Generated by All in One SEO v5.0.1.1, this is an llms.txt file, used by LLMs to index the site. # Network Services Group Providing high tech, full-service support with a commitment to quality IT and telecom services delivered on time and within budget. ## Sitemaps - [XML Sitemap](https://www.netservicesgroup.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Blog](https://www.netservicesgroup.com/blog/) - [How to use Excel slicers to filter data faster and more clearly](https://www.netservicesgroup.com/blog/how-to-use-excel-slicers-to-filter-data-faster-and-more-clearly/) - Anyone who has spent time wrangling a large dataset in Excel knows the frustration of dropdown filters that are slow to navigate and difficult to read at a glance. Slicers are Excel’s answer to that problem — a visual, button-based filtering interface that makes it faster to drill into the data you actually need, and - [Number porting explained: What businesses need to know before switching providers](https://www.netservicesgroup.com/blog/number-porting-explained-what-businesses-need-to-know-before-switching-providers/) - Switching to a new phone provider doesn’t have to mean starting over with new numbers. Number portability — the right to take your existing phone numbers with you when you change carriers — is a federal protection established by the Federal Communications Commission (FCC) and available to virtually all businesses. But knowing you can port - [How to set up and manage shared mailboxes in Microsoft 365](https://www.netservicesgroup.com/blog/how-to-set-up-and-manage-shared-mailboxes-in-microsoft-365/) - A shared mailbox in Microsoft 365 lets multiple people send and receive email from a single address without any of them needing to log in separately or manage it as a personal inbox. When set up correctly, it’s an effective tool for managing shared communication. When set up incorrectly, however, it creates confusion, security exposure, - [Why your business needs a regular technology review](https://www.netservicesgroup.com/blog/why-your-business-needs-a-regular-technology-review/) - Technology changes faster than most business strategies do. What was a sensible IT investment two years ago may now be redundant, undersized, or quietly creating security exposure. A technology business review — a structured, periodic assessment of how your IT environment is performing and where it needs to go — is how small and mid-size - [Apple identity management for businesses: What IT teams need to know](https://www.netservicesgroup.com/blog/apple-identity-management-for-businesses-what-it-teams-need-to-know/) - As Apple devices have become fixtures in business environments, managing them at scale has grown more complex. Apple provides tools for device deployment, account management, security, and authentication, including Apple Business Manager (ABM), managed Apple Accounts, mobile device management integration, and Platform SSO. Understanding how these tools work together — and where additional configuration may - [What an IT security audit covers and why your business needs one](https://www.netservicesgroup.com/blog/what-an-it-security-audit-covers-and-why-your-business-needs-one/) - Most organizations know their cybersecurity needs attention; fewer know where it falls short. An IT security audit closes that gap. By systematically evaluating networks, devices, applications, and security controls, an audit produces a clear picture of where vulnerabilities exist, how well current defenses are performing, and what needs to change. For businesses handling sensitive data - [How to keep your servers and computers from overheating](https://www.netservicesgroup.com/blog/how-to-keep-your-servers-and-computers-from-overheating/) - Heat is one of the most persistent and underestimated threats to business IT infrastructure. Unlike a cyberattack or a power failure, overheating tends to develop gradually — reducing performance and component lifespan over months before causing an outright failure. A proactive approach to cooling isn’t just about preventing hardware damage; it’s about maintaining the reliability - [Chromium: CVE-2026-85046 Type confusion in V8](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-85046-type-confusion-in-v8/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Google is aware that an exploit for CVE-2026-85046 exists in the wild. - [What is call recording, and how can businesses use it effectively?](https://www.netservicesgroup.com/blog/what-is-call-recording-and-how-can-businesses-use-it-effectively/) - A single phone call can contain more information than anyone can reliably remember. Handwritten notes may not capture every detail and can be time-consuming. Call recording is a standard feature in modern VoIP systems that gives businesses an accurate, searchable record of every conversation. Used correctly, it can improve employee performance, create a record of - [7 Ways to make your Android data plan last longer](https://www.netservicesgroup.com/blog/7-ways-to-make-your-android-data-plan-last-longer/) - Mobile data limits have a way of making themselves known at exactly the wrong moment, like when you’re away from Wi-Fi or trying to load something important. Fortunately, Android gives you more control over your data consumption than most people realize. These seven habits and settings adjustments can meaningfully extend how far your plan goes - [FXS vs. FXO ports: What they are and why the difference matters for VoIP](https://www.netservicesgroup.com/blog/fxs-vs-fxo-ports-what-they-are-and-why-the-difference-matters-for-voip/) - If you’re setting up or expanding a VoIP phone system, you’re likely to encounter the terms FXS and FXO. They refer to two types of analog telephony interface ports, and understanding the difference between them is more than a technical detail. The relationship between FXS and FXO ports determines how your phones connect to your - [CVE-2026-45499 Azure OpenAI Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-45499-azure-openai-elevation-of-privilege-vulnerability/) - Updated an acknowledgement. This is an informational change only. - [CVE-2026-73024 Windows Services for NFS ONCRPC XDR Driver Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-73024-windows-services-for-nfs-oncrpc-xdr-driver-elevation-of-privilege-vulnerability/) - Updated an acknowledgement. This is an informational change only. - [CVE-2026-69492 Windows Partition Management Driver Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-69492-windows-partition-management-driver-elevation-of-privilege-vulnerability/) - Updated an acknowledgement. This is an informational change only. - [CVE-2026-69334 Windows Volume Manager Extension Driver Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-69334-windows-volume-manager-extension-driver-remote-code-execution-vulnerability/) - Updated an acknowledgement. This is an informational change only. - [CVE-2026-68877 Windows Storage Spaces Controller Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-68877-windows-storage-spaces-controller-remote-code-execution-vulnerability/) - Updated an acknowledgement. This is an informational change only. - [CVE-2026-69508 Windows MIDI Service Module Elevation of Privileges Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-69508-windows-midi-service-module-elevation-of-privileges-vulnerability/) - Updated an acknowledgement. This is an informational change only. - [CVE-2026-62693 Windows MIDI Service Module Elevation of Privileges Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-62693-windows-midi-service-module-elevation-of-privileges-vulnerability/) - Updated an acknowledgement. This is an informational change only. - [CVE-2026-69777 Windows DHCP Client Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-69777-windows-dhcp-client-elevation-of-privilege-vulnerability/) - Updated an acknowledgement. This is an informational change only. - [CVE-2026-81353 HEIF Image Extensions Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-81353-heif-image-extensions-remote-code-execution-vulnerability/) - Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally. - [CVE-2026-83990 Microsoft Graphics Component Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-83990-microsoft-graphics-component-elevation-of-privilege-vulnerability/) - Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. - [CVE-2026-69805 .NET Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-69805-net-elevation-of-privilege-vulnerability/) - External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network. - [CVE-2026-77484 Microsoft SQL Server Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-77484-microsoft-sql-server-remote-code-execution-vulnerability/) - Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network. - [CVE-2026-69709 Windows NTFS Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-69709-windows-ntfs-remote-code-execution-vulnerability/) - Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. - [CVE-2026-70583 Windows Core Messaging Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-70583-windows-core-messaging-elevation-of-privilege-vulnerability/) - Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges locally. - [CVE-2026-62895 Azure Arc SQL Server Extension Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-62895-azure-arc-sql-server-extension-elevation-of-privilege-vulnerability/) - Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network. - [CVE-2026-69480 Windows Partition Management Driver Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-69480-windows-partition-management-driver-elevation-of-privilege-vulnerability/) - Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally. - [CVE-2026-66306 Skype for Business Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-66306-skype-for-business-information-disclosure-vulnerability/) - Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network. - [CVE-2026-66308 Skype for Business and Lync Denial of Service Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-66308-skype-for-business-and-lync-denial-of-service-vulnerability/) - Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network. - [CVE-2026-66302 Skype for Business Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-66302-skype-for-business-remote-code-execution-vulnerability/) - External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network. - [A guide to the latest Microsoft 365 licensing cost adjustments](https://www.netservicesgroup.com/blog/a-guide-to-the-latest-microsoft-365-licensing-cost-adjustments/) - Microsoft 365 is getting a price increase. Announced in December 2025 and effective July 1, 2026, the update affects a broad range of commercial, nonprofit, and government subscriptions, from Business Basic to Enterprise E5. It also introduces changes to the features includes in some plans. If your organization relies on Microsoft 365 for email, productivity, - [How to keep your business VoIP running when problems strike](https://www.netservicesgroup.com/blog/how-to-keep-your-business-voip-running-when-problems-strike/) - VoIP downtime can bring sales calls, customer support, and team collaboration to a grinding halt. These seven practical steps will help your business build a more resilient phone system, minimize disruptions, and keep your team connected when technical issues strike. Look beyond price when choosing a VoIP provider A low-cost VoIP plan may not be - [Windows Update not working? Here’s how to fix the most common problems](https://www.netservicesgroup.com/blog/windows-update-not-working-heres-how-to-fix-the-most-common-problems/) - A failed Windows Update is more than a minor annoyance. It leaves your system without the latest security patches and can signal an underlying issue that’s worth addressing. The good news is that most Windows Update failures respond to a structured troubleshooting process, starting with a few quick checks and escalating only if the basics - [Cloud provider mistakes that cost businesses more than they expect](https://www.netservicesgroup.com/blog/cloud-provider-mistakes-that-cost-businesses-more-than-they-expect/) - Choosing a cloud provider is a major business decision that is surprisingly easy to get wrong. The biggest mistakes rarely come from a lack of technical options. Instead, they come from assumptions made too early: that providers are broadly interchangeable, that existing software will run without significant modification, or that cloud costs will remain predictable - [How to pick the right EMR system for your practice](https://www.netservicesgroup.com/blog/how-to-pick-the-right-emr-system-for-your-practice/) - Electronic medical record (EMR) systems are the operational backbone of modern healthcare practices. From appointment scheduling and medication tracking to post-visit documentation and reporting, the right system can make all the difference — but the wrong one can create as many problems as it solves. If your practice is evaluating EMR options, consider the following - [How to make threat intelligence platforms work for your business](https://www.netservicesgroup.com/blog/how-to-make-threat-intelligence-platforms-work-for-your-business/) - Many organizations invest in threat intelligence platforms designed to collect and analyze threat data. But broad data, shallow integration, and disconnected workflows often prevent that intelligence from ever translating into action. Luckily, businesses can apply a few practical solutions to bridge this gap. Start with relevance, not volume The most common mistake organizations make with - [How to choose the right projector for your office](https://www.netservicesgroup.com/blog/how-to-choose-the-right-projector-for-your-office/) - A projector can transform how your team presents, collaborates, and communicates, but only if you buy the right one. Walk into any audiovisual system retailer or browse a few product listings and you’ll quickly find that the spec sheets are long and the differences between models aren’t always obvious. This guide cuts through the noise - [Why your cloud bill keeps getting higher (and how to bring it back down)](https://www.netservicesgroup.com/blog/why-your-cloud-bill-keeps-getting-higher-and-how-to-bring-it-back-down/) - Cloud computing promises cost savings, yet for many organizations, the monthly bill tells a very different story. Expenses that were supposed to be predictable keep creeping upward, and the reasons are rarely obvious from the invoice alone. Understanding what’s actually driving cloud overspending is the first step toward getting it under control. Moving to the - [How to collect customer data securely (and why it matters more than ever)](https://www.netservicesgroup.com/blog/how-to-collect-customer-data-securely-and-why-it-matters-more-than-ever/) - Customer data is the engine behind better products, sharper marketing, and stronger business decisions. But how a business collects and protects that data has become as important as the data itself. Privacy regulations are tightening, customers are paying closer attention, and the consequences of getting it wrong have never been more significant. These five practices - [CVE-2026-58612 PowerShell Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-58612-powershell-information-disclosure-vulnerability/) - Acknowledgement Updated - [CVE-2026-62886 .NET Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-62886-net-elevation-of-privilege-vulnerability/) - Acknowledgement Updated - [CVE-2026-63513 Microsoft Office Graphics Component Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-63513-microsoft-office-graphics-component-remote-code-execution-vulnerability/) - Acknowledgement Updated - [CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-70337-microsoft-powershell-remote-code-execution-vulnerability/) - Acknowledgement Updated - [CVE-2026-63519 Microsoft Office Graphics Component Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-63519-microsoft-office-graphics-component-remote-code-execution-vulnerability/) - Acknowledgement Updated - [CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-66807-microsoft-office-graphics-component-remote-code-execution-vulnerability/) - Acknowledgement Updated - [CVE-2026-62722 Microsoft Brokering File System Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-62722-microsoft-brokering-file-system-elevation-of-privilege-vulnerability/) - Corrected the CVE description and title. This is an informational change only. - [CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-63518-microsoft-office-word-remote-code-execution-vulnerability/) - Acknowledgement Updated - [CVE-2026-56188 Windows Server Network driver Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-56188-windows-server-network-driver-remote-code-execution-vulnerability/) - Updated an acknowledgement. This is an informational change only. - [CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-40400-windows-powershell-remote-code-execution-vulnerability/) - Acknowledgement Updated - [CVE-2026-65769 Microsoft Teams iOS Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-65769-microsoft-teams-ios-information-disclosure-vulnerability/) - Corrected build number for the security update. This in an informational change only. - [CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-59124-microsoft-high-performance-computing-hpc-pack-remote-code-execution-vulnerability/) - Corrected the listed software in the Security Updates table. Microsoft recommends installing the security update as soon as possible. - [CVE-2026-65767 Microsoft Teams for Android Spoofing Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-65767-microsoft-teams-for-android-spoofing-vulnerability/) - Corrected build number for the security update. This in an informational change only. - [CVE-2026-57104 Azure Storage Explorer Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-57104-azure-storage-explorer-elevation-of-privilege-vulnerability/) - Corrected build number for the security update. This in an informational change only. - [CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-65768-microsoft-teams-remote-code-execution-vulnerability/) - Corrected build number for the security update. This in an informational change only. - [Chromium: CVE-2026-19560 Use after free in Blink](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-19560-use-after-free-in-blink/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-19559 Use after free in HTML](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-19559-use-after-free-in-html/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-19558 Use after free in Extensions](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-19558-use-after-free-in-extensions/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-19557 Use after free in TabStrip](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-19557-use-after-free-in-tabstrip/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-19556 Use after free in V8](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-19556-use-after-free-in-v8/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [5 Android features hiding in plain sight that are worth enabling](https://www.netservicesgroup.com/blog/5-android-features-hiding-in-plain-sight-that-are-worth-enabling/) - Android phones ship with a lot of features that most people never discover. Some are tucked into settings menus, some are disabled by default, and some have been available for years without ever getting the attention they deserve. Here are five worth enabling today. Notification history Android’s notification history feature maintains a complete log of - [Windows 11’s July 2026 update: What’s new and why it matters](https://www.netservicesgroup.com/blog/windows-11s-july-2026-update-whats-new-and-why-it-matters/) - Microsoft’s monthly Windows 11 updates are typically straightforward: you install them and move on. However, the July 2026 Security Update, which began rolling out on July 14 for Windows 11 versions 24H2 and 25H2, is worth a closer look. It introduces a useful new recovery feature, gives users more control over when updates install, and - [Spotting the early warning signs of a compromised corporate phone system](https://www.netservicesgroup.com/blog/spotting-the-early-warning-signs-of-a-compromised-corporate-phone-system/) - Corporate voice systems are a major target for cybercriminals seeking free long-distance routes and sensitive operational data. Identifying subtle shifts in call volumes and billing details allows your team to stop active intrusions before minor security gaps become major financial liabilities. Signs of a compromised phone system Cybercriminals frequently target Voice over Internet Protocol tools - [Switching from PC to Mac? Here’s how Windows Migration Assistant makes it easy](https://www.netservicesgroup.com/blog/switching-from-pc-to-mac-heres-how-windows-migration-assistant-makes-it-easy/) - Moving from a Windows PC to a Mac involves more than getting used to a new operating system. It also means bringing your files, applications, contacts, and account settings along with you. To make that process as seamless as possible, Apple created Windows Migration Assistant, a purpose-built tool that handles the heavy lifting, so you - [CVE-2026-56159 DHCP Server Service Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-56159-dhcp-server-service-remote-code-execution-vulnerability/) - Updated an acknowledgement. This is an informational change only. - [CVE-2026-50343 Microsoft Install Service Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-50343-microsoft-install-service-elevation-of-privilege-vulnerability/) - Updated an acknowledgement. This is an informational change only. - [CVE-2026-50697 Windows Common Log File System Driver Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-50697-windows-common-log-file-system-driver-elevation-of-privilege-vulnerability/) - Updated an acknowledgement. This is an informational change only. - [CVE-2026-50333 Windows Spaceport.sys Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-50333-windows-spaceport-sys-elevation-of-privilege-vulnerability/) - Updated an acknowledgement. This is an informational change only. - [CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-16461-rpcbind-rpcbind-stack-buffer-overflow-in-rpcinfo-rpcbdump-short-mode-version-list-formatting/) - Information published. - [CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-8450-httpdaemon-versions-before-6-17-for-perl-allow-os-command-injection-via-send_file/) - Information published. - [CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-16277-rpcbind-rpcbind-stack-buffer-overflow-in-rpcinfo-rpcbaddrlist/) - Information published. - [CVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-64530-net-sched-cls_api-handle-tc_act_consumed-in-tcf_qevent_handle/) - Information published. - [CVE-2024-14040 net: nexthop: Increase weight to u16](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-14040-net-nexthop-increase-weight-to-u16/) - Information published. - [Chromium: CVE-2026-16807 Out of bounds write in Codecs](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-16807-out-of-bounds-write-in-codecs/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-16806 Use after free in WebMCP](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-16806-use-after-free-in-webmcp/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-16805 Use after free in Blink](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-16805-use-after-free-in-blink/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-16804 Use after free in Input](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-16804-use-after-free-in-input/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [CVE-2026-48561 Microsoft Edge Copilot Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-48561-microsoft-edge-copilot-remote-code-execution-vulnerability/) - Corrected the CVE description and title. This is an informational change only. - [CVE-2026-62835 Azure Portal Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-62835-azure-portal-information-disclosure-vulnerability/) - Corrected the CVE description and title. This is an informational change only. - [CVE-2026-64600 xfs: resample the data fork mapping after cycling ILOCK](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-64600-xfs-resample-the-data-fork-mapping-after-cycling-ilock/) - Information published. - [CVE-2026-59677 Process Kill Attack Vector in killall() in seunshare](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-59677-process-kill-attack-vector-in-killall-in-seunshare/) - Information published. - [CVE-2026-59676 Local File Deletion Attack Vector in rm_rf() in seunshare](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-59676-local-file-deletion-attack-vector-in-rm_rf-in-seunshare/) - Information published. - [CVE-2026-49159 Microsoft Graph Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-49159-microsoft-graph-information-disclosure-vulnerability/) - Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. - [CVE-2026-35425 Azure API Management (APIM) Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-35425-azure-api-management-apim-remote-code-execution-vulnerability/) - Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. - [Stop believing these 6 disaster recovery myths](https://www.netservicesgroup.com/blog/stop-believing-these-6-disaster-recovery-myths/) - Let’s be honest: disaster recovery (DR) is one of those IT topics most of us would rather ignore until an emergency forces the issue. It’s easy to push it to the back burner, especially when persistent myths make you feel safer than you actually are. Let’s set the record straight and break down six common - [Fileless malware: The threat your antivirus can’t always see](https://www.netservicesgroup.com/blog/fileless-malware-the-threat-your-antivirus-cant-always-see/) - Most cybersecurity tools are built around a simple assumption: malicious software leaves files behind. Fileless malware is designed specifically to defeat that assumption. Rather than dropping a suspicious executable onto a hard drive, it operates entirely in memory, using your system’s own trusted tools against you, and leaving little to nothing for a traditional antivirus - [VoIP analytics: Turning call data into a competitive edge](https://www.netservicesgroup.com/blog/voip-analytics-turning-call-data-into-a-competitive-edge/) - Most businesses think of their phone system as something that either works or doesn’t. In reality, it can also be a powerful source of business intelligence. Voice over Internet Protocol (VoIP) analytics turns call data into actionable insights. By analyzing every call, businesses can uncover trends in network health, customer experience, and team performance that - [Business intelligence: Leveraging data to make smarter decisions](https://www.netservicesgroup.com/blog/business-intelligence-leveraging-data-to-make-smarter-decisions/) - From sales figures and customer interactions to website traffic and support tickets, every business generates a vast amount of data. Business intelligence (BI) provides the tools and practices to turn raw information into actionable insights for decision-makers. Think of it as a circulatory system for your organization: it pulls data from internal databases, customer touchpoints, - [Web hosting explained: How to choose the right plan for your business](https://www.netservicesgroup.com/blog/web-hosting-explained-how-to-choose-the-right-plan-for-your-business/) - Every business website needs somewhere to live. Web hosting is the infrastructure that makes that possible — the servers, storage, and software that keep your site accessible around the clock. Choosing the wrong type of hosting doesn’t just cost money; it can slow your site down, limit your ability to grow, and leave you scrambling - [CVE-2026-62389 ws < 8.21.1 Default maxFragments Allows Memory Exhaustion DoS](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-62389-ws-8-21-1-default-maxfragments-allows-memory-exhaustion-dos/) - Information published. - [CVE-2026-45784 rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-45784-rust-openssl-potential-out-of-bounds-write-in-cipherctxrefcipher_update_inplace-for-aes-kw-pad-ciphers/) - Information published. - [CVE-2026-63808 exfat: fix potential use-after-free in exfat_find_dir_entry()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-63808-exfat-fix-potential-use-after-free-in-exfat_find_dir_entry/) - Information published. - [CVE-2026-53381 virtiofs: fix UAF on submount umount](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-53381-virtiofs-fix-uaf-on-submount-umount/) - Information published. - [CVE-2026-63827 apparmor: fix use-after-free in rawdata dedup loop](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-63827-apparmor-fix-use-after-free-in-rawdata-dedup-loop/) - Information published. - [CVE-2026-53398 NFSD: Fix SECINFO_NO_NAME decode error cleanup](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-53398-nfsd-fix-secinfo_no_name-decode-error-cleanup/) - Information published. - [CVE-2026-63795 9p: avoid putting oldfid in p9_client_walk() error path](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-63795-9p-avoid-putting-oldfid-in-p9_client_walk-error-path/) - Information published. - [CVE-2026-53382 media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-53382-media-vidtv-fix-null-pointer-dereference-in-vidtv_mux_push_si/) - Information published. - [CVE-2026-53383 ksmbd: reject non-VALID session in compound request branch](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-53383-ksmbd-reject-non-valid-session-in-compound-request-branch/) - Information published. - [CVE-2026-63814 f2fs: validate ACL entry sizes in f2fs_acl_from_disk()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-63814-f2fs-validate-acl-entry-sizes-in-f2fs_acl_from_disk/) - Information published. - [CVE-2026-63828 apparmor: mediate the implicit connect of TCP fast open sendmsg](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-63828-apparmor-mediate-the-implicit-connect-of-tcp-fast-open-sendmsg/) - Information published. - [CVE-2026-63801 tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-63801-tipc-fix-slab-use-after-free-read-in-tipc_aead_decrypt_done/) - Information published. - [CVE-2026-53390 ksmbd: fix out-of-bounds read in smb_check_perm_dacl()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-53390-ksmbd-fix-out-of-bounds-read-in-smb_check_perm_dacl/) - Information published. - [CVE-2026-53385 vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-53385-vc_screen-fix-null-ptr-deref-in-vcs_notifier-during-concurrent-vcs_write/) - Information published. - [CVE-2026-63812 f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-63812-f2fs-fix-incorrect-fi_no_extent-handling-in-__destroy_extent_node/) - Information published. - [CVE-2026-63802 blk-cgroup: fix UAF in __blkcg_rstat_flush()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-63802-blk-cgroup-fix-uaf-in-__blkcg_rstat_flush/) - Information published. - [CVE-2026-63831 mac802154: llsec: add skb_cow_data() before in-place crypto](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-63831-mac802154-llsec-add-skb_cow_data-before-in-place-crypto/) - Information published. - [CVE-2026-63804 gfs2: fix use-after-free in gfs2_qd_dealloc](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-63804-gfs2-fix-use-after-free-in-gfs2_qd_dealloc/) - Information published. - [CVE-2026-63817 f2fs: validate compress cache inode only when enabled](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-63817-f2fs-validate-compress-cache-inode-only-when-enabled/) - Information published. - [CVE-2026-63796 ocfs2: reject oversized group bitmap descriptors](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-63796-ocfs2-reject-oversized-group-bitmap-descriptors/) - Information published. - [Make every VoIP hold message count for your business](https://www.netservicesgroup.com/blog/make-every-voip-hold-message-count-for-your-business/) - Callers may not enjoy waiting, but businesses can make those moments feel less frustrating and more valuable. A well-planned Voice over Internet Protocol (VoIP) on-hold message can support better communication, smoother service, and a more professional customer experience. Define what callers need to hear Before writing your on-hold message, decide what callers should hear while - [How AI and virtual care are reshaping health tech in 2026](https://www.netservicesgroup.com/blog/how-ai-and-virtual-care-are-reshaping-health-tech-in-2026/) - Healthcare organizations are moving beyond isolated pilot programs and adopting technology that addresses real operational and clinical challenges. In 2026, virtual care, administrative AI, interoperability, and data analytics are becoming deeply integrated into everyday care delivery. Virtual care moves into routine care delivery Virtual care involves the use of technology to provide healthcare services remotely. - [HDD vs. SSD: How to choose the right storage for your business](https://www.netservicesgroup.com/blog/hdd-vs-ssd-how-to-choose-the-right-storage-for-your-business/) - Keeping your organization's data secure starts with choosing the right storage solutions to match the mobility demands of your workforce. Let’s explore the underlying traits of current drive choices and reveal the best fit for your stationary and remote assets. Understanding the mechanical design of traditional hard disk drives (HDDs) Mechanical hard drives operate through - [Virtualization vs. cloud computing: What’s the real difference?](https://www.netservicesgroup.com/blog/virtualization-vs-cloud-computing-whats-the-real-difference/) - Virtualization and cloud computing are used almost interchangeably in everyday conversation, and it’s easy to see why: both let businesses do more with their IT resources, and both have become foundational to modern operations. But virtualization and cloud computing are built around different ownership models, and understanding that distinction matters when deciding which solution fits - [Microsoft is ending Office 2021 support in 2026](https://www.netservicesgroup.com/blog/microsoft-is-ending-office-2021-support-in-2026/) - If you or your team are still running Office 2021, which houses the standalone perpetual-license versions of Word, Excel, PowerPoint, and Outlook, mark your calendar. Microsoft has confirmed that support ends on October 13, 2026. The software won’t stop working that day, but what happens afterward is worth understanding well before the deadline arrives. What - [Using Microsoft 365 and CoPilot to transform your daily spreadsheet workflows](https://www.netservicesgroup.com/blog/using-microsoft-365-and-copilot-to-transform-your-daily-spreadsheet-workflows/) - Relying on manually created tracking tools often leads to formatting errors and broken data connections across your organization. Discover how the latest processing capabilities shift software from a passive database into an active, self-correcting partner. The launch of Agent Mode within Microsoft 365 Copilot changes how professionals interact with their data, allowing them to collaborate - [What happens if you stop paying for cloud storage?](https://www.netservicesgroup.com/blog/what-happens-if-you-stop-paying-for-cloud-storage/) - Cloud storage has become such a regular part of daily life that most people rarely think about what the service actually entails — or what happens to their data when the payments stop. Whether it’s a forgotten credit card charge, a subscription you decided to cancel, or a business account that lapses, the consequences for - [How to get more work done on an Android tablet](https://www.netservicesgroup.com/blog/how-to-get-more-work-done-on-an-android-tablet/) - Android tablets are powerful work tools, but many businesses only scratch the surface of their capabilities. Implementing the following tips and tricks can help you maximize your productivity on these devices. Choose the right productivity apps The apps employees use can have a huge impact on how productive they are on an Android tablet. Implement - [NameDrop on iPhone: The faster way to share your contact card](https://www.netservicesgroup.com/blog/namedrop-on-iphone-the-faster-way-to-share-your-contact-card/) - NameDrop makes it easy to trade contact details by holding two compatible Apple devices close together. Here’s how the feature works, what information it shares, and how to control it. What is NameDrop? NameDrop is part of Apple’s AirDrop system and is specifically designed for sharing contact information between iPhones and supported Apple Watch models. - [CVE-2026-50304 Windows Active Directory Federation Services Denial of Service Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-50304-windows-active-directory-federation-services-denial-of-service-vulnerability/) - Updated product information in the Software Update table. This is an informational change only. - [CVE-2026-50368 Windows Active Directory Federation Services Denial of Service Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-50368-windows-active-directory-federation-services-denial-of-service-vulnerability/) - Updated product information in the Software Update table. This is an informational change only. - [CVE-2026-58598 Windows Backup Service Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-58598-windows-backup-service-elevation-of-privilege-vulnerability/) - Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally. - [CVE-2026-58643 Windows Admin Center Spoofing Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-58643-windows-admin-center-spoofing-vulnerability/) - Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network. - [CVE-2026-50653 Azure Active Directory Denial of Service Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-50653-azure-active-directory-denial-of-service-vulnerability/) - Updated product information in the Software Update table. This is an informational change only. - [CVE-2026-50324 Windows Active Directory Federation Services Denial of Service Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-50324-windows-active-directory-federation-services-denial-of-service-vulnerability/) - Updated product information in the Software Update table. This is an informational change only. - [CVE-2026-50355 Windows Active Directory Federation Services Denial of Service Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-50355-windows-active-directory-federation-services-denial-of-service-vulnerability/) - Updated product information in the Software Update table. This is an informational change only. - [CVE-2026-50652 Azure Active Directory Denial of Service Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-50652-azure-active-directory-denial-of-service-vulnerability/) - Updated product information in the Software Update table. This is an informational change only. - [CVE-2026-59117 Windows Terminal Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-59117-windows-terminal-remote-code-execution-vulnerability/) - Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network. - [CVE-2026-56171 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-56171-windows-remote-desktop-protocol-rdp-information-disclosure-vulnerability/) - Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network. - [CVE-2026-50647 Active Directory Federation Server Denial of Service Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-50647-active-directory-federation-server-denial-of-service-vulnerability/) - Updated product information in the Software Update table. This is an informational change only. - [CVE-2026-50411 Windows Active Directory Federation Services Denial of Service Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-50411-windows-active-directory-federation-services-denial-of-service-vulnerability/) - Updated product information in the Software Update table. This is an informational change only. - [CVE-2026-59831 GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-59831-github-cli-gh-codespace-jupyter-could-allow-remote-code-execution-when-connecting-to-a-malicious-codespace/) - Information published. - [CVE-2026-56182 Windows NTFS Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-56182-windows-ntfs-elevation-of-privilege-vulnerability/) - Updated acknowledgment. This is an informational change only. - [CVE-2026-50375 DirectX Graphics Kernel Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-50375-directx-graphics-kernel-elevation-of-privilege-vulnerability/) - Updated acknowledgment. This is an informational change only. - [CVE-2026-50341 Windows NTFS Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-50341-windows-ntfs-information-disclosure-vulnerability/) - Updated acknowledgment. This is an informational change only. - [CVE-2026-45637 Microsoft DWM Core Library Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-45637-microsoft-dwm-core-library-elevation-of-privilege-vulnerability/) - Updated acknowledgment. This is an informational change only. - [CVE-2026-58644 Microsoft SharePoint Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-58644-microsoft-sharepoint-remote-code-execution-vulnerability/) - Corrected the Exploitability Index, Exploited flag and CVSS vector which was incorrect at the time of publication on 7/14/2026. This is an informational change only. - [CVE-2026-58253 NATS Server: Route API Auth Bypass](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-58253-nats-server-route-api-auth-bypass/) - Information published. - [CVE-2026-58209 NATS Server: MQTT retained and QoS replay bypass subscribe deny filters](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-58209-nats-server-mqtt-retained-and-qos-replay-bypass-subscribe-deny-filters/) - Information published. - [CVE-2026-58252 NATS Server: Subscribe Authz Bypass via Wildcard-Overlap](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-58252-nats-server-subscribe-authz-bypass-via-wildcard-overlap/) - Information published. - [CVE-2026-58250 NATS Server: Pre-auth server crash via double INFO in leafnode handshake](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-58250-nats-server-pre-auth-server-crash-via-double-info-in-leafnode-handshake/) - Information published. - [CVE-2026-58208 NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-58208-nats-server-mqtt-over-websocket-path-can-crash-websocket-only-jetstream-servers-before-mqtt-is-enabled/) - Information published. - [CVE-2026-58251 NATS Server: Queue Subscribe Authz Bypass](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-58251-nats-server-queue-subscribe-authz-bypass/) - Information published. - [CVE-2026-58207 NATS Server: Remote crash via integer overflow in Connz pagination](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-58207-nats-server-remote-crash-via-integer-overflow-in-connz-pagination/) - Information published. - [CVE-2026-56288 NULL Pointer Dereference in GNU patch](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-56288-null-pointer-dereference-in-gnu-patch/) - Information published. - [CVE-2026-56289 Loop with Unreachable Exit Condition in GNU patch](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-56289-loop-with-unreachable-exit-condition-in-gnu-patch/) - Information published. - [CVE-2026-43966 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-43966-http-response-splitting-via-non-vchar-bytes-in-cow_http_struct_hdescape_string-2/) - Information published. - [CVE-2026-15308 Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-15308-incremental-htmlparser-feed-allows-cpu-exhaustion-dos-via-repeated-unterminated-markup-declarations/) - Information published. - [CVE-2026-57215 RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-57215-rabbitmq-direct-reply-to-binding-persistence-can-lead-to-unauthorized-reply-channel-injection-and-persistent-phantom/) - Information published. - [CVE-2025-71073 Input: lkkbd - disable pending work before freeing device](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71073-input-lkkbd-disable-pending-work-before-freeing-device/) - Information published. - [CVE-2026-45445 AES-OCB IV Ignored on EVP_Cipher() Path](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-45445-aes-ocb-iv-ignored-on-evp_cipher-path/) - Information published. - [CVE-2026-9076 Out-of-Bounds Read in CMS Password-Based Decryption](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-9076-out-of-bounds-read-in-cms-password-based-decryption/) - Information published. - [CVE-2026-34180 Heap Buffer Over-read in ASN.1 Content Parsing](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34180-heap-buffer-over-read-in-asn-1-content-parsing/) - Information published. - [CVE-2026-42767 NULL Pointer Dereference in CRMF EncryptedValue Decryption](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42767-null-pointer-dereference-in-crmf-encryptedvalue-decryption/) - Information published. - [CVE-2026-42766 Possible NULL Dereference in Password-Based CMS Decryption](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42766-possible-null-dereference-in-password-based-cms-decryption/) - Information published. - [CVE-2026-7383 Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-7383-possible-heap-buffer-overflow-in-asn-1-multibyte-string-conversion/) - Information published. - [CVE-2026-45447 Heap Use-After-Free in the PKCS7_verify() Function](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-45447-heap-use-after-free-in-the-pkcs7_verify-function/) - Information published. - [CVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-25681-invoking-incorrect-handling-of-character-references-in-doctype-nodes-in-golang-org-x-net-html/) - Information published. - [CVE-2026-25680 Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-25680-invoking-denial-of-service-when-parsing-arbitrary-html-in-golang-org-x-net-html/) - Information published. - [CVE-2026-48854 Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-48854-unbounded-request-body-accumulation-causes-memory-exhaustion-in-elixir-grpc-grpc/) - Information published. - [CVE-2026-46293 clk: microchip: mpfs-ccc: fix out of bounds access during output registration](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-46293-clk-microchip-mpfs-ccc-fix-out-of-bounds-access-during-output-registration/) - Information published. - [CVE-2026-46291 crypto: caam - guard HMAC key hex dumps in hash_digest_key](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-46291-crypto-caam-guard-hmac-key-hex-dumps-in-hash_digest_key/) - Information published. - [CVE-2026-46274 io-wq: check that the predecessor is hashed in io_wq_remove_pending()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-46274-io-wq-check-that-the-predecessor-is-hashed-in-io_wq_remove_pending/) - Information published. - [CVE-2026-46292 pmdomain: core: Fix detach procedure for virtual devices in genpd](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-46292-pmdomain-core-fix-detach-procedure-for-virtual-devices-in-genpd/) - Information published. - [CVE-2025-71072 shmem: fix recovery on rename failures](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71072-shmem-fix-recovery-on-rename-failures/) - Information published. - [CVE-2026-47636 Microsoft SharePoint Server Spoofing Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-47636-microsoft-sharepoint-server-spoofing-vulnerability/) - Acknowledgement added. This is an informational change only. - [CVE-2026-42915 Microsoft Windows VMSwitch Denial of Service Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42915-microsoft-windows-vmswitch-denial-of-service-vulnerability/) - Corrected the CVE description and title. This is an informational change only. - [CVE-2026-50656 Microsoft Defender Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-50656-microsoft-defender-elevation-of-privilege-vulnerability/) - Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available. - [CVE-2026-45602 Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-45602-windows-dynamic-host-configuration-protocol-dhcp-tampering-vulnerability/) - Updated CWE value. This is an informational change only. - [CVE-2026-40371 Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-40371-microsoft-dynamics-365-on-premises-elevation-of-privilege-vulnerability/) - Updated the fixed version information and download link. The fix was previously believed to be included in Dynamics 365 Server (on-premises) version 6.2; however, it has been confirmed that the fix is included in Dynamics 365 Server v9.1 (on-premises) Update 1.45 (version 9.1.0045.0011). The download link, release notes, and build number has been updated accordingly - [How VoIP helps remote teams work smarter](https://www.netservicesgroup.com/blog/how-voip-helps-remote-teams-work-smarter/) - Flexibility is a necessity in the era of remote work. That’s why Voice over Internet Protocol (VoIP) has become the linchpin that connects teams across homes, offices, and client sites. By consolidating calling, video meetings, messaging, and collaboration into one powerful platform, VoIP empowers remote teams to work smarter, not harder. Team members can stay - [Use Viva Insights to build a more productive team](https://www.netservicesgroup.com/blog/use-viva-insights-to-build-a-more-productive-team/) - Microsoft Viva Insights helps organizations understand how work actually gets done, from meeting habits and collaboration patterns to broader productivity trends. With the right setup, it can reveal where teams are losing time and productivity and how they can work more efficiently. Viva Insights is part of Microsoft Viva and works with Microsoft 365 tools - [Microsoft Edge features that help you work smarter in 2026](https://www.netservicesgroup.com/blog/microsoft-edge-features-that-help-you-work-smarter-in-2026/) - Microsoft Edge has been around for years, but users are still overlooking some nifty features beyond its web browsing capabilities. In 2026, the browser has several newer tools and clever built-in features that can help users organize research, manage tabs, share files, listen to content, and work more efficiently. Here are the Microsoft Edge features - [Practical strategies for securing your corporate Windows webcams](https://www.netservicesgroup.com/blog/practical-strategies-for-securing-your-corporate-windows-webcams/) - Digital communication relies heavily on integrated cameras, yet these same devices represent an attractive entry point for malicious actors. Implementing standard security protocols on your desktop assets helps prevent unauthorized video access and protects your corporate data. Most laptops and desktops now feature high-definition cameras built right into the bezel or connected via universal serial - [Should you use private browsing to protect your data?](https://www.netservicesgroup.com/blog/should-you-use-private-browsing-to-protect-your-data/) - Keeping your personal information safe online often feels like a massive challenge. Every day, you share a huge amount of data just by clicking around the internet. Private browsing modes offer a built-in way to stop websites from tracking your digital footprint. They block companies from collecting your search habits and sharing them with others. - [How hospitals can keep thousands of connected devices secure](https://www.netservicesgroup.com/blog/how-hospitals-can-keep-thousands-of-connected-devices-secure/) - Hospitals rely on thousands of connected devices every day, from bedside monitors and imaging systems to staff laptops, printers, tablets, and administrative tools. These devices help teams deliver care, coordinate treatment, and keep operations moving, but every connected device can also become a security risk. This article explores how health systems can keep track of - [Why identity is the new internal highway for cyberattacks](https://www.netservicesgroup.com/blog/why-identity-is-the-new-internal-highway-for-cyberattacks/) - Organizations spend tens to hundreds of thousands fortifying their perimeters, but the biggest threats often originate from within. This article explores how saved passwords and autonomous AI agents can create hidden pathways for cybercriminals, bypassing traditional defenses and highlighting the need for a unified approach to mapping user access. The perimeter is an illusion Modern - [Optimizing desktop and laptop settings for eco-friendly computing](https://www.netservicesgroup.com/blog/optimizing-desktop-and-laptop-settings-for-eco-friendly-computing/) - Keeping an entire fleet of corporate computers running efficiently requires balancing performance with environmental responsibility. A look into your device's settings can reveal several simple ways to reduce power consumption. Calibrating monitor brightness levels Display panels are among the primary power consumers in a standard office setup. Standard factory settings frequently push display luminance far - [How SaaS helps SMBs save money and work more efficiently](https://www.netservicesgroup.com/blog/how-saas-helps-smbs-save-money-and-work-more-efficiently/) - Software-as-a-Service (SaaS) gives small and medium-sized businesses (SMBs) a simpler, more flexible way to access the software they need. Aside from reducing upfront IT costs, it supports remote work, easier scaling, app integrations, and stronger security protections. Many companies are shifting to SaaS. Rather than purchasing software to install on company computers or servers, they - [CVE-2026-34182 CMS AuthEnvelopedData Processing May Accept Forged Messages](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34182-cms-authenvelopeddata-processing-may-accept-forged-messages/) - Information published. - [CVE-2026-54411 Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-54411-linux-pam-through-1-7-2-contains-an-observable-timing-discrepancy-cwe-208-in-the-pam_userdb-modules-plaintext-password-comparison-path-in-modules-pam_userdb-pam_userdb-c-that-al/) - Information published. - [Chromium: CVE-2026-11700 Use after free in Tracing](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-11700-use-after-free-in-tracing/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-11699 Use after free in Bluetooth](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-11699-use-after-free-in-bluetooth/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-11698 Use after free in Bluetooth](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-11698-use-after-free-in-bluetooth/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-11697 Insufficient validation of untrusted input in UI](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-11697-insufficient-validation-of-untrusted-input-in-ui/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-11696 Uninitialized Use in Video](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-11696-uninitialized-use-in-video/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-11695 Inappropriate implementation in Passwords](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-11695-inappropriate-implementation-in-passwords/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-11694 Use after free in ServiceWorker](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-11694-use-after-free-in-serviceworker/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-11693 Inappropriate implementation in Plugins](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-11693-inappropriate-implementation-in-plugins/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-11692 Use after free in Read Anything](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-11692-use-after-free-in-read-anything/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-11691 Insufficient validation of untrusted input in New Tab Page](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-11691-insufficient-validation-of-untrusted-input-in-new-tab-page/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-11690 Out of bounds read and write in Media](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-11690-out-of-bounds-read-and-write-in-media/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-11689 Insufficient validation of untrusted input in Passwords](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-11689-insufficient-validation-of-untrusted-input-in-passwords/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-11688 Object lifecycle issue in SVG](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-11688-object-lifecycle-issue-in-svg/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-11687 Use after free in Dawn](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-11687-use-after-free-in-dawn/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-11686 Insufficient validation of untrusted input in Dawn](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-11686-insufficient-validation-of-untrusted-input-in-dawn/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-11685 Insufficient data validation in MediaCapture](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-11685-insufficient-data-validation-in-mediacapture/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-11684 Insufficient policy enforcement in Network](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-11684-insufficient-policy-enforcement-in-network/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Chromium: CVE-2026-11683 Use after free in WebCodecs](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-11683-use-after-free-in-webcodecs/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. - [Transforming online retail through cloud order management systems](https://www.netservicesgroup.com/blog/transforming-online-retail-through-cloud-order-management-systems/) - Managing incoming sales across multiple platforms often leads to administrative gridlock for expanding online stores. Transitioning your transaction workflows to a secure cloud platform provides the clarity needed to efficiently handle order fulfillment. When a business relies on disconnected infrastructure or legacy, on-premise hardware, keeping up with this multi-channelled demand becomes a major administrative burden. - [CVE-2026-39829 Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39829-invoking-pathological-rsa-dsa-parameters-may-cause-dos-in-golang-org-x-crypto-ssh/) - Information published. - [CVE-2026-39821 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39821-invoking-failure-to-reject-ascii-only-punycode-encoded-labels-in-golang-org-x-net-idna/) - Information published. - [CVE-2026-39835 Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39835-invoking-server-panic-during-checkhostkey-authenticate-in-golang-org-x-crypto-ssh/) - Information published. - [CVE-2026-21717 A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade performance of the Node.js process. The most common trigger is any endpoint that calls `JSON.parse()` on attacker-controlled input, as JSON parsing automatically internalizes short strings into the affected hash table. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21717-a-flaw-in-v8s-string-hashing-mechanism-causes-integer-like-strings-to-be-hashed-to-their-numeric-value-making-hash-collisions-trivially-predictable-by-crafting-a-request-that-ca/) - Information published. - [Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)](https://www.netservicesgroup.com/msrc-blog-alerts/type-confusion-in-v8-in-google-chrome-prior-to-142-0-7444-59-allowed-a-remote-attacker-to-potentially-exploit-heap-corruption-via-a-crafted-html-page-chromium-security-severity-high/) - Information published. - [CVE-2025-23167 A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `rnrX` instead of the required `rnrn`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination. Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-23167-a-flaw-in-node-js-20s-http-parser-allows-improper-termination-of-http-1-headers-using-rnrx-instead-of-the-required-rnrn-this-inconsistency-enables-request-smuggling-a/) - Information published. - [CVE-2024-36137 A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-36137-a-vulnerability-has-been-identified-in-node-js-affecting-users-of-the-experimental-permission-model-when-the-allow-fs-write-flag-is-used-node-js-permission-model-do-not-operate-o/) - Information published. - [CVE-2024-22018 A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-22018-a-vulnerability-has-been-identified-in-node-js-affecting-users-of-the-experimental-permission-model-when-the-allow-fs-read-flag-is-used-this-flaw-arises-from-an-inadequate-permissio/) - Information published. - [CVE-2026-40034 gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-40034-gitoxide-command-injection-via-partial-gitmodules-override-in-gix-submodule/) - Information published. - [CVE-2026-44839 RabbitMQ: Unsanitized vhost names allow for XSS in management UI](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-44839-rabbitmq-unsanitized-vhost-names-allow-for-xss-in-management-ui/) - Information published. - [CVE-2025-15649 IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-15649-iouncompressunzip-versions-before-2-215-for-perl-propagate-uncaught-exception-when-parsing-zip-header-with-malformed-dos-date/) - Information published. - [CVE-2026-48962 IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-48962-iocompress-versions-before-2-220-for-perl-can-execute-arbitrary-code-in-fileglobmapper-via-an-attacker-controlled-output-glob/) - Information published. - [CVE-2026-28387 Potential Use-after-free in DANE Client Code](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-28387-potential-use-after-free-in-dane-client-code/) - Information published. - [CVE-2026-28388 NULL Pointer Dereference When Processing a Delta CRL](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-28388-null-pointer-dereference-when-processing-a-delta-crl/) - Information published. - [CVE-2026-34874 An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34874-an-issue-was-discovered-in-mbed-tls-through-3-6-5-and-4-x-through-4-0-0-there-is-a-null-pointer-dereference-in-distinguished-name-parsing-that-allows-an-attacker-to-write-to-address-0/) - Information published. - [Keep your Mac safe from modern ransomware threats](https://www.netservicesgroup.com/blog/keep-your-mac-safe-from-modern-ransomware-threats/) - Many people believe Apple computers are immune to malicious software. Unfortunately, attackers constantly develop new methods to compromise these systems and lock away your important files. Understanding how these threats operate empowers you to protect your personal data and maintain peace of mind. This article will show you the best ways to secure your Mac - [How MTD boosts Android devices' security](https://www.netservicesgroup.com/blog/how-mtd-boosts-android-devices-security/) - Android devices have become essential work tools that offer convenient access to email, apps, files, and company systems. But that convenience also comes with security risks, especially for staff who work remotely or work in a hybrid environment. Fortunately, with mobile threat defense (MTD), businesses can spot and address these risks before they lead to - [CVE-2026-41054 Missing exit out of permission check in haveged could lead to root exploit](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41054-missing-exit-out-of-permission-check-in-haveged-could-lead-to-root-exploit/) - Information published. - [CVE-2026-43619 Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-43619-rsync-3-4-3-symlink-race-condition-via-path-based-syscalls/) - Information published. - [CVE-2026-44673 libyang: lyb_read_string() integer overflow → heap buffer overflow](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-44673-libyang-lyb_read_string-integer-overflow-→-heap-buffer-overflow/) - Information published. - [CVE-2025-68768 inet: frags: flush pending skbs in fqdir_pre_exit()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68768-inet-frags-flush-pending-skbs-in-fqdir_pre_exit/) - Information published. - [CVE-2026-44390 Unbounded name compression in certain cases causes degradation of service](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-44390-unbounded-name-compression-in-certain-cases-causes-degradation-of-service/) - Information published. - [CVE-2025-51480 Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory restrictions.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-51480-path-traversal-vulnerability-in-onnx-external_data_helper-save_external_data-in-onnx-1-17-0-allows-attackers-to-overwrite-arbitrary-files-by-supplying-crafted-external_data-location-pat/) - Information published. - [CVE-2026-42944 Heap overflow with multiple NSID, COOKIE, PADDING EDNS options](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42944-heap-overflow-with-multiple-nsid-cookie-padding-edns-options/) - Information published. - [CVE-2026-42923 Degradation of service with unbounded NSEC3 hash calculations](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42923-degradation-of-service-with-unbounded-nsec3-hash-calculations/) - Information published. - [CVE-2025-38096 wifi: iwlwifi: don't warn when if there is a FW error](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-38096-wifi-iwlwifi-dont-warn-when-if-there-is-a-fw-error/) - Information published. - [CVE-2026-40622 Another 'ghost domain names' attack variant](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-40622-another-ghost-domain-names-attack-variant/) - Information published. - [CVE-2025-38140 dm: limit swapping tables for devices with zone write plugs](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-38140-dm-limit-swapping-tables-for-devices-with-zone-write-plugs/) - Information published. - [CVE-2026-42534 Jostle logic bypass degrades resolution performance](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42534-jostle-logic-bypass-degrades-resolution-performance/) - Information published. - [CVE-2026-41292 Long list of incoming EDNS options degrades performance](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41292-long-list-of-incoming-edns-options-degrades-performance/) - Information published. - [CVE-2026-33278 Possible arbitrary code execution during DNSSEC validation](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-33278-possible-arbitrary-code-execution-during-dnssec-validation/) - Information published. - [CVE-2026-41035 In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41035-in-rsync-3-0-1-through-3-4-1-receive_xattr-relies-on-an-untrusted-length-value-during-a-qsort-call-leading-to-a-receiver-use-after-free-the-victim-must-run-rsync-with-x-aka-xattr/) - Information published. - [CVE-2026-44608 Use after free and crash under special conditions in RPZ code](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-44608-use-after-free-and-crash-under-special-conditions-in-rpz-code/) - Information published. - [CVE-2026-42959 Crash during DNSSEC validation of malicious content](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42959-crash-during-dnssec-validation-of-malicious-content/) - Information published. - [CVE-2026-42960 Possible cache poisoning via promiscuous records for the authority section](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42960-possible-cache-poisoning-via-promiscuous-records-for-the-authority-section/) - Information published. - [CVE-2026-32792 Packet of death with DNSCrypt](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-32792-packet-of-death-with-dnscrypt/) - Information published. - [5 Ways softphones help businesses work smarter](https://www.netservicesgroup.com/blog/5-ways-softphones-help-businesses-work-smarter/) - A softphone is a calling app that lets employees make and receive business calls using a computer, tablet, or smartphone instead of a desk phone. Unlike traditional office phones, softphones work over the internet and give teams more flexibility. Here are five ways softphones can improve communication, lower costs, and support modern work. Remote accessibility - [7 Windows 11 features SMBs should use](https://www.netservicesgroup.com/blog/7-windows-11-features-smbs-should-use/) - Windows 11 is packed with tools that can help small and medium-sized businesses (SMBs) save time, minimize distractions, secure accounts, and simplify daily tasks. Read the article below to learn about seven powerful Windows 11 tools you can use to boost your business. Snap Layouts for better multitasking If your employees constantly switch between multiple - [Elevating search rankings through smart image optimization](https://www.netservicesgroup.com/blog/elevating-search-rankings-through-smart-image-optimization/) - Many businesses focus their search engine strategy on text, but a website's visual elements also play a major role in ranking. This article discusses ways you can better handle images to reduce load times and improve your visibility to potential clients. Scaling and resizing for better performance Uploading high-resolution, unedited images is a common mistake - [CVE-2026-43352 i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-43352-i3c-mipi-i3c-hci-correct-ring_ctrl_abort-handling-in-dma-dequeue/) - Information published. - [CVE-2026-31717 ksmbd: validate owner of durable handle on reconnect](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31717-ksmbd-validate-owner-of-durable-handle-on-reconnect/) - Information published. - [CVE-2026-41673 xmldom: Denial of service via uncontrolled recursion in XML serialization](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41673-xmldom-denial-of-service-via-uncontrolled-recursion-in-xml-serialization/) - Information published. - [CVE-2026-41675 xmldom: XML node injection through unvalidated processing instruction serialization](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41675-xmldom-xml-node-injection-through-unvalidated-processing-instruction-serialization/) - Information published. - [CVE-2026-41674 xmldom: XML injection through unvalidated DocumentType serialization](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41674-xmldom-xml-injection-through-unvalidated-documenttype-serialization/) - Information published. - [CVE-2026-41672 xmldom: XML node injection through unvalidated comment serialization](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41672-xmldom-xml-node-injection-through-unvalidated-comment-serialization/) - Information published. - [CVE-2026-43869 Apache Thrift: TSSLTransportFactory.java hostname verification](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-43869-apache-thrift-tssltransportfactory-java-hostname-verification/) - Information published. - [CVE-2026-43870 Apache Thrift: Node.js web_server.js multi-vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-43870-apache-thrift-node-js-web_server-js-multi-vulnerability/) - Information published. - [CVE-2026-43868 Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-43868-apache-thrift-rust-implementation-vulnerable-to-cve-2020-13949-pattern/) - Information published. - [CVE-2026-41082 In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41082-in-ocaml-opam-before-2-5-1-a-install-field-containing-a-destination-filepath-can-use-to-reach-a-parent-directory/) - Information published. - [CVE-2026-25833 Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-25833-mbed-tls-3-5-0-to-3-6-5-fixed-in-3-6-6-and-4-1-0-has-a-buffer-overflow-in-the-x509_inet_pton_ipv6-function/) - Information published. - [CVE-2026-25834 Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-25834-mbed-tls-v3-3-0-up-to-3-6-5-and-4-0-0-allows-algorithm-downgrade/) - Information published. - [CVE-2026-34872 An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle).](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34872-an-issue-was-discovered-in-mbed-tls-3-5-x-and-3-6-x-through-3-6-5-and-tf-psa-crypto-1-0-there-is-a-lack-of-contributory-behavior-in-ffdh-due-to-improper-input-validation-using-finite/) - Information published. - [CVE-2026-34871 An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG).](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34871-an-issue-was-discovered-in-mbed-tls-before-3-6-6-and-4-x-before-4-1-0-and-tf-psa-crypto-before-1-1-0-there-is-a-predictable-seed-in-a-pseudo-random-number-generator-prng/) - Information published. - [CVE-2026-7210 The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-7210-the-expat-and-elementtree-parsers-use-insufficient-entropy-for-xml-hash-flooding-protection/) - Information published. - [CVE-2026-34873 An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34873-an-issue-was-discovered-in-mbed-tls-3-5-0-through-4-0-0-client-impersonation-can-occur-while-resuming-a-tls-1-3-session/) - Information published. - [CVE-2026-8328 FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-8328-ftp-pasv-ssrf-ftpcp-does-not-use-actual-peer-address-trusts-server-supplied-pasv-host-address/) - Information published. - [CVE-2026-7246 Pallets Click contains a command injection via Unsanitized Filename "click.edit()"](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-7246-pallets-click-contains-a-command-injection-via-unsanitized-filename-click-edit/) - Information published. - [CVE-2026-43443 ASoC: amd: acp-mach-common: Add missing error check for clock acquisition](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-43443-asoc-amd-acp-mach-common-add-missing-error-check-for-clock-acquisition/) - Information published. - [CVE-2026-44662 rust-openssl: Heap buffer overflow when encrypting with AES key-wrap-with-padding](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-44662-rust-openssl-heap-buffer-overflow-when-encrypting-with-aes-key-wrap-with-padding/) - Information published. - [How to pick an EMR system that actually works for your practice](https://www.netservicesgroup.com/blog/how-to-pick-an-emr-system-that-actually-works-for-your-practice/) - The right electronic medical record (EMR) system can help your team manage patient information more easily and reduce administrative headaches. The wrong one, however, can create bottlenecks, frustrate staff, and complicate routine tasks. Here’s what to consider before choosing an EMR platform for your practice. Start with your current workflow Before comparing EMR software vendors, - [CVE-2026-42154 Prometheus: remote read endpoint allows denial of service via crafted snappy payload](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42154-prometheus-remote-read-endpoint-allows-denial-of-service-via-crafted-snappy-payload/) - Information published. - [CVE-2026-6210 Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crash](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-6210-type-confusion-and-heap-buffer-overflow-in-qt-svg-marker-handling-causing-application-crash/) - Information published. - [CVE-2026-42898 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42898-microsoft-dynamics-365-on-premises-remote-code-execution-vulnerability/) - Acknowledgement Updated - [CVE-2026-42833 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42833-microsoft-dynamics-365-on-premises-remote-code-execution-vulnerability/) - Updated the fixed version number. This is an informational change only. - [CVE-2026-41636 Apache Thrift: Node.js skip() recursion](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41636-apache-thrift-node-js-skip-recursion/) - Information published. - [CVE-2026-41605 Apache Thrift: Swift Compact Protocol integer overflow](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41605-apache-thrift-swift-compact-protocol-integer-overflow/) - Information published. - [CVE-2026-41603 Apache Thrift: Java TSSLTransportFactory hostname verification](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41603-apache-thrift-java-tssltransportfactory-hostname-verification/) - Information published. - [CVE-2026-41602 Apache Thrift: Go TFramedTransport uint32 overflow](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41602-apache-thrift-go-tframedtransport-uint32-overflow/) - Information published. - [CVE-2025-48431 Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-48431-apache-thrift-specially-crafted-input-can-crash-a-c_glib-thrift-server-with-invalid-pointer-error/) - Information published. - [CVE-2026-42151 Prometheus Azure AD remote write OAuth client secret exposed via config API](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42151-prometheus-azure-ad-remote-write-oauth-client-secret-exposed-via-config-api/) - Information published. - [Choosing the right VPN for your business](https://www.netservicesgroup.com/blog/choosing-the-right-vpn-for-your-business/) - Online privacy threats are increasing, making virtual private networks (VPN) more important than ever for businesses and individual users alike. But the sheer number of VPN providers can make choosing the right one overwhelming. Before investing in a VPN service, make sure to follow these steps. Review the VPN’s security standards Since data protection is - [Simple fixes for better home Wi-Fi](https://www.netservicesgroup.com/blog/simple-fixes-for-better-home-wi-fi/) - Hybrid work has made reliable home Wi-Fi more important than ever. Video meetings, cloud apps, file sharing, and online collaboration tools all depend on a steady connection. If your network has been slowing down your workday, these practical tips can help improve your home Wi-Fi performance. Optimize router placement Wireless signals lose strength when they - [CVE-2026-31575 mm/userfaultfd: fix hugetlb fault mutex hash calculation](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31575-mm-userfaultfd-fix-hugetlb-fault-mutex-hash-calculation/) - Information published. - [CVE-2025-39779 btrfs: subpage: keep TOWRITE tag until folio is cleaned](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-39779-btrfs-subpage-keep-towrite-tag-until-folio-is-cleaned/) - Information published. - [CVE-2026-43311 soc/tegra: pmc: Fix unsafe generic_handle_irq() call](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-43311-soc-tegra-pmc-fix-unsafe-generic_handle_irq-call/) - Information published. - [CVE-2025-21634 cgroup/cpuset: remove kernfs active break](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-21634-cgroup-cpuset-remove-kernfs-active-break/) - Information published. - [CVE-2026-31568 s390/mm: Add missing secure storage access fixups for donated memory](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31568-s390-mm-add-missing-secure-storage-access-fixups-for-donated-memory/) - Information published. - [CVE-2025-39707 drm/amdgpu: check if hubbub is NULL in debugfs/amdgpu_dm_capabilities](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-39707-drm-amdgpu-check-if-hubbub-is-null-in-debugfs-amdgpu_dm_capabilities/) - Information published. - [CVE-2026-43398 drm/amdgpu: add upper bound check on user inputs in wait ioctl](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-43398-drm-amdgpu-add-upper-bound-check-on-user-inputs-in-wait-ioctl/) - Information published. - [CVE-2025-21635 rds: sysctl: rds_tcp_{rcv,snd}buf: avoid using current->nsproxy](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-21635-rds-sysctl-rds_tcp_rcvsndbuf-avoid-using-current-nsproxy/) - Information published. - [CVE-2025-39747 drm/msm: Add error handling for krealloc in metadata setup](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-39747-drm-msm-add-error-handling-for-krealloc-in-metadata-setup/) - Information published. - [CVE-2023-52586 drm/msm/dpu: Add mutex lock in control vblank irq](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2023-52586-drm-msm-dpu-add-mutex-lock-in-control-vblank-irq/) - Information published. - [CVE-2025-39746 wifi: ath10k: shutdown driver when hardware is unreliable](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-39746-wifi-ath10k-shutdown-driver-when-hardware-is-unreliable/) - Information published. - [CVE-2026-31579 wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31579-wireguard-device-use-exit_rtnl-callback-instead-of-manual-rtnl_lock-in-pre_exit/) - Information published. - [CVE-2025-21696 mm: clear uffd-wp PTE/PMD state on mremap()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-21696-mm-clear-uffd-wp-pte-pmd-state-on-mremap/) - Information published. - [CVE-2025-39762 drm/amd/display: add null check](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-39762-drm-amd-display-add-null-check/) - Information published. - [CVE-2026-43308 btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-43308-btrfs-dont-bug-on-unexpected-delayed-ref-type-in-run_one_delayed_ref/) - Information published. - [CVE-2025-21672 afs: Fix merge preference rule failure condition](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-21672-afs-fix-merge-preference-rule-failure-condition/) - Information published. - [CVE-2025-39754 mm/smaps: fix race between smaps_hugetlb_range and migration](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-39754-mm-smaps-fix-race-between-smaps_hugetlb_range-and-migration/) - Information published. - [CVE-2026-43421 usb: gadget: f_ncm: Fix net_device lifecycle with device_move](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-43421-usb-gadget-f_ncm-fix-net_device-lifecycle-with-device_move/) - Information published. - [Why VoIP scams keep spreading, and why they’re hard to stop](https://www.netservicesgroup.com/blog/why-voip-scams-keep-spreading-and-why-theyre-hard-to-stop/) - Phone scams have evolved far beyond simple robocalls. Cybercriminals now exploit Voice over Internet Protocol (VoIP) systems to impersonate trusted parties, tricking individuals into disclosing sensitive data. This article explores why VoIP phishing, known as vishing, is so widespread and what your organization can do to combat it. Why vishing is so prevalent There are - [CVE-2026-42501 Malicious module proxy can bypass checksum database in cmd/go](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42501-malicious-module-proxy-can-bypass-checksum-database-in-cmd-go/) - Information published. - [CVE-2026-42499 Quadratic string concatenation in consumePhrase in net/mail](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42499-quadratic-string-concatenation-in-consumephrase-in-net-mail/) - Information published. - [CVE-2026-39836 Panic in Dial and LookupPort when handling NUL byte on Windows in net](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39836-panic-in-dial-and-lookupport-when-handling-nul-byte-on-windows-in-net/) - Information published. - [CVE-2026-39826 Escaper bypass leads to XSS in html/template](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39826-escaper-bypass-leads-to-xss-in-html-template/) - Information published. - [CVE-2026-39825 ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39825-reverseproxy-forwards-queries-with-more-than-urlmaxqueryparams-parameters-in-net-http-httputil/) - Information published. - [CVE-2026-39823 Bypass of meta content URL escaping causes XSS in html/template](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39823-bypass-of-meta-content-url-escaping-causes-xss-in-html-template/) - Information published. - [CVE-2026-39820 Quadratic string concatentation in consumeComment in net/mail](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39820-quadratic-string-concatentation-in-consumecomment-in-net-mail/) - Information published. - [CVE-2026-39819 Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39819-invoking-go-bug-follows-symlinks-in-predictable-temporary-filenames-in-cmd-go/) - Information published. - [CVE-2026-39817 Invoking "go tool pack" does not sanitize output paths in cmd/go](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39817-invoking-go-tool-pack-does-not-sanitize-output-paths-in-cmd-go/) - Information published. - [CVE-2026-33814 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-33814-infinite-loop-in-http-2-transport-when-given-bad-settings_max_frame_size-in-net-http-internal-http2-in-golang-org-x-net/) - Information published. - [CVE-2026-33811 Crash when handling long CNAME response in net](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-33811-crash-when-handling-long-cname-response-in-net/) - Information published. - [CVE-2026-44656 Vim: OS Command Injection via 'path' completion](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-44656-vim-os-command-injection-via-path-completion/) - Information published. - [CVE-2026-45130 Vim: Heap Buffer Overflow in spell file loading](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-45130-vim-heap-buffer-overflow-in-spell-file-loading/) - Information published. - [CVE-2026-6666 PgBouncer crash in kill_pool_logins_server_error](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-6666-pgbouncer-crash-in-kill_pool_logins_server_error/) - Information published. - [CVE-2026-6667 PgBouncer missing authorization check in KILL_CLIENT admin command](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-6667-pgbouncer-missing-authorization-check-in-kill_client-admin-command/) - Information published. - [CVE-2026-6665 PgBouncer buffer overflow in SCRAM](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-6665-pgbouncer-buffer-overflow-in-scram/) - Information published. - [CVE-2026-6664 PgBouncer integer overflow in PgBouncer network packet parsing](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-6664-pgbouncer-integer-overflow-in-pgbouncer-network-packet-parsing/) - Information published. - [CVE-2026-3832 Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-3832-gnutls-gnutls-security-bypass-allows-acceptance-of-revoked-server-certificates-via-crafted-ocsp-response/) - Information published. - [CVE-2026-41889 pgx: SQL Injection via placeholder confusion with dollar quoted string literals](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41889-pgx-sql-injection-via-placeholder-confusion-with-dollar-quoted-string-literals/) - Information published. - [CVE-2026-33079 Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-33079-mistune-redos-in-link_title_re-allows-denial-of-service-with-crafted-markdown-titles/) - Information published. - [CVE-2026-37457](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-37457/) - Information published. - [CVE-2026-40170 ngtcp2 has a qlog transport parameter serialization stack buffer overflow](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-40170-ngtcp2-has-a-qlog-transport-parameter-serialization-stack-buffer-overflow/) - Information published. - [CVE-2026-42798](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42798/) - Information published. - [Elevate your business data analysis with key Excel tools](https://www.netservicesgroup.com/blog/elevate-your-business-data-analysis-with-key-excel-tools/) - Microsoft Excel remains a staple in the modern office, yet many professionals only scratch the surface of its capabilities. Learning just a few specific functions can improve how you handle data and save hours of manual entry. Counting with precision using COUNT and COUNTA Managing large lists often requires knowing exactly how many entries you - [CVE-2026-41080](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41080/) - Information published. - [CVE-2026-28532 FRRouting < 10.5.3 Integer Overflow in OSPF TLV Parser Functions](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-28532-frrouting-10-5-3-integer-overflow-in-ospf-tlv-parser-functions/) - Information published. - [CVE-2026-32148 Lockfile checksums not verified in Hex allows dependency integrity bypass](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-32148-lockfile-checksums-not-verified-in-hex-allows-dependency-integrity-bypass/) - Information published. - [CVE-2025-9403 jqlang jq JSON jq_test.c run_jq_tests assertion](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-9403-jqlang-jq-json-jq_test-c-run_jq_tests-assertion/) - Information published. - [CVE-2017-20230 Storable versions before 3.05 for Perl has a stack overflow](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2017-20230-storable-versions-before-3-05-for-perl-has-a-stack-overflow/) - Information published. - [CVE-2026-6843 Nano: nano: format string vulnerability leads to denial of service](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-6843-nano-nano-format-string-vulnerability-leads-to-denial-of-service/) - Information published. - [CVE-2026-6842 Nano: nano: local attacker can inject malicious .desktop launcher due to insecure directory permissions](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-6842-nano-nano-local-attacker-can-inject-malicious-desktop-launcher-due-to-insecure-directory-permissions/) - Information published. - [CVE-2026-30656](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-30656/) - Information published. - [CVE-2025-11083 GNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflow](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-11083-gnu-binutils-linker-elfcode-h-elf_swap_shdr-heap-based-overflow/) - Information published. - [CVE-2025-8224 GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereference](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-8224-gnu-binutils-bfd-library-elf-c-bfd_elf_get_str_section-null-pointer-dereference/) - Information published. - [CVE-2026-6846 Binutils: binutils: arbitrary code execution via malformed xcoff object file processing](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-6846-binutils-binutils-arbitrary-code-execution-via-malformed-xcoff-object-file-processing/) - Information published. - [CVE-2026-6845 Binutils: binutils: denial of service via crafted elf file](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-6845-binutils-binutils-denial-of-service-via-crafted-elf-file/) - Information published. - [CVE-2026-43058 media: vidtv: fix pass-by-value structs causing MSAN warnings](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-43058-media-vidtv-fix-pass-by-value-structs-causing-msan-warnings/) - Information published. - [CVE-2026-31431 crypto: algif_aead - Revert to operating out-of-place](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31431-crypto-algif_aead-revert-to-operating-out-of-place/) - Information published. - [CVE-2026-37555](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-37555/) - Information published. - [CVE-2026-7598 libssh2 userauth.c userauth_password integer overflow](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-7598-libssh2-userauth-c-userauth_password-integer-overflow/) - Information published. - [CVE-2026-31608 smb: server: avoid double-free in smb_direct_free_sendmsg after smb_direct_flush_send_list()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31608-smb-server-avoid-double-free-in-smb_direct_free_sendmsg-after-smb_direct_flush_send_list/) - Information published. - [CVE-2026-31598 ocfs2: fix possible deadlock between unlink and dio_end_io_write](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31598-ocfs2-fix-possible-deadlock-between-unlink-and-dio_end_io_write/) - Information published. - [CVE-2026-31602 ALSA: ctxfi: Limit PTP to a single page](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31602-alsa-ctxfi-limit-ptp-to-a-single-page/) - Information published. - [Website design in 2026: What actually drives results for small businesses](https://www.netservicesgroup.com/blog/website-design-in-2026-what-actually-drives-results-for-small-businesses/) - For many small businesses, a website is the first point of contact for potential customers, making its design critical to defining first impressions. In 2026, web design priorities have shifted toward creating smooth, responsive, and personalized experiences that encourage visitors to take action. Here’s what’s shaping modern website design and how it can support your - [CVE-2026-33825 Microsoft Defender Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-33825-microsoft-defender-elevation-of-privilege-vulnerability/) - Added FAQ information. This is an informational change only. - [CVE-2026-24051 OpenTelemetry-Go Affected by Arbitrary Code Execution via PATH Hijacking](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-24051-opentelemetry-go-affected-by-arbitrary-code-execution-via-path-hijacking/) - Information published. - [CVE-2026-6019 BaseCookie.js_output() does not neutralize embedded characters](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-6019-basecookie-js_output-does-not-neutralize-embedded-characters/) - Information published. - [CVE-2026-41898 rust-openssl: Unchecked callback-returned length in PSK and cookie generate trampolines can cause OpenSSL to leak adjacent memory to the network peer](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41898-rust-openssl-unchecked-callback-returned-length-in-psk-and-cookie-generate-trampolines-can-cause-openssl-to-leak-adjacent-memory-to-the-network-peer/) - Information published. - [CVE-2026-6732 Libxml2: libxml2: denial of service via crafted xsd-validated document](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-6732-libxml2-libxml2-denial-of-service-via-crafted-xsd-validated-document/) - Information published. - [CVE-2026-2708 Libsoup: libsoup: http request smuggling via duplicate content-length headers](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-2708-libsoup-libsoup-http-request-smuggling-via-duplicate-content-length-headers/) - Information published. - [CVE-2019-1547 ECDSA remote timing attack](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2019-1547-ecdsa-remote-timing-attack/) - Information published. - [CVE-2026-5778 Integer underflow leads to out-of-bounds access in sniffer ChaCha decrypt path.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-5778-integer-underflow-leads-to-out-of-bounds-access-in-sniffer-chacha-decrypt-path/) - Information published. - [CVE-2026-5188 Integer underflow in X.509 SAN parsing in wolfSSL](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-5188-integer-underflow-in-x-509-san-parsing-in-wolfssl/) - Information published. - [CVE-2019-1543 ChaCha20-Poly1305 with long nonces](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2019-1543-chacha20-poly1305-with-long-nonces/) - Information published. - [CVE-2026-5295 Stack Buffer Overflow in wolfSSL PKCS7 wc_PKCS7_DecryptOri() via Oversized OID](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-5295-stack-buffer-overflow-in-wolfssl-pkcs7-wc_pkcs7_decryptori-via-oversized-oid/) - Information published. - [CVE-2026-5503 out-of-bounds write in TLSX_EchChangeSNI via attacker-controlled publicName](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-5503-out-of-bounds-write-in-tlsx_echchangesni-via-attacker-controlled-publicname/) - Information published. - [CVE-2019-1563 Padding Oracle in PKCS7_dataDecode and CMS_decrypt_set1_pkey](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2019-1563-padding-oracle-in-pkcs7_datadecode-and-cms_decrypt_set1_pkey/) - Information published. - [CVE-2026-5507 Session Cache Restore — Arbitrary Free via Deserialized Pointer](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-5507-session-cache-restore-arbitrary-free-via-deserialized-pointer/) - Information published. - [CVE-2019-1551 rsaz_512_sqr overflow bug on x86_64](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2019-1551-rsaz_512_sqr-overflow-bug-on-x86_64/) - Information published. - [CVE-2026-5504 PKCS7 CBC Padding Oracle — Plaintext Recovery](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-5504-pkcs7-cbc-padding-oracle-plaintext-recovery/) - Information published. - [CVE-2026-5393 OOB Read in DoTls13CertificateVerify with WOLFSSL_DUAL_ALG_CERTS](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-5393-oob-read-in-dotls13certificateverify-with-wolfssl_dual_alg_certs/) - Information published. - [CVE-2026-31420 bridge: mrp: reject zero test interval to avoid OOM panic](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31420-bridge-mrp-reject-zero-test-interval-to-avoid-oom-panic/) - Information published. - [CVE-2026-34477 Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34477-apache-log4j-core-verifyhostname-attribute-silently-ignored-in-tls-configuration-allowing-hostname-verification-bypass/) - Information published. - [CVE-2026-31584 media: mediatek: vcodec: fix use-after-free in encoder release path](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31584-media-mediatek-vcodec-fix-use-after-free-in-encoder-release-path/) - Information published. - [CVE-2026-31576 media: hackrf: fix to not free memory after the device is registered in hackrf_probe()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31576-media-hackrf-fix-to-not-free-memory-after-the-device-is-registered-in-hackrf_probe/) - Information published. - [CVE-2026-31588 KVM: x86: Use scratch field in MMIO fragment to hold small write values](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31588-kvm-x86-use-scratch-field-in-mmio-fragment-to-hold-small-write-values/) - Information published. - [CVE-2026-31649 net: stmmac: fix integer underflow in chain mode](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31649-net-stmmac-fix-integer-underflow-in-chain-mode/) - Information published. - [CVE-2026-31582 hwmon: (powerz) Fix use-after-free on USB disconnect](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31582-hwmon-powerz-fix-use-after-free-on-usb-disconnect/) - Information published. - [CVE-2026-31669 mptcp: fix slab-use-after-free in __inet_lookup_established](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31669-mptcp-fix-slab-use-after-free-in-__inet_lookup_established/) - Information published. - [CVE-2026-31628 x86/CPU: Fix FPDSS on Zen1](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31628-x86-cpu-fix-fpdss-on-zen1/) - Information published. - [CVE-2026-31630 rxrpc: proc: size address buffers for %pISpc output](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31630-rxrpc-proc-size-address-buffers-for-pispc-output/) - Information published. - [CVE-2026-31629 nfc: llcp: add missing return after LLCP_CLOSED checks](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31629-nfc-llcp-add-missing-return-after-llcp_closed-checks/) - Information published. - [CVE-2026-31657 batman-adv: hold claim backbone gateways by reference](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31657-batman-adv-hold-claim-backbone-gateways-by-reference/) - Information published. - [CVE-2026-31616 usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31616-usb-gadget-f_phonet-fix-skb-frags-overflow-in-pn_rx_complete/) - Information published. - [CVE-2026-34591 Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34591-poetry-has-wheel-path-traversal-which-can-lead-to-arbitrary-file-write/) - Information published. - [CVE-2026-23388 Squashfs: check metadata block offset is within range](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23388-squashfs-check-metadata-block-offset-is-within-range/) - Information published. - [CVE-2026-31619 ALSA: fireworks: bound device-supplied status before string array lookup](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31619-alsa-fireworks-bound-device-supplied-status-before-string-array-lookup/) - Information published. - [CVE-2026-31592 KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31592-kvm-sev-protect-all-of-sev_mem_enc_register_region-with-kvm-lock/) - Information published. - [CVE-2026-31597 ocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31597-ocfs2-fix-use-after-free-in-ocfs2_fault-when-vm_fault_retry/) - Information published. - [CVE-2026-31578 media: as102: fix to not free memory after the device is registered in as102_usb_probe()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31578-media-as102-fix-to-not-free-memory-after-the-device-is-registered-in-as102_usb_probe/) - Information published. - [CVE-2026-31586 mm: blk-cgroup: fix use-after-free in cgwb_release_workfn()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31586-mm-blk-cgroup-fix-use-after-free-in-cgwb_release_workfn/) - Information published. - [How a small business can get real returns from AI](https://www.netservicesgroup.com/blog/how-a-small-business-can-get-real-returns-from-ai/) - Many business owners are pouring money into AI tools, but few know whether that money is coming back. Recent research shows that 90% of leaders see the value of AI, but they don’t all define that value the same way. You can join the group of successful owners by focusing on management rather than just - [A hidden Android flaw that breaks the lock screen in seconds](https://www.netservicesgroup.com/blog/a-hidden-android-flaw-that-breaks-the-lock-screen-in-seconds/) - A critical vulnerability, tracked as CVE-2026-20435, is affecting up to 875 million Android phones powered by MediaTek chips. The flaw exists in the device’s early boot process, raising serious questions about how secure locked phones really are, and why this issue is more dangerous than it first appears. What makes this vulnerability dangerous and different? - [M5 MacBook Air vs. MacBook Neo: Which Apple laptop is right for you?](https://www.netservicesgroup.com/blog/m5-macbook-air-vs-macbook-neo-which-apple-laptop-is-right-for-you/) - Apple’s new MacBook Neo introduces a relatively low-cost entry to the macOS ecosystem, but it comes with trade-offs. This article compares it with the M5 MacBook Air to help you decide which one fits your needs. At a glance: The spec sheet Key specification MacBook Neo MacBook Air (M5) Starting price $599 $1,099 (13-inch) $1,299 - [CVE-2026-32202 Windows Shell Spoofing Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-32202-windows-shell-spoofing-vulnerability/) - Corrected the Exploitability Index, Exploited flag and CVSS vector which was incorrect at the time of publication on 4/14/2026. This is an informational change only. - [CVE-2018-0734 Timing attack against DSA](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2018-0734-timing-attack-against-dsa/) - Information published. - [CVE-2018-0735 Timing attack against ECDSA signature generation](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2018-0735-timing-attack-against-ecdsa-signature-generation/) - Information published. - [CVE-2026-23372 nfc: rawsock: cancel tx_work before socket teardown](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23372-nfc-rawsock-cancel-tx_work-before-socket-teardown/) - Information published. - [CVE-2026-23371 sched/deadline: Fix missing ENQUEUE_REPLENISH during PI de-boosting](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23371-sched-deadline-fix-missing-enqueue_replenish-during-pi-de-boosting/) - Information published. - [CVE-2026-23370 platform/x86: dell-wmi-sysman: Don't hex dump plaintext password data](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23370-platform-x86-dell-wmi-sysman-dont-hex-dump-plaintext-password-data/) - Information published. - [CVE-2026-23368 net: phy: register phy led_triggers during probe to avoid AB-BA deadlock](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23368-net-phy-register-phy-led_triggers-during-probe-to-avoid-ab-ba-deadlock/) - Information published. - [CVE-2026-23364 ksmbd: Compare MACs in constant time](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23364-ksmbd-compare-macs-in-constant-time/) - Information published. - [CVE-2026-23362 can: bcm: fix locking for bcm_op runtime updates](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23362-can-bcm-fix-locking-for-bcm_op-runtime-updates/) - Information published. - [CVE-2026-31656 drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31656-drm-i915-gt-fix-refcount-underflow-in-intel_engine_park_heartbeat/) - Information published. - [CVE-2026-23361 PCI: dwc: ep: Flush MSI-X write before unmapping its ATU entry](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23361-pci-dwc-ep-flush-msi-x-write-before-unmapping-its-atu-entry/) - Information published. - [CVE-2026-23359 bpf: Fix stack-out-of-bounds write in devmap](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23359-bpf-fix-stack-out-of-bounds-write-in-devmap/) - Information published. - [CVE-2026-23357 can: mcp251x: fix deadlock in error path of mcp251x_open](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23357-can-mcp251x-fix-deadlock-in-error-path-of-mcp251x_open/) - Information published. - [CVE-2026-23356 drbd: fix "LOGIC BUG" in drbd_al_begin_io_nonblock()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23356-drbd-fix-logic-bug-in-drbd_al_begin_io_nonblock/) - Information published. - [CVE-2026-23352 x86/efi: defer freeing of boot services memory](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23352-x86-efi-defer-freeing-of-boot-services-memory/) - Information published. - [CVE-2026-31658 net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31658-net-altera-tse-fix-skb-leak-on-dma-mapping-error-in-tse_start_xmit/) - Information published. - [CVE-2026-23351 netfilter: nft_set_pipapo: split gc into unlink and reclaim phase](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23351-netfilter-nft_set_pipapo-split-gc-into-unlink-and-reclaim-phase/) - Information published. - [Why internet-based calling is becoming the backbone of modern business operations](https://www.netservicesgroup.com/blog/why-internet-based-calling-is-becoming-the-backbone-of-modern-business-operations/) - Voice over Internet Protocol (VoIP) has evolved from a simple money-saver into a fundamental tool for modern business operations. In this article, we'll dive into the key trends, anticipated growth, and innovative features that are defining the future of business communication. In the past, office communication meant desk phones, tangled cords, and expensive long-distance charges. - [CVE-2026-40372 ASP.NET Core Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-40372-asp-net-core-elevation-of-privilege-vulnerability/) - Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. - [CVE-2026-26168 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-26168-windows-ancillary-function-driver-for-winsock-elevation-of-privilege-vulnerability/) - Acknowledgement added. This is an informational change only. - [CVE-2026-32288 Unbounded allocation for old GNU sparse in archive/tar](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-32288-unbounded-allocation-for-old-gnu-sparse-in-archive-tar/) - Information published. - [CVE-2026-41254](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41254/) - Information published. - [CVE-2026-32077 Windows UPnP Device Host Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-32077-windows-upnp-device-host-elevation-of-privilege-vulnerability/) - Added Security Only packages to Windows Server 2012 security updates. This is an informational change only. - [CVE-2026-21523 GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21523-github-copilot-and-visual-studio-code-remote-code-execution-vulnerability/) - Added acknowledgements. This is an informational change only. - [Microsoft halts automatic Copilot rollout for Windows](https://www.netservicesgroup.com/blog/microsoft-halts-automatic-copilot-rollout-for-windows/) - Microsoft has temporarily halted the automatic rollout of the Microsoft 365 Copilot app on Windows 11 following backlash from users and enterprise customers. The pause reflects growing concerns over forced installations and signals a shift toward giving users and IT admins more control over AI feature deployment. Automatic rollout paused In 2025, Microsoft announced that - [Chromium: CVE-2026-6297 Use after free in Proxy](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-6297-use-after-free-in-proxy/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-6296 Heap buffer overflow in ANGLE](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-6296-heap-buffer-overflow-in-angle/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-6364 Out of bounds read in Skia](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-6364-out-of-bounds-read-in-skia/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-6363 Type Confusion in V8](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-6363-type-confusion-in-v8/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-6362 Use after free in Codecs](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-6362-use-after-free-in-codecs/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [CVE-2026-4786 Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-4786-incomplete-mitigation-of-cve-2026-4519-¬tion-expansion-for-command-injection-to-webbrowser-open/) - Information published. - [CVE-2026-6100 Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-6100-use-after-free-in-lzma-lzmadecompressor-bz2-bz2decompressor-and-gzip-gzipfile-after-re-use-under-memory-pressure/) - Information published. - [CVE-2026-5160](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-5160/) - Information published. - [CVE-2026-33056 tar-rs: unpack_in can chmod arbitrary directories by following symlinks](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-33056-tar-rs-unpack_in-can-chmod-arbitrary-directories-by-following-symlinks/) - Information published. - [CVE-2026-33055 tar-rs incorrectly ignores PAX size headers if header size is nonzero](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-33055-tar-rs-incorrectly-ignores-pax-size-headers-if-header-size-is-nonzero/) - Information published. - [Chromium: CVE-2026-6307 Type Confusion in Turbofan](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-6307-type-confusion-in-turbofan/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-6306 Heap buffer overflow in PDFium](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-6306-heap-buffer-overflow-in-pdfium/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-6305 Heap buffer overflow in PDFium](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-6305-heap-buffer-overflow-in-pdfium/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-6304 Use after free in Graphite](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-6304-use-after-free-in-graphite/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-6303 Use after free in Codecs](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-6303-use-after-free-in-codecs/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-6302 Use after free in Video](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-6302-use-after-free-in-video/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-6301 Type Confusion in Turbofan](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-6301-type-confusion-in-turbofan/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-6300 Use after free in CSS](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-6300-use-after-free-in-css/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-6299 Use after free in Prerender](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-6299-use-after-free-in-prerender/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-6298 Heap buffer overflow in Skia](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-6298-heap-buffer-overflow-in-skia/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Scaling Internet of Things networks with Infrastructure-as-Code](https://www.netservicesgroup.com/blog/scaling-internet-of-things-networks-with-infrastructure-as-code/) - The Internet of Things (IoT) connects everyday devices to the web so they can share information and automate tasks. As businesses use more smart devices, managing these growing networks gets much harder. You need a reliable way to handle hundreds of connections without system crashes. Infrastructure-as-Code (IaC) offers an effective method to build and manage - [PHI security best practices for healthcare organizations](https://www.netservicesgroup.com/blog/phi-security-best-practices-for-healthcare-organizations/) - Patient confidentiality remains central to quality care and extends to protected health information (PHI), which includes data connected to a person’s medical history, treatment, or billing details. As healthcare environments become more digital, protecting PHI calls for more deliberate safeguards. A structured approach can help reduce risk and maintain trust. The following best practices highlight - [CVE-2026-35201 Discount has an Out-of-bounds Read in rdiscount](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-35201-discount-has-an-out-of-bounds-read-in-rdiscount/) - Information published. - [CVE-2026-40179 Prometheus: Stored XSS via metric names and label values in web UI tooltips and metrics explorer](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-40179-prometheus-stored-xss-via-metric-names-and-label-values-in-web-ui-tooltips-and-metrics-explorer/) - Information published. - [CVE-2025-14821 Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-14821-libssh-libssh-insecure-default-configuration-leads-to-local-man-in-the-middle-attacks-on-windows/) - Information published. - [CVE-2026-39956 jq: Missing runtime type checks for _strindices lead to crash and limited memory disclosure](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39956-jq-missing-runtime-type-checks-for-_strindices-lead-to-crash-and-limited-memory-disclosure/) - Information published. - [CVE-2026-35199 SymCrypt SymCryptXmssSign function - Heap overflow via 64->32-bit leaf-count truncation](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-35199-symcrypt-symcryptxmsssign-function-heap-overflow-via-64-32-bit-leaf-count-truncation/) - Information published. - [CVE-2026-41035](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41035/) - Information published. - [CVE-2026-35469 SpdyStream: DOS on CRI](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-35469-spdystream-dos-on-cri/) - Information published. - [CVE-2026-40164 jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-40164-jq-algorithmic-complexity-dos-via-hardcoded-murmurhash3-seed/) - Information published. - [CVE-2026-39979 jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39979-jq-out-of-bounds-read-in-jv_parse_sized-error-formatting-for-non-nul-terminated-counted-buffers/) - Information published. - [CVE-2026-33948 jq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed Input](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-33948-jq-embedded-nul-truncation-in-cli-json-input-path-causes-prefix-only-validation-of-malformed-input/) - Information published. - [CVE-2026-33947 jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-33947-jq-unbounded-recursion-in-jv_setpath-jv_getpath-and-delpaths_sorted/) - Information published. - [CVE-2026-32316 jq: Integer overflow in jvp_string_append() allows Heap-based Buffer Overflow](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-32316-jq-integer-overflow-in-jvp_string_append-allows-heap-based-buffer-overflow/) - Information published. - [CVE-2026-32223 Windows USB Printing Stack (usbprint.sys) Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-32223-windows-usb-printing-stack-usbprint-sys-elevation-of-privilege-vulnerability/) - Acknowledgement added. This is an informational change only. - [CVE-2025-64669 Windows Admin Center Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-64669-windows-admin-center-elevation-of-privilege-vulnerability/) - Acknowledgement added. This is an informational change only. - [CVE-2026-23666 .NET Framework Denial of Service Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23666-net-framework-denial-of-service-vulnerability/) - Executive Summary updated - [CVE-2026-27143 Missing bound checks can lead to memory corruption in safe Go in cmd/compile](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-27143-missing-bound-checks-can-lead-to-memory-corruption-in-safe-go-in-cmd-compile/) - Information published. - [CVE-2026-32282 TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-32282-toctou-permits-root-escape-on-linux-via-root-chmod-in-os-in-internal-syscall-unix/) - Information published. - [CVE-2026-31418 netfilter: ipset: drop logically empty buckets in mtype_del](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31418-netfilter-ipset-drop-logically-empty-buckets-in-mtype_del/) - Information published. - [CVE-2026-3184 Util-linux: util-linux: access control bypass due to improper hostname canonicalization](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-3184-util-linux-util-linux-access-control-bypass-due-to-improper-hostname-canonicalization/) - Information published. - [CVE-2026-27456 util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-27456-util-linux-toctou-race-condition-in-util-linux-mount8-loop-device-setup/) - Information published. - [CVE-2026-4647 Binutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-4647-binutils-out-of-bounds-read-in-xcoff-relocation-processing-in-gnu-binutils-bfd-library/) - Information published. - [Modern password tips based on NIST guidelines](https://www.netservicesgroup.com/blog/modern-password-tips-based-on-nist-guidelines/) - Passwords are an inherently flawed security measure in an era of constant phishing attacks and massive data leaks. This guide breaks down the latest recommendations from the National Institute of Standards and Technology (NIST) and shows how to improve security with longer passwords, smarter tools, and modern authentication methods. Why should your business listen to - [CVE-2026-39856 osslsigncode has an Out-of-Bounds Read via Unvalidated Section Bounds in PE Page Hash Calculation](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39856-osslsigncode-has-an-out-of-bounds-read-via-unvalidated-section-bounds-in-pe-page-hash-calculation/) - Information published. - [CVE-2026-39855 osslsigncode has an Integer Underflow in PE Page Hash Calculation Can Cause Out-of-Bounds Read](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39855-osslsigncode-has-an-integer-underflow-in-pe-page-hash-calculation-can-cause-out-of-bounds-read/) - Information published. - [CVE-2026-39853 osslsigncode has a Stack Buffer Overflow via Unbounded Digest Copy During Signature Verification](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39853-osslsigncode-has-a-stack-buffer-overflow-via-unbounded-digest-copy-during-signature-verification/) - Information published. - [CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-28390-possible-null-dereference-when-processing-cms-keytransportrecipientinfo/) - Information published. - [CVE-2026-28389 Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-28389-possible-null-dereference-when-processing-cms-keyagreerecipientinfo/) - Information published. - [CVE-2026-40226](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-40226/) - Information published. - [CVE-2026-34757 LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34757-libpng-has-a-yse-after-free-in-png_set_plte-png_set_trns-and-png_set_hist-leading-to-corrupted-chunk-data-and-potential-heap-information-disclosure/) - Information published. - [CVE-2026-35206 Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-35206-helm-chart-extraction-output-directory-collapse-via-chart-yaml-name-dot-segment/) - Information published. - [CVE-2026-34743 XZ Utils: Buffer overflow in lzma_index_append()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34743-xz-utils-buffer-overflow-in-lzma_index_append/) - Information published. - [CVE-2026-35535](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-35535/) - Information published. - [CVE-2026-35385](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-35385/) - Information published. - [CVE-2026-35386](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-35386/) - Information published. - [CVE-2026-35388](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-35388/) - Information published. - [CVE-2026-4878 Libcap: libcap: privilege escalation via toctou race condition in cap_set_file()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-4878-libcap-libcap-privilege-escalation-via-toctou-race-condition-in-cap_set_file/) - Information published. - [CVE-2026-33810 Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-33810-case-sensitive-excludedsubtrees-name-constraints-cause-auth-bypass-in-crypto-x509/) - Information published. - [CVE-2026-27140 Code execution vulnerability in SWIG code generation in cmd/go](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-27140-code-execution-vulnerability-in-swig-code-generation-in-cmd-go/) - Information published. - [Cut IT costs without cutting corners: The case for thin and zero clients](https://www.netservicesgroup.com/blog/cut-it-costs-without-cutting-corners-the-case-for-thin-and-zero-clients/) - Rising IT expenses are pushing businesses to explore smarter alternatives to traditional desktops. Thin and zero clients offer a cost-effective, secure, and easier-to-manage solution by shifting computing power to centralized systems. A different way to think about workstations Traditional desktops are designed to handle everything locally. Processing, storage, and applications all happen on the machine - [2026 guide to choosing the best VoIP headset for peak productivity](https://www.netservicesgroup.com/blog/2026-guide-to-choosing-the-best-voip-headset-for-peak-productivity/) - A subpar Voice over Internet Protocol (VoIP) headset often leads to distracting background noise, unclear audio, and even physical discomfort after just a few hours. That’s why you need a high-quality headset that supports the way you work. But with so many options on the market, how do you find the right one? Here are - [6 Simple ways to recover lost Excel files](https://www.netservicesgroup.com/blog/6-simple-ways-to-recover-lost-excel-files/) - Your Microsoft Excel spreadsheets are likely the lifeblood of your small business. Whether it’s your monthly budget, an upcoming payroll sheet, or your entire inventory list, seeing hours of hard work vanish in an instant is terrifying. Before you start retyping everything from scratch, take a deep breath. Your data is probably still hiding on - [CVE-2026-23411 apparmor: fix race between freeing data and fs accessing it](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23411-apparmor-fix-race-between-freeing-data-and-fs-accessing-it/) - Information published. - [CVE-2026-23410 apparmor: fix race on rawdata dereference](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23410-apparmor-fix-race-on-rawdata-dereference/) - Information published. - [CVE-2026-23409 apparmor: fix differential encoding verification](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23409-apparmor-fix-differential-encoding-verification/) - Information published. - [CVE-2026-23408 apparmor: Fix double free of ns_name in aa_replace_profiles()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23408-apparmor-fix-double-free-of-ns_name-in-aa_replace_profiles/) - Information published. - [CVE-2026-23407 apparmor: fix missing bounds check on DEFAULT table in verify_dfa()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23407-apparmor-fix-missing-bounds-check-on-default-table-in-verify_dfa/) - Information published. - [CVE-2026-23406 apparmor: fix side-effect bug in match_char() macro usage](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23406-apparmor-fix-side-effect-bug-in-match_char-macro-usage/) - Information published. - [CVE-2026-23405 apparmor: fix: limit the number of levels of policy namespaces](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23405-apparmor-fix-limit-the-number-of-levels-of-policy-namespaces/) - Information published. - [CVE-2026-23404 apparmor: replace recursive profile removal with iterative approach](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23404-apparmor-replace-recursive-profile-removal-with-iterative-approach/) - Information published. - [CVE-2026-23403 apparmor: fix memory leak in verify_header](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23403-apparmor-fix-memory-leak-in-verify_header/) - Information published. - [CVE-2026-39881 Vim Ex command injection in Vims NetBeans integration](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39881-vim-ex-command-injection-in-vims-netbeans-integration/) - Information published. - [CVE-2026-40024 Sleuth Kit tsk_recover Path Traversal](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-40024-sleuth-kit-tsk_recover-path-traversal/) - Information published. - [CVE-2026-40025 Sleuth Kit APFS Keybag Parser Out-of-Bounds Read](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-40025-sleuth-kit-apfs-keybag-parser-out-of-bounds-read/) - Information published. - [CVE-2026-40026 Sleuth Kit ISO9660 SUSP Extension Reference Out-of-Bounds Read](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-40026-sleuth-kit-iso9660-susp-extension-reference-out-of-bounds-read/) - Information published. - [CVE-2026-32241 Flannel vulnerable to cross-node remote code execution via extension backend BackendData injection](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-32241-flannel-vulnerable-to-cross-node-remote-code-execution-via-extension-backend-backenddata-injection/) - Information published. - [Master your Gmail inbox: Combat email overload for better productivity](https://www.netservicesgroup.com/blog/master-your-gmail-inbox-combat-email-overload-for-better-productivity/) - A Gmail inbox flooded with messages is a hidden productivity killer. The constant need to check and manage your inbox can pull your attention away from the tasks that matter most. This article reveals practical strategies to declutter your inbox and regain control, turning Gmail into a tool that supports efficiency, not hinders it. Write - [CVE-2026-21715](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21715/) - Information published. - [CVE-2026-21710](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21710/) - Information published. - [CVE-2026-21717](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21717/) - Information published. - [CVE-2025-66038 OpenSC: `sc_compacttlv_find_tag` can return out-of-bounds pointers](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-66038-opensc-sc_compacttlv_find_tag-can-return-out-of-bounds-pointers/) - Information published. - [CVE-2025-66037 OpenSC: Out of Bounds vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-66037-opensc-out-of-bounds-vulnerability/) - Information published. - [CVE-2025-66215 OpenSC: Stack-buffer-overflow WRITE in card-oberthur](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-66215-opensc-stack-buffer-overflow-write-in-card-oberthur/) - Information published. - [CVE-2025-49010 OpenSC: Stack-buffer-overflow WRITE in GET RESPONSE](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-49010-opensc-stack-buffer-overflow-write-in-get-response/) - Information published. - [CVE-2026-34445 ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34445-onnx-malicious-onnx-models-can-crash-servers-by-exploiting-unprotected-object-settings/) - Information published. - [CVE-2026-34446 ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34446-onnx-arbitrary-file-read-via-externaldata-hardlink-bypass-in-onnx-load/) - Information published. - [CVE-2026-35177 Path traversal issue with zip.vim in Vim](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-35177-path-traversal-issue-with-zip-vim-in-vim/) - Information published. - [CVE-2026-34982 Vim modeline bypass via various options affects Vim < 9.2.0276](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34982-vim-modeline-bypass-via-various-options-affects-vim-9-2-0276/) - Information published. - [CVE-2026-35093 Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-35093-libinput-libinput-unauthorized-code-execution-and-information-disclosure-through-lua-bytecode-plugins/) - Information published. - [Unlock business growth with email automation](https://www.netservicesgroup.com/blog/unlock-business-growth-with-email-automation/) - Streamline your email campaigns and improve customer relationships with email automation. By automating your communications, you can save time, deliver personalized content, and boost engagement, making your marketing efforts more efficient and effective. Understanding email automation Email automation uses technology to send targeted, timely emails to subscribers without manual effort. These messages are triggered automatically - [CVE-2026-32287 Infinite loop in github.com/antchfx/xpath](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-32287-infinite-loop-in-github-com-antchfx-xpath/) - Information published. - [CVE-2026-29785 NATS Server panic via malicious compression on leafnode port](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-29785-nats-server-panic-via-malicious-compression-on-leafnode-port/) - Information published. - [CVE-2026-33216 NATS has MQTT plaintext password disclosure](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-33216-nats-has-mqtt-plaintext-password-disclosure/) - Information published. - [CVE-2026-33416 LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE`](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-33416-libpng-has-use-after-free-via-pointer-aliasing-in-png_set_trns-and-png_set_plte/) - Information published. - [CVE-2026-2436 Libsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-2436-libsoup-libsoup-denial-of-service-via-use-after-free-in-soupserver-during-tls-handshake/) - Information published. - [CVE-2026-4732 Out-of-bounds Read Overflow in tildearrow/furnace](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-4732-out-of-bounds-read-overflow-in-tildearrow-furnace/) - Information published. - [CVE-2026-4897 Polkit: polkit: denial of service via unbounded input processing through standard input](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-4897-polkit-polkit-denial-of-service-via-unbounded-input-processing-through-standard-input/) - Information published. - [CVE-2026-34043 Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34043-serialize-javascript-has-cpu-exhaustion-denial-of-service-via-crafted-array-like-objects/) - Information published. - [CVE-2026-33936 python-ecdsa: Denial of Service via improper DER length validation in crafted private keys](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-33936-python-ecdsa-denial-of-service-via-improper-der-length-validation-in-crafted-private-keys/) - Information published. - [CVE-2026-5107 FRRouting FRR EVPN Type-2 Route bgp_evpn.c process_type2_route access control](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-5107-frrouting-frr-evpn-type-2-route-bgp_evpn-c-process_type2_route-access-control/) - Information published. - [CVE-2026-34714](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34714/) - Information published. - [CVE-2026-33636 LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-33636-libpng-has-arm-neon-palette-expansion-out-of-bounds-read-on-aarch64/) - Information published. - [3 Reasons you should turn off location services on your Android right now](https://www.netservicesgroup.com/blog/3-reasons-you-should-turn-off-location-services-on-your-android-right-now/) - Your Android phone tracks your location more often than you think. While location services can be helpful for navigation, they also pose significant privacy risks and can drain your battery. Here are three compelling reasons why you should consider turning off location services. Protect your privacy One of the biggest concerns with location services is - [CVE-2026-33542 Incus does not verify combined fingerprint when downloading images from simplestreams servers](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-33542-incus-does-not-verify-combined-fingerprint-when-downloading-images-from-simplestreams-servers/) - Information published. - [CVE-2026-33750 brace-expansion: Zero-step sequence causes process hang and memory exhaustion](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-33750-brace-expansion-zero-step-sequence-causes-process-hang-and-memory-exhaustion/) - Information published. - [CVE-2026-34353](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34353/) - Information published. - [CVE-2026-21712](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21712/) - Information published. - [CVE-2026-0964 Libssh: improper sanitation of paths received from scp servers](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-0964-libssh-improper-sanitation-of-paths-received-from-scp-servers/) - Information published. - [CVE-2026-0966 Libssh: buffer underflow in ssh_get_hexa() on invalid input](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-0966-libssh-buffer-underflow-in-ssh_get_hexa-on-invalid-input/) - Information published. - [CVE-2026-0967 Libssh: libssh: denial of service via inefficient regular expression processing](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-0967-libssh-libssh-denial-of-service-via-inefficient-regular-expression-processing/) - Information published. - [CVE-2026-0965 Libssh: libssh: denial of service via improper configuration file handling](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-0965-libssh-libssh-denial-of-service-via-improper-configuration-file-handling/) - Information published. - [CVE-2025-67030](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-67030/) - Information published. - [CVE-2026-4645 Github.com/antchfx/xpath: xpath: denial of service via crafted boolean xpath expressions](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-4645-github-com-antchfx-xpath-xpath-denial-of-service-via-crafted-boolean-xpath-expressions/) - Information published. - [CVE-2026-4746 Heap Buffer Over-Write Vulenrabilty in timeplus-io/proton](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-4746-heap-buffer-over-write-vulenrabilty-in-timeplus-io-proton/) - Information published. - [CVE-2024-41013 xfs: don't walk off the end of a directory data block](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-41013-xfs-dont-walk-off-the-end-of-a-directory-data-block/) - Information published. - [CVE-2024-35839 netfilter: bridge: replace physindev with physinif in nf_bridge_info](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-35839-netfilter-bridge-replace-physindev-with-physinif-in-nf_bridge_info/) - Information published. - [CVE-2023-52676 bpf: Guard stack limits against 32bit overflow](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2023-52676-bpf-guard-stack-limits-against-32bit-overflow/) - Information published. - [CVE-2026-29111 systemd: Local unprivileged user can trigger an assert](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-29111-systemd-local-unprivileged-user-can-trigger-an-assert/) - Information published. - [CVE-2026-21711](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21711/) - Information published. - [CVE-2026-21713](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21713/) - Information published. - [CVE-2026-21716](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21716/) - Information published. - [CVE-2026-21714](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21714/) - Information published. - [CVE-2026-33937 Handlebars.js has JavaScript Injection via AST Type Confusion](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-33937-handlebars-js-has-javascript-injection-via-ast-type-confusion/) - Information published. - [CVE-2026-23324 can: usb: etas_es58x: correctly anchor the urb in the read bulk callback](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23324-can-usb-etas_es58x-correctly-anchor-the-urb-in-the-read-bulk-callback/) - Information published. - [Windows 11 update: New features you need to know about](https://www.netservicesgroup.com/blog/windows-11-update-new-features-you-need-to-know-about/) - On September 20, 2022, Microsoft released the first major update for Windows 11 in line with the operating system's upcoming first anniversary. This free upgrade will make PCs more accessible, convenient, secure, and eco-friendly. Here are some features that come with the Windows 11 update. - [Unmistakable signs that you should get a new Mac in 2026](https://www.netservicesgroup.com/blog/unmistakable-signs-that-you-should-get-a-new-mac-in-2026/) - Even the most reliable devices eventually show their age. The signs can be subtle at first, but become more obvious over time. Here are the signs your device may be falling behind in 2026 and why an upgrade might be a good idea. Your Mac is slower than it needs to be A noticeable drop - [CVE-2026-23367 wifi: radiotap: reject radiotap with unknown bits](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23367-wifi-radiotap-reject-radiotap-with-unknown-bits/) - Information published. - [CVE-2026-23389 ice: Fix memory leak in ice_set_ringparam()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23389-ice-fix-memory-leak-in-ice_set_ringparam/) - Information published. - [CVE-2026-23327 cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23327-cxl-mbox-validate-payload-size-before-accessing-contents-in-cxl_payload_from_user_allowed/) - Information published. - [CVE-2026-23343 xdp: produce a warning when calculated tailroom is negative](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23343-xdp-produce-a-warning-when-calculated-tailroom-is-negative/) - Information published. - [CVE-2025-66413 Git for Windows leaks NTLM hash when cloning from an attacker-controlled server](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-66413-git-for-windows-leaks-ntlm-hash-when-cloning-from-an-attacker-controlled-server/) - Information published. - [CVE-2026-2297 SourcelessFileLoader does not use io.open_code()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-2297-sourcelessfileloader-does-not-use-io-open_code/) - Information published. - [CVE-2025-68357 iomap: allocate s_dio_done_wq for async reads as well](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68357-iomap-allocate-s_dio_done_wq-for-async-reads-as-well/) - Information published. - [CVE-2024-45336 Sensitive headers incorrectly sent after cross-domain redirect in net/http](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-45336-sensitive-headers-incorrectly-sent-after-cross-domain-redirect-in-net-http/) - Information published. - [CVE-2024-45341 Usage of IPv6 zone IDs can bypass URI name constraints in crypto/x509](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-45341-usage-of-ipv6-zone-ids-can-bypass-uri-name-constraints-in-crypto-x509/) - Information published. - [CVE-2026-23393 bridge: cfm: Fix race condition in peer_mep deletion](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23393-bridge-cfm-fix-race-condition-in-peer_mep-deletion/) - Information published. - [CVE-2026-23284 net: ethernet: mtk_eth_soc: Reset prog ptr to old_prog in case of error in mtk_xdp_setup()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23284-net-ethernet-mtk_eth_soc-reset-prog-ptr-to-old_prog-in-case-of-error-in-mtk_xdp_setup/) - Information published. - [CVE-2026-23365 net: usb: kalmia: validate USB endpoints](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23365-net-usb-kalmia-validate-usb-endpoints/) - Information published. - [CVE-2026-23379 net/sched: ets: fix divide by zero in the offload path](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23379-net-sched-ets-fix-divide-by-zero-in-the-offload-path/) - Information published. - [CVE-2026-23279 wifi: mac80211: fix NULL pointer dereference in mesh_rx_csa_frame()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23279-wifi-mac80211-fix-null-pointer-dereference-in-mesh_rx_csa_frame/) - Information published. - [Why SMBs need regular technology business reviews](https://www.netservicesgroup.com/blog/why-smbs-need-regular-technology-business-reviews/) - Technology is always evolving, and for small or mid-sized businesses like yours, staying ahead means taking a close look at your IT strategy. A technology business review helps you spot inefficiencies, security risks, and growth opportunities. By conducting these reviews regularly, you can make sure your technology supports your goals, boosts productivity, and stays cost-effective. - [Understanding the true cost of a new VoIP system](https://www.netservicesgroup.com/blog/understanding-the-true-cost-of-a-new-voip-system/) - Upgrading your office phones might seem like a huge expense at first glance, but Voice over Internet Protocol (VoIP) phone systems actually offer incredible value compared to old-school landlines. You get powerful communication tools for a steady monthly rate. However, even with these savings, you still need to plan for several specific expenses. This article - [Chromium: CVE-2026-4452 Integer overflow in ANGLE](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-4452-integer-overflow-in-angle/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-4451 Insufficient validation of untrusted input in Navigation](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-4451-insufficient-validation-of-untrusted-input-in-navigation/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-4450 Out of bounds write in V8](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-4450-out-of-bounds-write-in-v8/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-4449 Use after free in Blink](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-4449-use-after-free-in-blink/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-4448 Heap buffer overflow in ANGLE](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-4448-heap-buffer-overflow-in-angle/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-4447 Inappropriate implementation in V8](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-4447-inappropriate-implementation-in-v8/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-4446 Use after free in WebRTC](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-4446-use-after-free-in-webrtc/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [CVE-2026-4438 gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-4438-gethostbyaddr-and-gethostbyaddr_r-return-invalid-dns-hostnames/) - Information published. - [CVE-2026-4437 gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS response](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-4437-gethostbyaddr-and-gethostbyaddr_r-may-incorrectly-handle-dns-response/) - Information published. - [Chromium: CVE-2026-4464 Integer overflow in ANGLE](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-4464-integer-overflow-in-angle/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-4463 Heap buffer overflow in WebRTC](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-4463-heap-buffer-overflow-in-webrtc/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-4462 Out of bounds read in Blink](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-4462-out-of-bounds-read-in-blink/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-4461 Inappropriate implementation in V8](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-4461-inappropriate-implementation-in-v8/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-4460 Out of bounds read in Skia](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-4460-out-of-bounds-read-in-skia/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-4458 Use after free in Extensions](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-4458-use-after-free-in-extensions/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-4457 Type Confusion in V8](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-4457-type-confusion-in-v8/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-4456 Use after free in Digital Credentials API](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-4456-use-after-free-in-digital-credentials-api/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-4455 Heap buffer overflow in PDFium](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-4455-heap-buffer-overflow-in-pdfium/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Chromium: CVE-2026-4454 Use after free in Network](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-4454-use-after-free-in-network/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. - [Cutting cloud costs: Smart strategies to avoid overspending](https://www.netservicesgroup.com/blog/cutting-cloud-costs-smart-strategies-to-avoid-overspending/) - Are your cloud costs higher than expected? Many businesses overspend on cloud solutions due to poor planning, underutilized resources, and hidden fees. This article breaks down the biggest cost drivers in cloud computing and provides actionable insights to help you reduce waste, improve efficiency, and take control of your cloud budget. - [Improve your PC experience with simple disk cleanups](https://www.netservicesgroup.com/blog/improve-your-pc-experience-with-simple-disk-cleanups/) - Your computer collects junk files over time, which can slow down its performance. To keep your PC running at its best, it's important to perform regular maintenance. In this article, we’ll explore how clearing out cluttered data with a disk cleanup can help optimize your system’s speed and overall functionality. What is disk cleanup? Disk - [A business guide to moving legacy applications to the cloud](https://www.netservicesgroup.com/blog/a-business-guide-to-moving-legacy-applications-to-the-cloud/) - Older business applications often struggle to keep up with modern security, performance, and scalability requirements. Migrating these legacy systems to the cloud can unlock greater flexibility and efficiency, but the process requires thoughtful planning. So, how can organizations approach this transition effectively? Evaluate your existing applications Begin by creating a detailed inventory of your applications, - [CVE-2026-27135 nghttp2 Denial of service: Assertion failure due to the missing state validation](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-27135-nghttp2-denial-of-service-assertion-failure-due-to-the-missing-state-validation/) - Information published. - [CVE-2026-3479 pkgutil.get_data() does not enforce documented restrictions](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-3479-pkgutil-get_data-does-not-enforce-documented-restrictions/) - Information published. - [CVE-2026-30922 pyasn1 Vulnerable to Denial of Service via Unbounded Recursion](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-30922-pyasn1-vulnerable-to-denial-of-service-via-unbounded-recursion/) - Information published. - [CVE-2026-3633 Libsoup: libsoup: header and http request injection via crlf injection](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-3633-libsoup-libsoup-header-and-http-request-injection-via-crlf-injection/) - Information published. - [CVE-2026-3632 Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-3632-libsoup-libsoup-http-smuggling-and-server-side-request-forgery-via-malformed-hostnames/) - Information published. - [CVE-2026-3634 Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-3634-libsoup-libsoup-http-header-injection-and-response-splitting-via-crlf-injection-in-content-type-header/) - Information published. - [CVE-2026-32766 astral-tokio-tar insufficiently validates PAX extensions during extraction](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-32766-astral-tokio-tar-insufficiently-validates-pax-extensions-during-extraction/) - Information published. - [CVE-2026-23276 net: add xmit recursion limit to tunnel xmit functions](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23276-net-add-xmit-recursion-limit-to-tunnel-xmit-functions/) - Information published. - [CVE-2026-23271 perf: Fix __perf_event_overflow() vs perf_remove_from_context() race](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23271-perf-fix-__perf_event_overflow-vs-perf_remove_from_context-race/) - Information published. - [CVE-2026-23272 netfilter: nf_tables: unconditionally bump set->nelems before insertion](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23272-netfilter-nf_tables-unconditionally-bump-set-nelems-before-insertion/) - Information published. - [CVE-2026-23278 netfilter: nf_tables: always walk all pending catchall elements](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23278-netfilter-nf_tables-always-walk-all-pending-catchall-elements/) - Information published. - [CVE-2026-23277 net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23277-net-sched-teql-fix-null-pointer-dereference-in-iptunnel_xmit-on-teql-slave-xmit/) - Information published. - [CVE-2026-23274 netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23274-netfilter-xt_idletimer-reject-rev0-reuse-of-alarm-timer-labels/) - Information published. - [CVE-2026-23204 net/sched: cls_u32: use skb_header_pointer_careful()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23204-net-sched-cls_u32-use-skb_header_pointer_careful/) - Information published. - [CVE-2026-26118 Azure MCP Server Tools Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-26118-azure-mcp-server-tools-elevation-of-privilege-vulnerability/) - Added products to the Security Updates table that document the various packaging methods used to deliver Azure MCP Server Tools. - [How to choose the right hardware for your needs](https://www.netservicesgroup.com/blog/how-to-choose-the-right-hardware-for-your-needs/) - The right computer hardware can enhance productivity, improve workflow, and support future growth, while the wrong choices can lead to unnecessary expenses and technical headaches. To make an informed decision, businesses should evaluate several key factors before investing in new hardware. - [CVE-2026-3644 Incomplete control character validation in http.cookies](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-3644-incomplete-control-character-validation-in-http-cookies/) - Information published. - [CVE-2026-4224 Stack overflow parsing XML with deeply nested DTD content models](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-4224-stack-overflow-parsing-xml-with-deeply-nested-dtd-content-models/) - Information published. - [CVE-2026-27459 pyOpenSSL DTLS cookie callback buffer overflow](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-27459-pyopenssl-dtls-cookie-callback-buffer-overflow/) - Information published. - [CVE-2026-27448 pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-27448-pyopenssl-allows-tls-connection-bypass-via-unhandled-callback-exception-in-set_tlsext_servername_callback/) - Information published. - [CVE-2025-71265 fs: ntfs3: fix infinite loop in attr_load_runs_range on inconsistent metadata](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71265-fs-ntfs3-fix-infinite-loop-in-attr_load_runs_range-on-inconsistent-metadata/) - Information published. - [CVE-2026-23243 RDMA/umad: Reject negative data_len in ib_umad_write](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23243-rdma-umad-reject-negative-data_len-in-ib_umad_write/) - Information published. - [CVE-2026-23247 tcp: secure_seq: add back ports to TS offset](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23247-tcp-secure_seq-add-back-ports-to-ts-offset/) - Information published. - [CVE-2026-23244 nvme: fix memory allocation in nvme_pr_read_keys()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23244-nvme-fix-memory-allocation-in-nvme_pr_read_keys/) - Information published. - [CVE-2026-23246 wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23246-wifi-mac80211-bounds-check-link_id-in-ieee80211_ml_reconfiguration/) - Information published. - [CVE-2025-71267 fs: ntfs3: fix infinite loop triggered by zero-sized ATTR_LIST](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71267-fs-ntfs3-fix-infinite-loop-triggered-by-zero-sized-attr_list/) - Information published. - [CVE-2025-71266 fs: ntfs3: check return value of indx_find to avoid infinite loop](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71266-fs-ntfs3-check-return-value-of-indx_find-to-avoid-infinite-loop/) - Information published. - [CVE-2026-23248 perf/core: Fix refcount bug and potential UAF in perf_mmap](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23248-perf-core-fix-refcount-bug-and-potential-uaf-in-perf_mmap/) - Information published. - [CVE-2026-23245 net/sched: act_gate: snapshot parameters with RCU on replace](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23245-net-sched-act_gate-snapshot-parameters-with-rcu-on-replace/) - Information published. - [CVE-2026-23242 RDMA/siw: Fix potential NULL pointer dereference in header processing](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23242-rdma-siw-fix-potential-null-pointer-dereference-in-header-processing/) - Information published. - [CVE-2026-23233 f2fs: fix to avoid mapping wrong physical block for swapfile](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23233-f2fs-fix-to-avoid-mapping-wrong-physical-block-for-swapfile/) - Information published. - [CVE-2026-23236 fbdev: smscufx: properly copy ioctl memory to kernelspace](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23236-fbdev-smscufx-properly-copy-ioctl-memory-to-kernelspace/) - Information published. - [CVE-2025-71239 audit: add fchmodat2() to change attributes class](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71239-audit-add-fchmodat2-to-change-attributes-class/) - Information published. - [CVE-2026-23241 audit: add missing syscalls to read class](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23241-audit-add-missing-syscalls-to-read-class/) - Information published. - [How healthcare organizations can reduce insider threats: 5 Practical strategies](https://www.netservicesgroup.com/blog/how-healthcare-organizations-can-reduce-insider-threats-5-practical-strategies/) - Insider threats are one of the biggest risks facing healthcare organizations today. Learn five practical strategies that hospitals and clinics can use to safeguard patient data and strengthen internal security. Practical steps healthcare organizations can take When people think about cybersecurity threats in healthcare, they often imagine hackers breaking into systems from the outside. In - [CVE-2026-32249 NFA regex engine NULL pointer dereference affects Vim < 9.2.0137](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-32249-nfa-regex-engine-null-pointer-dereference-affects-vim-9-2-0137/) - Information published. - [CVE-2026-23069 vsock/virtio: fix potential underflow in virtio_transport_get_credit()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23069-vsock-virtio-fix-potential-underflow-in-virtio_transport_get_credit/) - Information published. - [CVE-2026-23066 rxrpc: Fix recvmsg() unconditional requeue](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23066-rxrpc-fix-recvmsg-unconditional-requeue/) - Information published. - [CVE-2025-69648](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-69648/) - Information published. - [CVE-2025-69647](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-69647/) - Information published. - [CVE-2026-1703 Limited path traversal when installing wheel archives](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-1703-limited-path-traversal-when-installing-wheel-archives/) - Information published. - [CVE-2026-4105 Systemd: systemd: privilege escalation via improper access control in registermachine d-bus method](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-4105-systemd-systemd-privilege-escalation-via-improper-access-control-in-registermachine-d-bus-method/) - Information published. - [CVE-2026-2673 OpenSSL TLS 1.3 server may choose unexpected key agreement group](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-2673-openssl-tls-1-3-server-may-choose-unexpected-key-agreement-group/) - Information published. - [CVE-2026-4111 Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-4111-libarchive-infinite-loop-denial-of-service-in-rar5-decompression-via-archive_read_data-in-libarchive/) - Information published. - [CVE-2026-23943 Pre-auth SSH DoS via unbounded zlib inflate](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23943-pre-auth-ssh-dos-via-unbounded-zlib-inflate/) - Information published. - [CVE-2026-23942 SFTP root escape via component-agnostic prefix check in ssh_sftpd](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23942-sftp-root-escape-via-component-agnostic-prefix-check-in-ssh_sftpd/) - Information published. - [CVE-2026-23941 Request smuggling via first-wins Content-Length parsing in inets httpd](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23941-request-smuggling-via-first-wins-content-length-parsing-in-inets-httpd/) - Information published. - [CVE-2026-32775](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-32775/) - Information published. - [CVE-2026-32777](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-32777/) - Information published. - [CVE-2026-32778](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-32778/) - Information published. - [CVE-2026-32776](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-32776/) - Information published. - [Chromium: CVE-2026-3909 Out of bounds write in Skia](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-3909-out-of-bounds-write-in-skia/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2021) for more information. Google is aware that an exploit for CVE-2026-3909 exists in the wild. - [Understanding the three types of hackers and what drives them](https://www.netservicesgroup.com/blog/understanding-the-three-types-of-hackers-and-what-drives-them/) - Hackers are often portrayed as cybercriminals lurking in the shadows, but the reality is more complex. From malicious attackers to ethical security experts, hackers come in different forms. This article explains the three main types of hackers and how their motivations and activities differ. Understanding the history of hackers The word "hacker" often conjures a - [What HIPAA compliance means for your business — and why you can't ignore it](https://www.netservicesgroup.com/blog/what-hipaa-compliance-means-for-your-business-and-why-you-cant-ignore-it/) - Compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) isn't just a legal box to check — it’s a critical responsibility for any business in or tied to the healthcare sector. This article breaks down what HIPAA is, who needs to comply, and why it matters for your organization. Read on to learn how staying compliant protects your patients, reputation, and bottom line. - [Why firmware updates keep your business secure](https://www.netservicesgroup.com/blog/why-firmware-updates-keep-your-business-secure/) - Every business relies on office equipment to run smoothly. Yet, many companies overlook the invisible software powering those machines. Firmware operates quietly in the background to keep everything functioning, and ignoring its maintenance leaves your network vulnerable to cyberattacks. Updating these systems protects your sensitive data and keeps operations running without a hitch. What firmware - [Chromium: CVE-2026-3939 Use after free in WebView](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-3939-use-after-free-in-webview/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2021) for more information. - [Chromium: CVE-2026-3938 Insufficient policy enforcement in Clipboard](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-3938-insufficient-policy-enforcement-in-clipboard/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2021) for more information. - [Chromium: CVE-2026-3937 Incorrect security UI in Downloads](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-3937-incorrect-security-ui-in-downloads/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2021) for more information. - [Chromium: CVE-2026-3936 Use after free in WebView](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-3936-use-after-free-in-webview/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2021) for more information. - [Chromium: CVE-2026-3935 Incorrect security UI in WebAppInstalls](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-3935-incorrect-security-ui-in-webappinstalls/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2021) for more information. - [CVE-2026-27171 zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-27171-zlib-before-1-3-2-allows-cpu-consumption-via-crc32_combine64-and-crc32_combine_gen64-because-x2nmodp-can-do-right-shifts-within-a-loop-that-has-no-termination-condition/) - Information published. - [CVE-2026-3381 Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-3381-compressrawzlib-versions-through-2-219-for-perl-use-potentially-insecure-versions-of-zlib/) - Information published. - [CVE-2026-31802 node-tar Symlink Path Traversal via Drive-Relative Linkpath](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31802-node-tar-symlink-path-traversal-via-drive-relative-linkpath/) - Information published. - [Chromium: CVE-2026-3910 Inappropriate implementation in V8](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-3910-inappropriate-implementation-in-v8/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2021) for more information. Google is aware that an exploit for CVE-2026-3910 exists in the wild. - [Chromium: CVE-2026-3942 Incorrect security UI in PictureInPicture](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-3942-incorrect-security-ui-in-pictureinpicture/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2021) for more information. - [Chromium: CVE-2026-3941 Insufficient policy enforcement in DevTools](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-3941-insufficient-policy-enforcement-in-devtools/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2021) for more information. - [Chromium: CVE-2026-3940 Insufficient policy enforcement in DevTools](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-3940-insufficient-policy-enforcement-in-devtools/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2021) for more information. - [A simple guide to safer web browsing](https://www.netservicesgroup.com/blog/a-simple-guide-to-safer-web-browsing/) - You’ve probably noticed the tiny padlock symbol in your browser’s address bar, but do you know what it means? This article breaks down how HTTPS (Hypertext Transfer Protocol Secure) works behind the scenes to protect your personal information from prying eyes. From encrypted data to verified website identities, learn why HTTPS should be a nonnegotiable feature when browsing or shopping online. - [CVE-2026-3805 use after free in SMB connection reuse](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-3805-use-after-free-in-smb-connection-reuse/) - Information published. - [CVE-2026-3904](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-3904/) - Information published. - [CVE-2026-26133 M365 Copilot Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-26133-m365-copilot-information-disclosure-vulnerability/) - Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. - [CVE-2026-26030 GitHub: CVE-2026-26030 Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-26030-github-cve-2026-26030-microsoft-semantic-kernel-inmemoryvectorstore-filter-functionality-vulnerable/) - Acknowledgement added. This is an informational change only. - [Windows 10 is nearing its end of life — here’s what you need to know](https://www.netservicesgroup.com/blog/windows-10-is-nearing-its-end-of-life-heres-what-you-need-to-know/) - Microsoft will officially cease support for Windows 10 in October 2025, marking the end of an era for one of the most widely used operating systems. But there's no need to worry just yet, you still have plenty of time to prepare. To help you navigate this transition, we've put together a straightforward guide to explore your next steps. - [How SMBs can harness the power of UCaaS and CCaaS convergence](https://www.netservicesgroup.com/blog/how-smbs-can-harness-the-power-of-ucaas-and-ccaas-convergence/) - As small and mid-sized businesses (SMBs) seek to improve team collaboration and customer service, many are turning to a powerful combination: UCaaS and CCaaS. Together, these cloud-based solutions create a smoother, more efficient experience by bridging internal communication with customer support. This article explores why this convergence matters, outlines its key benefits, and offers guidance on how SMBs can embrace this growing trend. - [CVE-2026-3784 wrong proxy connection reuse with credentials](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-3784-wrong-proxy-connection-reuse-with-credentials/) - Information published. - [CVE-2026-1965 bad reuse of HTTP Negotiate connection](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-1965-bad-reuse-of-http-negotiate-connection/) - Information published. - [CVE-2026-3783 token leak with redirect and netrc](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-3783-token-leak-with-redirect-and-netrc/) - Information published. - [CVE-2026-23240 tls: Fix race condition in tls_sw_cancel_work_tx()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23240-tls-fix-race-condition-in-tls_sw_cancel_work_tx/) - Information published. - [CVE-2026-23239 espintcp: Fix race condition in espintcp_close()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23239-espintcp-fix-race-condition-in-espintcp_close/) - Information published. - [CVE-2026-23868](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23868/) - Information published. - [CVE-2026-25679 Incorrect parsing of IPv6 host literals in net/url](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-25679-incorrect-parsing-of-ipv6-host-literals-in-net-url/) - Information published. - [Chromium: CVE-2026-3537 Object lifecycle issue in PowerVR](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-3537-object-lifecycle-issue-in-powervr/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2021) for more information. - [CVE-2026-26148 Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-26148-microsoft-azure-ad-ssh-login-extension-for-linux-elevation-of-privilege-vulnerability/) - Acknowledgement Updated - [CVE-2026-24293 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-24293-windows-ancillary-function-driver-for-winsock-elevation-of-privilege-vulnerability/) - Acknowledgement added. This is an informational change only. - [How Microsoft Copilot AI agents are changing the way we work](https://www.netservicesgroup.com/blog/how-microsoft-copilot-ai-agents-are-changing-the-way-we-work/) - Artificial intelligence (AI) is fast becoming a key business tool, and Microsoft 365 Copilot is leading the way. The AI-powered tool now features new AI agents that help organizations boost productivity, simplify tasks, and expand its functionality. Here’s how these agents work and how to start using them to maximize your Microsoft 365 investment. - [CVE-2025-69646 Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-69646-binutils-objdump-contains-a-denial-of-service-vulnerability-when-processing-a-crafted-binary-with-malformed-dwarf-debug_rnglists-data-a-logic-error-in-the-handling-of-the-debug_rnglist/) - Information published. - [CVE-2026-29786 node-tar: Hardlink Path Traversal via Drive-Relative Linkpath](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-29786-node-tar-hardlink-path-traversal-via-drive-relative-linkpath/) - Information published. - [CVE-2026-3731 libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-3731-libssh-sftp-extension-name-sftp-c-sftp_extensions_get_data-out-of-bounds/) - Information published. - [CVE-2024-14027 xattr: switch to CLASS(fd)](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-14027-xattr-switch-to-classfd/) - Information published. - [CVE-2026-27139 FileInfo can escape from a Root in os](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-27139-fileinfo-can-escape-from-a-root-in-os/) - Information published. - [CVE-2026-26018 CoreDNS Loop Detection Denial of Service Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-26018-coredns-loop-detection-denial-of-service-vulnerability/) - Information published. - [CVE-2026-26017 CoreDNS ACL Bypass](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-26017-coredns-acl-bypass/) - Information published. - [CVE-2026-26127 .NET Denial of Service Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-26127-net-denial-of-service-vulnerability/) - Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network. - [CVE-2026-3713 pnggroup libpng pnm2png pnm2png.c do_pnm2png heap-based overflow](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-3713-pnggroup-libpng-pnm2png-pnm2png-c-do_pnm2png-heap-based-overflow/) - Information published. - [CVE-2026-27137 Incorrect enforcement of email constraints in crypto/x509](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-27137-incorrect-enforcement-of-email-constraints-in-crypto-x509/) - Information published. - [CVE-2026-27138 Panic in name constraint checking for malformed certificates in crypto/x509](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-27138-panic-in-name-constraint-checking-for-malformed-certificates-in-crypto-x509/) - Information published. - [CVE-2026-27142 URLs in meta content attribute actions are not escaped in html/template](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-27142-urls-in-meta-content-attribute-actions-are-not-escaped-in-html-template/) - Information published. - [CVE-2025-69644 An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-69644-an-issue-was-discovered-in-binutils-before-2-46-the-objdump-contains-a-denial-of-service-vulnerability-when-processing-a-crafted-binary-with-malformed-debug-information-a-logic-flaw-i/) - Information published. - [CVE-2025-69651 GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-69651-gnu-binutils-thru-2-46-readelf-contains-a-vulnerability-that-leads-to-an-invalid-pointer-free-when-processing-a-crafted-elf-binary-with-malformed-relocation-or-symbol-data-if-dump_relo/) - Information published. - [CVE-2025-69649 GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-69649-gnu-binutils-thru-2-46-readelf-contains-a-null-pointer-dereference-vulnerability-when-processing-a-crafted-elf-binary-with-malformed-header-fields-during-relocation-processing-an-inva/) - Information published. - [CVE-2025-69645 Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-69645-binutils-objdump-contains-a-denial-of-service-vulnerability-when-processing-a-crafted-binary-with-malformed-dwarf-debug-information-a-logic-error-in-the-handling-of-dwarf-compilation-u/) - Information published. - [CVE-2025-69652 GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-69652-gnu-binutils-thru-2-46-readelf-contains-a-vulnerability-that-leads-to-an-abort-sigabrt-when-processing-a-crafted-elf-binary-with-malformed-dwarf-abbrev-or-debug-information-due-to-in/) - Information published. - [CVE-2025-69650 GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-69650-gnu-binutils-thru-2-46-readelf-contains-a-double-free-vulnerability-when-processing-a-crafted-elf-binary-with-malformed-relocation-data-during-got-relocation-handling-dump_relocations/) - Information published. - [Business phones in 2026: Key VoIP features every company should look for](https://www.netservicesgroup.com/blog/business-phones-in-2026-key-voip-features-every-company-should-look-for/) - Choosing the right VoIP phone system for your business is more important than ever in 2026. Modern solutions go far beyond basic calling, offering advanced tools that improve communication, customer experience, and team productivity. Understanding the most important features can help organizations invest in a system that truly supports their operations. HD call quality High-definition - [CVE-2025-14524 bearer token leak on cross-protocol redirect](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-14524-bearer-token-leak-on-cross-protocol-redirect/) - Information published. - [CVE-2026-3494 MariaDB Server Audit Plugin Comment Handling Bypass](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-3494-mariadb-server-audit-plugin-comment-handling-bypass/) - Information published. - [CVE-2025-10966 missing SFTP host verification with wolfSSH](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-10966-missing-sftp-host-verification-with-wolfssh/) - Information published. - [6 Smart ways to strengthen security in Microsoft Teams](https://www.netservicesgroup.com/blog/6-smart-ways-to-strengthen-security-in-microsoft-teams/) - Employees use Microsoft Teams to chat, collaborate on files, host meetings, and coordinate projects, making platform security essential for protecting company data and maintaining smooth operations. The good news is that with the right setup and a few proactive practices, your organization can make its Microsoft Teams platform significantly more secure. Carefully manage third-party apps - [Enhance communications with these Skype substitutes in 2025](https://www.netservicesgroup.com/blog/enhance-communications-with-these-skype-substitutes-in-2025/) - The familiar blue icon of Skype has been a staple for online conversations for years. However, with Microsoft set to retire the platform on May 5, 2025, it's time for businesses to look for other options. The good news? Business communication tools have evolved dramatically, offering a wealth of smarter, more integrated alternatives that can truly elevate how your team connects and collaborates. Let's explore some upgrades that go beyond basic video calls and offer real value for your business. - [CVE-2026-22701 filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-22701-filelock-time-of-check-time-of-use-toctou-symlink-vulnerability-in-softfilelock/) - Information published. - [5 Low-effort ways to make your office hardware last longer](https://www.netservicesgroup.com/blog/5-low-effort-ways-to-make-your-office-hardware-last-longer/) - Keep your IT costs in check with smarter hardware habits. In this guide, we’ll walk you through simple, effective ways to maintain your business computers, printers, and workstations so they last longer and perform better. - [How emerging tech is rewriting the rules of data security](https://www.netservicesgroup.com/blog/how-emerging-tech-is-rewriting-the-rules-of-data-security/) - Data breaches are an unfortunate norm in today's digital world, and traditional encryption techniques are no longer enough to prevent them. In addition, as businesses become more data-driven and regulations tighten, the pressure is on to rethink how we secure sensitive information, not just during storage but also throughout its entire life cycle. - [CVE-2026-26122 Microsoft ACI Confidential Containers Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-26122-microsoft-aci-confidential-containers-information-disclosure-vulnerability/) - Information published. - [CVE-2026-23235 f2fs: fix out-of-bounds access in sysfs attribute read/write](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23235-f2fs-fix-out-of-bounds-access-in-sysfs-attribute-read-write/) - Information published. - [CVE-2026-23234 f2fs: fix to avoid UAF in f2fs_write_end_io()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23234-f2fs-fix-to-avoid-uaf-in-f2fs_write_end_io/) - Information published. - [CVE-2026-26125 Payment Orchestrator Service Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-26125-payment-orchestrator-service-elevation-of-privilege-vulnerability/) - Information published. - [CVE-2026-26124 Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-26124-microsoft-aci-confidential-containers-elevation-of-privilege-vulnerability/) - Information published. - [CVE-2026-21536 Microsoft Devices Pricing Program Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21536-microsoft-devices-pricing-program-remote-code-execution-vulnerability/) - Information published. - [CVE-2026-23651 Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23651-microsoft-aci-confidential-containers-elevation-of-privilege-vulnerability/) - Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. - [Enhance Google Chrome with features for speed and productivity](https://www.netservicesgroup.com/blog/enhance-google-chrome-with-features-for-speed-and-productivity/) - Is Google Chrome draining your computer's memory and slowing you down? Recent updates have introduced powerful built-in tools designed to boost performance, no complicated fixes required. This guide will show you how to turn your sluggish browser into a high-speed productivity powerhouse. Performance Detection Instead of manually hunting down background processes that slow down your - [CVE-2026-23231 netfilter: nf_tables: fix use-after-free in nf_tables_addchain()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23231-netfilter-nf_tables-fix-use-after-free-in-nf_tables_addchain/) - Information published. - [CVE-2025-71238 scsi: qla2xxx: Fix bsg_done() causing double free](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71238-scsi-qla2xxx-fix-bsg_done-causing-double-free/) - Information published. - [CVE-2026-23238 romfs: check sb_set_blocksize() return value](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23238-romfs-check-sb_set_blocksize-return-value/) - Information published. - [CVE-2026-23237 platform/x86: classmate-laptop: Add missing NULL pointer checks](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23237-platform-x86-classmate-laptop-add-missing-null-pointer-checks/) - Information published. - [CVE-2025-21985 drm/amd/display: Fix out-of-bound accesses](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-21985-drm-amd-display-fix-out-of-bound-accesses/) - Information published. - [CVE-2024-46754 bpf: Remove tst_run from lwt_seg6local_prog_ops.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-46754-bpf-remove-tst_run-from-lwt_seg6local_prog_ops/) - Information published. - [CVE-2024-53219 virtiofs: use pages instead of pointer for kernel direct IO](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-53219-virtiofs-use-pages-instead-of-pointer-for-kernel-direct-io/) - Information published. - [CVE-2022-4543 A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2022-4543-a-flaw-named-entrybleed-was-found-in-the-linux-kernel-page-table-isolation-kpti-this-issue-could-allow-a-local-attacker-to-leak-kaslr-base-via-prefetch-side-channels-based/) - Information published. - [CVE-2025-68121 Unexpected session resumption in crypto/tls](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68121-unexpected-session-resumption-in-crypto-tls/) - Information published. - [CVE-2026-0038 In multiple functions of mem_protect.c, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-0038-in-multiple-functions-of-mem_protect-c-there-is-a-possible-way-to-execute-arbitrary-code-due-to-a-logic-error-in-the-code-this-could-lead-to-local-escalation-of-privilege-with-no-addit/) - Information published. - [CVE-2026-3336 PKCS7_verify Certificate Chain Validation Bypass in AWS-LC](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-3336-pkcs7_verify-certificate-chain-validation-bypass-in-aws-lc/) - Information published. - [CVE-2026-3338 PKCS7_verify Signature Validation Bypass in AWS-LC](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-3338-pkcs7_verify-signature-validation-bypass-in-aws-lc/) - Information published. - [CVE-2026-23865 An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23865-an-integer-overflow-in-the-tt_var_load_item_variation_store-function-of-the-freetype-library-in-versions-2-13-2-and-2-13-3-may-allow-for-an-out-of-bounds-read-operation-when-parsing-hva/) - Information published. - [CVE-2026-24821 A heap-based buffer over-read that might affect a system that compiles untrusted Lua code in turanszkij/WickedEngine.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-24821-a-heap-based-buffer-over-read-that-might-affect-a-system-that-compiles-untrusted-lua-code-in-turanszkij-wickedengine/) - Information published. - [CVE-2026-27141 Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-27141-sending-certain-http-2-frames-can-cause-a-server-to-panic-in-golang-org-x-net/) - Information published. - [How to protect healthcare IoT devices from cyberthreats](https://www.netservicesgroup.com/blog/how-to-protect-healthcare-iot-devices-from-cyberthreats/) - With smart medical devices and other Internet of Things (IoT) technologies becoming staples in healthcare, boosting IoT security is more critical than ever. This article explores practical strategies to defend against cyberattacks, secure patient data, and maintain regulatory compliance in today's connected medical environments. - [Smart hospitals: The future of medical care is here](https://www.netservicesgroup.com/blog/smart-hospitals-the-future-of-medical-care-is-here/) - Smart hospitals are transforming the healthcare industry in significant ways. They demonstrate how digital technologies can dramatically improve patient care while boosting operational efficiency. But how exactly are smart hospitals changing the game? In this article, we explore the key technologies driving smart hospitals, assess their impact on healthcare systems, and examine the infrastructure and ethical challenges they present. - [Top mistakes businesses should avoid when choosing a cloud provider](https://www.netservicesgroup.com/blog/top-mistakes-businesses-should-avoid-when-choosing-a-cloud-provider/) - Cloud computing has become a cornerstone of modern business technology. Yet, many companies jump into the cloud without fully understanding the differences between providers or the complexities involved. This article uncovers the common missteps businesses make when selecting cloud providers and reveals key factors to consider before signing on the dotted line. - [CVE-2025-58160 Tracing logging user input may result in poisoning logs with ANSI escape sequences](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-58160-tracing-logging-user-input-may-result-in-poisoning-logs-with-ansi-escape-sequences/) - Information published. - [CVE-2026-25541 Bytes is vulnerable to integer overflow in BytesMut::reserve](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-25541-bytes-is-vulnerable-to-integer-overflow-in-bytesmutreserve/) - Information published. - [Keeping your VoIP and communication systems safe: What every business needs to know](https://www.netservicesgroup.com/blog/keeping-your-voip-and-communication-systems-safe-what-every-business-needs-to-know/) - Voice over Internet Protocol (VoIP) and online communication platforms have changed how businesses connect. These digital tools are incredibly powerful, but they are also often overlooked entry points for cyberthreats. This article will explain why safeguarding these vital communication channels is no longer optional and offer practical ways to protect your business. - [A guide to effectively leveraging threat intelligence](https://www.netservicesgroup.com/blog/a-guide-to-effectively-leveraging-threat-intelligence/) - Organizations that invest in threat intelligence platforms (TIPs) often struggle to use them effectively. TIPs are designed to collect, analyze, and share threat data, but they can become overwhelming or underutilized without the right approach. Our guide helps you choose a platform that aligns perfectly with your team’s skills and existing infrastructure, empowering you to respond to potential threats more efficiently and effectively. - [Disaster recovery misconceptions that could put your business at risk](https://www.netservicesgroup.com/blog/disaster-recovery-misconceptions-that-could-put-your-business-at-risk/) - Many businesses believe they’re protected simply because they have backups or use cloud services. This article explores common disaster recovery myths and explains why a comprehensive, tested recovery strategy is essential for long-term business continuity. When business leaders think about disaster recovery (DR), the conversation often centers on backups. If the data is backed up, - [Keep your business running with a simple guide to Android malware removal](https://www.netservicesgroup.com/blog/keep-your-business-running-with-a-simple-guide-to-android-malware-removal/) - Your Android smartphone is your business lifeline. Its popularity, however, makes it a prime target for malware that steals data and disrupts operations. Don't worry. Fixing an infected device is often a simple DIY job. We’ll walk you through identifying the problem, removing the malware, and securing your business. How to tell if your phone - [CVE-2025-71162 dmaengine: tegra-adma: Fix use-after-free](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71162-dmaengine-tegra-adma-fix-use-after-free/) - Information published. - [CVE-2025-71089 iommu: disable SVA when CONFIG_X86 is set](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71089-iommu-disable-sva-when-config_x86-is-set/) - Information published. - [CVE-2026-27199 Werkzeug safe_join() allows Windows special device names](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-27199-werkzeug-safe_join-allows-windows-special-device-names/) - Information published. - [How Microsoft Whiteboard brings visual collaboration to remote teams](https://www.netservicesgroup.com/blog/how-microsoft-whiteboard-brings-visual-collaboration-to-remote-teams/) - Modern work rarely happens in one place anymore. While emails and chat apps handle conversations well, they often fall short when teams need to brainstorm, plan, or visualize ideas together. That’s where Microsoft Whiteboard steps in. Let’s explore how businesses can use the app’s tools, templates, and sharing features to improve teamwork and turn ideas into action. - [Speed up Windows 11 with these tweaks](https://www.netservicesgroup.com/blog/speed-up-windows-11-with-these-tweaks/) - Windows 11 delivers a sleek, modern experience with new visual effects, updated interfaces, and enhanced multitasking tools. But all that polish can come at a cost, especially if your PC is older or not designed for heavy lifting. Over time, background processes, visual enhancements, and preinstalled software can chip away at your system’s speed. If your device feels bogged down, a few small tweaks can breathe life back into it. - [Deciding between open-source and proprietary VoIP for your business](https://www.netservicesgroup.com/blog/deciding-between-open-source-and-proprietary-voip-for-your-business/) - When selecting a Voice over Internet Protocol (VoIP) phone system, businesses often face a key decision: should they go with open-source or proprietary systems? This article breaks down the real-world pros and cons of each option so you can confidently choose the right fit for your organization. Understanding proprietary VoIP systems A proprietary VoIP system - [CVE-2026-28422 Vim has stack-buffer-overflow in build_stl_str_hl()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-28422-vim-has-stack-buffer-overflow-in-build_stl_str_hl/) - Information published. - [CVE-2026-28419 Vim has Heap-based Buffer Underflow in Emacs tags parsing](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-28419-vim-has-heap-based-buffer-underflow-in-emacs-tags-parsing/) - Information published. - [CVE-2026-28418 Vim has Heap-based Buffer Overflow in Emacs tags parsing](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-28418-vim-has-heap-based-buffer-overflow-in-emacs-tags-parsing/) - Information published. - [CVE-2026-28420 Vim has Heap-based Buffer Overflow and OOB Read in :terminal](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-28420-vim-has-heap-based-buffer-overflow-and-oob-read-in-terminal/) - Information published. - [CVE-2026-28421 Vim has a heap-buffer-overflow and a segmentation fault](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-28421-vim-has-a-heap-buffer-overflow-and-a-segmentation-fault/) - Information published. - [CVE-2026-28417 Vim has OS Command Injection in netrw](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-28417-vim-has-os-command-injection-in-netrw/) - Information published. - [How to seamlessly transfer your login info to Apple Passwords](https://www.netservicesgroup.com/blog/how-to-seamlessly-transfer-your-login-info-to-apple-passwords/) - Apple Passwords is here, offering a seamless and secure way to manage your login credentials across your Apple devices. If you've been using another password manager, here’s a step-by-step guide on how to import your saved passwords into Apple’s Passwords app and take full advantage of its features. - [How to improve VoIP call quality with QoS](https://www.netservicesgroup.com/blog/how-to-improve-voip-call-quality-with-qos/) - Have your Voice over Internet Protocol (VoIP) calls been dropping or sounding garbled? While VoIP phone systems offer plenty of benefits, their performance depends heavily on network quality. Setting up VoIP Quality of Service (QoS) can help ensure clear and reliable communication. - [CVE-2025-71232 scsi: qla2xxx: Free sp in error path to fix system crash](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71232-scsi-qla2xxx-free-sp-in-error-path-to-fix-system-crash/) - Information published. - [CVE-2025-71237 nilfs2: Fix potential block overflow that cause system hang](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71237-nilfs2-fix-potential-block-overflow-that-cause-system-hang/) - Information published. - [CVE-2026-23220 ksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error paths](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23220-ksmbd-fix-infinite-loop-caused-by-next_smb2_rcv_hdr_off-reset-in-error-paths/) - Information published. - [CVE-2025-71229 wifi: rtw88: Fix alignment fault in rtw_core_enable_beacon()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71229-wifi-rtw88-fix-alignment-fault-in-rtw_core_enable_beacon/) - Information published. - [CVE-2025-71235 scsi: qla2xxx: Delay module unload while fabric scan in progress](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71235-scsi-qla2xxx-delay-module-unload-while-fabric-scan-in-progress/) - Information published. - [CVE-2026-23228 smb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23228-smb-server-fix-leak-of-active_num_conn-in-ksmbd_tcp_new_connection/) - Information published. - [CVE-2026-23222 crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23222-crypto-omap-allocate-omap_crypto_force_copy-scatterlists-correctly/) - Information published. - [CVE-2026-23212 bonding: annotate data-races around slave->last_rx](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23212-bonding-annotate-data-races-around-slave-last_rx/) - Information published. - [CVE-2026-23216 scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23216-scsi-target-iscsi-fix-use-after-free-in-iscsit_dec_conn_usage_count/) - Information published. - [CVE-2025-68725 bpf: Do not let BPF test infra emit invalid GSO types to stack](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68725-bpf-do-not-let-bpf-test-infra-emit-invalid-gso-types-to-stack/) - Information published. - [CVE-2025-68223 drm/radeon: delete radeon_fence_process in is_signaled, no deadlock](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68223-drm-radeon-delete-radeon_fence_process-in-is_signaled-no-deadlock/) - Information published. - [CVE-2025-40164 usbnet: Fix using smp_processor_id() in preemptible code warnings](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-40164-usbnet-fix-using-smp_processor_id-in-preemptible-code-warnings/) - Information published. - [CVE-2025-40005 spi: cadence-quadspi: Implement refcount to handle unbind during busy](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-40005-spi-cadence-quadspi-implement-refcount-to-handle-unbind-during-busy/) - Information published. - [CVE-2025-38162 netfilter: nft_set_pipapo: prevent overflow in lookup table allocation](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-38162-netfilter-nft_set_pipapo-prevent-overflow-in-lookup-table-allocation/) - Information published. - [CVE-2026-28364 In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-28364-in-ocaml-before-4-14-3-and-5-x-before-5-4-1-a-buffer-over-read-in-marshal-deserialization-runtime-intern-c-enables-remote-code-execution-through-a-multi-phase-attack-chain-the-vulne/) - Information published. - [CVE-2025-40082 hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-40082-hfsplus-fix-slab-out-of-bounds-read-in-hfsplus_uni2asc/) - Information published. - [CVE-2026-22999 net/sched: sch_qfq: do not free existing class in qfq_change_class()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-22999-net-sched-sch_qfq-do-not-free-existing-class-in-qfq_change_class/) - Information published. - [Is your Mac acting weird? A practical checklist for spotting malware](https://www.netservicesgroup.com/blog/is-your-mac-acting-weird-a-practical-checklist-for-spotting-malware/) - macOS comes with strong built-in protections, and that’s a big reason people trust Macs. Still, secure by default doesn’t mean invincible. Malware exists for Macs, and it often slips in through fake updates, sketchy downloads, or sneaky browser add-ons. Here’s how to spot the warning signs before the problem grows. Frequent system crashes and slowdowns - [Simple fixes for common network problems](https://www.netservicesgroup.com/blog/simple-fixes-for-common-network-problems/) - You don’t need to be an IT expert to fix frustrating network errors. This post breaks down five common culprits — like DNS issues and IP conflicts — and explains how to resolve them using simple, practical solutions. Learn what to check, what to restart, and when to call for help. - [Zoom Phone or traditional VoIP? A straightforward guide for small-business owners](https://www.netservicesgroup.com/blog/zoom-phone-or-traditional-voip-a-straightforward-guide-for-small-business-owners/) - Not sure whether to upgrade your phone system to Zoom Phone or stick with traditional Voice over Internet Protocol (VoIP)? This simple guide explains the key differences without the jargon so you can decide what works best for your business. - [CVE-2025-69873 ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., "^(a|a)*$") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with $data: true for dynamic schema validation.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-69873-ajv-another-json-schema-validator-before-8-18-0-is-vulnerable-to-regular-expression-denial-of-service-redos-when-the-data-option-is-enabled-the-pattern-keyword-accepts-runtime-dat/) - Information published. - [CVE-2026-27969 Vitess users with backup storage access can write to arbitrary file paths on restore](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-27969-vitess-users-with-backup-storage-access-can-write-to-arbitrary-file-paths-on-restore/) - Information published. - [CVE-2026-27965 Vitess users with backup storage access can gain unauthorized access to production deployment environments](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-27965-vitess-users-with-backup-storage-access-can-gain-unauthorized-access-to-production-deployment-environments/) - Information published. - [Chromium: CVE-2026-3063 Inappropriate implementation in DevTools](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-3063-inappropriate-implementation-in-devtools/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information. - [Chromium: CVE-2026-3062 Out of bounds read and write in Tint](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-3062-out-of-bounds-read-and-write-in-tint/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information. - [Chromium: CVE-2026-3061 Out of bounds read in Media](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-3061-out-of-bounds-read-in-media/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information. - [CVE-2026-27571 nats-server websockets are vulnerable to pre-auth memory DoS](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-27571-nats-server-websockets-are-vulnerable-to-pre-auth-memory-dos/) - Information published. - [Essential Android apps to make your international trip a breeze](https://www.netservicesgroup.com/blog/essential-android-apps-to-make-your-international-trip-a-breeze/) - Preparing for a trip abroad? Make sure your Android phone is equipped with these five essential apps to help with navigation, document storage, communication, organization, and currency management. - [The hidden weaknesses of multifactor authentication](https://www.netservicesgroup.com/blog/the-hidden-weaknesses-of-multifactor-authentication/) - Multifactor authentication (MFA) works by requiring users to provide more than one form of identification when logging into a system or account. This extra layer of security is meant to prevent unauthorized access and protect sensitive information. However, while MFA may seem like a foolproof solution, it actually has its own set of vulnerabilities that - [CVE-2026-23225 sched/mmcid: Don't assume CID is CPU owned on mode switch](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23225-sched-mmcid-dont-assume-cid-is-cpu-owned-on-mode-switch/) - Information published. - [CVE-2026-23224 erofs: fix UAF issue for file-backed mounts w/ directio option](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23224-erofs-fix-uaf-issue-for-file-backed-mounts-w-directio-option/) - Information published. - [CVE-2026-23223 xfs: fix UAF in xchk_btree_check_block_owner](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23223-xfs-fix-uaf-in-xchk_btree_check_block_owner/) - Information published. - [CVE-2025-71230 hfs: ensure sb->s_fs_info is always cleaned up](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71230-hfs-ensure-sb-s_fs_info-is-always-cleaned-up/) - Information published. - [CVE-2026-23229 crypto: virtio - Add spinlock protection with virtqueue notification](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-23229-crypto-virtio-add-spinlock-protection-with-virtqueue-notification/) - Information published. - [CVE-2025-11563 wcurl path traversal with percent-encoded slashes](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-11563-wcurl-path-traversal-with-percent-encoded-slashes/) - Information published. - [CVE-2025-62878 Local Path Provisioner vulnerable to Path Traversal via parameters.pathPattern](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-62878-local-path-provisioner-vulnerable-to-path-traversal-via-parameters-pathpattern/) - Information published. - [CVE-2026-21863 Malformed Valkey Cluster bus message can lead to Remote DoS](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21863-malformed-valkey-cluster-bus-message-can-lead-to-remote-dos/) - Information published. - [CVE-2025-67733 Valkey Affected by RESP Protocol Injection via Lua error_reply](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-67733-valkey-affected-by-resp-protocol-injection-via-lua-error_reply/) - Information published. - [CVE-2025-61145 libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-61145-libtiff-up-to-v4-7-1-was-discovered-to-contain-a-double-free-via-the-component-tools-tiffcrop-c/) - Information published. - [CVE-2025-61144 libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-61144-libtiff-up-to-v4-7-1-was-discovered-to-contain-a-stack-overflow-via-the-readseparatestripsintobuffer-function/) - Information published. - [CVE-2025-61143 libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-61143-libtiff-up-to-v4-7-1-was-discovered-to-contain-a-null-pointer-dereference-via-the-component-libtiff-tif_open-c/) - Information published. - [CVE-2021-20233 A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2021-20233-a-flaw-was-found-in-grub2-in-versions-prior-to-2-06-setparam_prefix-in-the-menu-rendering-code-performs-a-length-calculation-on-the-assumption-that-expressing-a-quoted-single-quote-w/) - Information published. - [CVE-2021-20225 A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling certain commands with a large number of specific short forms of options. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2021-20225-a-flaw-was-found-in-grub2-in-versions-prior-to-2-06-the-option-parser-allows-an-attacker-to-write-past-the-end-of-a-heap-allocated-buffer-by-calling-certain-commands-with-a-large-numbe/) - Information published. - [CVE-2026-26960 node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-26960-node-tar-has-arbitrary-file-read-write-via-hardlink-target-escape-through-symlink-chain-in-extraction/) - Information published. - [CVE-2026-2739 This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-2739-this-affects-versions-of-the-package-bn-js-before-5-2-3-calling-maskn0-on-any-bn-instance-corrupts-the-internal-state-causing-tostring-divmod-and-other-methods-to-enter-an-infi/) - Information published. - [CVE-2026-21620 TFTP Path Traversal](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21620-tftp-path-traversal/) - Information published. - [CVE-2026-27211 Cloud Hypervisor: Host File Exfiltration via QCOW Backing File Abuse](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-27211-cloud-hypervisor-host-file-exfiltration-via-qcow-backing-file-abuse/) - Information published. - [CVE-2025-38656 wifi: iwlwifi: Fix error code in iwl_op_mode_dvm_start()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-38656-wifi-iwlwifi-fix-error-code-in-iwl_op_mode_dvm_start/) - Information published. - [One login, total access: Why businesses are switching to single sign-on](https://www.netservicesgroup.com/blog/one-login-total-access-why-businesses-are-switching-to-single-sign-on/) - Tired of managing endless passwords across your business apps? Single sign-on (SSO) offers a secure, streamlined solution that improves productivity while strengthening protection. Here’s why more organizations are making the switch. The case for using SSO Most employees are drowning in passwords. Email, project management tools, HR portals, cloud storage, accounting platforms — the list - [Unlock efficiency with Microsoft Power Automate](https://www.netservicesgroup.com/blog/unlock-efficiency-with-microsoft-power-automate/) - Running a small business often means wearing many hats. You're handling sales, marketing, customer service, and a lot more. It can get overwhelming, and you might find yourself doing the same tedious tasks day after day. But what if there is a way to free up some of your precious time and focus on growing your business? Enter Microsoft Power Automate, a handy tool that acts like your digital assistant, automating those repetitive tasks so you don’t have to keep doing them yourself. - [Is your PC slowing down? Here’s why defragmentation still matters](https://www.netservicesgroup.com/blog/is-your-pc-slowing-down-heres-why-defragmentation-still-matters/) - If your Windows PC feels slower than it used to, fragmented files could be part of the problem. Learn how disk defragmentation works, when it’s necessary, and how it can help restore performance and stability. We expect our computers to respond instantly — apps should launch quickly, files should open without delay, and the system - [CVE-2026-21525 Windows Remote Access Connection Manager Denial of Service Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21525-windows-remote-access-connection-manager-denial-of-service-vulnerability/) - Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally. - [Ransomware tops the threat list for US critical infrastructure](https://www.netservicesgroup.com/blog/ransomware-tops-the-threat-list-for-us-critical-infrastructure/) - According to the FBI’s 2024 Internet Crime Report, ransomware poses a persistent and growing threat to US critical infrastructure, which includes sectors such as healthcare, communications, energy, and financial services. Experts warn that phishing and social engineering are key tactics fueling these attacks, underscoring the importance of proactive cybersecurity measures. - [10 Strategies to speed up your digital transformation](https://www.netservicesgroup.com/blog/10-strategies-to-speed-up-your-digital-transformation/) - Digital transformation is essential for businesses to stay competitive and grow in today's fast-paced market. The sooner you act, the better. This article outlines 10 practical strategies to accelerate your digital journey. From adopting new technologies to fostering a culture of innovation, these tactics will help you modernize your business and move forward with confidence. - [8 Smart ways to slash your cloud costs](https://www.netservicesgroup.com/blog/8-smart-ways-to-slash-your-cloud-costs/) - Cloud expenses can spiral fast but with smart strategies, you can rein them in. This article breaks down nine simple yet clever ways to slash your cloud costs, from setting budgets with built-in consoles to using spot instances and offloading cold data. Whether you’re running a startup or an enterprise, these tips will help you cut waste and get the most bang for your buck. - [How you can align your IT systems with HIPAA regulations](https://www.netservicesgroup.com/blog/how-you-can-align-your-it-systems-with-hipaa-regulations/) - The Health Insurance Portability and Accountability Act (HIPAA) was created with a single goal: to keep medical records safe. HIPAA gives patients specific rights over who sees their private health details. If you operate a healthcare practice or any business that handles this data, following these rules is not optional. You must understand exactly where - [CVE-2026-21517 Windows App for Mac Installer Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21517-windows-app-for-mac-installer-elevation-of-privilege-vulnerability/) - Download links fixed - [CVE-2025-59213 Configuration Manager Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-59213-configuration-manager-elevation-of-privilege-vulnerability/) - Updated information to include CVSS scores. This is an informational change only. - [CVE-2025-71143 clk: samsung: exynos-clkout: Assign .num before accessing .hws](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71143-clk-samsung-exynos-clkout-assign-num-before-accessing-hws/) - Information published. - [CVE-2025-71109 MIPS: ftrace: Fix memory corruption when kernel is located beyond 32 bits](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71109-mips-ftrace-fix-memory-corruption-when-kernel-is-located-beyond-32-bits/) - Information published. - [CVE-2025-71067 ntfs: set dummy blocksize to read boot_block when mounting](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71067-ntfs-set-dummy-blocksize-to-read-boot_block-when-mounting/) - Information published. - [CVE-2025-13034 No QUIC certificate pinning with GnuTLS](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-13034-no-quic-certificate-pinning-with-gnutls/) - Information published. - [CVE-2025-71066 net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71066-net-sched-ets-always-remove-class-from-active-list-before-deleting-in-ets_qdisc_change/) - Information published. - [CVE-2025-71114 via_wdt: fix critical boot hang due to unnamed resource allocation](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71114-via_wdt-fix-critical-boot-hang-due-to-unnamed-resource-allocation/) - Information published. - [CVE-2025-71133 RDMA/irdma: avoid invalid read in irdma_net_event](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71133-rdma-irdma-avoid-invalid-read-in-irdma_net_event/) - Information published. - [CVE-2025-71101 platform/x86: hp-bioscfg: Fix out-of-bounds array access in ACPI package parsing](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71101-platform-x86-hp-bioscfg-fix-out-of-bounds-array-access-in-acpi-package-parsing/) - Information published. - [CVE-2025-68786 ksmbd: skip lock-range check on equal size to avoid size==0 underflow](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68786-ksmbd-skip-lock-range-check-on-equal-size-to-avoid-size0-underflow/) - Information published. - [CVE-2025-68771 ocfs2: fix kernel BUG in ocfs2_find_victim_chain](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68771-ocfs2-fix-kernel-bug-in-ocfs2_find_victim_chain/) - Information published. - [CVE-2025-71074 functionfs: fix the open/removal races](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71074-functionfs-fix-the-open-removal-races/) - Information published. - [CVE-2025-71081 ASoC: stm32: sai: fix OF node leak on probe](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71081-asoc-stm32-sai-fix-of-node-leak-on-probe/) - Information published. - [CVE-2025-40215 xfrm: delete x->tunnel as we delete x](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-40215-xfrm-delete-x-tunnel-as-we-delete-x/) - Information published. - [CVE-2025-71105 f2fs: use global inline_xattr_slab instead of per-sb slab cache](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71105-f2fs-use-global-inline_xattr_slab-instead-of-per-sb-slab-cache/) - Information published. - [CVE-2025-71064 net: hns3: using the num_tqps in the vf driver to apply for resources](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71064-net-hns3-using-the-num_tqps-in-the-vf-driver-to-apply-for-resources/) - Information published. - [CVE-2025-68817 ksmbd: fix use-after-free in ksmbd_tree_connect_put under concurrency](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68817-ksmbd-fix-use-after-free-in-ksmbd_tree_connect_put-under-concurrency/) - Information published. - [CVE-2025-71122 iommufd/selftest: Check for overflow in IOMMU_TEST_OP_ADD_RESERVED](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71122-iommufd-selftest-check-for-overflow-in-iommu_test_op_add_reserved/) - Information published. - [CVE-2025-68819 media: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68819-media-dvb-usb-dtv5100-fix-out-of-bounds-in-dtv5100_i2c_msg/) - Information published. - [CVE-2025-71119 powerpc/kexec: Enable SMT before waking offline CPUs](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71119-powerpc-kexec-enable-smt-before-waking-offline-cpus/) - Information published. - [CVE-2025-71118 ACPICA: Avoid walking the Namespace if start_node is NULL](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71118-acpica-avoid-walking-the-namespace-if-start_node-is-null/) - Information published. - [CVE-2025-71111 hwmon: (w83791d) Convert macros to functions to avoid TOCTOU](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71111-hwmon-w83791d-convert-macros-to-functions-to-avoid-toctou/) - Information published. - [CVE-2025-71136 media: adv7842: Avoid possible out-of-bounds array accesses in adv7842_cp_log_status()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71136-media-adv7842-avoid-possible-out-of-bounds-array-accesses-in-adv7842_cp_log_status/) - Information published. - [CVE-2025-71116 libceph: make decode_pool() more resilient against corrupted osdmaps](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71116-libceph-make-decode_pool-more-resilient-against-corrupted-osdmaps/) - Information published. - [CVE-2026-0861 Integer overflow in memalign leads to heap corruption](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-0861-integer-overflow-in-memalign-leads-to-heap-corruption/) - Information published. - [CVE-2017-1000097 On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2017-1000097-on-darwin-users-trust-preferences-for-root-certificates-were-not-honored-if-the-user-had-a-root-certificate-loaded-in-their-keychain-that-was-explicitly-not-trusted-a-go-prog/) - Information published. - [CVE-2025-68780 sched/deadline: only set free_cpus for online runqueues](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68780-sched-deadline-only-set-free_cpus-for-online-runqueues/) - Information published. - [CVE-2025-71069 f2fs: invalidate dentry cache on failed whiteout creation](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71069-f2fs-invalidate-dentry-cache-on-failed-whiteout-creation/) - Information published. - [CVE-2025-68794 iomap: adjust read range correctly for non-block-aligned positions](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68794-iomap-adjust-read-range-correctly-for-non-block-aligned-positions/) - Information published. - [CVE-2025-71094 net: usb: asix: validate PHY address before use](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71094-net-usb-asix-validate-phy-address-before-use/) - Information published. - [CVE-2025-71091 team: fix check for port enabled in team_queue_override_port_prio_changed()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-71091-team-fix-check-for-port-enabled-in-team_queue_override_port_prio_changed/) - Information published. - [CVE-2024-40635 containerd has an integer overflow in User ID handling](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-40635-containerd-has-an-integer-overflow-in-user-id-handling/) - Information published. - [CVE-2025-2295 Potential iSCSI R2T PDU Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-2295-potential-iscsi-r2t-pdu-vulnerability/) - Information published. - [CVE-2023-5764 Ansible: template injection](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2023-5764-ansible-template-injection/) - Information published. - [CVE-2023-6864 Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2023-6864-memory-safety-bugs-present-in-firefox-120-firefox-esr-115-5-and-thunderbird-115-5-some-of-these-bugs-showed-evidence-of-memory-corruption-and-we-presume-that-with-enough-effort-some-o/) - Information published. - [CVE-2021-32714 Integer Overflow in Chunked Transfer-Encoding](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2021-32714-integer-overflow-in-chunked-transfer-encoding/) - Information published. - [CVE-2017-15042 An unintended cleartext issue exists in Go before 1.8.4 and 1.9.x before 1.9.1. RFC 4954 requires that, during SMTP, the PLAIN auth scheme must only be used on network connections secured with TLS. The original implementation of smtp.PlainAuth in Go 1.0 enforced this requirement, and it was documented to do so. In 2013, upstream issue #5184, this was changed so that the server may decide whether PLAIN is acceptable. The result is that if you set up a man-in-the-middle SMTP server that doesn't advertise STARTTLS and does advertise that PLAIN auth is OK, the smtp.PlainAuth implementation sends the username and password.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2017-15042-an-unintended-cleartext-issue-exists-in-go-before-1-8-4-and-1-9-x-before-1-9-1-rfc-4954-requires-that-during-smtp-the-plain-auth-scheme-must-only-be-used-on-network-connections-secur/) - Information published. - [CVE-2023-6856 The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2023-6856-the-webgl-drawelementsinstanced-method-was-susceptible-to-a-heap-buffer-overflow-when-used-on-systems-with-the-mesa-vm-driver-this-issue-could-allow-an-attacker-to-perform-remote-cod/) - Information published. - [CVE-2025-24855 numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-24855-numbers-c-in-libxslt-before-1-1-43-has-a-use-after-free-because-in-nested-xpath-evaluations-an-xpath-context-node-can-be-modified-but-never-restored-this-is-related-to-xsltnumberform/) - Information published. - [CVE-2026-20841 Windows Notepad App Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20841-windows-notepad-app-remote-code-execution-vulnerability/) - Added FAQ information. This is an informational change only. - [CVE-2026-21518 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21518-github-copilot-and-visual-studio-code-security-feature-bypass-vulnerability/) - Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. - [CVE-2026-21519 Desktop Window Manager Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21519-desktop-window-manager-elevation-of-privilege-vulnerability/) - Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally. - [CVE-2025-2884 Cert CC: CVE-2025-2884 Out-of-Bounds read vulnerability in TCG TPM2.0 reference implementation](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-2884-cert-cc-cve-2025-2884-out-of-bounds-read-vulnerability-in-tcg-tpm2-0-reference-implementation/) - Added Affected Software for Windows packages - [Questions to ask before upgrading your servers](https://www.netservicesgroup.com/blog/questions-to-ask-before-upgrading-your-servers/) - Upgrading your company's servers is a crucial decision that affects everything from operations to long-term growth. Rather than rushing into a replacement, it’s important to pause and ask the right questions. The following questions will help you evaluate your current infrastructure and determine whether replacing your servers is the best course of action. How well - [Cloud vs. on-premises VoIP: Which option is best for your business?](https://www.netservicesgroup.com/blog/cloud-vs-on-premises-voip-which-option-is-best-for-your-business/) - As more businesses shift to VoIP, choosing between hosting it in the cloud or on-site has become crucial. This guide covers the key factors, such as security, cost, scalability, and customization, helping businesses make an informed decision based on their needs. Cost: Initial investment vs. ongoing expenses When comparing cloud-based and on-premises VoIP hosting, an - [CVE-2026-21247 Windows Hyper-V Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21247-windows-hyper-v-remote-code-execution-vulnerability/) - Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. - [CVE-2026-21251 Cluster Client Failover (CCF) Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21251-cluster-client-failover-ccf-elevation-of-privilege-vulnerability/) - Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally. - [CVE-2026-21260 Microsoft Outlook Spoofing Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21260-microsoft-outlook-spoofing-vulnerability/) - Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. - [CVE-2026-21248 Windows Hyper-V Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21248-windows-hyper-v-remote-code-execution-vulnerability/) - Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. - [CVE-2026-21258 Microsoft Excel Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21258-microsoft-excel-information-disclosure-vulnerability/) - Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. - [CVE-2026-21259 Microsoft Excel Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21259-microsoft-excel-elevation-of-privilege-vulnerability/) - Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally. - [CVE-2026-21512 Azure DevOps Server Cross-Site Scripting Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21512-azure-devops-server-cross-site-scripting-vulnerability/) - Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network. - [CVE-2026-21261 Microsoft Excel Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21261-microsoft-excel-information-disclosure-vulnerability/) - Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. - [CVE-2026-21246 Windows Graphics Component Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21246-windows-graphics-component-elevation-of-privilege-vulnerability/) - Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. - [CVE-2026-21242 Windows Subsystem for Linux Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21242-windows-subsystem-for-linux-elevation-of-privilege-vulnerability/) - Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. - [CVE-2026-21249 Windows NTLM Spoofing Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21249-windows-ntlm-spoofing-vulnerability/) - External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally. - [CVE-2026-21256 GitHub Copilot and Visual Studio Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21256-github-copilot-and-visual-studio-remote-code-execution-vulnerability/) - Changes made to the security updates links and information. This is an informational change only. - [CVE-2026-21511 Microsoft Outlook Spoofing Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21511-microsoft-outlook-spoofing-vulnerability/) - Acknowledgement added. This is an informational change only. - [CVE-2026-21255 Windows Hyper-V Security Feature Bypass Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21255-windows-hyper-v-security-feature-bypass-vulnerability/) - Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally. - [CVE-2026-21228 Azure Local Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21228-azure-local-remote-code-execution-vulnerability/) - Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network. - [CVE-2023-2804 Red Hat, Inc. CVE-2023-2804: Heap Based Overflow libjpeg-turbo](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2023-2804-red-hat-inc-cve-2023-2804-heap-based-overflow-libjpeg-turbo/) - A heap‑based buffer overflow exists in libjpeg‑turbo’s h2v2_merged_upsample_internal() function when processing 12‑bit lossless JPEG images. An attacker could craft an image containing out‑of‑range 12‑bit samples that, when decompressed with merged upsampling enabled, may trigger a segmentation fault or buffer overflow, resulting in an application crash. - [CVE-2026-21243 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21243-windows-lightweight-directory-access-protocol-ldap-denial-of-service-vulnerability/) - Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. - [CVE-2026-21238 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21238-windows-ancillary-function-driver-for-winsock-elevation-of-privilege-vulnerability/) - Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. - [5 Easy fixes for a website that isn’t bringing in business](https://www.netservicesgroup.com/blog/5-easy-fixes-for-a-website-that-isnt-bringing-in-business/) - Getting people to visit your website is hard work, but getting them to actually buy something or pick up the phone is even harder. Plenty of small-business sites look great but don't actually bring in sales. The good news is that you don’t need to be a tech wizard to fix this issue. We have - [Chromium: CVE-2026-1862 Type Confusion in V8](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-1862-type-confusion-in-v8/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information. - [The hidden file cleanup guide every Mac user should know about](https://www.netservicesgroup.com/blog/the-hidden-file-cleanup-guide-every-mac-user-should-know-about/) - If your Mac is feeling sluggish or you're running low on storage, hidden files might be the culprits. Here's a guide to help you identify and safely remove unnecessary hidden files from your Mac. - [Chromium: CVE-2026-1861 Heap buffer overflow in libvpx](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-1861-heap-buffer-overflow-in-libvpx/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information. - [CVE-2026-0391 Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-0391-microsoft-edge-chromium-based-for-android-spoofing-vulnerability/) - User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. - [CVE-2026-24300 Azure Front Door Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-24300-azure-front-door-elevation-of-privilege-vulnerability/) - Information published. - [CVE-2026-21532 Azure Function Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21532-azure-function-information-disclosure-vulnerability/) - Information published. - [CVE-2026-24302 Azure Arc Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-24302-azure-arc-elevation-of-privilege-vulnerability/) - Information published. - [20 Hidden Android 15 features you need to try](https://www.netservicesgroup.com/blog/20-hidden-android-15-features-you-need-to-try/) - Android 15 may look identical to its predecessor at first glance, but beneath the surface, it’s packed with enhancements designed to make your device smarter, faster, and more secure. Whether you’re using a Google Pixel, Samsung Galaxy, or any other Android mobile device, this blog discusses 20 advanced features that can transform how you use it. - [Strengthening BYOD security: Securing personal devices in the workplace](https://www.netservicesgroup.com/blog/strengthening-byod-security-securing-personal-devices-in-the-workplace/) - Bring your own device (BYOD) policies improve workflow flexibility by letting employees use personal devices for work. However, they also introduce security risks. Without proper safeguards, sensitive company information can be exposed through these devices. Fortunately, businesses can securely adopt BYOD by implementing the right precautions. - [Easy tips to keep your business safe from data loss](https://www.netservicesgroup.com/blog/easy-tips-to-keep-your-business-safe-from-data-loss/) - Data loss can be fatal for businesses. Losing critical files can lead to financial loss, operational disruption, and irreparable damage to customer trust. To avoid this grim predicament, it's crucial for businesses to implement the following preventive measures against data loss. Restrict access privileges to those who need it Access control defines who can view, - [Transform your brand with these video marketing strategies](https://www.netservicesgroup.com/blog/transform-your-brand-with-these-video-marketing-strategies/) - Video marketing is a great way to showcase your products and services, connect with your audience, and strengthen your brand’s identity. This article outlines practical ways to use video marketing to boost your brand recognition and reach. - [2026 Cybersecurity trends and predictions](https://www.netservicesgroup.com/blog/2026-cybersecurity-trends-and-predictions/) - Cybersecurity experts Rob Wright (Dark Reading), David Jones (Cybersecurity Dive), and Alissa Irei (TechTarget Search Security) recently came together to discuss the future of online security. Let's take a look at their insights on major trends and new risks to help businesses better navigate the challenges on the horizon. The evolution of AI-driven threats: Securing - [Coming soon: Smart glasses that tell you when you’re walking the wrong way](https://www.netservicesgroup.com/blog/coming-soon-smart-glasses-that-tell-you-when-youre-walking-the-wrong-way/) - Google is working on turning smart glasses into intelligent navigation tools. Through updates in the Google Maps app and the integration of Android XR and Gemini, users may soon get real-time walking directions and context-aware prompts that are hands free and overlaid on their real-world view. Imagine walking through an unfamiliar city, unsure of which - [How hybrid cloud solutions drive resilience and competitive edge](https://www.netservicesgroup.com/blog/how-hybrid-cloud-solutions-drive-resilience-and-competitive-edge/) - In an era defined by digital transformation, the ability to adapt, secure, and optimize is critical for sustained business success. Hybrid cloud solutions offer a sophisticated framework for achieving these goals, providing a versatile infrastructure that supports diverse business needs. From enhancing disaster recovery to enabling cutting-edge AI initiatives, hybrid clouds are fueling the forward momentum of businesses worldwide. - [Chromium: CVE-2026-1504 Inappropriate implementation in Background Fetch API](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-1504-inappropriate-implementation-in-background-fetch-api/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information. - [CVE-2026-20960 PowerApps Desktop Client Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20960-powerapps-desktop-client-remote-code-execution-vulnerability/) - Corrected Download links in the Security Updates table. This is an informational change only. - [Achieve more with Excel: A productivity guide for Microsoft 365 users](https://www.netservicesgroup.com/blog/achieve-more-with-excel-a-productivity-guide-for-microsoft-365-users/) - Excel for Microsoft 365 is packed with new features that can significantly improve your productivity. From real-time collaboration to dynamic arrays, discover the essential tools that can help you get the most out of this powerful spreadsheet tool. - [Mitigating the risk of TDoS attacks on your VoIP infrastructure](https://www.netservicesgroup.com/blog/mitigating-the-risk-of-tdos-attacks-on-your-voip-infrastructure/) - While Voice over Internet Protocol (VoIP) offers significant advantages — including cost efficiency, scalability, portability, and high-quality audio — it also introduces specific security risks. One such threat is telephony denial-of-service (TDoS). In the following article, we explore what TDoS is and how you can strengthen your VoIP infrastructure against it. - [iPhone users warned: Update now or stay exposed to spyware threats](https://www.netservicesgroup.com/blog/iphone-users-warned-update-now-or-stay-exposed-to-spyware-threats/) - Apple has confirmed critical iPhone vulnerabilities that can be patched by updating to iOS 26, yet the majority of users are still running older software versions. We explore why many are holding off and why upgrading is the only effective protection against ongoing spyware attacks. Update lag leaves millions exposed Although iOS 26 launched back - [CVE-2026-21509 Microsoft Office Security Feature Bypass Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21509-microsoft-office-security-feature-bypass-vulnerability/) - Updated FAQ information. This is an informational change only. - [A step-by-step guide to building your own PC](https://www.netservicesgroup.com/blog/a-step-by-step-guide-to-building-your-own-pc/) - Take charge of your computing experience by building your own PC. This guide will walk you through every step, from planning and selecting components to assembling your system, helping you create a machine perfectly tailored to your needs. - [5 VoIP trends small-business owners should know](https://www.netservicesgroup.com/blog/5-voip-trends-small-business-owners-should-know/) - For many small businesses, switching to Voice over Internet Protocol (VoIP) started as a simple way to cut costs. But the technology has matured from a budget alternative into a superior tool for growth and flexibility. VoIP communications now center on security and integration rather than just making calls. These five key trends show how - [Need some help using your threat intelligence platform? Here’s a quick guide](https://www.netservicesgroup.com/blog/need-some-help-using-your-threat-intelligence-platform-heres-a-quick-guide/) - Threat intelligence platforms (TIPs) are powerful tools that collect, analyze, and organize threat data, offering businesses actionable insights to mitigate risks and respond proactively to threats. However, fully leveraging TIPs can be challenging without the right approach. In this guide, we’ll share expert tips on how businesses can effectively integrate and utilize TIPs to maximize their impact. - [Proactive strategies for protecting healthcare IT operations](https://www.netservicesgroup.com/blog/proactive-strategies-for-protecting-healthcare-it-operations/) - Healthcare organizations are under increasing pressure to safeguard their IT infrastructures from a wide range of disruptive events that could compromise their ability to deliver care. This post outlines key strategies for maintaining critical IT systems. - [Why the next Windows 11 update is skipping Intel and AMD](https://www.netservicesgroup.com/blog/why-the-next-windows-11-update-is-skipping-intel-and-amd/) - Microsoft’s upcoming Windows 11 26H1 update is rolling out only to devices powered by Snapdragon chips, at least for now. While it might seem like Snapdragon is getting special treatment, the move has more to do with timing, development cycles, and Microsoft’s push for AI-ready devices than playing favorites. Why is Microsoft prioritizing Snapdragon devices? - [Chromium: CVE-2026-1220 Race in V8](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-1220-race-in-v8/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information. - [CVE-2026-24307 M365 Copilot Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-24307-m365-copilot-information-disclosure-vulnerability/) - Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network. - [CVE-2026-21227 Azure Logic Apps Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21227-azure-logic-apps-elevation-of-privilege-vulnerability/) - Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. - [CVE-2026-24305 Azure Entra ID Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-24305-azure-entra-id-elevation-of-privilege-vulnerability/) - Azure Entra ID Elevation of Privilege Vulnerability - [CVE-2026-21524 Azure Data Explorer Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21524-azure-data-explorer-information-disclosure-vulnerability/) - Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a network. - [CVE-2026-24306 Azure Front Door Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-24306-azure-front-door-elevation-of-privilege-vulnerability/) - Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network. - [CVE-2026-21264 Microsoft Account Spoofing Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21264-microsoft-account-spoofing-vulnerability/) - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network. - [CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-24304-azure-resource-manager-elevation-of-privilege-vulnerability/) - Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. - [CVE-2026-21520 Copilot Studio Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21520-copilot-studio-information-disclosure-vulnerability/) - Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector - [CVE-2026-21521 Word Copilot Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21521-word-copilot-information-disclosure-vulnerability/) - Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network. - [An intern's experience with Rust](https://www.netservicesgroup.com/msrc-blog-alerts/an-interns-experience-with-rust/) - Over the course of my internship at the Microsoft Security Response Center (MSRC), I worked on the safe systems programming languages (SSPL) team to promote safer languages for systems programming where runtime overhead is important, as outlined in this blog. My job was to port a security critical network processing agent into Rust to eliminate... - [CVE-2025-2308 HDF5 Scale-Offset Filter H5Z__scaleoffset_decompress_one_byte heap-based overflow](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-2308-hdf5-scale-offset-filter-h5z__scaleoffset_decompress_one_byte-heap-based-overflow/) - Information published. - [CVE-2025-2309 HDF5 Type Conversion Logic H5T__bit_copy heap-based overflow](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-2309-hdf5-type-conversion-logic-h5t__bit_copy-heap-based-overflow/) - Information published. - [CVE-2025-2915 HDF5 H5Faccum.c H5F__accum_free heap-based overflow](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-2915-hdf5-h5faccum-c-h5f__accum_free-heap-based-overflow/) - Information published. - [CVE-2025-58436 OpenPrinting CUPS slow client can halt cupsd, leading to a possible DoS attack](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-58436-openprinting-cups-slow-client-can-halt-cupsd-leading-to-a-possible-dos-attack/) - Information published. - [CVE-2026-20848 Windows SMB Server Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20848-windows-smb-server-elevation-of-privilege-vulnerability/) - Updated the build numbers. This is an informational update only. - [CVE-2026-21221 Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21221-capability-access-management-service-camsvc-elevation-of-privilege-vulnerability/) - Updated the build numbers. This is an informational update only. - [CVE-2026-20830 Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20830-capability-access-management-service-camsvc-elevation-of-privilege-vulnerability/) - Updated the build numbers. This is an informational update only. - [CVE-2026-20943 Microsoft Office Click-To-Run Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20943-microsoft-office-click-to-run-remote-code-execution-vulnerability/) - Updated FAQ information. This is an informational change only. - [CVE-2026-20818 Windows Kernel Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20818-windows-kernel-information-disclosure-vulnerability/) - Updated the build numbers. This is an informational update only. - [A step-by-step guide to moving your small business to the cloud](https://www.netservicesgroup.com/blog/a-step-by-step-guide-to-moving-your-small-business-to-the-cloud/) - For small businesses, cloud computing means ditching bulky servers, freeing up resources, and gaining flexibility like never before. This guide walks you through the entire cloud migration journey, from setting goals to hands-on migration tactics. If you’re ready to trade your legacy systems for smarter, scalable tools, this is your roadmap. Define your goals Before - [Health tech gets personal: CES 2026's boldest wellness innovations](https://www.netservicesgroup.com/blog/health-tech-gets-personal-ces-2026s-boldest-wellness-innovations/) - At CES 2026, the world’s biggest technology showcase, health tech took center stage, with devices that analyze everything from urine to facial blood flow. This article breaks down the standout trends in wellness technology that are changing how we monitor health at home. Health monitoring, straight from the bathroom One major theme was the growing - [Unlearn these 10 habits to speed up your Windows PC workflows](https://www.netservicesgroup.com/blog/unlearn-these-10-habits-to-speed-up-your-windows-pc-workflows/) - The way we use our PCs can seem adequate, but often, there’s always room for improvement. With just a few adjustments, you could be getting more done in less time. Streamline your workflow and boost productivity by breaking these 10 common habits. From eliminating unnecessary clicks to customizing your workspace, these tips will transform your Windows PC into a productivity powerhouse. - [Is your data safe? A guide to Backup-as-a-Service](https://www.netservicesgroup.com/blog/is-your-data-safe-a-guide-to-backup-as-a-service/) - What would happen if you lost all your critical business data tomorrow? For many companies, the answer is devastating. Hardware failures, natural disasters, and the ever-present threat of ransomware can bring operations to a grinding halt. Relying on outdated, on-site backup systems is a risky gamble. A more effective solution is Backup-as-a-Service (BaaS), which leverages the power of the cloud to keep your data safe and accessible. - [Tips for creating more secure business passwords](https://www.netservicesgroup.com/blog/tips-for-creating-more-secure-business-passwords/) - Strong passwords are one of the easiest and most effective ways to protect online accounts. Still, many businesses use weak or reuse credentials. Learning how to create stronger passwords can significantly lower your business’s risk without adding unnecessary complexity to your security practices. Why corporate password security is nonnegotiable Passwords are the cornerstone of protecting - [Chromium: CVE-2026-0908 Use after free in ANGLE](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-0908-use-after-free-in-angle/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information. - [Chromium: CVE-2026-0907 Incorrect security UI in Split View](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-0907-incorrect-security-ui-in-split-view/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information. - [Chromium: CVE-2026-0905 Insufficient policy enforcement in Network](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-0905-insufficient-policy-enforcement-in-network/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information. - [Chromium: CVE-2026-0906 Incorrect security UI](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-0906-incorrect-security-ui/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information. - [Chromium: CVE-2026-0904 Incorrect security UI in Digital Credentials](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-0904-incorrect-security-ui-in-digital-credentials/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information. - [Chromium: CVE-2026-0903 Insufficient validation of untrusted input in Downloads](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-0903-insufficient-validation-of-untrusted-input-in-downloads/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information. - [Chromium: CVE-2026-0902 Inappropriate implementation in V8](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-0902-inappropriate-implementation-in-v8/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information. - [Chromium: CVE-2026-0901 Inappropriate implementation in Blink](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-0901-inappropriate-implementation-in-blink/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information. - [Chromium: CVE-2026-0900 Inappropriate implementation in V8](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-0900-inappropriate-implementation-in-v8/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information. - [Chromium: CVE-2026-0899 Out of bounds memory access in V8](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-0899-out-of-bounds-memory-access-in-v8/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information. - [CVE-2026-21223 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21223-microsoft-edge-chromium-based-security-feature-bypass-vulnerability/) - Microsoft Edge Elevation Service exposes a privileged COM interface that inadequately validates the privileges of the calling process. A standard (non‑administrator) local user can invoke the IElevatorEdge interface method LaunchUpdateCmdElevatedAndWait, causing the service to execute privileged update commands as LocalSystem. This allows a non‑administrator to enable or disable Windows Virtualization‑Based Security (VBS) by modifying protected - [CVE-2026-20960 Microsoft Power Apps Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20960-microsoft-power-apps-remote-code-execution-vulnerability/) - Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network. - [CVE-2026-20929 Windows HTTP.sys Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20929-windows-http-sys-elevation-of-privilege-vulnerability/) - Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. - [CVE-2026-20867 Windows Management Services Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20867-windows-management-services-elevation-of-privilege-vulnerability/) - Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. - [CVE-2026-20849 Windows Kerberos Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20849-windows-kerberos-elevation-of-privilege-vulnerability/) - Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network. - [A quick guide to setting up a secure guest Wi-Fi network in your office](https://www.netservicesgroup.com/blog/a-quick-guide-to-setting-up-a-secure-guest-wi-fi-network-in-your-office/) - If clients, partners, or other visitors to your office occasionally ask for Wi-Fi access, you need more than just a shared password. A secure guest Wi-Fi setup protects your business from digital threats while still keeping visitors connected. Here's a guide to doing it right. Why guests shouldn’t share your main network It’s easy to - [CVE-2026-20958 Microsoft SharePoint Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20958-microsoft-sharepoint-information-disclosure-vulnerability/) - Updated acknowledgment. This is an informational change only. - [CVE-2025-64679 Windows DWM Core Library Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-64679-windows-dwm-core-library-elevation-of-privilege-vulnerability/) - Updated the build numbers. This is an informational update only. - [CVE-2026-20941 Host Process for Windows Tasks Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20941-host-process-for-windows-tasks-elevation-of-privilege-vulnerability/) - Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally. - [CVE-2026-20937 Windows File Explorer Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20937-windows-file-explorer-information-disclosure-vulnerability/) - Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. - [CVE-2026-20920 Win32k Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20920-win32k-elevation-of-privilege-vulnerability/) - Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. - [CVE-2026-20861 Windows Management Services Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20861-windows-management-services-elevation-of-privilege-vulnerability/) - Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. - [CVE-2026-20872 NTLM Hash Disclosure Spoofing Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20872-ntlm-hash-disclosure-spoofing-vulnerability/) - External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. - [CVE-2026-20953 Microsoft Office Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20953-microsoft-office-remote-code-execution-vulnerability/) - Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. - [CVE-2026-20808 Windows File Explorer Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20808-windows-file-explorer-elevation-of-privilege-vulnerability/) - Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attacker to elevate privileges locally. - [CVE-2026-20809 Windows Kernel Memory Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20809-windows-kernel-memory-elevation-of-privilege-vulnerability/) - Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally. - [CVE-2026-20804 Windows Hello Tampering Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20804-windows-hello-tampering-vulnerability/) - Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. - [CVE-2026-20805 Desktop Window Manager Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20805-desktop-window-manager-information-disclosure-vulnerability/) - Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. - [CVE-2026-20965 Windows Admin Center Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20965-windows-admin-center-elevation-of-privilege-vulnerability/) - Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally. - [CVE-2026-20803 Microsoft SQL Server Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20803-microsoft-sql-server-elevation-of-privilege-vulnerability/) - Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network. - [CVE-2026-20812 LDAP Tampering Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20812-ldap-tampering-vulnerability/) - Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network. - [CVE-2026-20924 Windows Management Services Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20924-windows-management-services-elevation-of-privilege-vulnerability/) - Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. - [CVE-2026-0386 Windows Deployment Services Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-0386-windows-deployment-services-remote-code-execution-vulnerability/) - Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network. - [CVE-2026-20932 Windows File Explorer Information Disclosure Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20932-windows-file-explorer-information-disclosure-vulnerability/) - Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. - [CVE-2026-20810 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20810-windows-ancillary-function-driver-for-winsock-elevation-of-privilege-vulnerability/) - Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. - [CVE-2026-20943 Microsoft Office Click-To-Run Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20943-microsoft-office-click-to-run-elevation-of-privilege-vulnerability/) - Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally. - [CVE-2026-20811 Win32k Elevation of Privilege Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20811-win32k-elevation-of-privilege-vulnerability/) - Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. - [CVE-2026-20963 Microsoft SharePoint Remote Code Execution Vulnerability](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-20963-microsoft-sharepoint-remote-code-execution-vulnerability/) - Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. - [7 VoIP call problems and the fixes you’ll actually use](https://www.netservicesgroup.com/blog/7-voip-call-problems-and-the-fixes-youll-actually-use/) - VoIP phone systems have become the go-to choice for many businesses thanks to their flexibility, features, and cost savings. But like any technology, they’re not immune to the occasional hiccup. If your calls are dropping, cutting out, or just sounding off, here’s a breakdown of the most common VoIP issues and how to fix them. - [Chromium: CVE-2026-0628 Insufficient policy enforcement in WebView tag](https://www.netservicesgroup.com/msrc-blog-alerts/chromium-cve-2026-0628-insufficient-policy-enforcement-in-webview-tag/) - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information. - [Why your business is more secure in the cloud than on premises](https://www.netservicesgroup.com/blog/why-your-business-is-more-secure-in-the-cloud-than-on-premises/) - Think cloud computing is just about storage? Think again. For small and medium businesses, the cloud offers major cybersecurity advantages, from expert protection to disaster recovery and fewer system vulnerabilities. Learn how the cloud can help you stay secure and competitive. Cybersecurity doesn’t have to be an uphill battle for small and medium-sized businesses (SMBs). - [The evolution of collaboration: Modernizing your work with Microsoft Loop](https://www.netservicesgroup.com/blog/the-evolution-of-collaboration-modernizing-your-work-with-microsoft-loop/) - The days of static documents and "version control" nightmares are officially over. In 2026, Microsoft Loop has evolved into a dynamic platform where content is portable and alive. From the new support in Outlook for Mac and Calendar to the deep integration with Microsoft Planner, Loop is transforming how teams interact. If you’re still working - [CVE-2024-41067 btrfs: scrub: handle RST lookup error correctly](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-41067-btrfs-scrub-handle-rst-lookup-error-correctly/) - Information published. - [CVE-2025-37745 PM: hibernate: Avoid deadlock in hibernate_compressor_param_set()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-37745-pm-hibernate-avoid-deadlock-in-hibernate_compressor_param_set/) - Information published. - [CVE-2024-56782 ACPI: x86: Add adev NULL check to acpi_quirk_skip_serdev_enumeration()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-56782-acpi-x86-add-adev-null-check-to-acpi_quirk_skip_serdev_enumeration/) - Information published. - [CVE-2024-56775 drm/amd/display: Fix handling of plane refcount](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-56775-drm-amd-display-fix-handling-of-plane-refcount/) - Information published. - [CVE-2024-57804 scsi: mpi3mr: Fix corrupt config pages PHY state is switched in sysfs](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-57804-scsi-mpi3mr-fix-corrupt-config-pages-phy-state-is-switched-in-sysfs/) - Information published. - [CVE-2024-35794 dm-raid: really frozen sync_thread during suspend](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-35794-dm-raid-really-frozen-sync_thread-during-suspend/) - Information published. - [CVE-2024-42107 ice: Don't process extts if PTP is disabled](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-42107-ice-dont-process-extts-if-ptp-is-disabled/) - Information published. - [CVE-2025-21732 RDMA/mlx5: Fix a race for an ODP MR which leads to CQE with error](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-21732-rdma-mlx5-fix-a-race-for-an-odp-mr-which-leads-to-cqe-with-error/) - Information published. - [CVE-2024-41932 sched: fix warning in sched_setaffinity](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-41932-sched-fix-warning-in-sched_setaffinity/) - Information published. - [CVE-2024-57875 block: RCU protect disk->conv_zones_bitmap](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-57875-block-rcu-protect-disk-conv_zones_bitmap/) - Information published. - [CVE-2025-55554 pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-55554-pytorch-v2-8-0-was-discovered-to-contain-an-integer-overflow-in-the-component-torch-nan_to_num-long/) - Information published. - [CVE-2025-55551 An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-55551-an-issue-in-the-component-torch-linalg-lu-of-pytorch-v2-8-0-allows-attackers-to-cause-a-denial-of-service-dos-when-performing-a-slice-operation/) - Information published. - [CVE-2024-57976 btrfs: do proper folio cleanup when cow_file_range() failed](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-57976-btrfs-do-proper-folio-cleanup-when-cow_file_range-failed/) - Information published. - [CVE-2025-37826 scsi: ufs: core: Add NULL check in ufshcd_mcq_compl_pending_transfer()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-37826-scsi-ufs-core-add-null-check-in-ufshcd_mcq_compl_pending_transfer/) - Information published. - [CVE-2025-37877 iommu: Clear iommu-dma ops on cleanup](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-37877-iommu-clear-iommu-dma-ops-on-cleanup/) - Information published. - [CVE-2024-42317 mm/huge_memory: avoid PMD-size page cache if needed](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-42317-mm-huge_memory-avoid-pmd-size-page-cache-if-needed/) - Information published. - [CVE-2024-47794 bpf: Prevent tailcall infinite loop caused by freplace](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-47794-bpf-prevent-tailcall-infinite-loop-caused-by-freplace/) - Information published. - [CVE-2024-24856 NULL pointer deference in acpi_db_convert_to_package of Linux acpi module](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-24856-null-pointer-deference-in-acpi_db_convert_to_package-of-linux-acpi-module/) - Information published. - [CVE-2024-57898 wifi: cfg80211: clear link ID from bitmap during link delete after clean up](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-57898-wifi-cfg80211-clear-link-id-from-bitmap-during-link-delete-after-clean-up/) - Information published. - [CVE-2024-57872 scsi: ufs: pltfrm: Dellocate HBA during ufshcd_pltfrm_remove()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-57872-scsi-ufs-pltfrm-dellocate-hba-during-ufshcd_pltfrm_remove/) - Information published. - [CVE-2025-68972 In GnuPG through 2.4.8, if a signed message has f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor" message is printed during verification). This is related to use of f as a marker to denote truncation of a long plaintext line.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68972-in-gnupg-through-2-4-8-if-a-signed-message-has-f-at-the-end-of-a-plaintext-line-an-adversary-can-construct-a-modified-message-that-places-additional-text-after-the-signed-material-su/) - Information published. - [CVE-2025-68766 irqchip/mchp-eic: Fix error code in mchp_eic_domain_alloc()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68766-irqchip-mchp-eic-fix-error-code-in-mchp_eic_domain_alloc/) - Information published. - [CVE-2025-68753 ALSA: firewire-motu: add bounds check in put_user loop for DSP events](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68753-alsa-firewire-motu-add-bounds-check-in-put_user-loop-for-dsp-events/) - Information published. - [CVE-2025-15284 arrayLimit bypass in bracket notation allows DoS via memory exhaustion](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-15284-arraylimit-bypass-in-bracket-notation-allows-dos-via-memory-exhaustion/) - Information published. - [CVE-2025-34468 libcoap Stack-Based Buffer Overflow in Address Resolution DoS or Potential RCE](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-34468-libcoap-stack-based-buffer-overflow-in-address-resolution-dos-or-potential-rce/) - Information published. - [CVE-2025-68367 macintosh/mac_hid: fix race condition in mac_hid_toggle_emumouse](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68367-macintosh-mac_hid-fix-race-condition-in-mac_hid_toggle_emumouse/) - Information published. - [CVE-2025-68729 wifi: ath12k: Fix MSDU buffer types handling in RX error path](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68729-wifi-ath12k-fix-msdu-buffer-types-handling-in-rx-error-path/) - Information published. - [CVE-2025-38425 i2c: tegra: check msg length in SMBUS block read](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-38425-i2c-tegra-check-msg-length-in-smbus-block-read/) - Information published. - [CVE-2025-38437 ksmbd: fix potential use-after-free in oplock/lease break ack](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-38437-ksmbd-fix-potential-use-after-free-in-oplock-lease-break-ack/) - Information published. - [CVE-2025-38259 ASoC: codecs: wcd9335: Fix missing free of regulator supplies](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-38259-asoc-codecs-wcd9335-fix-missing-free-of-regulator-supplies/) - Information published. - [CVE-2025-38257 s390/pkey: Prevent overflow in size calculation for memdup_user()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-38257-s390-pkey-prevent-overflow-in-size-calculation-for-memdup_user/) - Information published. - [CVE-2025-38230 jfs: validate AG parameters in dbMount() to prevent crashes](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-38230-jfs-validate-ag-parameters-in-dbmount-to-prevent-crashes/) - Information published. - [CVE-2025-68287 usb: dwc3: Fix race condition between concurrent dwc3_remove_requests() call paths](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68287-usb-dwc3-fix-race-condition-between-concurrent-dwc3_remove_requests-call-paths/) - Information published. - [CVE-2025-1744 Out-of-bounds Write in radare2](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-1744-out-of-bounds-write-in-radare2/) - Information published. - [CVE-2025-68476 KEDA has Arbitrary File Read via Insufficient Path Validation in HashiCorp Vault Service Account Credential](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68476-keda-has-arbitrary-file-read-via-insufficient-path-validation-in-hashicorp-vault-service-account-credential/) - Information published. - [CVE-2025-4432 Ring: some aes functions may panic when overflow checking is enabled in ring](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-4432-ring-some-aes-functions-may-panic-when-overflow-checking-is-enabled-in-ring/) - Information published. - [CVE-2025-11964 OOBW in utf_16le_to_utf_8_truncated() in libpcap](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-11964-oobw-in-utf_16le_to_utf_8_truncated-in-libpcap/) - Information published. - [CVE-2025-11961 OOBR and OOBW in pcap_ether_aton() in libpcap](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-11961-oobr-and-oobw-in-pcap_ether_aton-in-libpcap/) - Information published. - [CVE-2025-61594 URI Credential Leakage Bypass over CVE-2025-27221](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-61594-uri-credential-leakage-bypass-over-cve-2025-27221/) - Information published. - [CVE-2025-3001 PyTorch torch.lstm_cell memory corruption](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-3001-pytorch-torch-lstm_cell-memory-corruption/) - Information published. - [CVE-2000-0006 strace allows local users to read arbitrary files via memory mapped file names.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2000-0006-strace-allows-local-users-to-read-arbitrary-files-via-memory-mapped-file-names/) - Information published. - [Getting your tech dollar’s worth: Costly IT investment mistakes to avoid](https://www.netservicesgroup.com/blog/getting-your-tech-dollars-worth-costly-it-investment-mistakes-to-avoid/) - Technology can be a game-changer for growing businesses. From speeding up workflows to helping teams collaborate more efficiently, the right tools can drive great improvements. But not every tech investment pays off, especially when businesses jump in without a clear plan. If you're thinking of upgrading your systems or adding new software, steer clear of - [CVE-2025-68146 filelock has TOCTOU race condition that allows symlink attacks during lock file creation](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68146-filelock-has-toctou-race-condition-that-allows-symlink-attacks-during-lock-file-creation/) - Information published. - [CVE-2025-52881 runc: LSM labels can be bypassed with malicious config using dummy procfs files](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-52881-runc-lsm-labels-can-be-bypassed-with-malicious-config-using-dummy-procfs-files/) - Information published. - [CVE-2025-61099 FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LS Update packet.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-61099-frrouting-frr-from-v2-0-through-v10-4-1-was-discovered-to-contain-a-null-pointer-dereference-via-the-opaque_info_detail-function-at-ospf_opaque-c-this-vulnerability-allows-attackers-to/) - Information published. - [CVE-2025-61104 FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-61104-frrouting-frr-from-v4-0-through-v10-4-1-was-discovered-to-contain-a-null-pointer-dereference-via-the-show_vty_unknown_tlv-function-at-ospf_ext-c-this-vulnerability-allows-attackers-to/) - Information published. - [CVE-2025-61100 FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) under specific malformed LSA conditions.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-61100-frrouting-frr-from-v2-0-through-v10-4-1-was-discovered-to-contain-a-null-pointer-dereference-via-the-ospf_opaque_lsa_dump-function-at-ospf_opaque-c-this-vulnerability-allows-attackers/) - Information published. - [CVE-2025-61101 FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-61101-frrouting-frr-from-v4-0-through-v10-4-1-was-discovered-to-contain-a-null-pointer-dereference-via-the-show_vty_ext_link_rmt_itf_addr-function-at-ospf_ext-c-this-vulnerability-allows-att/) - Information published. - [CVE-2025-61102 FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-61102-frrouting-frr-from-v4-0-through-v10-4-1-was-discovered-to-contain-a-null-pointer-dereference-via-the-show_vty_ext_link_adj_sid-function-at-ospf_ext-c-this-vulnerability-allows-attacker/) - Information published. - [CVE-2025-61107 FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LSA Update packet.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-61107-frrouting-frr-from-v4-0-through-v10-4-1-was-discovered-to-contain-a-null-pointer-dereference-via-the-show_vty_ext_pref_pref_sid-function-at-ospf_ext-c-this-vulnerability-allows-attacke/) - Information published. - [CVE-2025-61106 FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-61106-frrouting-frr-from-v4-0-through-v10-4-1-was-discovered-to-contain-a-null-pointer-dereference-via-the-show_vty_ext_pref_pref_sid-function-at-ospf_ext-c-this-vulnerability-allows-attacke/) - Information published. - [CVE-2025-61103 FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_lan_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-61103-frrouting-frr-from-v4-0-through-v10-4-1-was-discovered-to-contain-a-null-pointer-dereference-via-the-show_vty_ext_link_lan_adj_sid-function-at-ospf_ext-c-this-vulnerability-allows-atta/) - Information published. - [The new cyberthreat: What happens when your IT pro betrays you?](https://www.netservicesgroup.com/blog/the-new-cyberthreat-what-happens-when-your-it-pro-betrays-you/) - Picture the person you call when your email breaks. You likely trust them with every password you own. But what if that person used their skills against you? Security threats are no longer limited to clumsy employees clicking bad links. Now, they include skilled professionals intentionally opening doors for criminals. Technical expertise does not always - [CVE-2025-68727 ntfs3: Fix uninit buffer allocated by __getname()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68727-ntfs3-fix-uninit-buffer-allocated-by-__getname/) - Information published. - [CVE-2025-68372 nbd: defer config put in recv_work](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68372-nbd-defer-config-put-in-recv_work/) - Information published. - [CVE-2025-68615 Net-SNMP snmptrapd crash](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68615-net-snmp-snmptrapd-crash/) - Information published. - [CVE-2025-13912 Potential non-constant time compiled code with Clang LLVM](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-13912-potential-non-constant-time-compiled-code-with-clang-llvm/) - Information published. - [CVE-2025-13281 Portworx Half-Blind SSRF in kube-controller-manager](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-13281-portworx-half-blind-ssrf-in-kube-controller-manager/) - Information published. - [CVE-2023-52970 MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, 11.0 through 11.0.*, and 11.1 through 11.4.* crashes in Item_direct_view_ref::derived_field_transformer_for_where.](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2023-52970-mariadb-server-10-4-through-10-5-10-6-through-10-6-10-7-through-10-11-11-0-through-11-0-and-11-1-through-11-4-crashes-in-item_direct_view_refderived_field_transformer_fo/) - Information published. - [CVE-2025-68973 In GnuPG through 2.4.8, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68973-in-gnupg-through-2-4-8-armor_filter-in-g10-armor-c-has-two-increments-of-an-index-variable-where-one-is-intended-leading-to-an-out-of-bounds-write-for-crafted-input-for-extendedlts/) - Information published. - [CVE-2025-14180 NULL Pointer Dereference in PDO quoting](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-14180-null-pointer-dereference-in-pdo-quoting/) - Information published. - [CVE-2025-14178 Heap buffer overflow in array_merge()](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-14178-heap-buffer-overflow-in-array_merge/) - Information published. - [CVE-2025-14177 Information Leak of Memory in getimagesize](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-14177-information-leak-of-memory-in-getimagesize/) - Information published. - [10 Android messaging tricks to increase communications efficiency](https://www.netservicesgroup.com/blog/10-android-messaging-tricks-to-increase-communications-efficiency/) - Android Messages has evolved into a capable platform with tools that go beyond simple texting. From customizing notifications to scheduling messages and managing clutter automatically, this article highlights 10 built-in features that can significantly improve your messaging experience. Custom notifications for important contacts Assigning unique notification sounds and icons to key contacts helps distinguish critical - [CVE-2025-12084 Quadratic complexity in node ID cache clearing](https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-12084-quadratic-complexity-in-node-id-cache-clearing/) - Information published. ## Pages - [Welcome to Network Services Group](https://www.netservicesgroup.com/) - Network Services Group provides top quality desktop support and computer repair services for your laptop or small business. Call (989) 776-2080. - [NSG Speedtest](https://www.netservicesgroup.com/nsg-speedtest/) - [speedy_content] - [Parked Domain](https://www.netservicesgroup.com/parked-domain/) - Welcome to Network Services Group [parked_domain] is hosted by Network Services Group. Managed Services Managed Services from Network Services Group will eliminate the hassles of dealing with unreliable IT that you are unable to corral on your own. We will constantly monitor your IT systems, fixing what needs to be fixed before it becomes a - [Network Protection - Security Threat Detected](https://www.netservicesgroup.com/network-protection-security-threat-detected/) - [General Terms & Conditions](https://www.netservicesgroup.com/terms/) - Revision date: 9/28/2016 Network Services Group (NSG) is dedicated to providing its customers with the highest quality service possible. To maintain the level of quality that our customers have come to expect, we feel it is necessary to apply some basic Terms and Conditions to your account with us. These terms and conditions are the - [Privacy Policy](https://www.netservicesgroup.com/privacy/) - Revision date: 9/26/2017 Our Commitment To Privacy Your privacy is important to us. To better protect your privacy we provide this notice explaining our online information practices and the choices you can make about the way your information is collected and used. The Information We Collect This notice applies to all information collected or submitted - [NSG Customer Referral Program Form](https://www.netservicesgroup.com/nsg-customer-referral-program-form/) - [Weather Test Page](https://www.netservicesgroup.com/weather-test-page/) - [NSG Customer Referral Program](https://www.netservicesgroup.com/nsg-customer-referral-program/) - At Network Services Group, we believe referrals are the greatest form of flattery. As one of our valued customers, you already know the benefits of our services. By recommending your contacts, you can help them enjoy worry-free IT and reap some great rewards for yourself. Refer a Friend or Business Connection... Make 100 Bucks! Want - [Support Ends for Windows 10 22H2, Windows Server 2012 R2, Exchange 2013, Office 2016](https://www.netservicesgroup.com/support-ends-for-windows-10-22h2-windows-server-2012-r2-exchange-2013-office-2016/) - The final version of Windows 10 will reach end of support on October 14, 2025. The current version, 22H2, will be the last version of Windows 10. Technically, you can carry on using Windows 10 for as long as you like at no cost but it will be a dangerous risk without security updates. The - [NSG Remote Help](https://www.netservicesgroup.com/help/) - If you are experiencing troubles with your network and/or computers, we can often diagnose and fix the problems remotely, without the need for an office visit. *In no event will Network Services Group be liable for any loss or damage, including and without limitation, indirect or consequential loss or damage, or any loss or damage - [ASN 15154](https://www.netservicesgroup.com/asn-15154/) - [Image Share](https://www.netservicesgroup.com/image-share/) - [MSRC Blog Alerts](https://www.netservicesgroup.com/msrc-blog-alerts/) - [Strategic Partners](https://www.netservicesgroup.com/strategic-partners/) - 123.Net 123.net is a Michigan business, owned and managed by a team of accomplished executives with strong engineering backgrounds and proven success. Headquartered in the heart of Southfield, Michigan, 123.Net has been successfully providing voice, data, and colocation infrastructure services to enterprises, carriers, ISPs, and technology companies for over 15 years. For more information, please - [Careers at Network Services Group](https://www.netservicesgroup.com/careers-at-network-services-group/) - Network Services Group (NSG) is a cutting edge company that specializes in IT Support, Managed Services, and Cloud Integration for small to medium sized businesses in the Great Lakes Bay Region area that typically do not employ in-house IT staff. An NSG technician will be an experienced Microsoft network engineer with a strong background in Windows server - [NSG Security Risk Assessments](https://www.netservicesgroup.com/nsg-security-risk-assessments/) - Request Your IT Security Assessment Today Maintaining the security of your business data is much tougher and more critical than it’s ever been before. Don’t leave yourself open to fines, litigation, or the front page news. Network Services Group (NSG) provides an IT security assessment (also known as a security audit or security review) which will help - [NSG SD-WAN](https://www.netservicesgroup.com/nsg-sd-wan/) - Software Defined WAN | SD-WAN Simplify Branch Office Networking and Assure Optimal Application Performance Network Services Group (NSG) Managed SD-WAN Solutions NSG SD-WAN is a fully managed Software-Defined WAN (SD-WAN) Solution that provides significant value to businesses allowing for increased network agility and cost-savings over traditional MPLS or VPN WAN solutions. SD-WAN uses software and cloud-based technology - [NSG Metro Ethernet](https://www.netservicesgroup.com/nsg-metro-ethernet/) - Metro Ethernet Over Fiber Optics As a MPLS provider, Network Services Group (NSG) offers MPLS technology for speeding up network traffic flow and making it easier to manage. In addition to moving overall traffic faster, MPLS is flexible, fast, cost efficient and allows for network segmentation. NSG Fiber Optics With Fiber Optic speed and reliability, - [NSG Managed Services](https://www.netservicesgroup.com/nsg-managed-services/) - SaaS (Software as a Service) for IT Systems Management Network Services Group (NSG) provides you with a single source of professional expertise and resources you need to streamline system management and support functions at an affordable price. NSG uses advanced processes, tools, methodologies and a help line for your employees to deliver superior services that match your needs. Large - [NSG Colocation](https://www.netservicesgroup.com/nsg-colocation/) - Network Services Group (NSG) offers solutions for colocation and disaster recovery for businesses seeking to locate vital infrastructure within a secure data center. Our technology extends our customers a high level of comfort knowing their equipment is stored in the best possible environment. Our wide-ranging colocation services 24/7/365 offerings include: Secure, conditioned floor space for - [NSG Cloud Enabled File Server](https://www.netservicesgroup.com/nsg-cloud-enabled-file-server/) - Cloud enable traditional file servers for modern secure online access, by keeping file server's security and control model, and giving it cloud file sync and share functionality. Network Services Group (NSG) provides secure file server access from any device and location without a VPN and supports hybrid use cases for disaster recovery and business continuity. - [NSG Cloud Computing](https://www.netservicesgroup.com/nsg-cloud-computing/) - Network Services Group (NSG) offers public, private, and hybrid cloud computing solutions. These proven services are joined with the high level of security, redundancy, and reliability our enterprise customers demand. NSG boasts a handful of geographically diversified datacenters across the nation to ensure the uptime of our cloud solutions. Each premium datacenter has multiple redundant - [NSG Backup as a Service](https://www.netservicesgroup.com/nsg-backup-as-a-service/) - Protect your data with the Network Services Group (NSG) rapid, highly adaptable, and effective cloud-based Backup-as-a-Service (BaaS) solution. NSG BaaS provides customers with the additional safety measure they require by protecting and storing their data, making it readily available when needed for restoration. NSG enables a business to restore their data over the network from an - [About Us](https://www.netservicesgroup.com/about-us/) - About Network Services Group Even in a fast-paced, global environment, we still make a priority of sitting down and getting to know you. Our list of clients - and the geographic areas we serve - continue to grow. Our work is not restricted by geographic barriers. We have the pleasure of working with clients around the world. Although technology enables us to - [About Network Services Group](https://www.netservicesgroup.com/about-nsg/) - We provide reliable IT solutions to small and medium-sized businesses Even in a fast-paced, global environment, we still make a priority of sitting down and getting to know you. Our list of clients - and the geographic areas we serve - continue to grow. Our work is not restricted by geographic barriers. We have the pleasure of working with clients around the world. - [Contact Us](https://www.netservicesgroup.com/contact-us/) - Network Services Group is here to serve you. We want your input and your questions. Have ideas on how to improve our service? Want to see a particular new product available? We always appreciate your ideas and suggestions. By serving you, we continue to make Network Services Group a top telecommunications provider! If you want - [Local Engine Optimization](https://www.netservicesgroup.com/local-engine-optimization/) - Network Services Group (NSG) is excited to introduce our local engine optimization (LEO) service. It’s our very special optimization and search engine seeding program designed to improve website rankings. LEO utilizes a combination of software and reporting to manage your business presence, location data, reputation, analytics and website health. Through LEO, Network Services Group can - [Test2 Test2 Test2](https://www.netservicesgroup.com/test2-test2-test2/) - Test2 Test2 Test2 - [Privacy Policy](https://www.netservicesgroup.com/privacy-policy/) - Who we are Suggested text: Our website address is: https://www.netservicesgroup.com. Comments Suggested text: When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection. An anonymized string created from your email address (also called a - [Sample Page](https://www.netservicesgroup.com/sample-page/) - This is an example page. It's different from a blog post because it will stay in one place and will show up in your site navigation (in most themes). Most people start with an About page that introduces them to potential site visitors. It might say something like this: Hi there! I'm a bike messenger ## Categories - [NSG Blog](https://www.netservicesgroup.com/blog/) - [Microsoft Security Response Center Blog Alerts](https://www.netservicesgroup.com/msrc-blog-alerts/) - [US-CERT Blog Alerts](https://www.netservicesgroup.com/us-cert-blog-alerts/) - [Slashdot](https://www.netservicesgroup.com/slashdot/)