Known Vulnerabilities for products from Microsoft

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Microsoft".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Additional devices specifications by Microsoft can be found at device.report : Microsoft

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-40321 json Not Provided 2026-04-17 2026-04-20
CVE-2026-40306 json Not Provided 2026-04-17 2026-04-20
CVE-2026-40305 json Not Provided 2026-04-17 2026-04-20
CVE-2026-39844 json NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath only recognizes forward slashes (/) as path sepa... Not Provided 2026-04-08 2026-04-15
CVE-2026-39424 json Not Provided 2026-04-14 2026-04-16
CVE-2026-35654 json Not Provided 2026-04-10 2026-04-13
CVE-2026-35562 json Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a th... Not Provided 2026-04-03 2026-04-14
CVE-2026-35561 json Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver bef... Not Provided 2026-04-03 2026-04-14
CVE-2026-35560 json Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 mi... Not Provided 2026-04-03 2026-04-14
CVE-2026-35559 json Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor... Not Provided 2026-04-03 2026-04-14
CVE-2026-35558 json Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0 migh... Not Provided 2026-04-03 2026-04-14
CVE-2026-35199 json SymCrypt is the core cryptographic function library currently used by Windows. From 103.5.0 to before 103.11.0, The SymCryptX... Not Provided 2026-04-06 2026-04-16
CVE-2026-34721 json Not Provided 2026-04-08 2026-04-09
CVE-2026-34626 json Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modific... Not Provided 2026-04-14 2026-04-16
CVE-2026-34622 json Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modific... Not Provided 2026-04-14 2026-04-16
CVE-2026-34621 json Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Objec... Not Provided 2026-04-11 2026-04-13
CVE-2026-34506 json Not Provided 2026-03-31 2026-03-31
CVE-2026-34401 json XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prio... Not Provided 2026-03-31 2026-04-13
CVE-2026-34397 json Not Provided 2026-04-01 2026-04-04
CVE-2026-34294 json Not Provided 2026-04-21 2026-04-21

Known software with vulnerabilities from Microsoft

Type Vendor Product Version
ApplicationMicrosoft.net Core1.0
ApplicationMicrosoft.net Framework-
ApplicationMicrosoft.net Windows Server-
ApplicationMicrosoft365 Apps-
ApplicationMicrosoft3d Viewer-
ApplicationMicrosoftAccess-
ApplicationMicrosoftAccess Multilingual User Interface Pack2007
ApplicationMicrosoftActivesync-
ApplicationMicrosoftActivex-
ApplicationMicrosoftActive Directory-
ApplicationMicrosoftActive Directory Application Mode-
ApplicationMicrosoftActive Directory Federation Services1.0
ApplicationMicrosoftActive Directory Lightweight Directory Service-
ApplicationMicrosoftActive Directory Services-
ApplicationMicrosoftAmpx-
ApplicationMicrosoftAntigen-
ApplicationMicrosoftAntispyware-
ApplicationMicrosoftApplicationinspector1.0.1
ApplicationMicrosoftApplication Inspector1.0.23
ApplicationMicrosoftAsp.net-