From Our Security Partners
CVE-2026-41094 Microsoft Data Formulator Remote Code Execution Vulnerability
Improper control of generation of code (‘code injection’) in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network.
CVE-2026-34345 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-41101 Microsoft Word for Android Spoofing Vulnerability
Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.
CVE-2026-34347 Windows Win32k Elevation of Privilege Vulnerability
Use after free in Windows Win32K – GRFX allows an authorized attacker to elevate privileges locally.
CVE-2026-41611 Visual Studio Code Remote Code Execution Vulnerability
Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally.
CVE-2026-34350 Windows Storport Miniport Driver Denial of Service Vulnerability
Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network.
CVE-2026-40360 Microsoft Excel Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-34351 Windows TCP/IP Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization (‘race condition’) in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CVE-2026-40364 Microsoft Word Remote Code Execution Vulnerability
Access of resource using incompatible type (‘type confusion’) in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-35415 Windows Storage Spaces Controller Elevation of Privilege Vulnerability
Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.