A vulnerability has been found in Microsoft Office 2019/365 Apps/LTSC 2021/LTSC 2024 and classified as critical. The impacted element is an unknown function. This manipulation causes use after free.
This vulnerability is registered as CVE-2026-40419. Remote exploitation of the attack is possible. No exploit is available.
Applying a patch is the recommended action to fix this issue.
A vulnerability, which was classified as critical, was found in Microsoft Office 2019/365 Apps/LTSC 2021/LTSC 2024. The affected element is an unknown function. The manipulation results in use after free.
This vulnerability is cataloged as CVE-2026-40418. The attack may be launched remotely. There is no exploit available.
It is advisable to implement a patch to correct this issue.
A vulnerability, which was classified as critical, has been found in Microsoft Dynamics 365 Business Central. Impacted is an unknown function. The manipulation leads to weak authentication.
This vulnerability is listed as CVE-2026-40417. The attack must be carried out locally. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in Microsoft Windows. This issue affects some unknown processing of the component TCPIP. Executing a manipulation can lead to use after free.
This vulnerability is tracked as CVE-2026-40415. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in Microsoft Windows. This vulnerability affects unknown code of the component TCPIP. Performing a manipulation results in null pointer dereference.
This vulnerability is identified as CVE-2026-40414. The attack can only be performed from the local network. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in Microsoft Windows. This affects an unknown part of the component TCPIP. Such manipulation leads to null pointer dereference.
This vulnerability is referenced as CVE-2026-40413. The attack needs to be initiated within the local network. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability marked as critical has been reported in Microsoft Windows. Affected by this issue is some unknown functionality of the component SMB Client. This manipulation causes use after free.
The identification of this vulnerability is CVE-2026-40410. The attack can only be executed locally. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in Microsoft Windows. Affected by this vulnerability is an unknown functionality of the component WAN ARP Driver. The manipulation results in use after free.
This vulnerability was named CVE-2026-40408. The attack needs to be approached locally. There is no available exploit.
The affected component should be upgraded.
A vulnerability identified as critical has been detected in Microsoft Windows. Affected is an unknown function of the component Common Log File System Driver. The manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2026-40407. Local access is required to approach this attack. No exploit exists.
You should upgrade the affected component.
A vulnerability categorized as problematic has been discovered in Microsoft Windows. This impacts an unknown function of the component TCPIP. Executing a manipulation can lead to use after free.
This vulnerability is handled as CVE-2026-40406. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in Microsoft Windows 11 24H2/11 25H2/11 26H1/Server 2025. It has been rated as critical. This affects an unknown function of the component TCPIP. Performing a manipulation results in null pointer dereference.
This vulnerability is known as CVE-2026-40405. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
A vulnerability was found in Microsoft Windows. It has been declared as critical. The impacted element is an unknown function of the component Graphics. Such manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2026-40403. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A threat actor claims to have breached FutureShop Egypt, an Egyptian grocery delivery platform, by exploiting an entirely exposed API that required no authentication.
A vulnerability was found in Microsoft Windows 11 23H2/Server 2022. It has been classified as critical. The affected element is an unknown function of the component Hyper-V. This manipulation causes use after free.
This vulnerability appears as CVE-2026-40402. The attack requires local access. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability was found in Microsoft Windows and classified as critical. Impacted is an unknown function of the component TCPIP. The manipulation results in null pointer dereference.
This vulnerability is reported as CVE-2026-40401. The attack requires a local approach. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability has been found in Microsoft Windows and classified as critical. This issue affects some unknown processing of the component TCPIP. The manipulation leads to stack-based buffer overflow.
This vulnerability is documented as CVE-2026-40399. The attack needs to be performed locally. There is not any exploit available.
The affected component should be upgraded.
Researchers at Ontinue have discovered an undocumented malware campaign targeting developers with fake Claude Code installers to steal browser passwords and cookies.
A vulnerability, which was classified as critical, was found in Microsoft Windows. This vulnerability affects unknown code of the component Remote Desktop Services. Executing a manipulation can lead to heap-based buffer overflow.
This vulnerability is registered as CVE-2026-40398. The attack needs to be launched locally. No exploit is available.
You should upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Microsoft Windows. This affects an unknown part of the component Common Log File System Driver. Performing a manipulation results in integer underflow.
This vulnerability is cataloged as CVE-2026-40397. The attack must be initiated from a local position. There is no exploit available.
It is advisable to upgrade the affected component.