CVE-2026-56165 Microsoft
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
CVSS 9.8
Update availability Patch status unknown Affected: Microsoft Account
Updated July 23, 2026
CVE-2026-56167 Microsoft
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
CVSS 8.5
Update availability Patch status unknown Affected: Azure AI Search
Updated July 23, 2026
CVE-2026-56191 Microsoft
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
CVSS 10.0
Update availability Patch status unknown Affected: Microsoft Exchange Online
Updated July 23, 2026
CVE-2026-57106 Microsoft
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
Update availability Patch status unknown Affected: Microsoft Purview Data Governance
Updated July 23, 2026
CVE-2026-58275 Microsoft
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
Update availability Patch status unknown Affected: Azure DNS
Updated July 23, 2026
CVE-2026-58630 Microsoft
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
Update availability Patch status unknown Affected: Azure App Service for Linux
Updated July 23, 2026
CVE-2026-62825 Microsoft
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
Update availability Patch status unknown Affected: Azure Key Vault
Updated July 23, 2026
CVE-2026-42533 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.1
Update availability Patch status unknown Affected: azl3 nginx 1.28.3-6 on Azure Linux 3.0
Updated July 22, 2026
CVE-2026-50522 Microsoft
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVSS 9.8
Update availability Security update available Affected: Microsoft SharePoint Enterprise Server 2016 · Microsoft SharePoint Server 2019 · +1 more
Updated July 14, 2026
CVE-2026-60082 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.1
Update availability Patch status unknown Affected: azl3 perl-DBI 1.643-5 on Azure Linux 3.0
Updated July 21, 2026
CVE-2026-15043 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 perl-DBI 1.643-5 on Azure Linux 3.0
Updated July 21, 2026
CVE-2026-57433 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 perl 5.38.2-512 on Azure Linux 3.0
Updated July 21, 2026
CVE-2026-63882 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.144.1-1 on Azure Linux 3.0
Updated July 21, 2026
CVE-2026-63881 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.144.1-1 on Azure Linux 3.0
Updated July 21, 2026
CVE-2026-63959 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.144.1-1 on Azure Linux 3.0
Updated July 21, 2026
CVE-2026-63833 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.144.1-1 on Azure Linux 3.0
Updated July 20, 2026
CVE-2026-53376 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.144.1-1 on Azure Linux 3.0
Updated July 20, 2026
CVE-2026-53403 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.144.1-1 on Azure Linux 3.0
Updated July 20, 2026
CVE-2026-53374 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.144.1-1 on Azure Linux 3.0
Updated July 20, 2026
CVE-2026-58644 Microsoft
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVSS 9.8
Update availability Security update available Affected: Microsoft SharePoint Enterprise Server 2016 · Microsoft SharePoint Server 2019 · +1 more
Updated July 15, 2026
CVE-2026-42982 Microsoft
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +23 more
Updated July 14, 2026
CVE-2026-48564 Microsoft
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +13 more
Updated July 14, 2026
CVE-2026-49164 Microsoft
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
CVSS 8.1
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +25 more
Updated July 14, 2026
CVE-2026-49796 Microsoft
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +25 more
Updated July 14, 2026