Skip to main content
Griffin Technology PartnersGTP

Public security advisories

GTP Security Intelligence

Current vulnerabilities, known exploitation, Microsoft security updates, and practical guidance from Griffin Technology Partners.

Primary sources

Microsoft Security Response Center
CISA Known Exploited Vulnerabilities

Subscribe via RSS

Vulnerability intelligence

Security bulletins

Last collection: October 9, 2026
Six-hour refresh · Public-source information only

571 bulletins · Page 7 of 24

JSON feed
Critical
CVE-2026-38968Microsoft

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking.

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.

CVSS
9.8
Update availability
Security update available

Affected: azl3 ntopng 5.2.1-6 on Azure Linux 3.0 · azl3 ntopng 5.2.1-7 on Azure Linux 3.0

Updated

Critical
CVE-2026-53009Microsoft

ice: fix double-free of tx_buf skb

Review the authoritative advisory for the vulnerability description and applicability.

CVSS
9.8
Update availability
Security update available

Affected: azl3 kernel 6.6.143.1-1 on Azure Linux 3.0 · azl3 kernel 6.6.144.1-1 on Azure Linux 3.0 · +3 more

Updated

Critical
CVE-2026-83498Microsoft

Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

CVSS
7.8
Update availability
Security update available

Affected: Windows 11 Version 23H2 for ARM64-based Systems · Windows 11 Version 23H2 for x64-based Systems · +8 more

Updated

Critical
CVE-2026-91749Microsoft

Chromium CVE-2026-91749: Use after free

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases ]( https://chromereleases.googleblog.com/2026 )) for more information.

CVSS
9.6
Update availability
Patch status unknown

Affected: Microsoft Edge (Chromium-based)

Updated

Sources & coverage

The collection starts with 90 days of Microsoft updates and CISA additions, plus older Microsoft vulnerabilities still listed by CISA. Older entries do not imply that a product remains supported. Counts describe this collection, not every vulnerability or any customer environment.

Microsoft Security Response Center (opens in a new tab)

Last successful check: October 9, 2026

CISA Known Exploited Vulnerabilities (opens in a new tab)

Last successful check: October 9, 2026

Managed by GTP?

Griffin Technology Partners managed customers may receive additional environment-specific security guidance and remediation assistance through their managed services relationship.

Security bulletins are provided for informational purposes and compiled from authoritative public sources. Vulnerability applicability varies by environment. Validate affected products, configuration, compatibility requirements, and vendor guidance before making production changes.