CVE-2026-98199 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.157.1-1 on Azure Linux 3.0
Updated October 7, 2026
CVE-2026-75820 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 thrift 0.24.0-1 on Azure Linux 3.0
Updated October 7, 2026
CVE-2026-85483 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 thrift 0.24.0-1 on Azure Linux 3.0
Updated October 7, 2026
CVE-2026-98254 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.157.1-1 on Azure Linux 3.0
Updated October 7, 2026
CVE-2026-105712 Microsoft
gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk.
CVSS 3.6
Update availability Patch status unknown Affected: azl3 gnupg2 2.4.9-3 on Azure Linux 3.0
Updated October 7, 2026
CVE-2026-91137 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 thrift 0.24.0-1 on Azure Linux 3.0
Updated October 7, 2026
CVE-2026-98252 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.157.1-1 on Azure Linux 3.0
Updated October 7, 2026
CVE-2026-105773 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.0
Update availability Patch status unknown Affected: azl3 clamav 1.5.4-2 on Azure Linux 3.0
Updated October 7, 2026
CVE-2026-50387 Microsoft
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft Office 365 for Mac · Microsoft Office LTSC for Mac 2021 · +29 more
Updated October 6, 2026
CVE-2026-54128 Microsoft
Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.
CVSS 8.4
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +25 more
Updated October 6, 2026
CVE-2026-61927 Microsoft
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 11 Version 24H2 for ARM64-based Systems · Windows 11 Version 24H2 for x64-based Systems · +6 more
Updated October 6, 2026
CVE-2026-61936 Microsoft
Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.
CVSS 5.5
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +20 more
Updated October 6, 2026
CVE-2026-62698 Microsoft
Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated October 6, 2026
CVE-2026-72131 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 5.3
Update availability Patch status unknown Affected: azl3 kernel 6.6.157.1-1 on Azure Linux 3.0
Updated October 6, 2026
CVE-2026-83745 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 thrift 0.24.0-1 on Azure Linux 3.0
Updated October 5, 2026
CVE-2026-66858 Microsoft
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: skip() does not apply the recursion limit (Python accelerator, PHP, Perl, Lua, Smalltalk, OCaml)
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 thrift 0.24.0-1 on Azure Linux 3.0
Updated October 5, 2026
CVE-2026-83632 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 thrift 0.24.0-1 on Azure Linux 3.0
Updated October 5, 2026
CVE-2026-96287 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 thrift 0.24.0-1 on Azure Linux 3.0
Updated October 5, 2026
CVE-2026-94654 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 thrift 0.24.0-1 on Azure Linux 3.0
Updated October 5, 2026
CVE-2026-66054 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 thrift 0.24.0-1 on Azure Linux 3.0
Updated October 5, 2026
CVE-2026-94656 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 thrift 0.24.0-1 on Azure Linux 3.0
Updated October 5, 2026
CVE-2026-96277 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 thrift 0.24.0-1 on Azure Linux 3.0
Updated October 5, 2026
CVE-2026-96286 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 thrift 0.24.0-1 on Azure Linux 3.0
Updated October 5, 2026
CVE-2026-68804 Microsoft
Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +12 more
Updated October 5, 2026