From Our Security Partners
CVE-2026-35420 Windows Kernel Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-40408 Windows WAN ARP Driver Elevation of Privilege Vulnerability
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
CVE-2026-35419 Windows DWM Core Library Information Disclosure Vulnerability
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2026-40406 Windows TCP/IP Information Disclosure Vulnerability
Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.
CVE-2026-35418 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-40399 Windows TCP/IP Elevation of Privilege Vulnerability
Stack-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
Microsoft’s May 2026 Patch Tuesday Addresses 118 CVEs (CVE-2026-41103)
This post was originally published on this site. 16Critical 102Important 0Moderate 0Low Microsoft addresses 118 CVEs in its May 2026 Patch Tuesday release, with no zero-days exploited in the wild or publicly disclosed for the first time since June 2024. Microsoft patched 118 CVEs in its May 2026 Patch Tuesday release, with 16 rated critical […]
Microsoft’s May 2026 Patch Tuesday Addresses 118 CVEs (CVE-2026-41103)
16Critical 102Important 0Moderate 0Low Microsoft addresses 118 CVEs in its May 2026 Patch Tuesday release, with no zero-days exploited in the wild or publicly disclosed for the first time since June 2024. Microsoft patched 118 CVEs in its May 2026 Patch Tuesday release, with 16 rated critical and 102 rated as important. Our counts omitted […]
Advisory: Linux Kernel LPE – Dirty Frag
This post was originally published on this site.Severity: Informational First Published: Fri, 08 May 2026 09:00:00 GMT Updated: Tue, 12 May 2026 00:00:00 GMT Publication ID: sophos-sa-20260508-dirtyfrag Article Version: 2
CVE-2026-32226 .NET Framework Denial of Service Vulnerability
This CVE has been updated to include additional Security Updates for .NET Framework