Complete feed
Security advisories & CVEs
1354 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-61933] Windows DWM Core Library Information Disclosure Vulnerability
Windows DWM Core Library Information Disclosure Vulnerability Affected product named by the advisory: Windows Server 2025.
Medium [CVE-2026-61928] Windows Hello Tampering Vulnerability
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. Affected products named by the advisory: Windows Server 2016; Windows Server 2016 (Server Core installation); Windows Server 2019; Windows Server 2019 (Server Core installation); and 3 more. Affected products named by the advisory: Windows Server 2022; Windows Server 2025 (Server Core installation).
Medium [CVE-2026-61368] Windows Hyper-V Information Disclosure Vulnerability
Windows Hyper-V Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016.
Medium [CVE-2026-61347] Windows Event Logging Service Information Disclosure Vulnerability
Windows Event Logging Service Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
Medium [CVE-2026-61345] Microsoft Remote Registry Service Denial of Service Vulnerability
Microsoft Remote Registry Service Denial of Service Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
Medium [CVE-2026-59136] Microsoft COM for Windows Information Disclosure Vulnerability
Microsoft COM for Windows Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
Medium [CVE-2026-59135] Microsoft Windows Search Component Information Disclosure Vulnerability
Microsoft Windows Search Component Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
Medium [CVE-2026-59128] Windows Encrypting File System (EFS) Information Disclosure Vulnerability
Windows Encrypting File System (EFS) Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
Medium [CVE-2026-63512] Microsoft SharePoint Server Tampering Vulnerability
Microsoft SharePoint Server Tampering Vulnerability Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.
Medium [CVE-2026-62837] Microsoft SharePoint Server Information Disclosure Vulnerability
Microsoft SharePoint Server Information Disclosure Vulnerability Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.
Medium [CVE-2026-62829] Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability Affected products named by the advisory: Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.
Medium [CVE-2026-6727] MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability
MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.
Critical [CVE-2026-49798] Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
Critical [CVE-2026-58644] Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.
Critical [CVE-2026-54118] Microsoft SQL Server Remote Code Execution Vulnerability
Microsoft SQL Server Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft SQL Server 2016; Microsoft SQL Server 2019; Microsoft SQL Server 2022; Microsoft SQL Server 2017; and 1 more. Affected products named by the advisory: Microsoft SQL Server 2025.
Critical [CVE-2026-54117] Microsoft SQL Server Remote Code Execution Vulnerability
Microsoft SQL Server Remote Code Execution Vulnerability Affected product named by the advisory: Microsoft SQL Server 2025.
Critical [CVE-2026-55008] Microsoft Exchange Server Spoofing Vulnerability
Microsoft Exchange Server Spoofing Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2016 Cumulative Update 23; Microsoft Exchange Server 2019 Cumulative Update 14; Microsoft Exchange Server 2019 Cumulative Update 15; Microsoft Exchange Server Subscription Edition RTM.
Critical [CVE-2026-54990] Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability Affected product named by the advisory: Windows Server 2025.
Critical [CVE-2026-49172] Windows FTP Service Remote Code Execution Vulnerability
Windows FTP Service Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2025; Windows Server 2022; Windows Server 2019.
Critical [CVE-2026-42990] SQL Server ODBC driver Elevation of Privilege Vulnerability
SQL Server ODBC driver Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.