Microsoft threat watch

Security Update Guide, advisories, and patch watch.

Watch items

Recent Microsoft watch items

Showing the 20 most recent items, newest first. Each row links to the official advisory.

20 rows ยท sorted newest first

Operations view

FFC-DH Peer Validation Uses Attacker-Supplied q (CVE-2026-42770)

low
activeVendor advisoryCVE-2026-42770

Information published. Information published.

Jul 21, 2026, 3:05 AMOfficial source

Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write (CVE-2026-3842)

high
activeVendor advisoryCVE-2026-3842

Information published. Information published. Information published.

Jul 19, 2026, 3:02 AMOfficial source

NGINX ngx_http_ssi_module vulnerability (CVE-2026-56434)

medium
activeVendor advisoryCVE-2026-56434

Information published. Information published. Information published.

Jul 19, 2026, 3:02 AMOfficial source

NGINX Map directive and Regex matching vulnerability (CVE-2026-42533)

high
activeVendor advisoryCVE-2026-42533

Information published. Information published. Information published.

Jul 19, 2026, 3:02 AMOfficial source

A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. (CVE-2026-38755)

high
activeVendor advisoryCVE-2026-38755

Information published. Information published. Information published.

Jul 19, 2026, 3:02 AMOfficial source

A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. (CVE-2026-38754)

high
activeVendor advisoryCVE-2026-38754

Information published. Information published. Information published.

Jul 19, 2026, 3:01 AMOfficial source

CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record (CVE-2026-62299)

medium
activeVendor advisoryCVE-2026-62299

Information published. Information published.

Jul 18, 2026, 3:01 AMOfficial source

Chromium: CVE-2026-15905 Use after free in Aura (CVE-2026-15905)

activeVendor advisoryCVE-2026-15905

Information published.

Jul 17, 2026, 7:42 PMOfficial source

Chromium: CVE-2026-15904 Use after free in Ozone (CVE-2026-15904)

activeVendor advisoryCVE-2026-15904

Information published.

Jul 17, 2026, 7:42 PMOfficial source

Chromium: CVE-2026-15903 Out of bounds read and write in V8 (CVE-2026-15903)

activeVendor advisoryCVE-2026-15903

Information published.

Jul 17, 2026, 7:42 PMOfficial source

Chromium: CVE-2026-15902 Use after free in Cast (CVE-2026-15902)

activeVendor advisoryCVE-2026-15902

Information published.

Jul 17, 2026, 7:42 PMOfficial source

Chromium: CVE-2026-15901 Use after free in Network (CVE-2026-15901)

activeVendor advisoryCVE-2026-15901

Information published.

Jul 17, 2026, 7:42 PMOfficial source

Chromium: CVE-2026-15900 Use after free in GPU (CVE-2026-15900)

activeVendor advisoryCVE-2026-15900

Information published.

Jul 17, 2026, 7:42 PMOfficial source

Chromium: CVE-2026-15899 Use after free in CameraCapture (CVE-2026-15899)

activeVendor advisoryCVE-2026-15899

Information published.

Jul 17, 2026, 7:42 PMOfficial source

pyasn1: Uncontrolled resource consumption when converting decoded REAL values (CVE-2026-59886)

high
activeVendor advisoryCVE-2026-59886

Information published. Information published.

Jul 17, 2026, 3:02 AMOfficial source

pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs (CVE-2026-59884)

high
activeVendor advisoryCVE-2026-59884

Information published. Information published.

Jul 17, 2026, 3:02 AMOfficial source

pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service (CVE-2026-59885)

high
activeVendor advisoryCVE-2026-59885

Information published. Information published.

Jul 17, 2026, 3:02 AMOfficial source

DBI::ProfileData versions before 1.651 for Perl do not limit the path index (CVE-2026-60081)

high
activeVendor advisoryCVE-2026-60081

Information published. Information published.

Jul 17, 2026, 3:02 AMOfficial source

DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location (CVE-2026-15392)

high
activeVendor advisoryCVE-2026-15392

Information published. Information published.

Jul 17, 2026, 3:02 AMOfficial source

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row (CVE-2026-60082)

critical
activeVendor advisoryCVE-2026-60082

Information published. Information published.

Jul 17, 2026, 3:02 AMOfficial source

Vendor watch hub

What this page covers

The Microsoftwatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.

  • Confirm whether recent Microsoft activity overlaps with your environment.
  • Prioritize advisories by MSP-relevance score, severity, and status.
  • Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.

At a glance

Tracked

4845

Active

3999

Featured

4076

Unique CVEs

20

Most recent entry

Jul 21, 2026, 3:05 AM

Feed refreshes daily ยท 5:15 a.m. Central

SourcesยทMicrosoft Security Update Guide (MSRC), CISA KEV, and NVD

"Most recent entry" is the newest item the upstream feed has published โ€” not our sync time.

Related vendors

Other productivity vendors in the radar

Vendor watch FAQ

Common questions

What is the Microsoft threat watch page?

It is the Microsoft-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.

How should teams use the Microsoft watch page?

Use it to confirm whether current Microsoft issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.

Can ITECS help respond to Microsoft security issues?

Yes. ITECS can help map Microsoft advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.