| | CVE-2026-21519 | Microsoft | high | 7.8 | 3.6%
| ⚠ KEV | Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an au… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21518 | Microsoft | high | 8.8 | 0.0%
| | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilo… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21517 | Microsoft | medium | 4.7 | 0.0%
| | Improper link resolution before file access ('link following') in Windows App for Mac allows an auth… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21512 | Microsoft | medium | 6.5 | 0.1%
| | Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform s… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21259 | Microsoft | high | 7.8 | 0.0%
| | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate priv… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21258 | Microsoft | medium | 5.5 | 0.0%
| | Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose info… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21260 | Microsoft | high | 7.5 | 0.0%
| | Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an una… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21248 | Microsoft | high | 7.3 | 0.0%
| | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21247 | Microsoft | high | 7.3 | 0.0%
| | Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21246 | Microsoft | high | 7.8 | 0.0%
| | Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate … | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21242 | Microsoft | high | 7.0 | 0.0%
| | Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges lo… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21235 | Microsoft | high | 7.3 | 0.0%
| | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges l… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21234 | Microsoft | high | 7.0 | 0.0%
| | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21236 | Microsoft | high | 7.8 | 0.0%
| | Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized att… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21218 | Microsoft | high | 7.5 | 0.0%
| | Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoo… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-23655 | Microsoft | medium | 6.5 | 0.1%
| | Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21523 | Microsoft | high | 8.0 | 0.0%
| | Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an auth… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21229 | Microsoft | high | 8.0 | 0.1%
| | Improper input validation in Power BI allows an authorized attacker to execute code over a network. | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21533 | Microsoft | high | 7.8 | 3.1%
| ⚠ KEV | Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate pri… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21513 | Microsoft | high | 8.8 | 5.2%
| ⚠ KEV | Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a securit… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21522 | Microsoft | medium | 6.7 | 0.0%
| | Improper neutralization of special elements used in a command ('command injection') in Azure Compute… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21527 | Microsoft | medium | 6.5 | 0.1%
| | User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21528 | Microsoft | medium | 6.5 | 0.1%
| | Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to discl… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21531 | Microsoft | critical | 9.8 | 0.3%
| | Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over … | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21510 | Microsoft | high | 8.8 | 4.2%
| ⚠ KEV | Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security f… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21537 | Microsoft | high | 8.8 | 0.1%
| | Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an … | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21529 | Microsoft | medium | 5.7 | 0.0%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsi… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21514 | Microsoft | high | 7.8 | 4.9%
| ⚠ KEV | Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized … | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21525 | Microsoft | medium | 6.2 | 3.7%
| ⚠ KEV | Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21516 | Microsoft | high | 8.8 | 0.0%
| | Improper neutralization of special elements used in a command ('command injection') in Github Copilo… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21511 | Microsoft | high | 7.5 | 0.2%
| | Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to per… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21508 | Microsoft | high | 7.0 | 0.0%
| | Improper authentication in Windows Storage allows an authorized attacker to elevate privileges local… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21261 | Microsoft | medium | 5.5 | 0.0%
| | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21257 | Microsoft | high | 8.0 | 0.0%
| | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilo… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21256 | Microsoft | high | 8.8 | 0.0%
| | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilo… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21255 | Microsoft | high | 8.8 | 0.0%
| | Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security featur… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21253 | Microsoft | high | 7.0 | 0.0%
| | Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally. | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21251 | Microsoft | high | 7.8 | 0.0%
| | Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privilege… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21250 | Microsoft | high | 7.8 | 0.0%
| | Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privilege… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21249 | Microsoft | low | 3.3 | 0.0%
| | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spo… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21245 | Microsoft | high | 7.8 | 0.0%
| | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21244 | Microsoft | high | 7.3 | 0.0%
| | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21243 | Microsoft | high | 7.5 | 0.1%
| | Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthori… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21240 | Microsoft | high | 7.8 | 0.0%
| | Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker … | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21241 | Microsoft | high | 7.0 | 0.0%
| | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21239 | Microsoft | high | 7.8 | 0.0%
| | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21238 | Microsoft | high | 7.8 | 0.0%
| | Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attack… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21237 | Microsoft | high | 7.0 | 0.0%
| | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21232 | Microsoft | high | 7.8 | 0.0%
| | Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privilege… | Feb 10, 2026 | Mar 13, 2026 |
| | CVE-2026-21231 | Microsoft | high | 7.8 | 0.0%
| | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Feb 10, 2026 | Mar 13, 2026 |