CVE-2026-21260 Microsoft Outlook Spoofing Vulnerability
Published February 12, 2026
Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
Published February 12, 2026
Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
Published February 12, 2026
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
Published February 12, 2026
Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Published February 12, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally.
Published February 12, 2026
Changes made to the security updates links and information. This is an informational change only.
Published February 12, 2026
Acknowledgement added. This is an informational change only.
Published February 12, 2026
Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.
Published February 12, 2026
Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network.
Published February 12, 2026
A heap‑based buffer overflow exists in libjpeg‑turbo’s h2v2_merged_upsample_internal() function when processing 12‑bit lossless JPEG images. An attacker could craft an image containing out‑of‑range 12‑bit samples that, when decompressed with merged upsampling enabled, may trigger a segmentation fault or buffer overflow, resulting in an application crash.
Published February 12, 2026
Null pointer dereference in Windows LDAP – Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.