{"page":1,"per_page":10,"total_vulns":385,"total_pages":39,"vulnerabilities":[{"_id":"6a8491e9ce923952960e46b5","cveID":"CVE-2026-55040","dateAdded":"2026-08-18","dueDate":"2026-08-21","notes":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-55040","product":"SharePoint","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.","vendorProject":"Microsoft","vulnerabilityName":"Microsoft SharePoint Weak Authentication Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":9.1,"nvdReferences":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040","source":"secure@microsoft.com","tags":["Patch","Vendor Advisory"]},{"url":"https://github.com/sfewer-r7/CVE-2026-55040","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"vulnStatus":"Modified"}],"githubPocs":["https://github.com/sfewer-r7/CVE-2026-55040","https://github.com/l0ggg/CVE-2026-55040"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":["Mirage Kitten, Fox Tempest, Qilin Ransomware, Helpdesk Hijackers, MedusaHVNC, Dysphoria","ATT&CK"],"communityMalwareFamilies":["Beyondtrust","Viewstate","Azure synapse","Medusa","Stormencryptor","Azure dns"],"communityAffectedIndustries":["Financial services","Healthcare","Education","Finance"]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a8491e9ce923952960e46b3","cveID":"CVE-2026-33824","dateAdded":"2026-08-18","dueDate":"2026-08-21","notes":"https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-33824 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-33824","product":"Internet Key Exchange (IKE) Service Extensions","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.","vendorProject":"Microsoft","vulnerabilityName":"Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":9.8,"nvdReferences":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824","source":"secure@microsoft.com","tags":["Vendor Advisory"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/EpSiLoNPoInTOrI/IKEV2-POC","https://github.com/z3r0h3ro/CVE-2026-33824"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a7b819a6b6eb7f206544dec","cveID":"CVE-2026-68820","dateAdded":"2026-08-11","dueDate":"2026-08-25","notes":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68820 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-68820","product":"Windows Ancillary Function Driver for WinSock ","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.","vendorProject":"Microsoft","vulnerabilityName":"Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability","nvdData":[{"attackVector":"LOCAL","attackComplexity":"HIGH","baseSeverity":"HIGH","exploitabilityScore":1.0,"baseScore":7.0,"nvdReferences":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820","source":"secure@microsoft.com","tags":["Patch","Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-68820","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/HORKimhab/CVE-2026-68820","https://github.com/ubitquity/Windows-WinSock-UAF-Mitigation"],"openThreatData":[{"adversaries":["Lazarus"],"malwareFamiles":["Securitypdf","Olympic destroyer - s0365","Fudmodule","Foresttiger","Relayshell","Mistpen"],"affectedIndustries":["Aerospace","Defense","Aviation"],"communityAdversaries":["Lazarus","Abyssos RAT, Project CAV3RN, Head Mare delivering backdoors, Operation Dream Job, DeadLock ransomwar"],"communityMalwareFamilies":["Securitypdf","Olympic destroyer - s0365","Fudmodule","Foresttiger","Relayshell","Mistpen"],"communityAffectedIndustries":["Aerospace","Defense","Aviation"]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a6123990eca39cef33960d4","cveID":"CVE-2026-50522","dateAdded":"2026-07-22","dueDate":"2026-07-25","notes":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-50522","product":"SharePoint","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.","vendorProject":"Microsoft","vulnerabilityName":"Microsoft SharePoint Deserialization of Untrusted Data Vulnerability ","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":9.8,"nvdReferences":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522","source":"secure@microsoft.com","tags":["Patch","Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50522","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"vulnStatus":"Modified"}],"githubPocs":["https://github.com/HORKimhab/CVE-2026-50522","https://github.com/4minx/CVE-2026-50522","https://github.com/darses/CVE-2026-50522","https://github.com/ChPratik/CVE-2026-50522","https://github.com/WismanSec/sharepoint-2026-poc"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":["Azure synapse","Azure dns"],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a591e79f177f3de7ce9962c","cveID":"CVE-2026-58644","dateAdded":"2026-07-16","dueDate":"2026-07-19","notes":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-58644","product":"SharePoint","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.","vendorProject":"Microsoft","vulnerabilityName":"Microsoft SharePoint Deserialization of Untrusted Data Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":9.8,"nvdReferences":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644","source":"secure@microsoft.com","tags":["Patch","Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-58644","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":[],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":["Azure dns","Azure synapse","Viewstate"],"communityAffectedIndustries":["Financial services"]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a56898912d1215ae54993fb","cveID":"CVE-2026-56164","dateAdded":"2026-07-14","dueDate":"2026-07-17","notes":"https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56164 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-56164","product":"SharePoint Server","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.","vendorProject":"Microsoft","vulnerabilityName":"Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"MEDIUM","exploitabilityScore":3.9,"baseScore":5.3,"nvdReferences":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164","source":"secure@microsoft.com","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56164","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/sentinel-aidefense/CVE-2026-56164-EXP","https://github.com/sam00/POC-CVE-2026-56164-exploit"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":["Mirage Kitten, Fox Tempest, Qilin Ransomware, Helpdesk Hijackers, MedusaHVNC, Dysphoria"],"communityMalwareFamilies":["Viewstate","Azure dns","Azure synapse"],"communityAffectedIndustries":["Financial services"]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a56898912d1215ae54993fa","cveID":"CVE-2026-56155","dateAdded":"2026-07-14","dueDate":"2026-07-28","notes":"https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-56155","product":"Active Directory Federation Services","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.","vendorProject":"Microsoft","vulnerabilityName":"Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability ","nvdData":[{"attackVector":"LOCAL","attackComplexity":"LOW","baseSeverity":"HIGH","exploitabilityScore":1.8,"baseScore":7.8,"nvdReferences":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155","source":"secure@microsoft.com","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56155","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":[],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":["Mirage Kitten, Fox Tempest, Qilin Ransomware, Helpdesk Hijackers, MedusaHVNC, Dysphoria"],"communityMalwareFamilies":["Azure dns","Azure synapse"],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a4574197f69a7c885040791","cveID":"CVE-2026-45659","dateAdded":"2026-07-01","dueDate":"2026-07-04","notes":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-45659","product":"SharePoint Server","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.","vendorProject":"Microsoft","vulnerabilityName":"Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"HIGH","exploitabilityScore":2.8,"baseScore":8.8,"nvdReferences":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659","source":"secure@microsoft.com","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45659","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"vulnStatus":"Modified"}],"githubPocs":["https://github.com/mistbarbarianspot/CVE-2026-45659-SharePoint-RCE","https://github.com/HORKimhab/CVE-2026-45659","https://github.com/amnsecurity/CVE-2026-45659-SharePoint-RCE"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":["Mirage Kitten, Fox Tempest, Qilin Ransomware, Helpdesk Hijackers, MedusaHVNC, Dysphoria"],"communityMalwareFamilies":["Viewstate"],"communityAffectedIndustries":["Financial services"]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a0deae9d5f9c3f2c2b822c3","cveID":"CVE-2010-0249","dateAdded":"2026-06-03","dueDate":"2026-06-03","notes":"https://learn.microsoft.com/en-us/security-updates/SecurityAdvisories/2010/979352 ; https://nvd.nist.gov/vuln/detail/CVE-2010-0249","product":"Internet Explorer","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.","vendorProject":"Microsoft","vulnerabilityName":"Microsoft Internet Explorer Use-After-Free Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"HIGH","exploitabilityScore":2.8,"baseScore":8.8,"nvdReferences":[{"url":"http://blogs.technet.com/msrc/archive/2010/01/14/security-advisory-979352.aspx","source":"secure@microsoft.com","tags":["Broken Link","Vendor Advisory"]},{"url":"http://news.cnet.com/8301-27080_3-10435232-245.html","source":"secure@microsoft.com","tags":["Broken Link"]},{"url":"http://osvdb.org/61697","source":"secure@microsoft.com","tags":["Broken Link"]},{"url":"http://securitytracker.com/id?1023462","source":"secure@microsoft.com","tags":["Broken Link","Third Party Advisory","VDB Entry"]},{"url":"http://support.microsoft.com/kb/979352","source":"secure@microsoft.com","tags":["Patch","Vendor Advisory"]},{"url":"http://www.exploit-db.com/exploits/11167","source":"secure@microsoft.com","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"http://www.kb.cert.org/vuls/id/492515","source":"secure@microsoft.com","tags":["Third Party Advisory","US Government Resource"]},{"url":"http://www.microsoft.com/technet/security/advisory/979352.mspx","source":"secure@microsoft.com","tags":["Broken Link","Patch","Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/37815","source":"secure@microsoft.com","tags":["Broken Link","Exploit","Third Party Advisory","VDB Entry"]},{"url":"http://www.us-cert.gov/cas/techalerts/TA10-055A.html","source":"secure@microsoft.com","tags":["Broken Link","Third Party Advisory","US Government Resource"]},{"url":"http://www.vupen.com/english/advisories/2010/0135","source":"secure@microsoft.com","tags":["Broken Link"]},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-002","source":"secure@microsoft.com","tags":["Patch","Vendor Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55642","source":"secure@microsoft.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6835","source":"secure@microsoft.com","tags":["Broken Link"]},{"url":"http://blogs.technet.com/msrc/archive/2010/01/14/security-advisory-979352.aspx","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"http://news.cnet.com/8301-27080_3-10435232-245.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"http://osvdb.org/61697","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"http://securitytracker.com/id?1023462","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"]},{"url":"http://support.microsoft.com/kb/979352","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"http://www.exploit-db.com/exploits/11167","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"http://www.kb.cert.org/vuls/id/492515","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"]},{"url":"http://www.microsoft.com/technet/security/advisory/979352.mspx","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch","Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/37815","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Exploit","Third Party Advisory","VDB Entry"]},{"url":"http://www.us-cert.gov/cas/techalerts/TA10-055A.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","US Government Resource"]},{"url":"http://www.vupen.com/english/advisories/2010/0135","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-002","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55642","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6835","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}],"vulnStatus":"Modified"}],"githubPocs":[],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[""]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a0deae9d5f9c3f2c2b822c9","cveID":"CVE-2026-45498","dateAdded":"2026-05-20","dueDate":"2026-06-03","notes":"https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45498 ; https://nvd.nist.gov/vuln/detail/CVE-2026-45498","product":"Defender","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Microsoft Defender contains an unspecified vulnerability that allows for denial of service.","vendorProject":"Microsoft","vulnerabilityName":"Microsoft Defender Denial of Service Vulnerability","nvdData":[{"attackVector":"LOCAL","attackComplexity":"LOW","baseSeverity":"MEDIUM","exploitabilityScore":2.5,"baseScore":4.0,"nvdReferences":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45498","source":"secure@microsoft.com","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45498","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Third Party Advisory","US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/salihuahmad105-creator/Vulnerability-scanner"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"}]}