Microsoft threat watch

Security Update Guide, advisories, and patch watch.

Watch items

Recent Microsoft watch items

Showing the 20 most recent items, newest first. Each row links to the official advisory.

20 rows ยท sorted newest first

Operations view

gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (CVE-2026-64577)

activeVendor advisoryCVE-2026-64577

Information published.

Aug 9, 2026, 3:43 AMOfficial source

btrfs: reject free space cache with more entries than pages (CVE-2026-64567)

activeVendor advisoryCVE-2026-64567

Information published.

Aug 9, 2026, 3:43 AMOfficial source

mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n (CVE-2026-64569)

activeVendor advisoryCVE-2026-64569

Information published.

Aug 9, 2026, 3:43 AMOfficial source

ipv4: fib: free fib_alias with kfree_rcu() on insert error path (CVE-2026-64572)

activeVendor advisoryCVE-2026-64572

Information published.

Aug 9, 2026, 3:42 AMOfficial source

Bluetooth: qca: fix NVM tag length underflow in TLV parser (CVE-2026-64573)

activeVendor advisoryCVE-2026-64573

Information published.

Aug 9, 2026, 3:42 AMOfficial source

wifi: mac80211: tear down new links on vif update error path (CVE-2026-64574)

activeVendor advisoryCVE-2026-64574

Information published.

Aug 9, 2026, 3:42 AMOfficial source

ipv6: ndisc: fix NULL deref in accept_untracked_na() (CVE-2026-64542)

activeVendor advisoryCVE-2026-64542

Information published.

Aug 9, 2026, 3:41 AMOfficial source

Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass (CVE-2026-48145)

high
activeVendor advisoryCVE-2026-48145

Information published.

Aug 7, 2026, 3:22 AMOfficial source

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression Size Limit (CVE-2026-48586)

high
activeVendor advisoryCVE-2026-48586

Information published. Information published.

Aug 7, 2026, 3:22 AMOfficial source

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit (CVE-2026-43871)

high
activeVendor advisoryCVE-2026-43871

Information published. Information published.

Aug 7, 2026, 3:21 AMOfficial source

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable() (CVE-2026-55969)

high
activeVendor advisoryCVE-2026-55969

Information published. Information published.

Aug 7, 2026, 3:21 AMOfficial source

Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport (CVE-2026-41608)

high
activeVendor advisoryCVE-2026-41608

Information published.

Aug 7, 2026, 3:20 AMOfficial source

Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat() (CVE-2026-55970)

medium
activeVendor advisoryCVE-2026-55970

Information published.

Aug 7, 2026, 3:20 AMOfficial source

xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() (CVE-2026-64580)

activeVendor advisoryCVE-2026-64580

Information published. Information published.

Aug 7, 2026, 3:19 AMOfficial source

nexthop: initialize extack in nh_res_bucket_migrate() (CVE-2026-64576)

activeVendor advisoryCVE-2026-64576

Information published. Information published.

Aug 7, 2026, 3:19 AMOfficial source

Apache Thrift: Python TSSLSocket Hostname Matcher Import (CVE-2026-66053)

medium
activeVendor advisoryCVE-2026-66053

Information published.

Aug 7, 2026, 3:19 AMOfficial source

xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert (CVE-2026-64579)

activeVendor advisoryCVE-2026-64579

Information published. Information published.

Aug 7, 2026, 3:19 AMOfficial source

wifi: p54: validate RX frame length in p54_rx_eeprom_readback() (CVE-2026-64571)

activeVendor advisoryCVE-2026-64571

Information published. Information published.

Aug 7, 2026, 3:18 AMOfficial source

Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass (CVE-2026-58662)

critical
activeVendor advisoryCVE-2026-58662

Information published.

Aug 7, 2026, 3:18 AMOfficial source

ksmbd: validate compound request size before reading StructureSize2 (CVE-2026-64578)

activeVendor advisoryCVE-2026-64578

Information published. Information published.

Aug 7, 2026, 3:18 AMOfficial source

Vendor watch hub

What this page covers

The Microsoftwatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.

  • Confirm whether recent Microsoft activity overlaps with your environment.
  • Prioritize advisories by MSP-relevance score, severity, and status.
  • Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.

At a glance

Tracked

5533

Active

4621

Featured

4735

Unique CVEs

20

Most recent entry

Aug 9, 2026, 3:43 AM

Feed refreshes daily ยท 5:15 a.m. Central

SourcesยทMicrosoft Security Update Guide (MSRC), CISA KEV, and NVD

"Most recent entry" is the newest item the upstream feed has published โ€” not our sync time.

Related vendors

Other productivity vendors in the radar

Vendor watch FAQ

Common questions

What is the Microsoft threat watch page?

It is the Microsoft-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.

How should teams use the Microsoft watch page?

Use it to confirm whether current Microsoft issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.

Can ITECS help respond to Microsoft security issues?

Yes. ITECS can help map Microsoft advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.