Skip to main content
Griffin Technology PartnersGTP

Public security advisories

GTP Security Intelligence

Current vulnerabilities, known exploitation, Microsoft security updates, and practical guidance from Griffin Technology Partners.

Primary sources

Microsoft Security Response Center
CISA Known Exploited Vulnerabilities

Subscribe via RSS

Vulnerability intelligence

Security bulletins

Last collection: October 9, 2026
Six-hour refresh · Public-source information only

2,707 bulletins · Page 20 of 113

JSON feed
High
CVE-2026-96269Microsoft

GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions.

GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no particular user settings are required to trigger it.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: azl3 emacs 29.4-6 on Azure Linux 3.0

Updated

High
CVE-2026-55969Microsoft

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()

Review the authoritative advisory for the vulnerability description and applicability.

CVSS
7.5
Update availability
Security update available

Affected: azl3 influxdb 2.7.5-19 on Azure Linux 3.0 · azl3 kata-containers-cc 3.15.0.aks0-16 on Azure Linux 3.0 · +6 more

Updated

High
CVE-2026-17527Microsoft

Virt-cdi-operator: containerized-data-importer: cdi.kubevirt.io:view aggregated clusterrole grants create on datavolumes/source, allowing unauthorized pvc clone

Review the authoritative advisory for the vulnerability description and applicability.

CVSS
7.7
Update availability
Security update available

Affected: azl3 containerized-data-importer 1.62.0-7 on Azure Linux 3.0 · azl3 containerized-data-importer 1.62.0-8 on Azure Linux 3.0 · +3 more

Updated

High
CVE-2026-66373Microsoft

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending…

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.

CVSS
7.5
Update availability
Patch status unknown

Affected: azl3 valkey 8.0.10-1 on Azure Linux 3.0 · azl3 valkey 8.0.11-1 on Azure Linux 3.0 · +1 more

Updated

Sources & coverage

The collection starts with 90 days of Microsoft updates and CISA additions, plus older Microsoft vulnerabilities still listed by CISA. Older entries do not imply that a product remains supported. Counts describe this collection, not every vulnerability or any customer environment.

Microsoft Security Response Center (opens in a new tab)

Last successful check: October 9, 2026

CISA Known Exploited Vulnerabilities (opens in a new tab)

Last successful check: October 9, 2026

Managed by GTP?

Griffin Technology Partners managed customers may receive additional environment-specific security guidance and remediation assistance through their managed services relationship.

Security bulletins are provided for informational purposes and compiled from authoritative public sources. Vulnerability applicability varies by environment. Validate affected products, configuration, compatibility requirements, and vendor guidance before making production changes.