CVE-2026-64078 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.144.1-1 on Azure Linux 3.0 · azl3 kernel 6.6.150.1-1 on Azure Linux 3.0 · +2 more
Updated September 24, 2026
CVE-2026-89526 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.1
Update availability Security update available Affected: azl3 kernel 6.6.150.1-1 on Azure Linux 3.0 · azl3 kernel 6.6.152.1-1 on Azure Linux 3.0 · +1 more
Updated September 24, 2026
CVE-2026-64079 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.144.1-1 on Azure Linux 3.0 · azl3 kernel 6.6.150.1-1 on Azure Linux 3.0 · +2 more
Updated September 24, 2026
CVE-2026-74345 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.150.1-1 on Azure Linux 3.0 · azl3 kernel 6.6.152.1-1 on Azure Linux 3.0 · +1 more
Updated September 24, 2026
CVE-2026-89631 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.1
Update availability Security update available Affected: azl3 kernel 6.6.150.1-1 on Azure Linux 3.0 · azl3 kernel 6.6.152.1-1 on Azure Linux 3.0 · +1 more
Updated September 24, 2026
CVE-2026-38968 Microsoft
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.
CVSS 9.8
Update availability Security update available Affected: azl3 ntopng 5.2.1-6 on Azure Linux 3.0 · azl3 ntopng 5.2.1-7 on Azure Linux 3.0
Updated September 24, 2026
CVE-2026-80616 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.150.1-1 on Azure Linux 3.0 · azl3 kernel 6.6.152.1-1 on Azure Linux 3.0 · +1 more
Updated September 24, 2026
CVE-2026-80698 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.150.1-1 on Azure Linux 3.0 · azl3 kernel 6.6.152.1-1 on Azure Linux 3.0 · +1 more
Updated September 24, 2026
CVE-2026-80637 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.150.1-1 on Azure Linux 3.0 · azl3 kernel 6.6.152.1-1 on Azure Linux 3.0 · +1 more
Updated September 24, 2026
CVE-2026-80650 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.150.1-1 on Azure Linux 3.0 · azl3 kernel 6.6.152.1-1 on Azure Linux 3.0 · +1 more
Updated September 24, 2026
CVE-2026-80654 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.150.1-1 on Azure Linux 3.0 · azl3 kernel 6.6.152.1-1 on Azure Linux 3.0 · +1 more
Updated September 24, 2026
CVE-2026-90037 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Security update available Affected: azl3 kernel 6.6.150.1-1 on Azure Linux 3.0 · azl3 kernel 6.6.152.1-1 on Azure Linux 3.0 · +1 more
Updated September 24, 2026
CVE-2026-53009 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Security update available Affected: azl3 kernel 6.6.143.1-1 on Azure Linux 3.0 · azl3 kernel 6.6.144.1-1 on Azure Linux 3.0 · +3 more
Updated September 24, 2026
CVE-2026-80653 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.150.1-1 on Azure Linux 3.0 · azl3 kernel 6.6.152.1-1 on Azure Linux 3.0 · +1 more
Updated September 24, 2026
CVE-2026-80694 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.150.1-1 on Azure Linux 3.0 · azl3 kernel 6.6.152.1-1 on Azure Linux 3.0 · +1 more
Updated September 24, 2026
CVE-2026-89972 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Security update available Affected: azl3 kernel 6.6.150.1-1 on Azure Linux 3.0 · azl3 kernel 6.6.152.1-1 on Azure Linux 3.0 · +1 more
Updated September 24, 2026
CVE-2026-80607 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.150.1-1 on Azure Linux 3.0 · azl3 kernel 6.6.152.1-1 on Azure Linux 3.0 · +1 more
Updated September 24, 2026
CVE-2026-90036 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Security update available Affected: azl3 kernel 6.6.150.1-1 on Azure Linux 3.0 · azl3 kernel 6.6.152.1-1 on Azure Linux 3.0 · +1 more
Updated September 24, 2026
CVE-2026-89422 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 erlang 26.2.5.21-6 on Azure Linux 3.0
Updated September 24, 2026
CVE-2026-77405 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Security update available Affected: azl3 keda 2.14.1-18 on Azure Linux 3.0 · azl3 keda 2.14.1-19 on Azure Linux 3.0 · +2 more
Updated September 24, 2026
CVE-2026-55123 Microsoft
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated September 21, 2026
CVE-2026-63532 Microsoft
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated September 21, 2026
CVE-2026-83498 Microsoft
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 11 Version 23H2 for ARM64-based Systems · Windows 11 Version 23H2 for x64-based Systems · +8 more
Updated September 21, 2026
CVE-2026-91749 Microsoft
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases ]( https://chromereleases.googleblog.com/2026 )) for more information.
CVSS 9.6
Update availability Patch status unknown Affected: Microsoft Edge (Chromium-based)
Updated September 17, 2026