CVE-2026-41991 Predictable Temporary File in GNU gzip
Information published.
EPSS 0.00 CVE-2026-41991 GNU US
Information published.
EPSS 0.00 CVE-2026-41991 GNU US
Information published.
EPSS 0.00 CVE-2026-54371 attr US
Information published.
EPSS 0.00 CVE-2026-54369 libacl US
Information published.
EPSS 0.01 CVE-2026-58058 Nmap US
Information published.
EPSS 0.00 CVE-2026-58055 nghttp2 US
Information published.
EPSS 0.00 CVE-2026-58051 libssh2 US
Information published.
EPSS 0.00 CVE-2026-58050 libssh2 US
Information published.
EPSS 0.00 CVE-2024-26962 US
Information published.
EPSS 0.00 CVE-2024-50091 US
Information published.
EPSS 0.00 CVE-2024-47703 US
Information published.
EPSS 0.00 CVE-2024-24864 US
Information published.
EPSS 0.00 CVE-2026-53655 US
Information published.
EPSS 0.00 CVE-2026-53265 US
Information published.
EPSS 0.01 CVE-2025-15661 libssh2 US
Information published.
EPSS 0.04 CVE-2026-55200 libssh2 US
Information published.
EPSS 0.01 CVE-2026-55199 libssh2 US
Information published.
EPSS 0.00 CVE-2026-0864 US
Information published.
EPSS 0.00 CVE-2026-11972 US
Information published.
EPSS 0.00 CVE-2026-9697 US
Information published.
EPSS 0.00 CVE-2026-9675 US
Information published.
EPSS 0.00 CVE-2026-56132 US
Information published.
EPSS 0.00 CVE-2026-56403 libexpat US
Information published.
EPSS 0.00 CVE-2026-11525 US
Information published.
EPSS 0.00 CVE-2026-56407 US
Information published.
EPSS 0.01 CVE-2026-48142 NGINX US
Information published.
EPSS 0.00 CVE-2026-56406 libexpat US
Information published.
EPSS 0.00 CVE-2026-56404 US
Information published.
EPSS 0.00 CVE-2026-56405 libexpat US
Added Edge software to the Security Updates table. Customers that are running supported version of Edge are encouraged to update to the indicated version to be protected from this vulnerability.
EPSS 0.00 CVE-2026-50521 Microsoft US
Information published.
EPSS 0.01 CVE-2026-11816 Keras US
Information published.
EPSS 0.00 CVE-2026-12003 Python Software Foundation US
Information published.
EPSS 0.00 CVE-2026-43966 US
Information published.
EPSS 0.00 CVE-2026-9669 US
Information published.
EPSS 0.00 CVE-2026-12087 US
Information published.
EPSS 0.00 CVE-2026-53689 US
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-47646 US
Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-47645 Microsoft US
Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-48582 Microsoft US
Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-48584 Microsoft US
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-47647 Microsoft US
Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-54130 US
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
EPSS 0.01 CVE-2026-42895 Microsoft US
Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-45480 US
Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-32174 US
Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-47633 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-32208 Microsoft US
Information published.
EPSS 0.00 CVE-2026-48854 US
Information published.
EPSS 0.00 CVE-2026-43973 US
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.
EPSS 0.11 CVE-2026-50656 Microsoft US
Information published.
EPSS 0.00 CVE-2026-54411 Linux-PAM US
Information published.
EPSS 0.01 CVE-2026-11526 GD US
Information published.
EPSS 0.00 CVE-2026-34181 US
Information published.
EPSS 0.01 CVE-2026-34180 US
Information published.
EPSS 0.00 CVE-2026-42769 US
Information published.
EPSS 0.01 CVE-2026-42767 US
Information published.
EPSS 0.01 CVE-2026-42766 US
Information published.
EPSS 0.01 CVE-2026-42764 US
Information published.
EPSS 0.00 CVE-2026-45446 US
Information published.
EPSS 0.01 CVE-2026-9076 US
Information published.
EPSS 0.01 CVE-2026-42768 US