<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Advisory &#8211; First Hackers News</title>
	<atom:link href="https://firsthackersnews.com/category/security-advisory/feed/" rel="self" type="application/rss+xml" />
	<link>https://firsthackersnews.com</link>
	<description>Latest cybersecurity news, real attacks, and practical IOCs—made simple and actionable.</description>
	<lastBuildDate>Wed, 12 Aug 2026 16:54:51 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.7</generator>

<image>
	<url>https://firsthackersnews.com/wp-content/uploads/2026/03/cropped-FHN_512x512-32x32.png</url>
	<title>Security Advisory &#8211; First Hackers News</title>
	<link>https://firsthackersnews.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>WhatsApp Scam Alert: New Protection Against Hackers</title>
		<link>https://firsthackersnews.com/whatsapp-scam-alert-feature/</link>
					<comments>https://firsthackersnews.com/whatsapp-scam-alert-feature/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 12 Aug 2026 16:54:49 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[AI security]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Messaging Security]]></category>
		<category><![CDATA[Meta]]></category>
		<category><![CDATA[Online scams]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Scam Alert]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[whatsapp]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12190</guid>

					<description><![CDATA[<p>WhatsApp has introduced a new optional feature called Scam Alert to help users identify potentially fraudulent messages while</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-scam-alert-feature/">WhatsApp Scam Alert: New Protection Against Hackers</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>WhatsApp has introduced a new optional feature called <strong>Scam Alert</strong> to help users identify potentially fraudulent messages while keeping its end-to-end encryption intact.</p>



<p>The feature is designed to address the growing use of more convincing scams, including messages created with the help of AI. Instead of sending messages to WhatsApp’s servers for analysis, Scam Alert uses a small machine learning model that runs directly on the user’s device.</p>



<p>Once enabled, the model examines messages from people who are not saved as contacts. It looks for patterns in the conversation and language that may indicate common scam techniques.</p>



<p>The message itself stays on the device during this process. WhatsApp says it does not automatically send messages to Meta, WhatsApp, or another third party for review. Users decide what happens next.</p>



<p>If a message appears suspicious, WhatsApp can display a warning to the recipient. The user can then choose to <strong>block the sender, report the conversation, continue chatting, or mark the conversation as trusted</strong> if they believe the warning is incorrect.</p>



<h3 class="wp-block-heading">Privacy Is a Key Part of Scam Alert</h3>



<p>WhatsApp says the system was designed around three main ideas: <strong>local processing, no automatic reporting, and user control</strong>.</p>



<p>The company still needs some information to understand how well the feature performs. Instead of collecting individual messages, WhatsApp uses a privacy-focused analytics system that gathers limited information such as how many warnings were displayed and what actions users took.</p>



<p>This information is processed using <strong>Trusted Execution Environments (TEEs)</strong> and additional privacy techniques before aggregated statistics are sent to Meta.</p>



<h3 class="wp-block-heading">Protecting the AI Model</h3>



<p>Another concern is making sure attackers cannot secretly deliver a modified version of the scam-detection model to specific users.</p>



<p>WhatsApp says each model version is published with a <strong>SHA-256 hash</strong> in an append-only transparency system before it is deployed. This creates a record that can be used to verify that the model has not been secretly changed.</p>



<p>Model downloads also use an <strong>Oblivious HTTP (OHTTP) relay</strong>, which helps prevent the server from directly linking a model request to a user&#8217;s IP address.</p>



<p>WhatsApp says even the process used to assign users to different model versions for testing happens locally on their devices rather than being controlled by the server.</p>



<h3 class="wp-block-heading">Additional Security Controls</h3>



<p>The company says Scam Alert was designed to protect against several types of threats, including outside attackers, malicious employees, and compromised third-party suppliers.</p>



<p>Its security measures include isolated confidential computing environments, encrypted memory, and additional protections around the systems running the analytics infrastructure.</p>



<p>Users can also check information about the feature through WhatsApp&#8217;s transparency controls. The in-app activity section shows details such as which messages were analyzed and which model version was used.</p>



<h3 class="wp-block-heading">External Researchers Can Test the System</h3>



<p>WhatsApp is also expanding its <strong>Bug Bounty program</strong> to cover parts of the Scam Alert technology, including the machine learning models and analytics infrastructure.</p>



<p>This gives security researchers an opportunity to look for weaknesses and verify whether the system is being used only for its stated purpose of detecting scams.</p>



<h3 class="wp-block-heading">Limited Beta Release</h3>



<p>Scam Alert is initially being introduced through a <strong>limited beta rollout</strong>. WhatsApp says it plans to continue testing the technology with security researchers before making it more widely available.</p>



<p>The company also plans to publish a technical white paper explaining how the system works in greater detail.</p>



<p>The approach reflects a growing focus on building AI-powered security features without giving up user privacy. Instead of sending private conversations to the cloud for analysis, WhatsApp is attempting to combine <strong>on-device AI, confidential computing, and transparency mechanisms</strong> to detect scams while keeping message content protected.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-scam-alert-feature/">WhatsApp Scam Alert: New Protection Against Hackers</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/whatsapp-scam-alert-feature/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>LLM API Bugs Leak Hidden Reasoning Traces</title>
		<link>https://firsthackersnews.com/llm-api-vulnerability-hidden-reasoning/</link>
					<comments>https://firsthackersnews.com/llm-api-vulnerability-hidden-reasoning/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 11 Aug 2026 22:08:32 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[AI security]]></category>
		<category><![CDATA[AI Vulnerability]]></category>
		<category><![CDATA[Anthropic]]></category>
		<category><![CDATA[api security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[Generative AI]]></category>
		<category><![CDATA[Google Gemini]]></category>
		<category><![CDATA[LLM]]></category>
		<category><![CDATA[openAI]]></category>
		<category><![CDATA[Prompt Injection]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12186</guid>

					<description><![CDATA[<p>A new security research report has uncovered a serious weakness in the way major AI providers protect the</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/llm-api-vulnerability-hidden-reasoning/">LLM API Bugs Leak Hidden Reasoning Traces</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A new security research report has uncovered a serious weakness in the way major AI providers protect the hidden reasoning generated by their large language models.</p>



<p>The research involves <strong>OpenAI, Anthropic, and Google</strong>, and shows that encrypted reasoning data produced by powerful models could potentially be reused with less restricted models from the same provider. In some cases, this could allow the hidden reasoning to be reconstructed in readable text.</p>



<p>Researchers from the <strong>ELLIS Institute Tübingen, Max Planck Institute, MATS Research, and Snyk</strong> investigated the issue across the Claude, GPT, and Gemini ecosystems. The attack does not require special privileges and can be carried out through normal API access.</p>



<h2 class="wp-block-heading"><strong>How the Attack Works</strong></h2>



<p>Modern reasoning models perform additional processing before producing their final answers. Much of this internal reasoning is intentionally hidden from users because it may contain sensitive information, system instructions, safety-related decisions, or proprietary model behavior.</p>



<p>Instead of keeping all conversation state on the server, some AI APIs return encrypted data that can be sent back with later requests. This allows the model to continue a conversation without storing every detail on the provider&#8217;s side.</p>



<p>Researchers found a potential weakness in how these encrypted reasoning packages were protected.</p>



<p>The data was not sufficiently tied to the <strong>specific model, user, or session</strong> that originally created it. This meant a reasoning package generated by a more heavily protected model could potentially be submitted to another model within the same provider&#8217;s ecosystem.</p>



<h2 class="wp-block-heading"><strong>Using Smaller Models to Reveal Hidden Data</strong></h2>



<p>The researchers demonstrated an attack technique in which a reasoning package from a powerful model was passed to a less restricted model.</p>



<p>The smaller model could then be prompted to reproduce information contained inside the encrypted package.</p>



<p>This creates an unusual security problem. The attacker does not necessarily need to break the encryption directly. Instead, another model can potentially act as an intermediary that helps expose the information.</p>



<p>The research team reported similar behavior across the <strong>GPT, Claude, and Gemini</strong> model families.</p>



<p>Researchers also compared the recovered reasoning data with usage information provided through the APIs to determine whether the extracted material corresponded to the original reasoning process.</p>



<h2 class="wp-block-heading"><strong>Hidden Reasoning Can Contain Sensitive Information</strong></h2>



<p>The concern goes beyond exposing how an AI model thinks.</p>



<p>Researchers analyzed thousands of publicly available AI agent transcripts collected from sources such as GitHub and Hugging Face. Their analysis identified hundreds of pieces of potentially sensitive information inside recovered reasoning data.</p>



<p>This included:</p>



<ul class="wp-block-list">
<li><strong>367</strong> pieces of personally identifiable information</li>



<li><strong>182</strong> hardcoded credentials</li>



<li><strong>62</strong> API keys</li>



<li><strong>33</strong> passwords</li>



<li><strong>30</strong> personal email addresses</li>
</ul>



<p>The problem is that some of this information may never appear in the model&#8217;s visible response.</p>



<p>A developer could therefore publish an AI session or agent log believing it contains no secrets, while sensitive information remains hidden inside associated reasoning data.</p>



<h2 class="wp-block-heading"><strong>A New Risk for AI Agents</strong></h2>



<p>The research also highlights a potential problem for autonomous AI systems.</p>



<p>If security monitoring only examines the visible conversation between a user and an AI agent, malicious instructions hidden inside reasoning-related data could potentially escape detection.</p>



<p>An attacker could attempt to place instructions inside an encrypted reasoning package and have those instructions processed later by an AI agent.</p>



<p>This creates a potential <strong>indirect prompt injection</strong> scenario where the malicious content is not obvious in the conversation that security tools are monitoring.</p>



<p>For organizations using AI agents to interact with cloud services, databases, code repositories, or business applications, this type of hidden input deserves particular attention.</p>



<h2 class="wp-block-heading"><strong>Which AI Platforms Were Studied?</strong></h2>



<p>The research covered major model ecosystems from three providers:</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><th><strong>Provider</strong></th><th><strong>Models Studied</strong></th><th><strong>Potential Risk</strong></th></tr><tr><td><strong>Anthropic</strong></td><td>Claude family</td><td>Hidden reasoning, system prompts, credentials</td></tr><tr><td><strong>OpenAI</strong></td><td>GPT family</td><td>Reasoning data, safety information, sensitive content</td></tr><tr><td><strong>Google</strong></td><td>Gemini family</td><td>Secrets, hidden instructions, and personal information</td></tr></tbody></table></figure>



<p>The exact attack paths and model combinations varied between providers, but the broader issue was similar: <strong>reasoning data was not sufficiently isolated from other models within the same ecosystem</strong>.</p>



<h2 class="wp-block-heading"><strong>Providers Have Already Responded</strong></h2>



<p>The researchers reported the findings to the affected companies through responsible disclosure.</p>



<p><strong>OpenAI, Anthropic, and Google acknowledged the research and introduced server-side protections.</strong> According to the researchers, the original proof-of-concept attacks could no longer be reproduced against the updated API implementations.</p>



<p>That reduces the immediate risk from the specific attack demonstrated in the research, but the findings highlight a larger issue for the AI industry.</p>



<p>As AI systems become more complex, security controls need to protect not only visible prompts and responses but also the internal data exchanged between models and supporting services.</p>



<h2 class="wp-block-heading"><strong>How Organizations Can Reduce the Risk</strong></h2>



<p>AI providers and companies building applications around LLMs can take several steps to protect sensitive reasoning-related data.</p>



<p><strong>Bind encrypted data to its source.</strong> Reasoning packages should be cryptographically linked to the specific model, user, and session that created them.</p>



<p><strong>Separate model tiers.</strong> A payload generated by one model should not automatically be accepted by another model unless that behavior is explicitly intended and securely controlled.</p>



<p><strong>Rotate older cryptographic keys.</strong> Where historical encrypted data may have been exposed, organizations should consider key rotation and invalidation strategies.</p>



<p><strong>Protect AI logs.</strong> Developers should treat reasoning-related payloads, signatures, and encrypted model data as sensitive information. These fields should be removed or sanitized before logs are shared publicly.</p>



<h2 class="wp-block-heading"><strong>Why This Matters</strong></h2>



<p>The research shows that protecting AI systems is not only about securing the model itself.</p>



<p>Modern LLM platforms involve APIs, model tiers, encrypted payloads, agent frameworks, logging systems, and multiple supporting services. A weakness in the connection between these components can create a security problem even when the underlying model remains protected.</p>



<p>For organizations adopting AI agents and reasoning models, the lesson is clear: <strong>hidden data should be treated as sensitive data, even when users cannot see it.</strong></p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/llm-api-vulnerability-hidden-reasoning/">LLM API Bugs Leak Hidden Reasoning Traces</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/llm-api-vulnerability-hidden-reasoning/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>394 Microsoft Flaws Patched in August Update</title>
		<link>https://firsthackersnews.com/microsoft-august-2026-patch-tuesday/</link>
					<comments>https://firsthackersnews.com/microsoft-august-2026-patch-tuesday/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 11 Aug 2026 15:54:00 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[CVE]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[Security updates]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[Zero-day]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12182</guid>

					<description><![CDATA[<p>Microsoft’s August 2026 security release is a big one. The company has fixed 394 vulnerabilities across its software</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/microsoft-august-2026-patch-tuesday/">394 Microsoft Flaws Patched in August Update</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Microsoft’s August 2026 security release is a big one. The company has fixed <strong>394 vulnerabilities</strong> across its software ecosystem, covering Windows, Office, SharePoint, Azure, PowerShell, .NET, Visual Studio Code, and other products.</p>



<p>The update was released on <strong>August 11, 2026</strong>, and security teams have another important reason to move quickly: <strong>three of the vulnerabilities were already publicly known or are being actively exploited</strong>, according to Microsoft’s advisory information.</p>



<p>For organizations with large Microsoft environments, this is a release that should be reviewed early rather than left for the normal monthly patching cycle.</p>



<h2 class="wp-block-heading"><strong>Three Vulnerabilities Need Immediate Attention</strong></h2>



<p>The most important issues this month involve Windows components.</p>



<p><strong>CVE-2026-72971</strong> affects the Windows Container Isolation File System Filter Driver (<code>unionfs.sys</code>). Microsoft rates it as Important and says the vulnerability was publicly disclosed before the security update was released. The issue could allow an attacker to tamper with protected system or container-related data.</p>



<p>Another publicly disclosed issue, <strong>CVE-2026-62832</strong>, affects the Windows User Profile Service. It is an elevation-of-privilege vulnerability, meaning an attacker with an existing foothold could potentially use it to obtain additional permissions on a vulnerable machine.</p>



<p>The biggest concern is <strong>CVE-2026-68820</strong>. Microsoft lists this Windows WinSock-related vulnerability as <strong>actively exploited in the wild</strong>. Because attackers are already using the flaw, organizations should give this update priority and investigate potentially affected endpoints.</p>



<h2 class="wp-block-heading"><strong>Where the 394 Vulnerabilities Fall</strong></h2>



<p>The vulnerabilities fixed this month cover several major security categories:</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><th><strong>Category</strong></th><th><strong>Count</strong></th></tr><tr><td>Elevation of Privilege</td><td>150</td></tr><tr><td>Remote Code Execution</td><td>132</td></tr><tr><td>Information Disclosure</td><td>66</td></tr><tr><td>Spoofing</td><td>21</td></tr><tr><td>Denial of Service</td><td>12</td></tr><tr><td>Security Feature Bypass</td><td>9</td></tr><tr><td>Tampering</td><td>4</td></tr><tr><td><strong>Total</strong></td><td><strong>394</strong></td></tr></tbody></table></figure>



<p>The numbers show that privilege escalation and remote code execution continue to make up a significant portion of Microsoft&#8217;s monthly security workload.</p>



<p>For defenders, this means patching should not focus only on vulnerabilities carrying a Critical rating. An Important vulnerability can still become dangerous when it is combined with another weakness or used after an attacker gains initial access.</p>



<h2 class="wp-block-heading"><strong>SharePoint Remains a Key Target</strong></h2>



<p>Several SharePoint Server vulnerabilities are included in the August release.</p>



<p>Among them are <strong>CVE-2026-70355, CVE-2026-70326, and CVE-2026-70324</strong>, which involve privilege escalation, as well as <strong>CVE-2026-70321</strong>, a remote code execution vulnerability.</p>



<p>SharePoint environments deserve special attention because they often sit close to valuable corporate information. A compromised server could potentially give attackers access to documents, accounts, internal applications, or other parts of an organization&#8217;s environment.</p>



<p>Companies running internet-accessible SharePoint servers should therefore make these systems a priority during their patching process.</p>



<h2 class="wp-block-heading"><strong>Azure and Windows Infrastructure Also Affected</strong></h2>



<p>The update includes <strong>CVE-2026-71331</strong>, a Critical remote code execution vulnerability involving Microsoft Azure Attestation and Device Health Attestation services.</p>



<p>Issues affecting cloud and device-trust infrastructure can have broader implications because these services may be part of an organization&#8217;s authentication and security architecture.</p>



<p>Windows infrastructure is also covered by several fixes, including vulnerabilities affecting DNS, Windows Management Services, Windows Installer, and other system components.</p>



<p>Organizations should identify which of these services are actually deployed in their environments and prioritize systems that are externally accessible or support critical business operations.</p>



<h2 class="wp-block-heading"><strong>Don&#8217;t Forget PowerShell and Developer Machines</strong></h2>



<p>Microsoft has also patched vulnerabilities in <strong>PowerShell Core and .NET</strong>.</p>



<p>One PowerShell issue, <strong>CVE-2026-70337</strong>, could lead to remote code execution, while <strong>CVE-2026-70338</strong> involves a security feature bypass.</p>



<p>This is particularly relevant to security teams because PowerShell is both an essential administration tool and a common technique used during attacks. Keeping the platform patched should go hand in hand with monitoring suspicious PowerShell activity.</p>



<p>Developer environments should also be included in patching plans. Vulnerabilities affecting Visual Studio Code and GitHub Copilot could create additional risk when compromised developer machines have access to source repositories, cloud credentials, or CI/CD infrastructure.</p>



<p>A developer endpoint is not just another workstation. In many organizations, it can provide a pathway into systems that are critical to software development and production deployment.</p>



<h2 class="wp-block-heading"><strong>Microsoft Office Is Part of the Release</strong></h2>



<p>Office applications receive their share of security fixes as well.</p>



<p>The August updates cover <strong>Outlook, Word, Excel, PowerPoint, and Microsoft Office</strong>, including remote code execution and information-disclosure vulnerabilities.</p>



<p>These issues deserve attention because attackers frequently use Office documents and email as an entry point for phishing and malware campaigns. A vulnerability that appears less urgent in isolation can become much more serious when combined with social engineering.</p>



<h2 class="wp-block-heading"><strong>What Security Teams Should Do Now</strong></h2>



<p>The size of this month&#8217;s release can make patching 394 vulnerabilities seem overwhelming. The practical approach is to prioritize based on exposure and exploitability.</p>



<p>Start with the vulnerabilities that are actively exploited or publicly disclosed. Next, focus on Critical vulnerabilities and systems exposed to the internet, particularly SharePoint and important Azure or Windows infrastructure.</p>



<p>After that, review developer workstations, PowerShell installations, Office applications, and other Microsoft products used across the organization.</p>



<p>Teams should also use this update as an opportunity to check whether vulnerable systems are being properly identified through asset inventories and vulnerability-management tools.</p>



<p>The key takeaway from Microsoft&#8217;s August 2026 release is simple: don&#8217;t treat Patch Tuesday as just another routine update cycle. With 394 vulnerabilities addressed and an actively exploited Windows flaw among them, organizations should move quickly to identify their exposure and deploy the appropriate security fixes.</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">CVE Number</th><th>CVE Title</th><th>Max Severity</th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72971" target="_blank" rel="noopener">CVE-2026-72971</a></td><td>Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71331" target="_blank" rel="noopener">CVE-2026-71331</a></td><td>Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70355" target="_blank" rel="noopener">CVE-2026-70355</a></td><td>Microsoft SharePoint Server Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70354" target="_blank" rel="noopener">CVE-2026-70354</a></td><td>.NET Core Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70348" target="_blank" rel="noopener">CVE-2026-70348</a></td><td>Windows Management Services Denial of Service Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70347" target="_blank" rel="noopener">CVE-2026-70347</a></td><td>Windows Installer Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70346" target="_blank" rel="noopener">CVE-2026-70346</a></td><td>Windows Installer Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70345" target="_blank" rel="noopener">CVE-2026-70345</a></td><td>Windows Installer Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70344" target="_blank" rel="noopener">CVE-2026-70344</a></td><td>Windows Installer Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70340" target="_blank" rel="noopener">CVE-2026-70340</a></td><td>Azure CycleCloud Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70338" target="_blank" rel="noopener">CVE-2026-70338</a></td><td>Microsoft PowerShell Security Feature Bypass Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70337" target="_blank" rel="noopener">CVE-2026-70337</a></td><td>Microsoft PowerShell Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70336" target="_blank" rel="noopener">CVE-2026-70336</a></td><td>Visual Studio Code Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70335" target="_blank" rel="noopener">CVE-2026-70335</a></td><td>GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70330" target="_blank" rel="noopener">CVE-2026-70330</a></td><td>Windows DNS Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70329" target="_blank" rel="noopener">CVE-2026-70329</a></td><td>Microsoft Outlook Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70328" target="_blank" rel="noopener">CVE-2026-70328</a></td><td>Microsoft Excel Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70327" target="_blank" rel="noopener">CVE-2026-70327</a></td><td>Microsoft Excel Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70326" target="_blank" rel="noopener">CVE-2026-70326</a></td><td>Microsoft SharePoint Server Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70325" target="_blank" rel="noopener">CVE-2026-70325</a></td><td>Powerpoint Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70324" target="_blank" rel="noopener">CVE-2026-70324</a></td><td>Microsoft SharePoint Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70323" target="_blank" rel="noopener">CVE-2026-70323</a></td><td>Microsoft Office Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70322" target="_blank" rel="noopener">CVE-2026-70322</a></td><td>Powerpoint Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70321" target="_blank" rel="noopener">CVE-2026-70321</a></td><td>Microsoft SharePoint Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70320" target="_blank" rel="noopener">CVE-2026-70320</a></td><td>Powerpoint Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70319" target="_blank" rel="noopener">CVE-2026-70319</a></td><td>Microsoft Office Word Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70318" target="_blank" rel="noopener">CVE-2026-70318</a></td><td>Microsoft Excel Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70317" target="_blank" rel="noopener">CVE-2026-70317</a></td><td>Microsoft Office Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70316" target="_blank" rel="noopener">CVE-2026-70316</a></td><td>Powerpoint Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70315" target="_blank" rel="noopener">CVE-2026-70315</a></td><td>Microsoft Office Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70314" target="_blank" rel="noopener">CVE-2026-70314</a></td><td>Microsoft Office Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70313" target="_blank" rel="noopener">CVE-2026-70313</a></td><td>Microsoft PowerPoint Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70312" target="_blank" rel="noopener">CVE-2026-70312</a></td><td>Powerpoint Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70311" target="_blank" rel="noopener">CVE-2026-70311</a></td><td>Microsoft Office Word Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70310" target="_blank" rel="noopener">CVE-2026-70310</a></td><td>Microsoft Word Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70307" target="_blank" rel="noopener">CVE-2026-70307</a></td><td>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70306" target="_blank" rel="noopener">CVE-2026-70306</a></td><td>Microsoft Office SharePoint Spoofing Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70304" target="_blank" rel="noopener">CVE-2026-70304</a></td><td>Windows DNS Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70130" target="_blank" rel="noopener">CVE-2026-70130</a></td><td>Microsoft Office Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69320" target="_blank" rel="noopener">CVE-2026-69320</a></td><td>Visual Studio Code Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69306" target="_blank" rel="noopener">CVE-2026-69306</a></td><td>Visual Studio Code Security Feature Bypass Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69278" target="_blank" rel="noopener">CVE-2026-69278</a></td><td>Visual Studio Code Security Feature Bypass Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68821" target="_blank" rel="noopener">CVE-2026-68821</a></td><td>Windows Package Manager Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820" target="_blank" rel="noopener">CVE-2026-68820</a></td><td>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68819" target="_blank" rel="noopener">CVE-2026-68819</a></td><td>Windows Network File System Denial of Service Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68817" target="_blank" rel="noopener">CVE-2026-68817</a></td><td>Microsoft Excel Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68816" target="_blank" rel="noopener">CVE-2026-68816</a></td><td>Microsoft Excel Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68815" target="_blank" rel="noopener">CVE-2026-68815</a></td><td>Microsoft Excel Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68814" target="_blank" rel="noopener">CVE-2026-68814</a></td><td>Microsoft Excel Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68813" target="_blank" rel="noopener">CVE-2026-68813</a></td><td>Microsoft Excel Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68812" target="_blank" rel="noopener">CVE-2026-68812</a></td><td>Microsoft Excel Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68811" target="_blank" rel="noopener">CVE-2026-68811</a></td><td>Microsoft Excel Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68810" target="_blank" rel="noopener">CVE-2026-68810</a></td><td>Microsoft Excel Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68809" target="_blank" rel="noopener">CVE-2026-68809</a></td><td>Powerpoint Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68808" target="_blank" rel="noopener">CVE-2026-68808</a></td><td>Microsoft Excel Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68807" target="_blank" rel="noopener">CVE-2026-68807</a></td><td>Microsoft Excel Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68806" target="_blank" rel="noopener">CVE-2026-68806</a></td><td>Microsoft Excel Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68805" target="_blank" rel="noopener">CVE-2026-68805</a></td><td>Microsoft Excel Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68804" target="_blank" rel="noopener">CVE-2026-68804</a></td><td>Microsoft Excel Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68803" target="_blank" rel="noopener">CVE-2026-68803</a></td><td>Microsoft Excel Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68802" target="_blank" rel="noopener">CVE-2026-68802</a></td><td>Microsoft Excel Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68801" target="_blank" rel="noopener">CVE-2026-68801</a></td><td>Microsoft Excel Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68800" target="_blank" rel="noopener">CVE-2026-68800</a></td><td>Microsoft Excel Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68799" target="_blank" rel="noopener">CVE-2026-68799</a></td><td>Microsoft Excel Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68798" target="_blank" rel="noopener">CVE-2026-68798</a></td><td>Microsoft Excel Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68797" target="_blank" rel="noopener">CVE-2026-68797</a></td><td>Microsoft Excel Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68796" target="_blank" rel="noopener">CVE-2026-68796</a></td><td>Microsoft Excel Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68795" target="_blank" rel="noopener">CVE-2026-68795</a></td><td>Microsoft Excel Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68794" target="_blank" rel="noopener">CVE-2026-68794</a></td><td>Microsoft Excel Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68793" target="_blank" rel="noopener">CVE-2026-68793</a></td><td>Microsoft Excel Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68792" target="_blank" rel="noopener">CVE-2026-68792</a></td><td>Microsoft Office Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66810" target="_blank" rel="noopener">CVE-2026-66810</a></td><td>Microsoft Office Word Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66809" target="_blank" rel="noopener">CVE-2026-66809</a></td><td>Microsoft Office Graphics Component Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66808" target="_blank" rel="noopener">CVE-2026-66808</a></td><td>Microsoft SharePoint Server Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66807" target="_blank" rel="noopener">CVE-2026-66807</a></td><td>Microsoft Office Graphics Component Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66806" target="_blank" rel="noopener">CVE-2026-66806</a></td><td>Microsoft Office Word Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66805" target="_blank" rel="noopener">CVE-2026-66805</a></td><td>Microsoft SharePoint Server Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66804" target="_blank" rel="noopener">CVE-2026-66804</a></td><td>Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66802" target="_blank" rel="noopener">CVE-2026-66802</a></td><td>Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66799" target="_blank" rel="noopener">CVE-2026-66799</a></td><td>Windows Key Guard Elevation of Privilege Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66301" target="_blank" rel="noopener">CVE-2026-66301</a></td><td>Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65815" target="_blank" rel="noopener">CVE-2026-65815</a></td><td>Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65814" target="_blank" rel="noopener">CVE-2026-65814</a></td><td>Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65813" target="_blank" rel="noopener">CVE-2026-65813</a></td><td>Microsoft Exchange Server Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65811" target="_blank" rel="noopener">CVE-2026-65811</a></td><td>Power BI Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65810" target="_blank" rel="noopener">CVE-2026-65810</a></td><td>.NET Framework Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65807" target="_blank" rel="noopener">CVE-2026-65807</a></td><td>Microsoft Excel Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65806" target="_blank" rel="noopener">CVE-2026-65806</a></td><td>Azure CycleCloud Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65799" target="_blank" rel="noopener">CVE-2026-65799</a></td><td>Windows DNS Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65798" target="_blank" rel="noopener">CVE-2026-65798</a></td><td>Windows DNS Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65797" target="_blank" rel="noopener">CVE-2026-65797</a></td><td>Windows DNS Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65796" target="_blank" rel="noopener">CVE-2026-65796</a></td><td>Windows iSCSI Target Service Denial of Service Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65795" target="_blank" rel="noopener">CVE-2026-65795</a></td><td>Windows DNS Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65794" target="_blank" rel="noopener">CVE-2026-65794</a></td><td>Windows SMB Client Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65791" target="_blank" rel="noopener">CVE-2026-65791</a></td><td>Windows iSCSI Target Service Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65790" target="_blank" rel="noopener">CVE-2026-65790</a></td><td>Windows Message Queuing Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65789" target="_blank" rel="noopener">CVE-2026-65789</a></td><td>Windows DNS Server Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65788" target="_blank" rel="noopener">CVE-2026-65788</a></td><td>Desktop Window Manager Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65787" target="_blank" rel="noopener">CVE-2026-65787</a></td><td>Desktop Window Manager Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65786" target="_blank" rel="noopener">CVE-2026-65786</a></td><td>Desktop Window Manager Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65785" target="_blank" rel="noopener">CVE-2026-65785</a></td><td>Windows DHCP Client Denial of Service Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65784" target="_blank" rel="noopener">CVE-2026-65784</a></td><td>Windows NTFS Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65783" target="_blank" rel="noopener">CVE-2026-65783</a></td><td>Windows Autopilot Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65782" target="_blank" rel="noopener">CVE-2026-65782</a></td><td>Windows Autopilot Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65781" target="_blank" rel="noopener">CVE-2026-65781</a></td><td>Windows Autopilot Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65780" target="_blank" rel="noopener">CVE-2026-65780</a></td><td>Windows Autopilot Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65779" target="_blank" rel="noopener">CVE-2026-65779</a></td><td>Windows Autopilot Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65778" target="_blank" rel="noopener">CVE-2026-65778</a></td><td>Windows Autopilot Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65777" target="_blank" rel="noopener">CVE-2026-65777</a></td><td>Active Directory Security Feature Bypass Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65776" target="_blank" rel="noopener">CVE-2026-65776</a></td><td>Windows Win32k Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65775" target="_blank" rel="noopener">CVE-2026-65775</a></td><td>Windows Win32k Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65774" target="_blank" rel="noopener">CVE-2026-65774</a></td><td>Windows Installer Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65773" target="_blank" rel="noopener">CVE-2026-65773</a></td><td>Windows Kernel Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65769" target="_blank" rel="noopener">CVE-2026-65769</a></td><td>Microsoft Teams iOS Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65768" target="_blank" rel="noopener">CVE-2026-65768</a></td><td>Microsoft Teams Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65767" target="_blank" rel="noopener">CVE-2026-65767</a></td><td>Microsoft Teams for Android and iOS Spoofing Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65681" target="_blank" rel="noopener">CVE-2026-65681</a></td><td>Windows iSCSI Target Service Denial of Service Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65680" target="_blank" rel="noopener">CVE-2026-65680</a></td><td>Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65679" target="_blank" rel="noopener">CVE-2026-65679</a></td><td>Windows iSCSI Target Service Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65678" target="_blank" rel="noopener">CVE-2026-65678</a></td><td>Windows Win32k Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65675" target="_blank" rel="noopener">CVE-2026-65675</a></td><td>CoPilot Chat Security Feature Bypass Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65673" target="_blank" rel="noopener">CVE-2026-65673</a></td><td>Microsoft Entra Connect Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65672" target="_blank" rel="noopener">CVE-2026-65672</a></td><td>Remote Access API Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65671" target="_blank" rel="noopener">CVE-2026-65671</a></td><td>Remote Access API Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65665" target="_blank" rel="noopener">CVE-2026-65665</a></td><td>Microsoft SharePoint Server Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65664" target="_blank" rel="noopener">CVE-2026-65664</a></td><td>Microsoft Office Graphics Component Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65663" target="_blank" rel="noopener">CVE-2026-65663</a></td><td>Microsoft SharePoint Server Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65662" target="_blank" rel="noopener">CVE-2026-65662</a></td><td>Windows GDI Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65661" target="_blank" rel="noopener">CVE-2026-65661</a></td><td>Microsoft Office Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660" target="_blank" rel="noopener">CVE-2026-65660</a></td><td>Microsoft SharePoint Server Spoofing Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65658" target="_blank" rel="noopener">CVE-2026-65658</a></td><td>Microsoft SharePoint Server Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65657" target="_blank" rel="noopener">CVE-2026-65657</a></td><td>Microsoft Office Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65656" target="_blank" rel="noopener">CVE-2026-65656</a></td><td>Microsoft Office Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64922" target="_blank" rel="noopener">CVE-2026-64922</a></td><td>Microsoft SharePoint Server Spoofing Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64921" target="_blank" rel="noopener">CVE-2026-64921</a></td><td>Microsoft SharePoint Server Elevation of Privilege Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64920" target="_blank" rel="noopener">CVE-2026-64920</a></td><td>Microsoft Access Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64919" target="_blank" rel="noopener">CVE-2026-64919</a></td><td>Microsoft Access Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64917" target="_blank" rel="noopener">CVE-2026-64917</a></td><td>Microsoft Office Word Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64916" target="_blank" rel="noopener">CVE-2026-64916</a></td><td>Microsoft SharePoint Server Spoofing Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64915" target="_blank" rel="noopener">CVE-2026-64915</a></td><td>Microsoft Office Word Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64914" target="_blank" rel="noopener">CVE-2026-64914</a></td><td>Microsoft Access Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64912" target="_blank" rel="noopener">CVE-2026-64912</a></td><td>Microsoft Access Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64911" target="_blank" rel="noopener">CVE-2026-64911</a></td><td>Microsoft Office Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64910" target="_blank" rel="noopener">CVE-2026-64910</a></td><td>Microsoft Office Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64909" target="_blank" rel="noopener">CVE-2026-64909</a></td><td>Microsoft Office Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64908" target="_blank" rel="noopener">CVE-2026-64908</a></td><td>Microsoft Access Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64907" target="_blank" rel="noopener">CVE-2026-64907</a></td><td>Microsoft Office Word Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64906" target="_blank" rel="noopener">CVE-2026-64906</a></td><td>Microsoft Access Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64905" target="_blank" rel="noopener">CVE-2026-64905</a></td><td>Microsoft Office Word Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64904" target="_blank" rel="noopener">CVE-2026-64904</a></td><td>Microsoft Office Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64903" target="_blank" rel="noopener">CVE-2026-64903</a></td><td>Microsoft Office Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64902" target="_blank" rel="noopener">CVE-2026-64902</a></td><td>Microsoft SharePoint Server Spoofing Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64901" target="_blank" rel="noopener">CVE-2026-64901</a></td><td>Microsoft SharePoint Server Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64900" target="_blank" rel="noopener">CVE-2026-64900</a></td><td>Microsoft SharePoint Server Spoofing Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64899" target="_blank" rel="noopener">CVE-2026-64899</a></td><td>Microsoft Office Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64898" target="_blank" rel="noopener">CVE-2026-64898</a></td><td>Microsoft Office Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64897" target="_blank" rel="noopener">CVE-2026-64897</a></td><td>Microsoft SharePoint Server Spoofing Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63533" target="_blank" rel="noopener">CVE-2026-63533</a></td><td>Microsoft Office Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63532" target="_blank" rel="noopener">CVE-2026-63532</a></td><td>Microsoft Office Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63531" target="_blank" rel="noopener">CVE-2026-63531</a></td><td>Microsoft Office Word Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63530" target="_blank" rel="noopener">CVE-2026-63530</a></td><td>Microsoft Office Word Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63529" target="_blank" rel="noopener">CVE-2026-63529</a></td><td>Microsoft Office Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63528" target="_blank" rel="noopener">CVE-2026-63528</a></td><td>Microsoft Office Word Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63527" target="_blank" rel="noopener">CVE-2026-63527</a></td><td>Microsoft Office Word Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63526" target="_blank" rel="noopener">CVE-2026-63526</a></td><td>Microsoft Office Graphics Component Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63525" target="_blank" rel="noopener">CVE-2026-63525</a></td><td>Microsoft Office Word Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63524" target="_blank" rel="noopener">CVE-2026-63524</a></td><td>Microsoft Office Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63521" target="_blank" rel="noopener">CVE-2026-63521</a></td><td>Microsoft Office Word Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63520" target="_blank" rel="noopener">CVE-2026-63520</a></td><td>Microsoft SharePoint Server Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63519" target="_blank" rel="noopener">CVE-2026-63519</a></td><td>Microsoft Office Graphics Component Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63518" target="_blank" rel="noopener">CVE-2026-63518</a></td><td>Microsoft Office Word Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63517" target="_blank" rel="noopener">CVE-2026-63517</a></td><td>Microsoft Office Graphics Component Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63516" target="_blank" rel="noopener">CVE-2026-63516</a></td><td>Microsoft SharePoint Server Spoofing Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63515" target="_blank" rel="noopener">CVE-2026-63515</a></td><td>Microsoft Office Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63514" target="_blank" rel="noopener">CVE-2026-63514</a></td><td>Microsoft SharePoint Server Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63513" target="_blank" rel="noopener">CVE-2026-63513</a></td><td>Microsoft Office Graphics Component Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63512" target="_blank" rel="noopener">CVE-2026-63512</a></td><td>Microsoft SharePoint Server Tampering Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62917" target="_blank" rel="noopener">CVE-2026-62917</a></td><td>Microsoft SharePoint Server Spoofing Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62915" target="_blank" rel="noopener">CVE-2026-62915</a></td><td>Microsoft Exchange Server Security Feature Bypass Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62914" target="_blank" rel="noopener">CVE-2026-62914</a></td><td>Microsoft Exchange Server Spoofing Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62913" target="_blank" rel="noopener">CVE-2026-62913</a></td><td>Microsoft Exchange Server Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62912" target="_blank" rel="noopener">CVE-2026-62912</a></td><td>Microsoft Exchange Server Denial of Service Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911" target="_blank" rel="noopener">CVE-2026-62911</a></td><td>Microsoft Exchange Server Elevation of Privilege Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62910" target="_blank" rel="noopener">CVE-2026-62910</a></td><td>Microsoft Exchange Server Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62909" target="_blank" rel="noopener">CVE-2026-62909</a></td><td>.NET Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62908" target="_blank" rel="noopener">CVE-2026-62908</a></td><td>Windows Backup Engine Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62902" target="_blank" rel="noopener">CVE-2026-62902</a></td><td>.NET Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62901" target="_blank" rel="noopener">CVE-2026-62901</a></td><td>.NET Denial of Service Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62900" target="_blank" rel="noopener">CVE-2026-62900</a></td><td>.NET Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62899" target="_blank" rel="noopener">CVE-2026-62899</a></td><td>.NET Security Feature Bypass Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62898" target="_blank" rel="noopener">CVE-2026-62898</a></td><td>Microsoft QUIC Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62897" target="_blank" rel="noopener">CVE-2026-62897</a></td><td>.NET Framework Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62894" target="_blank" rel="noopener">CVE-2026-62894</a></td><td>Windows DWM Core Library Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62893" target="_blank" rel="noopener">CVE-2026-62893</a></td><td>Windows Deployment Services TFTP Server Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62892" target="_blank" rel="noopener">CVE-2026-62892</a></td><td>Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62890" target="_blank" rel="noopener">CVE-2026-62890</a></td><td>Windows GDI+ Elevation of Privilege Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62889" target="_blank" rel="noopener">CVE-2026-62889</a></td><td>Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62888" target="_blank" rel="noopener">CVE-2026-62888</a></td><td>Windows DWM Core Library Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62887" target="_blank" rel="noopener">CVE-2026-62887</a></td><td>Windows NTFS Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62886" target="_blank" rel="noopener">CVE-2026-62886</a></td><td>.NET Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62885" target="_blank" rel="noopener">CVE-2026-62885</a></td><td>Windows Win32k Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62883" target="_blank" rel="noopener">CVE-2026-62883</a></td><td>Windows DNS Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62882" target="_blank" rel="noopener">CVE-2026-62882</a></td><td>Microsoft Outlook Spoofing Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62881" target="_blank" rel="noopener">CVE-2026-62881</a></td><td>Windows DNS Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62880" target="_blank" rel="noopener">CVE-2026-62880</a></td><td>Windows NTFS Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62878" target="_blank" rel="noopener">CVE-2026-62878</a></td><td>Windows DNS Server Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62877" target="_blank" rel="noopener">CVE-2026-62877</a></td><td>Windows Win32k Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62876" target="_blank" rel="noopener">CVE-2026-62876</a></td><td>Windows Win32k Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62872" target="_blank" rel="noopener">CVE-2026-62872</a></td><td>.NET Framework Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62871" target="_blank" rel="noopener">CVE-2026-62871</a></td><td>.NET Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62842" target="_blank" rel="noopener">CVE-2026-62842</a></td><td>Microsoft Office Graphics Component Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62839" target="_blank" rel="noopener">CVE-2026-62839</a></td><td>Microsoft SharePoint Server Spoofing Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62837" target="_blank" rel="noopener">CVE-2026-62837</a></td><td>Microsoft SharePoint Server Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62832" target="_blank" rel="noopener">CVE-2026-62832</a></td><td>Windows User Profile Service Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62829" target="_blank" rel="noopener">CVE-2026-62829</a></td><td>Microsoft SharePoint Server Spoofing Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62827" target="_blank" rel="noopener">CVE-2026-62827</a></td><td>Microsoft SharePoint Server Elevation of Privilege Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62824" target="_blank" rel="noopener">CVE-2026-62824</a></td><td>Remote Desktop Client Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62823" target="_blank" rel="noopener">CVE-2026-62823</a></td><td>Windows DHCP Server Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62822" target="_blank" rel="noopener">CVE-2026-62822</a></td><td>Windows GDI+ Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62820" target="_blank" rel="noopener">CVE-2026-62820</a></td><td>Windows DNS Server Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62819" target="_blank" rel="noopener">CVE-2026-62819</a></td><td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62818" target="_blank" rel="noopener">CVE-2026-62818</a></td><td>Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62817" target="_blank" rel="noopener">CVE-2026-62817</a></td><td>Windows DNS Server Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62816" target="_blank" rel="noopener">CVE-2026-62816</a></td><td>Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62815" target="_blank" rel="noopener">CVE-2026-62815</a></td><td>Microsoft QUIC Remote Code Execution Vulnerability</td><td>Critical</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62814" target="_blank" rel="noopener">CVE-2026-62814</a></td><td>Windows DHCP Server Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62812" target="_blank" rel="noopener">CVE-2026-62812</a></td><td>Windows DHCP Server Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62811" target="_blank" rel="noopener">CVE-2026-62811</a></td><td>Windows HTTP.sys Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62807" target="_blank" rel="noopener">CVE-2026-62807</a></td><td>Windows DHCP Server Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62803" target="_blank" rel="noopener">CVE-2026-62803</a></td><td>Windows DHCP Server Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62800" target="_blank" rel="noopener">CVE-2026-62800</a></td><td>Windows SMBv3 Server Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62799" target="_blank" rel="noopener">CVE-2026-62799</a></td><td>Windows SMB Client Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62798" target="_blank" rel="noopener">CVE-2026-62798</a></td><td>Win32k Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62797" target="_blank" rel="noopener">CVE-2026-62797</a></td><td>Windows NTFS Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62796" target="_blank" rel="noopener">CVE-2026-62796</a></td><td>Windows NTFS Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62795" target="_blank" rel="noopener">CVE-2026-62795</a></td><td>Windows LDAP – Lightweight Directory Access Protocol Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62793" target="_blank" rel="noopener">CVE-2026-62793</a></td><td>Windows NTFS Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62792" target="_blank" rel="noopener">CVE-2026-62792</a></td><td>Windows TCP/IP Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62790" target="_blank" rel="noopener">CVE-2026-62790</a></td><td>Windows SMBv3 Server Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62788" target="_blank" rel="noopener">CVE-2026-62788</a></td><td>Windows Kernel Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62787" target="_blank" rel="noopener">CVE-2026-62787</a></td><td>Windows DNS Server Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62786" target="_blank" rel="noopener">CVE-2026-62786</a></td><td>Win32k Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62785" target="_blank" rel="noopener">CVE-2026-62785</a></td><td>Windows LDAP – Lightweight Directory Access Protocol Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62784" target="_blank" rel="noopener">CVE-2026-62784</a></td><td>Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62783" target="_blank" rel="noopener">CVE-2026-62783</a></td><td>Windows Remote Access Connection Manager Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62782" target="_blank" rel="noopener">CVE-2026-62782</a></td><td>Windows SMB Client Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62781" target="_blank" rel="noopener">CVE-2026-62781</a></td><td>RPC Runtime Library Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62780" target="_blank" rel="noopener">CVE-2026-62780</a></td><td>Windows Kernel Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62779" target="_blank" rel="noopener">CVE-2026-62779</a></td><td>Windows Schannel Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62778" target="_blank" rel="noopener">CVE-2026-62778</a></td><td>Windows DNS Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62777" target="_blank" rel="noopener">CVE-2026-62777</a></td><td>Windows License Manager Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62776" target="_blank" rel="noopener">CVE-2026-62776</a></td><td>Windows DHCP Server Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62775" target="_blank" rel="noopener">CVE-2026-62775</a></td><td>Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62774" target="_blank" rel="noopener">CVE-2026-62774</a></td><td>Windows Graphics Kernel Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62773" target="_blank" rel="noopener">CVE-2026-62773</a></td><td>Windows Kerberos Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62772" target="_blank" rel="noopener">CVE-2026-62772</a></td><td>Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62771" target="_blank" rel="noopener">CVE-2026-62771</a></td><td>Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62770" target="_blank" rel="noopener">CVE-2026-62770</a></td><td>Windows Shell Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62769" target="_blank" rel="noopener">CVE-2026-62769</a></td><td>Windows DNS Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62768" target="_blank" rel="noopener">CVE-2026-62768</a></td><td>Windows Installer Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62766" target="_blank" rel="noopener">CVE-2026-62766</a></td><td>Windows Kerberos Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62761" target="_blank" rel="noopener">CVE-2026-62761</a></td><td>Windows DHCP Server Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62758" target="_blank" rel="noopener">CVE-2026-62758</a></td><td>Windows Remote Access Connection Manager Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62757" target="_blank" rel="noopener">CVE-2026-62757</a></td><td>Windows Schannel Security Feature Bypass Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62755" target="_blank" rel="noopener">CVE-2026-62755</a></td><td>Windows DHCP Client Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62754" target="_blank" rel="noopener">CVE-2026-62754</a></td><td>Windows Kerberos Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62753" target="_blank" rel="noopener">CVE-2026-62753</a></td><td>Windows HTTP.sys Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62752" target="_blank" rel="noopener">CVE-2026-62752</a></td><td>Windows Kerberos Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62751" target="_blank" rel="noopener">CVE-2026-62751</a></td><td>Windows Projected File System Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62750" target="_blank" rel="noopener">CVE-2026-62750</a></td><td>Windows HTTP Protocol Stack Tampering Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62749" target="_blank" rel="noopener">CVE-2026-62749</a></td><td>Windows Kernel Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62748" target="_blank" rel="noopener">CVE-2026-62748</a></td><td>Windows Telephony Service Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62747" target="_blank" rel="noopener">CVE-2026-62747</a></td><td>Windows Device Association Service Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62746" target="_blank" rel="noopener">CVE-2026-62746</a></td><td>Win32k Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62745" target="_blank" rel="noopener">CVE-2026-62745</a></td><td>Windows DHCP Server Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62743" target="_blank" rel="noopener">CVE-2026-62743</a></td><td>Win32k Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62742" target="_blank" rel="noopener">CVE-2026-62742</a></td><td>Windows DHCP Server Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62741" target="_blank" rel="noopener">CVE-2026-62741</a></td><td>Windows HTTP.sys Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62740" target="_blank" rel="noopener">CVE-2026-62740</a></td><td>Windows Imaging Component Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62739" target="_blank" rel="noopener">CVE-2026-62739</a></td><td>Windows HTTP.sys Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62738" target="_blank" rel="noopener">CVE-2026-62738</a></td><td>Windows Management Instrumentation Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62737" target="_blank" rel="noopener">CVE-2026-62737</a></td><td>Windows Kernel Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62736" target="_blank" rel="noopener">CVE-2026-62736</a></td><td>Windows DHCP Client Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62735" target="_blank" rel="noopener">CVE-2026-62735</a></td><td>Windows HTTP.sys Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62734" target="_blank" rel="noopener">CVE-2026-62734</a></td><td>Windows Telephony Service Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62733" target="_blank" rel="noopener">CVE-2026-62733</a></td><td>Windows Win32k Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62732" target="_blank" rel="noopener">CVE-2026-62732</a></td><td>Windows Telephony Service Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62730" target="_blank" rel="noopener">CVE-2026-62730</a></td><td>Windows Wired AutoConfig Service Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62729" target="_blank" rel="noopener">CVE-2026-62729</a></td><td>Windows Telephony Service Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62728" target="_blank" rel="noopener">CVE-2026-62728</a></td><td>Windows Common Log File System Driver Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62726" target="_blank" rel="noopener">CVE-2026-62726</a></td><td>Windows Telephony Service Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62725" target="_blank" rel="noopener">CVE-2026-62725</a></td><td>Windows Telephony Service Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62724" target="_blank" rel="noopener">CVE-2026-62724</a></td><td>Windows Telephony Service Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62723" target="_blank" rel="noopener">CVE-2026-62723</a></td><td>Windows Telephony Service Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62722" target="_blank" rel="noopener">CVE-2026-62722</a></td><td>Windows Bind Filter Driver Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62721" target="_blank" rel="noopener">CVE-2026-62721</a></td><td>Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62720" target="_blank" rel="noopener">CVE-2026-62720</a></td><td>Windows DHCP Server Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62719" target="_blank" rel="noopener">CVE-2026-62719</a></td><td>Windows Message Queuing Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62718" target="_blank" rel="noopener">CVE-2026-62718</a></td><td>Windows DHCP Server Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62717" target="_blank" rel="noopener">CVE-2026-62717</a></td><td>Windows Message Queuing Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62716" target="_blank" rel="noopener">CVE-2026-62716</a></td><td>Windows DHCP Server Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62715" target="_blank" rel="noopener">CVE-2026-62715</a></td><td>Windows DHCP Server Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62714" target="_blank" rel="noopener">CVE-2026-62714</a></td><td>Windows DHCP Server Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62713" target="_blank" rel="noopener">CVE-2026-62713</a></td><td>Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62712" target="_blank" rel="noopener">CVE-2026-62712</a></td><td>Windows Win32k Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62711" target="_blank" rel="noopener">CVE-2026-62711</a></td><td>Windows Win32k Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62710" target="_blank" rel="noopener">CVE-2026-62710</a></td><td>Windows Device Association Service Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62709" target="_blank" rel="noopener">CVE-2026-62709</a></td><td>Windows GDI+ Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62708" target="_blank" rel="noopener">CVE-2026-62708</a></td><td>Windows Kernel Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62707" target="_blank" rel="noopener">CVE-2026-62707</a></td><td>Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62705" target="_blank" rel="noopener">CVE-2026-62705</a></td><td>Windows Bind Filter Driver Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62703" target="_blank" rel="noopener">CVE-2026-62703</a></td><td>Windows DWM Core Library Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62702" target="_blank" rel="noopener">CVE-2026-62702</a></td><td>Windows Graphics Kernel Denial of Service Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62701" target="_blank" rel="noopener">CVE-2026-62701</a></td><td>Windows Telephony Service Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62700" target="_blank" rel="noopener">CVE-2026-62700</a></td><td>Windows NTFS Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62699" target="_blank" rel="noopener">CVE-2026-62699</a></td><td>Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62698" target="_blank" rel="noopener">CVE-2026-62698</a></td><td>Microsoft Digest Authentication Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62696" target="_blank" rel="noopener">CVE-2026-62696</a></td><td>Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62695" target="_blank" rel="noopener">CVE-2026-62695</a></td><td>Windows Storage Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62693" target="_blank" rel="noopener">CVE-2026-62693</a></td><td>Windows MIDI Service Module Elevation of Privileges Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62692" target="_blank" rel="noopener">CVE-2026-62692</a></td><td>Windows Remote Desktop Services Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62690" target="_blank" rel="noopener">CVE-2026-62690</a></td><td>Windows Push Notifications Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62688" target="_blank" rel="noopener">CVE-2026-62688</a></td><td>Windows MIDI Service Module Elevation of Privileges Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61939" target="_blank" rel="noopener">CVE-2026-61939</a></td><td>Winlogon Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61938" target="_blank" rel="noopener">CVE-2026-61938</a></td><td>Windows Installer Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61937" target="_blank" rel="noopener">CVE-2026-61937</a></td><td>Windows HTTP.sys Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61936" target="_blank" rel="noopener">CVE-2026-61936</a></td><td>Windows Defender Firewall Service Security Feature Bypass Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61934" target="_blank" rel="noopener">CVE-2026-61934</a></td><td>Windows Bind Filter Driver Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61933" target="_blank" rel="noopener">CVE-2026-61933</a></td><td>Windows DWM Core Library Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61932" target="_blank" rel="noopener">CVE-2026-61932</a></td><td>Windows DWM Core Library Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61930" target="_blank" rel="noopener">CVE-2026-61930</a></td><td>Windows Kernel Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61929" target="_blank" rel="noopener">CVE-2026-61929</a></td><td>Windows Kernel Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61928" target="_blank" rel="noopener">CVE-2026-61928</a></td><td>Windows Hello Tampering Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61927" target="_blank" rel="noopener">CVE-2026-61927</a></td><td>Windows Bind Filter Driver Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61926" target="_blank" rel="noopener">CVE-2026-61926</a></td><td>Windows USB Driver Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61925" target="_blank" rel="noopener">CVE-2026-61925</a></td><td>Windows Installer Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61924" target="_blank" rel="noopener">CVE-2026-61924</a></td><td>Windows Remote Desktop Client Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61923" target="_blank" rel="noopener">CVE-2026-61923</a></td><td>Windows Display Enhancement Service Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61921" target="_blank" rel="noopener">CVE-2026-61921</a></td><td>Windows Remote Desktop Client Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61920" target="_blank" rel="noopener">CVE-2026-61920</a></td><td>Windows DNS Server Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61918" target="_blank" rel="noopener">CVE-2026-61918</a></td><td>Windows Remote Desktop Client Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61368" target="_blank" rel="noopener">CVE-2026-61368</a></td><td>Windows Hyper-V Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61367" target="_blank" rel="noopener">CVE-2026-61367</a></td><td>Windows Remote Desktop Services Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61366" target="_blank" rel="noopener">CVE-2026-61366</a></td><td>Windows Network Connection Broker Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61365" target="_blank" rel="noopener">CVE-2026-61365</a></td><td>Windows Remote Desktop Services Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61364" target="_blank" rel="noopener">CVE-2026-61364</a></td><td>Windows Remote Desktop Services Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61363" target="_blank" rel="noopener">CVE-2026-61363</a></td><td>Remote Desktop Client Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61361" target="_blank" rel="noopener">CVE-2026-61361</a></td><td>Windows DHCP Client Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61360" target="_blank" rel="noopener">CVE-2026-61360</a></td><td>Windows GDI Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61359" target="_blank" rel="noopener">CVE-2026-61359</a></td><td>Windows Storage Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61358" target="_blank" rel="noopener">CVE-2026-61358</a></td><td>Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61357" target="_blank" rel="noopener">CVE-2026-61357</a></td><td>Application Information Services Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61356" target="_blank" rel="noopener">CVE-2026-61356</a></td><td>Windows Remote Desktop Services Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61355" target="_blank" rel="noopener">CVE-2026-61355</a></td><td>Windows Sensor Data Service Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61353" target="_blank" rel="noopener">CVE-2026-61353</a></td><td>Windows Telephony Service Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61352" target="_blank" rel="noopener">CVE-2026-61352</a></td><td>Remote Desktop Client Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61350" target="_blank" rel="noopener">CVE-2026-61350</a></td><td>Windows NTFS Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61349" target="_blank" rel="noopener">CVE-2026-61349</a></td><td>Windows Work Folder Service Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61348" target="_blank" rel="noopener">CVE-2026-61348</a></td><td>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61347" target="_blank" rel="noopener">CVE-2026-61347</a></td><td>Windows Event Logging Service Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61346" target="_blank" rel="noopener">CVE-2026-61346</a></td><td>Windows Graphics Kernel Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61345" target="_blank" rel="noopener">CVE-2026-61345</a></td><td>Microsoft Remote Registry Service Denial of Service Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59138" target="_blank" rel="noopener">CVE-2026-59138</a></td><td>Microsoft Remote Registry Service Denial of Service Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59137" target="_blank" rel="noopener">CVE-2026-59137</a></td><td>Windows Event Logging Service Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59136" target="_blank" rel="noopener">CVE-2026-59136</a></td><td>Microsoft COM for Windows Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59135" target="_blank" rel="noopener">CVE-2026-59135</a></td><td>Microsoft Windows Search Component Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59134" target="_blank" rel="noopener">CVE-2026-59134</a></td><td>Remote Desktop Client Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59133" target="_blank" rel="noopener">CVE-2026-59133</a></td><td>Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59132" target="_blank" rel="noopener">CVE-2026-59132</a></td><td>Windows TCP/IP Denial of Service Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59131" target="_blank" rel="noopener">CVE-2026-59131</a></td><td>AMD Zen Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59130" target="_blank" rel="noopener">CVE-2026-59130</a></td><td>AMD Zen Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59128" target="_blank" rel="noopener">CVE-2026-59128</a></td><td>Windows Encrypting File System (EFS) Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59127" target="_blank" rel="noopener">CVE-2026-59127</a></td><td>Windows Installer Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59126" target="_blank" rel="noopener">CVE-2026-59126</a></td><td>Windows Event Logging Service Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59125" target="_blank" rel="noopener">CVE-2026-59125</a></td><td>Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59124" target="_blank" rel="noopener">CVE-2026-59124</a></td><td>Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59122" target="_blank" rel="noopener">CVE-2026-59122</a></td><td>Windows Telephony Service Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59119" target="_blank" rel="noopener">CVE-2026-59119</a></td><td>PowerShell Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59113" target="_blank" rel="noopener">CVE-2026-59113</a></td><td>Visual Studio Code Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58651" target="_blank" rel="noopener">CVE-2026-58651</a></td><td>Microsoft Word Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58650" target="_blank" rel="noopener">CVE-2026-58650</a></td><td>Visual Studio Code Security Feature Bypass Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58641" target="_blank" rel="noopener">CVE-2026-58641</a></td><td>.NET Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58639" target="_blank" rel="noopener">CVE-2026-58639</a></td><td>Microsoft SharePoint Server Spoofing Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58612" target="_blank" rel="noopener">CVE-2026-58612</a></td><td>PowerShell Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57105" target="_blank" rel="noopener">CVE-2026-57105</a></td><td>Microsoft Office SharePoint Spoofing Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57104" target="_blank" rel="noopener">CVE-2026-57104</a></td><td>Azure Storage Explorer Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56179" target="_blank" rel="noopener">CVE-2026-56179</a></td><td>Windows Network Address Translation (NAT) Spoofing Vulnerability</td><td>Moderate</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56174" target="_blank" rel="noopener">CVE-2026-56174</a></td><td>Windows Narrator Braille Elevation of Privilege Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54984" target="_blank" rel="noopener">CVE-2026-54984</a></td><td>Windows Imaging Component Remote Code Execution Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54981" target="_blank" rel="noopener">CVE-2026-54981</a></td><td>Visual Studio Code Python Extension Security Feature Bypass Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54123" target="_blank" rel="noopener">CVE-2026-54123</a></td><td>Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54113" target="_blank" rel="noopener">CVE-2026-54113</a></td><td>Remote Procedure Call Denial of Service Vulnerability</td><td>Important</td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50472" target="_blank" rel="noopener">CVE-2026-50472</a></td><td>Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability</td><td>Important</td></tr></tbody></table></figure>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/microsoft-august-2026-patch-tuesday/">394 Microsoft Flaws Patched in August Update</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/microsoft-august-2026-patch-tuesday/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Zoom Zero-Click Flaws Put Devices at Risk</title>
		<link>https://firsthackersnews.com/zoom-vulnerabilities-remote-code-execution/</link>
					<comments>https://firsthackersnews.com/zoom-vulnerabilities-remote-code-execution/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 11 Aug 2026 12:41:00 +0000</pubDate>
				<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Remote code execution]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[CVE-2026-53413]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[Zero-Click Attack]]></category>
		<category><![CDATA[zoom]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12178</guid>

					<description><![CDATA[<p>Zoom has released security updates for four newly discovered vulnerabilities that could allow an attacker to execute code</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/zoom-vulnerabilities-remote-code-execution/">Zoom Zero-Click Flaws Put Devices at Risk</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Zoom has released security updates for four newly discovered vulnerabilities that could allow an attacker to execute code on another meeting participant’s computer remotely. The most serious issue requires no clicks, downloads, or other interaction from the victim, exposing serious Zoom vulnerabilities.</p>



<p>The most critical vulnerability, tracked as <strong>CVE-2026-53413</strong>, has been named <strong>“Zoomsday”</strong> by A Security, the research team that discovered the flaw. Zoom has rated the vulnerability as <strong>high severity</strong>.</p>



<p>The problem is linked to Zoom’s <strong>annotation feature</strong>, which allows participants to draw, highlight, and add text while someone is sharing their screen. Behind the scenes, this feature uses a proprietary communication protocol to exchange data between participants.</p>



<p>Researchers found that Zoom’s annotation component does not properly validate certain formatting information received over the network. Specifically, the function responsible for processing annotation data uses fixed-size memory buffers while trusting size values provided by the sender.</p>



<p>An attacker could take advantage of this weakness by sending specially crafted data that is larger than the allocated memory space. This can cause a <strong>buffer overflow</strong>, potentially allowing the attacker to corrupt memory and take control of the application.</p>



<p>A Security demonstrated the issue on macOS by using the vulnerability to launch Safari on a targeted computer without the user taking any action. The demonstration showed that successful exploitation could occur quietly, without obvious signs that the device had been compromised.</p>



<p>The attacker only needs to join or host a Zoom meeting and target another participant.</p>



<h2 class="wp-block-heading"><strong>Three More Zoom Vulnerabilities</strong></h2>



<p>Zoom also disclosed three additional security issues as part of the same security update cycle.</p>



<p><strong>CVE-2026-53414</strong> is a medium-severity <strong>buffer over-read vulnerability</strong> affecting Zoom Clients. Successful exploitation could allow an attacker to access information from areas of memory that should not be exposed.</p>



<p><strong>CVE-2026-53415</strong> is a high-severity <strong>use-after-free vulnerability</strong>. It can cause memory corruption and could potentially lead to code execution when an attacker causes the application to access memory that has already been released.</p>



<p><strong>CVE-2026-53416</strong> affects the <strong>Zoom VDI Client</strong> and is caused by a <strong>path traversal vulnerability</strong>. An attacker could manipulate file paths to access files outside the directories intended by the application.</p>



<p>Zoom published these issues under security bulletins <strong>ZSB-26015 through ZSB-26018</strong>, with the bulletins published and updated on <strong>August 11, 2026</strong>.</p>



<h2 class="wp-block-heading"><strong>Zoom Releases Security Fixes</strong></h2>



<p>Zoom says the annotation-related vulnerabilities affect its clients across supported platforms, while the path traversal issue is limited to VDI environments.</p>



<p>The company has already released fixes. The affected products should be updated to the following versions:</p>



<ul class="wp-block-list">
<li><strong>Zoom Workplace:</strong> 7.1.5 or 7.0.6</li>



<li><strong>Zoom Rooms:</strong> 7.1.5</li>



<li><strong>Meeting SDK:</strong> 7.1.5</li>



<li><strong>Workplace VDI Client:</strong> 7.0.11 or 6.6.16</li>



<li><strong>VDI Plugin:</strong> 7.0.11 or 6.6.15</li>
</ul>



<h2 class="wp-block-heading"><strong>What Organizations Should Do</strong></h2>



<p>Zoom has not reported any confirmed exploitation of these vulnerabilities in the wild, and there is currently no publicly available proof-of-concept exploit.</p>



<p>However, the zero-click nature of CVE-2026-53413 makes the issue particularly important. Successful exploitation does not require the victim to open a file, click a link, or approve a prompt.</p>



<p>Organizations should prioritize updating Zoom across managed devices as soon as possible. IT and security teams should also consider deploying the updated packages centrally rather than depending entirely on users to update their applications themselves.</p>



<p>Keeping centralized installations updated can help prevent vulnerable versions from being reintroduced during future software deployments.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/zoom-vulnerabilities-remote-code-execution/">Zoom Zero-Click Flaws Put Devices at Risk</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/zoom-vulnerabilities-remote-code-execution/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Android Banking Malware Adopts New Evasion Techniques</title>
		<link>https://firsthackersnews.com/android-banking-malware-evasion-techniques/</link>
					<comments>https://firsthackersnews.com/android-banking-malware-evasion-techniques/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 10 Aug 2026 13:46:00 +0000</pubDate>
				<category><![CDATA[Android banking trojan]]></category>
		<category><![CDATA[Android malware]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Android Banking Malware]]></category>
		<category><![CDATA[android malware]]></category>
		<category><![CDATA[android security]]></category>
		<category><![CDATA[banking trojan]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Malware Droppers]]></category>
		<category><![CDATA[Mobile Banking Security]]></category>
		<category><![CDATA[mobile malware]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12169</guid>

					<description><![CDATA[<p>Android banking malware continues to evolve as cybercriminals adopt new methods to avoid detection and bypass app store</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/android-banking-malware-evasion-techniques/">Android Banking Malware Adopts New Evasion Techniques</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Android banking malware continues to evolve as cybercriminals adopt new methods to avoid detection and bypass app store security checks. Instead of distributing banking malware directly, attackers are increasingly using <strong>dropper applications</strong> that deliver the malicious payload only after the app has been installed.</p>



<p>According to recent security research, while the overall number of blocked Android malware attacks declined during the second quarter of 2026, banking malware remains one of the most active mobile threats. Rather than disappearing, attackers are changing how their malware is packaged and deployed.</p>



<h2 class="wp-block-heading"><strong>A Shift Toward Dropper-Based Attacks</strong></h2>



<p>A dropper is an application that appears harmless but is designed to download or activate malware after installation.</p>



<p>This approach allows attackers to hide the real banking Trojan during the initial app review process. Once the application is installed on a victim&#8217;s device, it can retrieve additional malicious components and begin targeting banking credentials.</p>



<p>By separating the delivery mechanism from the actual malware, cybercriminals can update or replace their payloads without creating entirely new malicious applications.</p>



<h2 class="wp-block-heading"><strong>Malicious Apps Disguised as Legitimate Software</strong></h2>



<p>Researchers observed attackers disguising malware as legitimate Android applications, including utility and document reader apps.</p>



<p>In one campaign, a PDF reader displayed what appeared to be a routine software update notification. Instead of installing an update, the application downloaded banking malware onto the victim&#8217;s device.</p>



<p>These fake update prompts make malicious activity appear normal, increasing the likelihood that users will unknowingly install the malware.</p>



<h2 class="wp-block-heading"><strong>Smarter Delivery Techniques</strong></h2>



<p>Modern Android droppers are becoming more selective in how they deliver malware.</p>



<p>Some applications first collect information about where they were downloaded and send that data to a command-and-control (C2) server. The server decides whether to deliver the malicious payload based on the installation source.</p>



<p>This selective delivery helps attackers avoid security researchers, automated analysis tools, and app store review systems while targeting real users.</p>



<h2 class="wp-block-heading"><strong>Banking Malware Continues to Evolve</strong></h2>



<p>Security researchers also observed continued activity from well-known Android banking malware families, including <strong>Mamont</strong> and <strong>Creduz</strong>.</p>



<p>New variants are being released regularly, suggesting that malware operators are continuously testing new delivery techniques, improving evasion methods, and developing updated versions to avoid detection.</p>



<h2 class="wp-block-heading"><strong>Why This Matters</strong></h2>



<p>The growing use of droppers shows that mobile threats are becoming more sophisticated. A reduction in traditional banking Trojan detections does not necessarily indicate a lower risk—it may simply reflect changes in how malware is delivered.</p>



<p>As attackers continue refining their techniques, users and organizations should remain cautious of applications that request unexpected updates or unnecessary permissions.</p>



<h2 class="wp-block-heading"><strong>How to Stay Protected</strong></h2>



<p>To reduce the risk of Android banking malware:</p>



<ul class="wp-block-list">
<li>Install apps only from trusted sources.</li>



<li>Keep Google Play Protect enabled.</li>



<li>Avoid downloading apps from unofficial websites.</li>



<li>Be cautious of unexpected in-app update requests.</li>



<li>Review requested permissions before installing applications.</li>



<li>Keep Android devices and applications updated.</li>



<li>Use a reputable mobile security solution.</li>
</ul>



<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>



<p>Android banking malware operators are shifting away from traditional delivery methods and increasingly relying on dropper applications to bypass security controls. As these techniques become more advanced, mobile users and organizations should strengthen their security practices, verify application sources, and remain alert to suspicious app behavior to reduce the risk of financial compromise.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/android-banking-malware-evasion-techniques/">Android Banking Malware Adopts New Evasion Techniques</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/android-banking-malware-evasion-techniques/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Windows Hello Key Flaw Opens Door to Entra ID Access</title>
		<link>https://firsthackersnews.com/windows-hello-for-business-security-flaw/</link>
					<comments>https://firsthackersnews.com/windows-hello-for-business-security-flaw/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 07 Aug 2026 15:50:00 +0000</pubDate>
				<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[Windows Security]]></category>
		<category><![CDATA[active directory]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[Entra ID]]></category>
		<category><![CDATA[identity security]]></category>
		<category><![CDATA[MFA]]></category>
		<category><![CDATA[Microsoft Entra]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[Passwordless Authentication]]></category>
		<category><![CDATA[security research]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<category><![CDATA[Windows Hello for Business]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[Zero Trust]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12149</guid>

					<description><![CDATA[<p>Security researcher Dirk-jan Mollema has uncovered a new technique that could allow attackers to misuse Windows Hello for</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/windows-hello-for-business-security-flaw/">Windows Hello Key Flaw Opens Door to Entra ID Access</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Security researcher <strong>Dirk-jan Mollema</strong> has uncovered a new technique that could allow attackers to misuse <strong>Windows Hello for Business (WHFB)</strong> to authenticate to Microsoft Entra ID services without requiring the victim&#8217;s password, PIN, or biometric verification.</p>



<p>Rather than breaking Windows Hello encryption, the technique takes advantage of an already authenticated Windows session. If an attacker gains access to a logged-in device, they may be able to leverage the victim&#8217;s existing Windows Hello credentials to request authentication tokens and potentially establish long-term access to Microsoft Entra resources.</p>



<p>The research highlights how attackers can abuse trusted authentication mechanisms once an endpoint has already been compromised.</p>



<h2 class="wp-block-heading"><strong>How the Attack Works</strong></h2>



<p>Windows Hello for Business replaces passwords with cryptographic keys that are securely stored on the user&#8217;s device, typically inside the <strong>Trusted Platform Module (TPM)</strong>. These keys are designed to remain protected and cannot normally be exported from the device.</p>



<p>However, the research demonstrates that an application running with standard user privileges inside an active Windows session can request cryptographic operations from the Windows Hello key without asking the user to re-enter their PIN or biometric authentication.</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="282" src="https://firsthackersnews.com/wp-content/uploads/2026/08/image-1024x282.png" alt="" class="wp-image-12153" srcset="https://firsthackersnews.com/wp-content/uploads/2026/08/image-300x83.png 300w, https://firsthackersnews.com/wp-content/uploads/2026/08/image-768x212.png 768w, https://firsthackersnews.com/wp-content/uploads/2026/08/image-1024x282.png 1024w, https://firsthackersnews.com/wp-content/uploads/2026/08/image-1536x423.png 1536w, https://firsthackersnews.com/wp-content/uploads/2026/08/image.png 1600w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><strong>Windows Hello Authentication Flow (Source: Dirk-jan Mollema)</strong></figcaption></figure>



<p>Instead of stealing the private key itself, the attacker simply instructs Windows to use it on their behalf. As long as the user remains logged in, Windows considers the authentication request valid.</p>



<p>This effectively allows attackers to &#8220;borrow&#8221; the trusted Windows Hello credentials without directly compromising them.</p>



<h2 class="wp-block-heading"><strong>Authentication Without Traditional Credentials</strong></h2>



<p>Researchers showed that the borrowed Windows Hello key can be used during Microsoft&#8217;s <strong>WebAuthn</strong> authentication process.</p>



<p>Since the authentication challenge is not permanently tied to a specific device or session, attackers can generate the request from their own system while having the victim&#8217;s compromised device perform the required cryptographic signing.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><strong>&#x200d;Follow Us on:<strong><a href="https://www.linkedin.com/in/firsthackers-news/" target="_blank" rel="noopener">Linkedin</a>,<a href="https://www.instagram.com/firsthackersnews/" target="_blank" rel="noreferrer noopener"> Instagram</a>, <a href="https://www.facebook.com/FirsthackerNews" target="_blank" rel="noreferrer noopener">Facebook</a></strong> to get the latest security news!</strong></p>
</blockquote>



<p>Once the challenge is successfully signed, Microsoft Entra treats the authentication as legitimate and issues cloud authentication tokens.</p>



<p>Unlike earlier attack techniques, this approach removes the need for attackers to control another Microsoft Entra-registered device, making exploitation significantly easier.</p>



<h2 class="wp-block-heading"><strong>Potential Impact</strong></h2>



<p>Successful exploitation could provide attackers with access to Microsoft Entra cloud resources while using legitimate authentication mechanisms.</p>



<p>Depending on the organization&#8217;s security configuration, attackers may be able to:</p>



<ul class="wp-block-list">
<li>Authenticate to Microsoft Entra services.</li>



<li>Obtain cloud authentication tokens.</li>



<li>Register attacker-controlled devices.</li>



<li>Add new authentication methods.</li>



<li>Maintain persistent access to cloud identities.</li>



<li>Expand access across enterprise environments.</li>
</ul>



<p>Because Windows Hello for Business satisfies multi-factor authentication requirements, attackers may also bypass additional protections designed to secure identity management functions.</p>



<h2 class="wp-block-heading"><strong>Why Organizations Should Pay Attention</strong></h2>



<p>The research demonstrates that passwordless authentication is only as secure as the endpoint itself.</p>



<p>Even though Windows Hello protects credentials from theft, an attacker who compromises an active Windows session may still abuse trusted authentication processes without ever knowing the user&#8217;s password or PIN.</p>



<p>This reinforces the importance of endpoint security alongside identity protection.</p>



<p>Organizations should not rely solely on passwordless authentication but should also focus on preventing attackers from gaining access to active user sessions.</p>



<h2 class="wp-block-heading"><strong>Detection and Mitigation</strong></h2>



<p>Security teams should monitor Microsoft Entra sign-in activity for unusual Windows Hello authentication events, particularly those that do not contain an associated device ID.</p>



<p>Administrators should also investigate unexpected device registrations, monitor changes to authentication methods, strengthen endpoint detection and response capabilities, and regularly review Conditional Access policies to ensure only trusted devices can register new authentication factors.</p>



<p>Monitoring active user sessions and detecting suspicious endpoint activity remain critical for preventing attackers from abusing trusted authentication mechanisms.</p>



<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>



<p>Mollema&#8217;s research demonstrates that compromising an active Windows session can have serious consequences, even in environments that have adopted passwordless authentication.</p>



<p>While the technique does not break Windows Hello&#8217;s cryptographic protections, it shows how trusted authentication workflows can be abused after an endpoint has been compromised.</p>



<p>Organizations using Windows Hello for Business and Microsoft Entra should prioritize endpoint protection, continuous monitoring, and identity security controls to reduce the risk of attackers turning temporary access into persistent cloud compromise.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/windows-hello-for-business-security-flaw/">Windows Hello Key Flaw Opens Door to Entra ID Access</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/windows-hello-for-business-security-flaw/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Fake Roblox Hacks Target Discord and Gaming Credentials</title>
		<link>https://firsthackersnews.com/fake-roblox-hacks-target-discord-and-gaming-credentials/</link>
					<comments>https://firsthackersnews.com/fake-roblox-hacks-target-discord-and-gaming-credentials/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 20:49:48 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[discord]]></category>
		<category><![CDATA[Gaming Security]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[Java RAT]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[remote access trojan]]></category>
		<category><![CDATA[Roblox]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<category><![CDATA[Xeno Cheat]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12135</guid>

					<description><![CDATA[<p>Security researchers have uncovered an ongoing malware campaign that uses fake Roblox Xeno cheat tools to infect gamers</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/fake-roblox-hacks-target-discord-and-gaming-credentials/">Fake Roblox Hacks Target Discord and Gaming Credentials</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Security researchers have uncovered an ongoing malware campaign that uses <strong>fake Roblox Xeno cheat tools</strong> to infect gamers with a powerful <strong>Java-based Remote Access Trojan (RAT)</strong>.</p>



<p>The attackers are primarily targeting users through <strong>Discord servers</strong> and gaming forums, where fake cheat downloads are shared as legitimate software. By taking advantage of the popularity of Roblox cheats, the campaign aims to steal sensitive information and gain complete control of victims&#8217; computers.</p>



<p>Researchers say the operation continues to evolve, with new infrastructure and malware capabilities being added regularly.</p>



<h2 class="wp-block-heading"><strong>How the Attack Works</strong></h2>



<p>The infection starts when users download what appears to be a genuine <strong>Xeno Roblox cheat</strong>.</p>



<p>The downloaded archive looks convincing, containing realistic folder structures and harmless-looking files that make it appear authentic.</p>



<p>Instead of launching a game cheat, the installer quietly begins executing malicious code in the background.</p>



<p>If Java is not already installed on the system, the malware automatically installs a local Java Runtime Environment without the user&#8217;s knowledge. This prepares the system for the next stage of the attack.</p>



<h2 class="wp-block-heading"><strong>Multi-Stage Malware Deployment</strong></h2>



<p>After the initial infection, the malware loads a heavily obfuscated Java application disguised as a normal Windows executable.</p>



<p>Before continuing, it performs several checks to determine whether it is running inside a virtual machine, sandbox, or debugging environment. These techniques help attackers avoid detection by security researchers.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><strong>&#x200d;Follow Us on:<strong><a href="https://www.linkedin.com/in/firsthackers-news/" target="_blank" rel="noopener">Linkedin</a>,<a href="https://www.instagram.com/firsthackersnews/" target="_blank" rel="noreferrer noopener"> Instagram</a>, <a href="https://www.facebook.com/FirsthackerNews" target="_blank" rel="noreferrer noopener">Facebook</a></strong> to get the latest security news!</strong></p>
</blockquote>



<p>The malware then collects basic system information and securely communicates with its command-and-control (C2) server to register the infected device and download additional malicious components.</p>



<h2 class="wp-block-heading"><strong>Java RAT Gains Full System Access</strong></h2>



<p>The final payload is a <strong>Java Remote Access Trojan (RAT)</strong> hidden inside folders designed to resemble legitimate Microsoft GameDVR files associated with the Xbox Game Bar.</p>



<p>To remain active after a reboot, the malware creates registry <strong>Run</strong> entries using names that appear to be legitimate Windows components. It also attempts to obtain elevated privileges, allowing it to perform more advanced malicious activities.</p>



<p>Once established, the RAT connects to attacker-controlled servers and waits for further instructions.</p>



<h2 class="wp-block-heading"><strong>What Information Does the Malware Target?</strong></h2>



<p>Unlike basic information-stealing malware, this campaign combines credential theft with powerful remote surveillance features.</p>



<p>The malware is capable of:</p>



<ul class="wp-block-list">
<li>Stealing saved passwords and browser cookies.</li>



<li>Collecting credentials from Chrome, Edge, Opera, and Brave.</li>



<li>Hijacking Discord, Roblox, and Minecraft accounts.</li>



<li>Targeting cryptocurrency wallets, including Exodus.</li>



<li>Capturing keystrokes and mouse activity.</li>



<li>Taking screenshots.</li>



<li>Streaming the victim&#8217;s desktop.</li>



<li>Accessing webcam feeds.</li>



<li>Uploading, downloading, and modifying files.</li>



<li>Running PowerShell commands.</li>



<li>Providing attackers with remote shell access.</li>
</ul>



<p>These capabilities allow attackers to fully control an infected computer while collecting valuable personal and financial information.</p>



<h2 class="wp-block-heading"><strong>Why Gamers Are Being Targeted</strong></h2>



<p>Researchers believe the campaign specifically targets Roblox players because many users search online for &#8220;free&#8221; or &#8220;undetected&#8221; cheat tools.</p>



<p>Young gamers are especially at risk, as they may download unofficial software from Discord communities or third-party websites without realizing it contains malware.</p>



<p>Since many gaming PCs are shared with family members, a successful infection could also expose banking information, personal documents, saved passwords, and private communications stored on the same device.</p>



<h2 class="wp-block-heading"><strong>Malware Campaign Continues to Evolve</strong></h2>



<p>Security researchers, including <strong>Bitdefender</strong> and previous investigations by <strong>ThreatLocker</strong>, have linked the campaign to malware previously tracked as <strong>Powercat</strong>.</p>



<p>The operation has reportedly been active since early 2026 and continues to expand through new command-and-control servers and updated malware modules. The attackers also use encrypted communications and in-memory payload execution, making the malware more difficult to detect and remove.</p>



<h2 class="wp-block-heading"><strong>How to Stay Protected</strong></h2>



<p>To reduce the risk of infection, users should follow these security best practices:</p>



<ul class="wp-block-list">
<li>Avoid downloading unofficial Roblox cheats or game modification tools.</li>



<li>Only install software from trusted sources.</li>



<li>Keep antivirus and security software up to date.</li>



<li>Enable multi-factor authentication (MFA) on gaming and email accounts.</li>



<li>Regularly update Windows and installed applications.</li>



<li>Be cautious of download links shared through Discord servers or online gaming forums.</li>
</ul>



<p>As cybercriminals increasingly target gaming communities, staying away from unofficial cheat software remains one of the most effective ways to avoid malware infections and protect personal information.</p>



<h2 class="wp-block-heading" id="h-iocs"><strong>IOCs</strong></h2>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>MD5</strong><strong></strong></td><td colspan="2"><strong>Description</strong><strong></strong></td></tr><tr><td>4bdaf7792e908f163ebef137854c571d</td><td colspan="2">archive containing fake Xeno installation</td></tr><tr><td>9930036e8f787674db39094e21413e77</td><td colspan="2">archive containing fake Xeno installation</td></tr><tr><td>9699bd6a448d0662a1e9e353223263b6</td><td colspan="2">archive containing fake Xeno installation</td></tr><tr><td>1a462c76efc4e73725b9e95c4a00fddb</td><td colspan="2">archive containing fake Xeno installation</td></tr><tr><td>7b96170259a376ea79411c5713beb396</td><td colspan="2">archive containing fake Xeno installation</td></tr><tr><td>2ead73ed62f1c2beb9043ce92e774e0b</td><td colspan="2">malicious xeno.exe loader</td></tr><tr><td>0aadd62b535e683a5a2fe31fde546d07</td><td colspan="2">malicious xeno.exe loader</td></tr></tbody></table></figure>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/fake-roblox-hacks-target-discord-and-gaming-credentials/">Fake Roblox Hacks Target Discord and Gaming Credentials</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/fake-roblox-hacks-target-discord-and-gaming-credentials/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Critical Vulnerability Disclosed in VS Code, Cursor, and Google Antigravity</title>
		<link>https://firsthackersnews.com/vs-code-cursor-google-antigravity-rce-vulnerability/</link>
					<comments>https://firsthackersnews.com/vs-code-cursor-google-antigravity-rce-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 05:04:10 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Vulnerability Research]]></category>
		<category><![CDATA[Code Editors]]></category>
		<category><![CDATA[Cursor]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Developer Security]]></category>
		<category><![CDATA[Google Antigravity]]></category>
		<category><![CDATA[rce]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[VS Code]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12125</guid>

					<description><![CDATA[<p>A recently patched security vulnerability exposed three popular code editors—Microsoft VS Code, Cursor, and Google Antigravity—to a serious</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/vs-code-cursor-google-antigravity-rce-vulnerability/">Critical Vulnerability Disclosed in VS Code, Cursor, and Google Antigravity</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A recently patched security vulnerability exposed three popular code editors—<strong>Microsoft VS Code, Cursor, and Google Antigravity</strong>—to a serious <strong>remote code execution (RCE)</strong> risk.</p>



<p>According to security researchers at <strong>AISLE</strong>, the flaw could have allowed attackers to compromise a developer&#8217;s system simply by convincing them to click a malicious link embedded in a Git commit message.</p>



<p>The issue has now been fixed across all affected platforms, but it highlights the growing security risks facing modern AI-powered development tools.</p>



<h2 class="wp-block-heading">How the Attack Worked</h2>



<p>The vulnerability relied on a malicious link hidden inside a Git commit message.</p>



<p>If a developer clicked the link while viewing the commit inside one of the affected editors, arbitrary code could run automatically with the same permissions as the developer.</p>



<p>The attack required only a single click and did not display any warning, confirmation message, or security prompt, making the compromise difficult to notice.</p>



<h2 class="wp-block-heading">What Attackers Could Do</h2>



<p>Successful exploitation could have given attackers extensive control over a developer&#8217;s machine.</p>



<p>Potential impacts included:</p>



<ul class="wp-block-list">
<li>Stealing API keys and other sensitive credentials.</li>



<li>Installing malware or keyloggers.</li>



<li>Accessing, modifying, or deleting local files.</li>



<li>Maintaining persistent access even after the editor was closed.</li>
</ul>



<p>Because the malicious activity could remain hidden, developers might not realize their systems had been compromised.</p>



<h2 class="wp-block-heading">Vulnerability Found Across Multiple Editors</h2>



<p>AISLE first discovered the flaw in <strong>Microsoft VS Code</strong> during security testing in late 2025.</p>



<p>Since <strong>Cursor</strong> is built on the VS Code codebase, it inherited the same vulnerability. Later, researchers identified the identical issue in <strong>Google Antigravity</strong>, another AI-assisted coding environment based on the same architecture.</p>



<p>The discovery shows how a single vulnerability in a shared codebase can spread across multiple developer tools used by millions of people.</p>



<h2 class="wp-block-heading">Vendors Released Security Fixes</h2>



<p>After receiving responsible disclosure reports, all three vendors addressed the issue.</p>



<ul class="wp-block-list">
<li>Cursor released a security update shortly after notification.</li>



<li>Google patched the vulnerability in Antigravity within days.</li>



<li>Microsoft later released a fix for VS Code.</li>
</ul>



<p>Current versions of all three editors are no longer affected.</p>



<h2 class="wp-block-heading">Why This Matters</h2>



<p>Many modern AI coding tools are developed using common open-source foundations such as VS Code. While this speeds up development and feature delivery, it also means a single security flaw can impact multiple products simultaneously.</p>



<p>This incident demonstrates the importance of continuous security testing and timely patch management, particularly for AI-powered development environments.</p>



<h2 class="wp-block-heading">What Developers Should Do</h2>



<p>Developers and organizations should take the following steps:</p>



<ul class="wp-block-list">
<li>Update VS Code, Cursor, or Google Antigravity to the latest version.</li>



<li>Review recent Git activity for anything suspicious.</li>



<li>Rotate API keys and credentials if older vulnerable versions were used.</li>



<li>Monitor developer systems for unusual behavior or unauthorized access.</li>
</ul>



<p>Keeping development tools fully updated and regularly reviewing credentials can help reduce the risk of future software supply chain attacks.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/vs-code-cursor-google-antigravity-rce-vulnerability/">Critical Vulnerability Disclosed in VS Code, Cursor, and Google Antigravity</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/vs-code-cursor-google-antigravity-rce-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Critical TP-Link Router Flaw Enables Remote Code Execution</title>
		<link>https://firsthackersnews.com/tp-link-router-vulnerability/</link>
					<comments>https://firsthackersnews.com/tp-link-router-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 03 Aug 2026 17:03:23 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[CVE-2026-12935]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[firmware update]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[router security]]></category>
		<category><![CDATA[Router Vulnerability]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<category><![CDATA[TL-WR940N]]></category>
		<category><![CDATA[tp-link]]></category>
		<category><![CDATA[TP-Link Router]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12110</guid>

					<description><![CDATA[<p>TP-Link has released a security advisory for a high-severity vulnerability affecting the TL-WR940N v6 wireless router. The flaw,</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/tp-link-router-vulnerability/">Critical TP-Link Router Flaw Enables Remote Code Execution</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>TP-Link has released a security advisory for a <strong>high-severity vulnerability</strong> affecting the <strong>TL-WR940N v6 wireless router</strong>. The flaw, tracked as <strong>CVE-2026-12935</strong>, could allow attackers to execute malicious code on vulnerable devices, potentially giving them full control of the router.</p>



<p>The vulnerability has been assigned a <strong>CVSS v4.0 score of 8.7</strong>, highlighting the importance of applying the latest firmware updates as soon as possible.</p>



<h2 class="wp-block-heading"><strong>Buffer Overflow Vulnerability Identified</strong></h2>



<p>The issue is caused by a <strong>stack-based buffer overflow</strong> in the router&#8217;s <strong>Real-Time Streaming Protocol (RTSP)</strong> connection-tracking component.</p>



<p>The vulnerability can be triggered when a device connected to the local network communicates with a malicious RTSP server. If the server responds with specially crafted data, it can cause improper memory handling inside the router, leading to a system crash or remote code execution.</p>



<p>Unlike many router vulnerabilities, this flaw does <strong>not require attackers to authenticate</strong> with the device under its default configuration.</p>



<p>However, exploitation requires some user interaction. A user must first access a malicious RTSP stream, such as opening a harmful media link or connecting to an attacker-controlled streaming service.</p>



<h2 class="wp-block-heading"><strong>Potential Security Risks</strong></h2>



<p>If successfully exploited, attackers could:</p>



<ul class="wp-block-list">
<li>Execute malicious code on the router.</li>



<li>Modify network or security settings.</li>



<li>Monitor or intercept network traffic.</li>



<li>Install persistent malware.</li>



<li>Use the compromised router to launch attacks against other devices on the network.</li>
</ul>



<p>Because routers act as the gateway between users and the internet, compromising one can expose every connected device to additional risks.</p>



<h2 class="wp-block-heading"><strong>Affected Versions and Fixes</strong></h2>



<p>The vulnerability only impacts <strong>TP-Link TL-WR940N hardware version v6</strong>.</p>



<p>TP-Link has released firmware updates that address the issue for regional versions, including:</p>



<ul class="wp-block-list">
<li><strong>(EN)_V6_260528</strong></li>



<li><strong>(US)_V6_260528</strong></li>



<li><strong>(JP)_V6_260527</strong></li>
</ul>



<p>Users should download and install the appropriate firmware from TP-Link&#8217;s official support website as soon as possible.</p>



<h2 class="wp-block-heading"><strong>Recommended Security Measures</strong></h2>



<p>Until systems are updated, users and organizations should:</p>



<ul class="wp-block-list">
<li>Install the latest TP-Link firmware.</li>



<li>Avoid connecting to untrusted RTSP streaming services.</li>



<li>Secure the router&#8217;s administration interface with a strong, unique password.</li>



<li>Monitor network activity for unusual behavior.</li>



<li>Regularly review router firmware for new security updates.</li>
</ul>



<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>



<p>The discovery of <strong>CVE-2026-12935</strong> highlights the importance of keeping networking devices up to date. Since routers are a critical part of any home or enterprise network, timely firmware updates and good security practices remain essential to protecting against remote attacks and maintaining a secure network environment.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><strong>&#x200d;Follow Us on:<strong><a href="https://www.linkedin.com/in/firsthackers-news/" target="_blank" rel="noopener">Linkedin</a>,<a href="https://www.instagram.com/firsthackersnews/" target="_blank" rel="noreferrer noopener"> Instagram</a>, <a href="https://www.facebook.com/FirsthackerNews" target="_blank" rel="noreferrer noopener">Facebook</a></strong> to get the latest security news!</strong></p>
</blockquote>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/tp-link-router-vulnerability/">Critical TP-Link Router Flaw Enables Remote Code Execution</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/tp-link-router-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Google Chrome 151 Patches Critical Vulnerabilities</title>
		<link>https://firsthackersnews.com/google-chrome-151-security-update/</link>
					<comments>https://firsthackersnews.com/google-chrome-151-security-update/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 31 Jul 2026 04:05:06 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Browser Security]]></category>
		<category><![CDATA[Chrome 151]]></category>
		<category><![CDATA[CVE]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[google chrome]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12107</guid>

					<description><![CDATA[<p>Google has released Chrome 151 for Windows, macOS, and Linux, bringing an important security update that fixes 370</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/google-chrome-151-security-update/">Google Chrome 151 Patches Critical Vulnerabilities</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Google has released <strong>Chrome 151</strong> for Windows, macOS, and Linux, bringing an important security update that fixes <strong>370 vulnerabilities</strong> across the browser. The update is being rolled out gradually, so it may take a few days before it becomes available to all users.</p>



<p>To help reduce the risk of attacks before users install the update, Google is temporarily limiting technical details about many of the vulnerabilities until the rollout is complete.</p>



<h2 class="wp-block-heading"><strong>370 Security Flaws Addressed</strong></h2>



<p>This release includes fixes for vulnerabilities affecting several core Chrome components, including graphics, networking, browser rendering, and platform-specific features.</p>



<p>Many of these issues were discovered by Google&#8217;s internal security teams using automated testing tools designed to detect memory errors and other software weaknesses before they could be exploited.</p>



<h2 class="wp-block-heading"><strong>Seven Critical Vulnerabilities Fixed</strong></h2>



<p>Chrome 151 resolves <strong>seven critical vulnerabilities</strong>, tracked as <strong>CVE-2026-17650</strong> through <strong>CVE-2026-17656</strong>.</p>



<p>Several of these are <strong>use-after-free</strong> memory vulnerabilities found in components such as <strong>Compositing, Views, Skia, and Ozone</strong>. If successfully exploited, these flaws could allow attackers to execute malicious code through specially crafted web content.</p>



<p>The update also fixes:</p>



<ul class="wp-block-list">
<li><strong>Insufficient input validation</strong> in the Dawn and ANGLE graphics libraries.</li>



<li><strong>A race condition</strong> in Chrome&#8217;s Updater that could lead to unexpected behavior during software updates.</li>
</ul>



<p>These vulnerabilities could potentially be used to bypass security protections, escalate privileges, or compromise browser stability.</p>



<h2 class="wp-block-heading"><strong>Additional High-Severity Fixes</strong></h2>



<p>Beyond the critical issues, Chrome 151 addresses numerous high-severity vulnerabilities affecting components such as:</p>



<ul class="wp-block-list">
<li>V8 JavaScript Engine</li>



<li>Navigation</li>



<li>QUIC</li>



<li>Audio and Media</li>



<li>WebGL</li>



<li>Downloads</li>
</ul>



<p>Many of these flaws involve memory corruption issues, including out-of-bounds reads and writes, integer overflows, and type confusion vulnerabilities, all of which could increase the risk of remote code execution.</p>



<h2 class="wp-block-heading"><strong>Medium and Low-Severity Improvements</strong></h2>



<p>The update also includes fixes for medium-severity vulnerabilities affecting features such as <strong>Autofill, DevTools, Extensions, Password Manager, WebXR, WebView, and ANGLE</strong>.</p>



<p>In addition, Google resolved several lower-severity issues impacting Enterprise features, Bluetooth, NFC, Google Lens, Settings, Picture-in-Picture, and AI-related functionality. While these vulnerabilities are less severe individually, addressing them helps strengthen Chrome&#8217;s overall security.</p>



<h2 class="wp-block-heading"><strong>Update Chrome as Soon as Possible</strong></h2>



<p>Google credited both its internal security teams and external researchers for identifying many of the vulnerabilities before they could be exploited.</p>



<p>With <strong>370 security fixes</strong>, including <strong>seven critical vulnerabilities</strong>, this release highlights the importance of keeping web browsers up to date. Users and organizations should install <strong>Chrome 151</strong> as soon as it becomes available to reduce the risk of attacks targeting known security flaws.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/google-chrome-151-security-update/">Google Chrome 151 Patches Critical Vulnerabilities</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/google-chrome-151-security-update/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
