Microsoft Security Response Center
Monthly Patch Tuesday advisories covering Windows, Azure, Office, and the wider Microsoft platform.
29,689 advisories tracked · showing 100
- Oct 3, 2026CVE-2026-95520HighCVSS 7.1CVE-2026-95520
Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffer overflow when parsing untrusted rpm packages
- Oct 3, 2026CVE-2026-103242HighCVSS 7.1CVE-2026-103242
Rpm: heap-based buffer overflow write in hex2binv() via a mistyped rpmtag_filesignatures header tag
- Oct 3, 2026CVE-2026-94640HighCVSS 7.5CVE-2026-94640
Rpcbind: unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of service
- Oct 3, 2026CVE-2026-66070HighCVE-2026-66070
RabbitMQ: CORS * reflects Origin with Allow-Credentials
- Oct 3, 2026CVE-2026-67235MediumCVE-2026-67235
RabbitMQ: AMQP 0-9-1 body assembly never validates accumulated size
- Oct 3, 2026CVE-2026-67232HighCVE-2026-67232
RabbitMQ: Web-MQTT decompression bomb
- Oct 3, 2026CVE-2026-66077HighCVE-2026-66077
RabbitMQ: Stored XSS via TLS peer-certificate DN in management UI
- Oct 3, 2026CVE-2026-67239MediumCVE-2026-67239
RabbitMQ: Stored XSS via TLS peer-certificate DN in stream-management UI
- Oct 3, 2026CVE-2026-66079HighCVE-2026-66079
RabbitMQ: Pre-auth AMQP 1.0 array32 zero-width element DoS
- Oct 3, 2026CVE-2026-15390CriticalCVE-2026-15390
Out-of-bounds write in Das U-Boot
- Oct 3, 2026CVE-2026-71972MediumCVSS 5.9CVE-2026-71972
U-Boot through 2026.10-rc5 Out-of-Bounds Write in BMP RLE8 Decoder
- Oct 3, 2026CVE-2026-71973MediumCVSS 5.2CVE-2026-71973
U-Boot before 2026.10-rc4 Integer Overflow in SquashFS Directory Table Allocation
- Oct 3, 2026CVE-2026-71971HighCVSS 8.2CVE-2026-71971
U-Boot before 2026.10-rc3 Out-of-Bounds Write in IP Fragment Reassembly
- Oct 3, 2026CVE-2026-74221HighCVSS 8.2CVE-2026-74221
U-Boot before 2026.10-rc5 Buffer Overflow via NFS READLINK
- Oct 3, 2026CVE-2026-74220HighCVSS 8.2CVE-2026-74220
U-Boot before 2026.10-rc5 Buffer Overflow via NFS READ Reply
- Oct 3, 2026CVE-2026-19445CriticalCVE-2026-19445
Use-after-free of a server-side SSLContext when sni_callback switches contexts
- Oct 3, 2026CVE-2026-19553HighCVE-2026-19553
SSLContext.wrap_bio() missing validation of server_hostname parameter
- Oct 3, 2026CVE-2026-12345MediumCVE-2026-12345
Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory
- Oct 3, 2026CVE-2026-102925HighCVSS 7.8CVE-2026-102925
virtualenv bash and fish activation scripts execute commands embedded in paths
- Oct 3, 2026CVE-2026-102930HighCVE-2026-102930
virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use
- Oct 3, 2026CVE-2026-97689HighCVE-2026-97689
urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
- Oct 3, 2026CVE-2026-102992CriticalCVE-2026-102992
piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env
- Oct 3, 2026CVE-2026-102598MediumCVE-2026-102598
Werkzeug safe_join() allows Windows special device names
- Oct 3, 2026CVE-2026-97687HighCVE-2026-97687
urllib3: HTTPS proxy TLS configuration may be ignored or overridden
- Oct 3, 2026CVE-2026-102937HighCVE-2026-102937
virtualenv: Command injection via --prompt in activate.bat (batch activator)
- Oct 3, 2026CVE-2026-73064LowCVSS 2.9CVE-2026-73064
In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. This only affects TLS 1.3 servers.
- Oct 3, 2026CVE-2026-102559HighCVSS 8.6CVE-2026-102559
Libsoup: libsoup: heap buffer overflow during websocket client-frame masking
- Oct 3, 2026CVE-2026-102556HighCVSS 8.6CVE-2026-102556
Libsoup: libsoup: heap buffer overflow from websocket pong signal type confusion
- Oct 3, 2026CVE-2026-102555HighCVSS 8.2CVE-2026-102555
Libsoup: libsoup: heap buffer overflow via uninitialized length in data-uri base64 decoding
- Oct 3, 2026CVE-2026-102558HighCVSS 8.6CVE-2026-102558
Libsoup: libsoup: heap buffer overflow during websocket receive-buffer growth
- Oct 3, 2026CVE-2026-102557HighCVSS 8.6CVE-2026-102557
Libsoup: libsoup: heap buffer overflow during websocket message reassembly
- Oct 3, 2026CVE-2026-102560HighCVSS 8.6CVE-2026-102560
Libsoup: libsoup: heap buffer overflow during outgoing permessage-deflate buffer growth
- Oct 3, 2026CVE-2026-63209HighCVSS 7.5CVE-2026-63209
Integer Overflow or Wraparound and Out-of-bounds Write in compress
- Oct 3, 2026CVE-2026-101276CriticalCVE-2026-101276
iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22.
- Oct 3, 2026CVE-2026-72897HighCVSS 7.5CVE-2026-72897
Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake
- Oct 3, 2026CVE-2026-84784HighCVSS 7.5CVE-2026-84784
QUIC: Unbounded RETIRE_CONNECTION_ID Backlog
- Oct 3, 2026CVE-2026-77696LowCVSS 3.7CVE-2026-77696
Timing Side-Channel in SM2 Signature Generation
- Oct 3, 2026CVE-2026-35191LowCVSS 3.7CVE-2026-35191
QUIC Unvalidated Amplification Credit may be Over Accounted
- Oct 3, 2026CVE-2026-75804MediumCVSS 5.3CVE-2026-75804
QUIC Connection-Level Flow Control is Not Enforced for Streams
- Oct 3, 2026CVE-2026-42772MediumCVSS 5.3CVE-2026-42772
Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC
- Oct 3, 2026CVE-2026-54875LowCVSS 3.7CVE-2026-54875
Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V
- Oct 3, 2026CVE-2026-54872LowCVSS 3.7CVE-2026-54872
Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves
- Oct 3, 2026CVE-2026-35189MediumCVSS 5.3CVE-2026-35189
Excessive Memory Allocation in Relative CRLDP Processing
- Oct 3, 2026CVE-2026-84782HighCVSS 8.2CVE-2026-84782
DTLS Retransmits Handshake Messages From a Stale Buffer Offset
- Oct 3, 2026CVE-2026-75806MediumCVSS 5.3CVE-2026-75806
Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS
- Oct 3, 2026CVE-2026-75805MediumCVSS 5.3CVE-2026-75805
NULL Pointer Dereference in CMP Client Revocation Response Handling
- Oct 3, 2026CVE-2026-54873HighCVSS 7.5CVE-2026-54873
QUIC STREAM Fragment Metadata DoS
- Oct 2, 2026CVE-2026-96940HighCVSS 8.8CVE-2026-96940
Microsoft Exchange Server Elevation of Privilege Vulnerability
- Oct 2, 2026CVE-2026-76844MediumCVSS 7.4CVE-2026-76844
zlib 1.2.11 through 1.3.2 Heap Buffer Overflow via Stale gzwrite Pointer After Failed Write
- Oct 1, 2026CVE-2026-92382MediumCVSS 4.1CVE-2026-92382
Usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write
- Oct 1, 2026CVE-2026-100419HighCVSS 7.0CVE-2026-100419
gitoxide gix-fs before 0.23.0 Worktree Escape via Symlink
- Oct 1, 2026CVE-2026-95519HighCVSS 7.8CVE-2026-95519
Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify manifest flows)
- Oct 1, 2026CVE-2026-95521HighCVSS 7.8CVE-2026-95521
Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when installing a source rpm
- Oct 1, 2026CVE-2026-67407MediumCVE-2026-67407
RabbitMQ: Incomplete fix for CVE-2026-44838: `escape_regex_char/1` does not escape `-`, leaving room for an MQTT topic permission bypass
- Oct 1, 2026CVE-2026-67224LowCVE-2026-67224
RabbitMQ: Admin path-traversal write via trace name
- Oct 1, 2026CVE-2026-67413MediumCVE-2026-67413
RabbitMQ: Authenticated RabbitMQ JMS Topic Selector Users Can Consume Broker CPU with an Unbounded LIKE Regular Expression
- Oct 1, 2026CVE-2026-67410HighCVE-2026-67410
RabbitMQ: OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint
- Oct 1, 2026CVE-2026-67223MediumCVE-2026-67223
RabbitMQ: LDAP DN injection via unescaped substitution
- Oct 1, 2026CVE-2026-66073MediumCVE-2026-66073
RabbitMQ: Atom table exhaustion via management API node field
- Oct 1, 2026CVE-2026-66071MediumCVE-2026-66071
RabbitMQ: Atom exhaustion: OAuth2 JWT tag: scope values
- Oct 1, 2026CVE-2026-67411MediumCVE-2026-67411
RabbitMQ: Web MQTT with PROXY Protocol enabled: a loopback-only user permission bypass
- Oct 1, 2026CVE-2026-67227MediumCVE-2026-67227
RabbitMQ: Atom exhaustion: to_atom on global-parameter :name
- Oct 1, 2026CVE-2026-67231HighCVE-2026-67231
RabbitMQ: Trust-store whitelist by Issuer+Serial only
- Oct 1, 2026CVE-2026-67412MediumCVE-2026-67412
RabbitMQ: Federation upstream skips vhost authorization allowing cross-vhost message access
- Oct 1, 2026CVE-2026-67230MediumCVE-2026-67230
RabbitMQ: Web-STOMP unbounded pre-auth accumulation
- Oct 1, 2026CVE-2026-93834HighCVSS 8.8CVE-2026-93834
Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape
- Oct 1, 2026CVE-2026-81627HighCVSS 8.2CVE-2026-81627
Qemu-kvm: vapic writable rom alias can escape the option-rom window and expose locked smram
- Oct 1, 2026CVE-2026-101904MediumCVE-2026-101904
Axios: Header Injection via Inherited headers After Minimal Interceptor
- Oct 1, 2026CVE-2026-97058MediumCVSS 5.3CVE-2026-97058
sprintf-js through 1.1.3 Denial of Service via Unbounded Precision
- Oct 1, 2026CVE-2026-102277MediumCVSS 5.3CVE-2026-102277
brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service
- Oct 1, 2026CVE-2026-102276HighCVSS 7.5CVE-2026-102276
brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
- Oct 1, 2026CVE-2026-101902MediumCVE-2026-101902
Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method
- Oct 1, 2026CVE-2026-102278HighCVSS 7.5CVE-2026-102278
brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
- Oct 1, 2026CVE-2026-102266HighCVSS 7.4CVE-2026-102266
PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation
- Oct 1, 2026CVE-2026-102274MediumCVSS 5.9CVE-2026-102274
PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set
- Oct 1, 2026CVE-2026-102275MediumCVSS 6.5CVE-2026-102275
PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion
- Oct 1, 2026CVE-2026-102265MediumCVSS 5.3CVE-2026-102265
PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header
- Oct 1, 2026CVE-2026-102273HighCVSS 7.4CVE-2026-102273
PyJWT accepts public JWK containers as HMAC secrets
- Oct 1, 2026CVE-2026-102272HighCVSS 7.4CVE-2026-102272
PyJWT BOM Bypass
- Oct 1, 2026CVE-2026-102271HighCVSS 7.4CVE-2026-102271
PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard
- Oct 1, 2026CVE-2026-101918MediumCVSS 5.3CVE-2026-101918
PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False)
- Oct 1, 2026CVE-2026-88816HighCVSS 7.5CVE-2026-88816
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName
- Oct 1, 2026CVE-2026-88815MediumCVSS 6.2CVE-2026-88815
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv
- Oct 1, 2026CVE-2026-92987MediumCVSS 7.5CVE-2026-92987
roxmltree through 0.21.1 Denial of Service via Quadratic Parsing
- Oct 1, 2026CVE-2026-94417LowCVSS 5.3CVE-2026-94417
CRL check skipped when OCSP enabled and certificate has no OCSP URL
- Oct 1, 2026CVE-2026-15442LowCVE-2026-15442
Heap use-after-free on read during bidirectional (D)TLS shutdown
- Oct 1, 2026CVE-2026-93304MediumCVE-2026-93304
(D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange
- Oct 1, 2026CVE-2026-89135MediumCVE-2026-89135
Failed X509_verify_cert leaves unverified CA in shared CertManager
- Oct 1, 2026CVE-2026-89102HighCVSS 6.5CVE-2026-89102
OCSP stapling v2 multi accepts non-CA chain certificates as issuers
- Oct 1, 2026CVE-2026-94419LowCVSS 5.4CVE-2026-94419
Client session cache reference poisoning allows resumption with wrong server
- Oct 1, 2026CVE-2026-94418LowCVE-2026-94418
Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY
- Oct 1, 2026CVE-2026-89136HighCVE-2026-89136
Client accepts unsolicited RawPublicKey server certificate type
- Oct 1, 2026CVE-2026-89133MediumCVE-2026-89133
NameConstraints not enforced across unconstrained intermediate CA
- Oct 1, 2026CVE-2026-19444MediumCVSS 6.5CVE-2026-19444
Kubernetes kubectl cp path traversal on Windows allows arbitrary file writes
- Oct 1, 2026CVE-2026-42784HighCVSS 7.4CVE-2026-42784
Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusion
- Oct 1, 2026CVE-2026-17545MediumCVE-2026-17545
PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can cause DoS
- Oct 1, 2026CVE-2026-88831MediumCVSS 5.3CVE-2026-88831
Busybox: busybox: httpd silently fails open when ip deny rules contain invalid cidr prefix lengths
- Oct 1, 2026CVE-2026-88832MediumCVSS 6.1CVE-2026-88832
Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label buffer, causing heap overflow
- Oct 1, 2026CVE-2026-88839MediumCVSS 6.7CVE-2026-88839
Busybox: busybox: passwd/group parser writes heap pointers out of bounds due to stale tokenize() endpoint
- Oct 1, 2026CVE-2026-103111HighCVSS 7.6CVE-2026-103111
PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.