Known Vulnerabilities for Surface by Microsoft
Listed below are 1 of the newest known vulnerabilities associated with "Surface" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-101065 json | Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart comma... | Not Provided | 2026-09-27 | 2026-09-30 |
| CVE-2026-93405 json | Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markdown, ... | Not Provided | 2026-09-24 | 2026-09-29 |
| CVE-2026-93114 json | In the Linux kernel, the following vulnerability has been resolved: platform/surface: acpi-notify: Check ACPI companion befo... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-91954 json | FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits comm... | Not Provided | 2026-09-15 | 2026-09-17 |
| CVE-2026-89589 json | In the Linux kernel, the following vulnerability has been resolved: acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work loc... | Not Provided | 2026-09-11 | 2026-09-21 |
| CVE-2026-86338 json | Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may not see ... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-85600 json | Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml()... | Not Provided | 2026-09-04 | 2026-09-05 |
| CVE-2026-82456 json | argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller creden... | Not Provided | 2026-08-29 | 2026-09-02 |
| CVE-2026-81530 json | A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management crede... | Not Provided | 2026-08-27 | 2026-08-28 |
| CVE-2026-81003 json | In the Linux kernel, the following vulnerability has been resolved: net/iucv: filter frames in afiucv_hs_rcv() by ingress de... | Not Provided | 2026-09-11 | 2026-09-14 |