- Sep 11, 2026CVE-2026-56143MediumCVSS 4.9CVE-2026-56143
Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service
- Sep 11, 2026CVE-2026-87625HighCVSS 8.8CVE-2026-87625
Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)
- Sep 11, 2026CVE-2026-87612HighCVSS 8.8CVE-2026-87612
Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Sep 11, 2026CVE-2026-87601MediumCVSS 7.5CVE-2026-87601
Race condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
- Sep 11, 2026CVE-2026-87587HighCVSS 8.8CVE-2026-87587
Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Sep 11, 2026CVE-2026-87564MediumCVSS 4.3CVE-2026-87564
Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Sep 11, 2026CVE-2026-87536HighCVSS 8.8CVE-2026-87536
Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Sep 11, 2026CVE-2026-86145HighCVSS 8.2CVE-2026-86145
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).
- Sep 11, 2026CVE-2026-86144MediumCVSS 5.6CVE-2026-86144
In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).
- Sep 11, 2026CVE-2026-86143MediumCVSS 6.9CVE-2026-86143
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
- Sep 11, 2026CVE-2026-86142MediumCVSS 6.9CVE-2026-86142
In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.
- Sep 11, 2026CVE-2026-86140HighCVSS 8.0CVE-2026-86140
In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.
- Sep 11, 2026CVE-2026-86138MediumCVSS 6.9CVE-2026-86138
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
- Sep 11, 2026CVE-2026-86137LowCVSS 2.9CVE-2026-86137
In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.
- Sep 11, 2026CVE-2026-86098HighCVSS 7.4CVE-2026-86098
ntop nDPI before 6.0 Heap Buffer Overflow via ndpi_json_string_escape
- Sep 11, 2026CVE-2026-86091HighCVSS 7.1CVE-2026-86091
ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete Handler
- Sep 11, 2026CVE-2026-86090HighCVSS 7.1CVE-2026-86090
ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient Delete Handlers
- Sep 11, 2026CVE-2026-85769MediumCVSS 6.5CVE-2026-85769
Libtpms: libtpms: heap out-of-bounds read in tpm2 state unmarshalling via unchecked block_skip_read() blocksize
- Sep 11, 2026CVE-2026-85534MediumCVSS 5.9CVE-2026-85534
Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initial_window_size shrinks during deferred body read
- Sep 11, 2026CVE-2026-85509CriticalCVSS 9.8CVE-2026-85509
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.
- Sep 11, 2026CVE-2026-85508CriticalCVSS 9.8CVE-2026-85508
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).
- Sep 11, 2026CVE-2026-85507CriticalCVSS 9.8CVE-2026-85507
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).
- Sep 11, 2026CVE-2026-85506CriticalCVSS 9.8CVE-2026-85506
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).
- Sep 11, 2026CVE-2026-85505MediumCVSS 7.5CVE-2026-85505
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).
- Sep 11, 2026CVE-2026-85504CriticalCVSS 9.8CVE-2026-85504
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.
- Sep 11, 2026CVE-2026-85197HighCVSS 7.6CVE-2026-85197
Libsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read() via goaway during body upload
- Sep 11, 2026CVE-2026-85091HighCVSS 7.4CVE-2026-85091
zlib 1.3.1.2 through 1.3.2 Heap Buffer Overflow via gz_vacate
- Sep 11, 2026CVE-2026-84838HighCVSS 7.8CVE-2026-84838
Rpm: command injection in rpmuncompress via unescaped filenames passed to popen()
- Sep 11, 2026CVE-2026-84304HighCVSS 4.4CVE-2026-84304
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
- Sep 11, 2026CVE-2026-84233MediumCVSS 7.0CVE-2026-84233
Rpm: command execution via macro expansion in `rpmuncompress -x` for crafted `.gem` filenames
- Sep 11, 2026CVE-2026-82209HighCVSS 8.2CVE-2026-82209
domain-scoped PSL domain cookie
- Sep 11, 2026CVE-2026-80925MediumCVSS 4.1CVE-2026-80925
vlan: fix skb_under_panic and races when toggling HW VLAN offload
- Sep 11, 2026CVE-2026-80923MediumCVSS 4.7CVE-2026-80923
xhci: dbgtty: Fix unregister on tty_register_driver() failure
- Sep 11, 2026CVE-2026-80921MediumCVSS 4.2CVE-2026-80921
KVM: s390: vsie: zero stale crypto bits
- Sep 11, 2026CVE-2026-80920LowCVSS 3.3CVE-2026-80920
io_uring: defer eventfd signaling when queued from a wakeup handler
- Sep 11, 2026CVE-2026-80918LowCVSS 2.4CVE-2026-80918
HID: core: fix number/pointer type confusion on long items
- Sep 11, 2026CVE-2026-80917MediumCVSS 4.1CVE-2026-80917
PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
- Sep 11, 2026CVE-2026-80914MediumCVSS 4.2CVE-2026-80914
Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready
- Sep 11, 2026CVE-2026-80913MediumCVSS 4.4CVE-2026-80913
selinux: require every boolean value to be defined
- Sep 11, 2026CVE-2026-80912MediumCVSS 4.4CVE-2026-80912
selinux: reject an unclaimed class value in security_get_classes()
- Sep 11, 2026CVE-2026-80909HighCVSS 7.8CVE-2026-80909
drm/amdgpu: Reject UVD message with invalid number of h265 refs
- Sep 11, 2026CVE-2026-80905MediumCVSS 5.5CVE-2026-80905
net: tap: fix wrong transport_header when sending VLAN-tagged frame
- Sep 11, 2026CVE-2026-80904MediumCVSS 5.9CVE-2026-80904
net/tls: Fail tls_sw_splice_read() after a failed async decrypt
- Sep 11, 2026CVE-2026-80902MediumCVSS 4.4CVE-2026-80902
dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA
- Sep 11, 2026CVE-2026-80901CVE-2026-80901
ipvs: fix the checksum validations
- Sep 11, 2026CVE-2026-80893LowCVSS 2.5CVE-2026-80893
mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()
- Sep 11, 2026CVE-2026-80890MediumCVSS 4.8CVE-2026-80890
sctp: reject stale cookies with mismatched verification tags
- Sep 11, 2026CVE-2026-80888MediumCVSS 5.5CVE-2026-80888
drm/vmwgfx: drop dma_buf reference on foreign-fd prime import
- Sep 11, 2026CVE-2026-80887CVE-2026-80887
drm/vmwgfx: use check_add_overflow for shader size+offset bound