Aggregator
Математика больше не для гениев-одиночек — нобелевский лауреат доказал, что ИИ и толпа справляются с задачами быстрее
2 weeks 1 day ago
Терри Тао показывает, как наука о числах будет выглядеть дальше.
CVE-2026-42913 | Microsoft Windows up to Server 2025 Remote Desktop Client race condition
2 weeks 1 day ago
A vulnerability described as critical has been identified in Microsoft Windows up to Server 2025. Affected by this issue is some unknown functionality of the component Remote Desktop Client. The manipulation results in race condition.
This vulnerability is reported as CVE-2026-42913. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-42912 | Microsoft Windows up to Server 2025 Telephony Service race condition
2 weeks 1 day ago
A vulnerability marked as critical has been reported in Microsoft Windows. Affected by this vulnerability is an unknown functionality of the component Telephony Service. The manipulation leads to race condition.
This vulnerability is documented as CVE-2026-42912. The attack needs to be performed locally. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-42911 | Microsoft Windows up to Server 2025 Ancillary Function Driver for WinSock use after free
2 weeks 1 day ago
A vulnerability labeled as critical has been found in Microsoft Windows. Affected is an unknown function of the component Ancillary Function Driver for WinSock. Executing a manipulation can lead to use after free.
This vulnerability is registered as CVE-2026-42911. The attack needs to be launched locally. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2026-42910 | Microsoft Windows 11 24H2/11 25H2/11 26H1/Server 2025 Hotpatch Monitoring Service out-of-bounds write
2 weeks 1 day ago
A vulnerability identified as critical has been detected in Microsoft Windows 11 24H2/11 25H2/11 26H1/Server 2025. This impacts an unknown function of the component Hotpatch Monitoring Service. Performing a manipulation results in out-of-bounds write.
This vulnerability is cataloged as CVE-2026-42910. The attack must be initiated from a local position. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-42909 | Microsoft Windows up to Server 2025 Remote Desktop Client race condition
2 weeks 1 day ago
A vulnerability categorized as critical has been discovered in Microsoft Windows. This affects an unknown function of the component Remote Desktop Client. Such manipulation leads to race condition.
This vulnerability is listed as CVE-2026-42909. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-42908 | Microsoft Windows up to Server 2025 Remote Desktop Protocol out-of-bounds
2 weeks 1 day ago
A vulnerability was found in Microsoft Windows. It has been rated as problematic. The impacted element is an unknown function of the component Remote Desktop Protocol. This manipulation causes out-of-bounds read.
This vulnerability is tracked as CVE-2026-42908. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-42907 | Microsoft Windows up to Server 2025 Shell information disclosure
2 weeks 1 day ago
A vulnerability was found in Microsoft Windows up to Server 2025. It has been declared as problematic. The affected element is an unknown function of the component Shell. The manipulation results in information disclosure.
This vulnerability is identified as CVE-2026-42907. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-42906 | Microsoft Windows up to Server 2025 Shell information disclosure
2 weeks 1 day ago
A vulnerability was found in Microsoft Windows up to Server 2025. It has been classified as problematic. Impacted is an unknown function of the component Shell. The manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2026-42906. The attack can only be performed from a local environment. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-42905 | Microsoft Windows up to Server 2025 DWM Core Library use after free
2 weeks 1 day ago
A vulnerability was found in Microsoft Windows and classified as critical. This issue affects some unknown processing of the component DWM Core Library. Executing a manipulation can lead to use after free.
The identification of this vulnerability is CVE-2026-42905. The attack can only be executed locally. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-42904 | Microsoft Windows up to Server 2025 TCP/IP heap-based overflow
2 weeks 1 day ago
A vulnerability has been found in Microsoft Windows up to Server 2025 and classified as very critical. This vulnerability affects unknown code of the component TCPIP. Performing a manipulation results in heap-based buffer overflow.
This vulnerability was named CVE-2026-42904. The attack needs to be approached within the local network. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-42903 | Microsoft Windows up to Server 2025 Kerberos null pointer dereference
2 weeks 1 day ago
A vulnerability, which was classified as critical, was found in Microsoft Windows. This affects an unknown part of the component Kerberos. Such manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2026-42903. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com
Microsoft Patch Tuesday June 2026 – 198 Vulnerabilities Fixed, Including 3 Zero-days
2 weeks 1 day ago
Microsoft has released its June 2026 Patch Tuesday security updates, addressing a hefty 198 vulnerabilities across its product ecosystem. The June rollout, published on June 9, 2026, stands out not only for its volume but also for the inclusion of three zero-day vulnerabilities that were actively exploited or publicly known before a fix was available. […]
The post Microsoft Patch Tuesday June 2026 – 198 Vulnerabilities Fixed, Including 3 Zero-days appeared first on Cyber Security News.
Guru Baran
CVE-2026-42902 | Microsoft PowerToys prior v0.99.1 improper authorization
2 weeks 1 day ago
A vulnerability, which was classified as critical, has been found in Microsoft PowerToys. Affected by this issue is some unknown functionality. This manipulation causes improper authorization.
This vulnerability is handled as CVE-2026-42902. It is possible to launch the attack on the local host. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-42837 | Microsoft Windows up to Server 2025 Projected File System out-of-bounds
2 weeks 1 day ago
A vulnerability classified as critical was found in Microsoft Windows up to Server 2025. Affected by this vulnerability is an unknown functionality of the component Projected File System. The manipulation results in out-of-bounds read.
This vulnerability is known as CVE-2026-42837. Attacking locally is a requirement. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-42836 | Microsoft Windows up to Server 2025 Function Discovery Service fdwsd.dll race condition
2 weeks 1 day ago
A vulnerability classified as critical has been found in Microsoft Windows. Affected is an unknown function in the library fdwsd.dll of the component Function Discovery Service. The manipulation leads to race condition.
This vulnerability is traded as CVE-2026-42836. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-42835 | Microsoft Teams 1.0.0.2026092103 on Android injection
2 weeks 1 day ago
A vulnerability described as problematic has been identified in Microsoft Teams 1.0.0.2026092103 on Android. This impacts an unknown function. Executing a manipulation can lead to injection.
This vulnerability appears as CVE-2026-42835. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-42829 | Microsoft Windows 11 24H2/11 25H2/11 26H1 Administrator Protection access control
2 weeks 1 day ago
A vulnerability marked as critical has been reported in Microsoft Windows 11 24H2/11 25H2/11 26H1. This affects an unknown function of the component Administrator Protection. Performing a manipulation results in improper access controls.
This vulnerability is reported as CVE-2026-42829. The attack requires a local approach. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-42828 | Microsoft Windows up to Server 2025 Projected File System buffer over-read
2 weeks 1 day ago
A vulnerability labeled as critical has been found in Microsoft Windows up to Server 2025. The impacted element is an unknown function of the component Projected File System. Such manipulation leads to buffer over-read.
This vulnerability is documented as CVE-2026-42828. The attack needs to be performed locally. There is not any exploit available.
The affected component should be upgraded.
vuldb.com