| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally. |
| Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. |
| Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are fetched from Microsoft's **multi-tenant** JWKS endpoint, an `id_token` minted in *any* Azure tenant — including one the attacker creates — passes signature verification, and the username and role assignments are then read from that attacker-controlled token. Anyone able to register an Azure tenant can therefore authenticate to the Airflow UI with no prior access to the deployment.
The fix for **CVE-2026-59243** was incomplete, and this advisory closes the remaining gap: that fix made the provider verify the `id_token` signature, but did not add issuer or audience checks. Operators who already applied the CVE-2026-59243 fix are **still affected and must upgrade again** — 3.7.3 is the release that shipped that fix, so every version containing it falls inside this affected range. Upgrade to apache-airflow-providers-fab `3.8.1` or later. |
| Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. |
| Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally. |
| Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally. |
| Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally. |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network. |
| Improper link resolution before file access ('link following') in Windows Container Manager Service allows an authorized attacker to bypass a security feature locally. |
| Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disclose information locally. |
| Missing authentication for critical function in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally. |
| Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical attack. |
| Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. |
| Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally. |
| Numeric truncation error in Internet Storage Name Service allows an authorized attacker to disclose information locally. |
| Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally. |
| Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally. |
| Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. |