CVE-2026-54171 Excon: redact additional sensitive/risky headers when following redirects MSRC Security Update Guide 23 juillet 2026 à 10:44 Information published.
CVE-2026-44508 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate. MSRC Security Update Guide 23 juillet 2026 à 10:06 Information published.
CVE-2026-44510 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate. MSRC Security Update Guide 23 juillet 2026 à 10:06 Information published.
CVE-2026-44509 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate. MSRC Security Update Guide 23 juillet 2026 à 10:06 Information published.
CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist() MSRC Security Update Guide 23 juillet 2026 à 10:06 Information published.
CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys MSRC Security Update Guide 23 juillet 2026 à 10:06 Information published.
CVE-2026-15788 WCOW cache mount source selector resolves NTFS junctions outside of cache root MSRC Security Update Guide 23 juillet 2026 à 10:06 Information published.
CVE-2026-26081 HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected. MSRC Security Update Guide 23 juillet 2026 à 10:05 Information published.
CVE-2026-26080 HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected. MSRC Security Update Guide 23 juillet 2026 à 10:05 Information published.
CVE-2026-15588 Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering MSRC Security Update Guide 23 juillet 2026 à 10:05 Information published.
CVE-2026-63308 Helm Files.Lines Denial of Service via Empty Chart Files MSRC Security Update Guide 23 juillet 2026 à 10:05 Information published.
CVE-2026-50243 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL MSRC Security Update Guide 23 juillet 2026 à 10:05 Information published.
CVE-2026-41637 Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries MSRC Security Update Guide 23 juillet 2026 à 10:05 Information published.
CVE-2026-50252 Possible cache poisoning attack by mapping source port population per thread MSRC Security Update Guide 23 juillet 2026 à 10:05 Information published.
CVE-2026-50251 Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush MSRC Security Update Guide 23 juillet 2026 à 10:05 Information published.
CVE-2026-55991 Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2 MSRC Security Update Guide 23 juillet 2026 à 10:05 Information published.
CVE-2026-55990 Packet of death for a DNSCrypt misconfigured Unbound MSRC Security Update Guide 23 juillet 2026 à 10:04 Information published.
CVE-2026-50046 Possible heap use-after-free in an error path when a DoT forwarded query is jostled out MSRC Security Update Guide 23 juillet 2026 à 10:04 Information published.
CVE-2026-14586 Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments MSRC Security Update Guide 23 juillet 2026 à 10:04 Information published.
CVE-2026-42955 Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records MSRC Security Update Guide 23 juillet 2026 à 10:04 Information published.
CVE-2026-46582 A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path MSRC Security Update Guide 23 juillet 2026 à 10:04 Information published.
CVE-2026-54478 DNS Cookie bypass when combined with proxy-protocol use MSRC Security Update Guide 23 juillet 2026 à 10:04 Information published.
CVE-2026-56444 Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration MSRC Security Update Guide 23 juillet 2026 à 10:04 Information published.
CVE-2026-32665 Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass MSRC Security Update Guide 23 juillet 2026 à 10:04 Information published.
CVE-2026-40691 Packet of death for DNSCrypt over TCP MSRC Security Update Guide 23 juillet 2026 à 10:04 Information published.
CVE-2026-55717 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash MSRC Security Update Guide 23 juillet 2026 à 10:04 Information published.
CVE-2026-44621 Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated MSRC Security Update Guide 23 juillet 2026 à 10:03 Information published.
CVE-2026-56416 Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name MSRC Security Update Guide 23 juillet 2026 à 10:03 Information published.
CVE-2026-52863 Memory corruption could lead to crash and denial of service MSRC Security Update Guide 23 juillet 2026 à 10:03 Information published.
CVE-2026-55708 Privacy/configuration issue when adding local data in views through 'unbound-control' MSRC Security Update Guide 23 juillet 2026 à 10:03 Information published.
CVE-2026-44690 Cross-zone wildcard cache poisoning via RRSIG.labels manipulation MSRC Security Update Guide 23 juillet 2026 à 10:03 Information published.
CVE-2026-50248 BOGUS configured primary hostname accepted for XFR in auth/rpz zones MSRC Security Update Guide 23 juillet 2026 à 10:03 Information published.
CVE-2026-50045 'max-global-quota' reset by DNSSEC validation restarts MSRC Security Update Guide 23 juillet 2026 à 10:03 Information published.
CVE-2026-44687 Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN MSRC Security Update Guide 23 juillet 2026 à 10:03 Information published.
CVE-2026-55973 'dns-error-reporting: yes' leads to stack buffer overflow MSRC Security Update Guide 23 juillet 2026 à 10:03 Information published.
CVE-2026-53910 Heap-based Buffer Overflow in GNU diffutils MSRC Security Update Guide 23 juillet 2026 à 10:02 Information published.
CVE-2026-62994 CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin MSRC Security Update Guide 23 juillet 2026 à 10:02 Information published.
CVE-2026-63136 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service MSRC Security Update Guide 23 juillet 2026 à 10:02 Information published.
CVE-2026-63263 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service MSRC Security Update Guide 23 juillet 2026 à 10:02 Information published.
CVE-2026-63140 Reachable Assertion in Elasticsearch Leading to Denial of Service MSRC Security Update Guide 23 juillet 2026 à 10:02 Information published.