PatchaPalooza — Microsoft Patch Tuesday CVEs https://patchapalooza.com/ 2026-03-19T13:36:28.000Z Latest Microsoft Patch Tuesday vulnerabilities tracked by PatchaPalooza. CVE-2026-4224: Stack overflow parsing XML with deeply nested DTD content models https://patchapalooza.com/cve/CVE-2026-4224 2026-03-19T13:36:28.000Z Stack overflow parsing XML with deeply nested DTD content models CVE-2026-4111: Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive https://patchapalooza.com/cve/CVE-2026-4111 2026-03-18T13:36:47.000Z Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive CVE-2026-4105: Systemd: systemd: privilege escalation via improper access control in registermachine d-bus method https://patchapalooza.com/cve/CVE-2026-4105 2026-03-17T00:02:38.000Z Systemd: systemd: privilege escalation via improper access control in registermachine d-bus method CVE-2026-3942: Chromium: CVE-2026-3942 Incorrect security UI in PictureInPicture https://patchapalooza.com/cve/CVE-2026-3942 2026-03-13T17:20:30.000Z Chromium: CVE-2026-3942 Incorrect security UI in PictureInPicture CVE-2026-3941: Chromium: CVE-2026-3941 Insufficient policy enforcement in DevTools https://patchapalooza.com/cve/CVE-2026-3941 2026-03-13T17:20:29.000Z Chromium: CVE-2026-3941 Insufficient policy enforcement in DevTools CVE-2026-3940: Chromium: CVE-2026-3940 Insufficient policy enforcement in DevTools https://patchapalooza.com/cve/CVE-2026-3940 2026-03-13T17:20:28.000Z Chromium: CVE-2026-3940 Insufficient policy enforcement in DevTools CVE-2026-3939: Chromium: CVE-2026-3939 Use after free in WebView https://patchapalooza.com/cve/CVE-2026-3939 2026-03-13T17:20:27.000Z Chromium: CVE-2026-3939 Use after free in WebView CVE-2026-3938: Chromium: CVE-2026-3938 Insufficient policy enforcement in Clipboard https://patchapalooza.com/cve/CVE-2026-3938 2026-03-13T17:20:26.000Z Chromium: CVE-2026-3938 Insufficient policy enforcement in Clipboard CVE-2026-3937: Chromium: CVE-2026-3937 Incorrect security UI in Downloads https://patchapalooza.com/cve/CVE-2026-3937 2026-03-13T17:20:25.000Z Chromium: CVE-2026-3937 Incorrect security UI in Downloads CVE-2026-3936: Chromium: CVE-2026-3936 Use after free in WebView https://patchapalooza.com/cve/CVE-2026-3936 2026-03-13T17:20:24.000Z Chromium: CVE-2026-3936 Use after free in WebView CVE-2026-3935: Chromium: CVE-2026-3935 Incorrect security UI in WebAppInstalls https://patchapalooza.com/cve/CVE-2026-3935 2026-03-13T17:20:23.000Z Chromium: CVE-2026-3935 Incorrect security UI in WebAppInstalls CVE-2026-3934: Chromium: CVE-2026-3934 Insufficient policy enforcement in ChromeDriver https://patchapalooza.com/cve/CVE-2026-3934 2026-03-13T17:20:22.000Z Chromium: CVE-2026-3934 Insufficient policy enforcement in ChromeDriver CVE-2026-3932: Chromium: CVE-2026-3932 Insufficient policy enforcement in PDF https://patchapalooza.com/cve/CVE-2026-3932 2026-03-13T17:20:21.000Z Chromium: CVE-2026-3932 Insufficient policy enforcement in PDF CVE-2026-3931: Chromium: CVE-2026-3931 Heap buffer overflow in Skia https://patchapalooza.com/cve/CVE-2026-3931 2026-03-13T17:20:20.000Z Chromium: CVE-2026-3931 Heap buffer overflow in Skia CVE-2026-3930: Chromium: CVE-2026-3930 Unsafe navigation in Navigation https://patchapalooza.com/cve/CVE-2026-3930 2026-03-13T17:20:19.000Z Chromium: CVE-2026-3930 Unsafe navigation in Navigation CVE-2026-3929: Chromium: CVE-2026-3929 Side-channel information leakage in ResourceTiming https://patchapalooza.com/cve/CVE-2026-3929 2026-03-13T17:20:18.000Z Chromium: CVE-2026-3929 Side-channel information leakage in ResourceTiming CVE-2026-3928: Chromium: CVE-2026-3928 Insufficient policy enforcement in Extensions https://patchapalooza.com/cve/CVE-2026-3928 2026-03-13T17:20:17.000Z Chromium: CVE-2026-3928 Insufficient policy enforcement in Extensions CVE-2026-3927: Chromium: CVE-2026-3927 Incorrect security UI in PictureInPicture https://patchapalooza.com/cve/CVE-2026-3927 2026-03-13T17:20:16.000Z Chromium: CVE-2026-3927 Incorrect security UI in PictureInPicture CVE-2026-3926: Chromium: CVE-2026-3926 Out of bounds read in V8 https://patchapalooza.com/cve/CVE-2026-3926 2026-03-13T17:20:15.000Z Chromium: CVE-2026-3926 Out of bounds read in V8 CVE-2026-3925: Chromium: CVE-2026-3925 Incorrect security UI in LookalikeChecks https://patchapalooza.com/cve/CVE-2026-3925 2026-03-13T17:20:14.000Z Chromium: CVE-2026-3925 Incorrect security UI in LookalikeChecks CVE-2026-3924: Chromium: CVE-2026-3924 Use after free in WindowDialog https://patchapalooza.com/cve/CVE-2026-3924 2026-03-13T17:20:13.000Z Chromium: CVE-2026-3924 Use after free in WindowDialog CVE-2026-3923: Chromium: CVE-2026-3923 Use after free in WebMIDI https://patchapalooza.com/cve/CVE-2026-3923 2026-03-13T17:20:12.000Z Chromium: CVE-2026-3923 Use after free in WebMIDI CVE-2026-3922: Chromium: CVE-2026-3922 Use after free in MediaStream https://patchapalooza.com/cve/CVE-2026-3922 2026-03-13T17:20:11.000Z Chromium: CVE-2026-3922 Use after free in MediaStream CVE-2026-3921: Chromium: CVE-2026-3921 Use after free in TextEncoding https://patchapalooza.com/cve/CVE-2026-3921 2026-03-13T17:20:10.000Z Chromium: CVE-2026-3921 Use after free in TextEncoding CVE-2026-3920: Chromium: CVE-2026-3920 Out of bounds memory access in WebML https://patchapalooza.com/cve/CVE-2026-3920 2026-03-13T17:20:09.000Z Chromium: CVE-2026-3920 Out of bounds memory access in WebML CVE-2026-3919: Chromium: CVE-2026-3919 Use after free in Extensions https://patchapalooza.com/cve/CVE-2026-3919 2026-03-13T17:20:08.000Z Chromium: CVE-2026-3919 Use after free in Extensions CVE-2026-3918: Chromium: CVE-2026-3918 Use after free in WebMCP https://patchapalooza.com/cve/CVE-2026-3918 2026-03-13T17:20:07.000Z Chromium: CVE-2026-3918 Use after free in WebMCP CVE-2026-3917: Chromium: CVE-2026-3917 Use after free in Agents https://patchapalooza.com/cve/CVE-2026-3917 2026-03-13T17:20:06.000Z Chromium: CVE-2026-3917 Use after free in Agents CVE-2026-3916: Chromium: CVE-2026-3916 Out of bounds read in Web Speech https://patchapalooza.com/cve/CVE-2026-3916 2026-03-13T17:20:05.000Z Chromium: CVE-2026-3916 Out of bounds read in Web Speech CVE-2026-3915: Chromium: CVE-2026-3915 Heap buffer overflow in WebML https://patchapalooza.com/cve/CVE-2026-3915 2026-03-13T17:20:04.000Z Chromium: CVE-2026-3915 Heap buffer overflow in WebML CVE-2026-3914: Chromium: CVE-2026-3914 Integer overflow in WebML https://patchapalooza.com/cve/CVE-2026-3914 2026-03-13T17:20:03.000Z Chromium: CVE-2026-3914 Integer overflow in WebML CVE-2026-3913: Chromium: CVE-2026-3913 Heap buffer overflow in WebML https://patchapalooza.com/cve/CVE-2026-3913 2026-03-13T17:20:00.000Z Chromium: CVE-2026-3913 Heap buffer overflow in WebML CVE-2026-3910: Chromium: CVE-2026-3910 Inappropriate implementation in V8 https://patchapalooza.com/cve/CVE-2026-3910 2026-03-13T21:11:14.000Z Chromium: CVE-2026-3910 Inappropriate implementation in V8 CVE-2026-3909: Chromium: CVE-2026-3909 Out of bounds write in Skia https://patchapalooza.com/cve/CVE-2026-3909 2026-03-16T17:09:34.000Z Chromium: CVE-2026-3909 Out of bounds write in Skia CVE-2026-3904: https://patchapalooza.com/cve/CVE-2026-3904 2026-03-13T00:03:00.000Z CVE-2026-3805: use after free in SMB connection reuse https://patchapalooza.com/cve/CVE-2026-3805 2026-03-13T00:03:13.000Z use after free in SMB connection reuse CVE-2026-3784: wrong proxy connection reuse with credentials https://patchapalooza.com/cve/CVE-2026-3784 2026-03-13T00:02:44.000Z wrong proxy connection reuse with credentials CVE-2026-3783: token leak with redirect and netrc https://patchapalooza.com/cve/CVE-2026-3783 2026-03-13T00:02:16.000Z token leak with redirect and netrc CVE-2026-3731: libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds https://patchapalooza.com/cve/CVE-2026-3731 2026-03-20T00:38:05.000Z libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds CVE-2026-3713: pnggroup libpng pnm2png pnm2png.c do_pnm2png heap-based overflow https://patchapalooza.com/cve/CVE-2026-3713 2026-03-11T00:03:59.000Z pnggroup libpng pnm2png pnm2png.c do_pnm2png heap-based overflow CVE-2026-3644: Incomplete control character validation in http.cookies https://patchapalooza.com/cve/CVE-2026-3644 2026-03-19T13:36:37.000Z Incomplete control character validation in http.cookies CVE-2026-3634: Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header https://patchapalooza.com/cve/CVE-2026-3634 2026-03-21T00:02:26.000Z Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header CVE-2026-3633: Libsoup: libsoup: header and http request injection via crlf injection https://patchapalooza.com/cve/CVE-2026-3633 2026-03-21T00:02:43.000Z Libsoup: libsoup: header and http request injection via crlf injection CVE-2026-3632: Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames https://patchapalooza.com/cve/CVE-2026-3632 2026-03-21T00:02:34.000Z Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames CVE-2026-3545: Chromium: CVE-2026-3545 Insufficient data validation in Navigation https://patchapalooza.com/cve/CVE-2026-3545 2026-03-06T20:23:08.000Z Chromium: CVE-2026-3545 Insufficient data validation in Navigation CVE-2026-3544: Chromium: CVE-2026-3544 Heap buffer overflow in WebCodecs https://patchapalooza.com/cve/CVE-2026-3544 2026-03-06T20:23:07.000Z Chromium: CVE-2026-3544 Heap buffer overflow in WebCodecs CVE-2026-3543: Chromium: CVE-2026-3543 Inappropriate implementation in V8 https://patchapalooza.com/cve/CVE-2026-3543 2026-03-06T20:23:06.000Z Chromium: CVE-2026-3543 Inappropriate implementation in V8 CVE-2026-3542: Chromium: CVE-2026-3542 Inappropriate implementation in WebAssembly https://patchapalooza.com/cve/CVE-2026-3542 2026-03-06T20:23:05.000Z Chromium: CVE-2026-3542 Inappropriate implementation in WebAssembly CVE-2026-3541: Chromium: CVE-2026-3541 Inappropriate implementation in CSS https://patchapalooza.com/cve/CVE-2026-3541 2026-03-06T20:23:04.000Z Chromium: CVE-2026-3541 Inappropriate implementation in CSS CVE-2026-3540: Chromium: CVE-2026-3540 Inappropriate implementation in WebAudio https://patchapalooza.com/cve/CVE-2026-3540 2026-03-06T20:23:03.000Z Chromium: CVE-2026-3540 Inappropriate implementation in WebAudio CVE-2026-3539: Chromium: CVE-2026-3539 Object lifecycle issue in DevTools https://patchapalooza.com/cve/CVE-2026-3539 2026-03-06T20:23:02.000Z Chromium: CVE-2026-3539 Object lifecycle issue in DevTools CVE-2026-3538: Chromium: CVE-2026-3538 Integer overflow in Skia https://patchapalooza.com/cve/CVE-2026-3538 2026-03-06T20:23:01.000Z Chromium: CVE-2026-3538 Integer overflow in Skia CVE-2026-3537: Chromium: CVE-2026-3537 Object lifecycle issue in PowerVR https://patchapalooza.com/cve/CVE-2026-3537 2026-03-11T06:00:00.000Z Chromium: CVE-2026-3537 Object lifecycle issue in PowerVR CVE-2026-3536: Chromium: CVE-2026-3536 Integer overflow in ANGLE https://patchapalooza.com/cve/CVE-2026-3536 2026-03-06T20:22:56.000Z Chromium: CVE-2026-3536 Integer overflow in ANGLE CVE-2026-3494: MariaDB Server Audit Plugin Comment Handling Bypass https://patchapalooza.com/cve/CVE-2026-3494 2026-03-14T00:37:11.000Z MariaDB Server Audit Plugin Comment Handling Bypass CVE-2026-3479: pkgutil.get_data() does not enforce documented restrictions https://patchapalooza.com/cve/CVE-2026-3479 2026-03-21T00:03:01.000Z pkgutil.get_data() does not enforce documented restrictions CVE-2026-3381: Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib https://patchapalooza.com/cve/CVE-2026-3381 2026-03-17T13:37:36.000Z Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib CVE-2026-3338: PKCS7_verify Signature Validation Bypass in AWS-LC https://patchapalooza.com/cve/CVE-2026-3338 2026-03-06T00:38:11.000Z PKCS7_verify Signature Validation Bypass in AWS-LC CVE-2026-3336: PKCS7_verify Certificate Chain Validation Bypass in AWS-LC https://patchapalooza.com/cve/CVE-2026-3336 2026-03-06T00:38:19.000Z PKCS7_verify Certificate Chain Validation Bypass in AWS-LC CVE-2026-32778: https://patchapalooza.com/cve/CVE-2026-32778 2026-03-19T00:01:59.000Z CVE-2026-32777: https://patchapalooza.com/cve/CVE-2026-32777 2026-03-19T00:01:43.000Z CVE-2026-32776: https://patchapalooza.com/cve/CVE-2026-32776 2026-03-19T00:01:27.000Z CVE-2026-32775: https://patchapalooza.com/cve/CVE-2026-32775 2026-03-21T00:36:45.000Z CVE-2026-32766: astral-tokio-tar insufficiently validates PAX extensions during extraction https://patchapalooza.com/cve/CVE-2026-32766 2026-03-21T00:02:18.000Z astral-tokio-tar insufficiently validates PAX extensions during extraction CVE-2026-32249: NFA regex engine NULL pointer dereference affects Vim < 9.2.0137 https://patchapalooza.com/cve/CVE-2026-32249 2026-03-17T00:39:07.000Z NFA regex engine NULL pointer dereference affects Vim < 9.2.0137 CVE-2026-32194: Microsoft Bing Images Remote Code Execution Vulnerability https://patchapalooza.com/cve/CVE-2026-32194 2026-03-19T06:00:00.000Z Microsoft Bing Images Remote Code Execution Vulnerability CVE-2026-32191: Microsoft Bing Images Remote Code Execution Vulnerability https://patchapalooza.com/cve/CVE-2026-32191 2026-03-19T06:00:00.000Z Microsoft Bing Images Remote Code Execution Vulnerability CVE-2026-32169: Azure Cloud Shell Elevation of Privilege Vulnerability https://patchapalooza.com/cve/CVE-2026-32169 2026-03-19T06:00:00.000Z Azure Cloud Shell Elevation of Privilege Vulnerability CVE-2026-31802: node-tar Symlink Path Traversal via Drive-Relative Linkpath https://patchapalooza.com/cve/CVE-2026-31802 2026-03-14T00:01:17.000Z node-tar Symlink Path Traversal via Drive-Relative Linkpath CVE-2026-30922: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion https://patchapalooza.com/cve/CVE-2026-30922 2026-03-21T00:02:51.000Z pyasn1 Vulnerable to Denial of Service via Unbounded Recursion CVE-2026-29786: node-tar: Hardlink Path Traversal via Drive-Relative Linkpath https://patchapalooza.com/cve/CVE-2026-29786 2026-03-11T00:02:00.000Z node-tar: Hardlink Path Traversal via Drive-Relative Linkpath CVE-2026-27601: Underscore.js has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack https://patchapalooza.com/cve/CVE-2026-27601 2026-03-17T13:38:08.000Z Underscore.js has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack CVE-2026-27459: pyOpenSSL DTLS cookie callback buffer overflow https://patchapalooza.com/cve/CVE-2026-27459 2026-03-21T00:37:02.000Z pyOpenSSL DTLS cookie callback buffer overflow CVE-2026-27448: pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback https://patchapalooza.com/cve/CVE-2026-27448 2026-03-21T00:36:53.000Z pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback CVE-2026-27142: URLs in meta content attribute actions are not escaped in html/template https://patchapalooza.com/cve/CVE-2026-27142 2026-03-17T13:38:34.000Z URLs in meta content attribute actions are not escaped in html/template CVE-2026-27139: FileInfo can escape from a Root in os https://patchapalooza.com/cve/CVE-2026-27139 2026-03-12T13:36:01.000Z FileInfo can escape from a Root in os CVE-2026-27138: Panic in name constraint checking for malformed certificates in crypto/x509 https://patchapalooza.com/cve/CVE-2026-27138 2026-03-14T00:37:26.000Z Panic in name constraint checking for malformed certificates in crypto/x509 CVE-2026-27137: Incorrect enforcement of email constraints in crypto/x509 https://patchapalooza.com/cve/CVE-2026-27137 2026-03-14T00:37:36.000Z Incorrect enforcement of email constraints in crypto/x509 CVE-2026-27135: nghttp2 Denial of service: Assertion failure due to the missing state validation https://patchapalooza.com/cve/CVE-2026-27135 2026-03-21T00:37:11.000Z nghttp2 Denial of service: Assertion failure due to the missing state validation CVE-2026-2673: OpenSSL TLS 1.3 server may choose unexpected key agreement group https://patchapalooza.com/cve/CVE-2026-2673 2026-03-17T00:02:24.000Z OpenSSL TLS 1.3 server may choose unexpected key agreement group CVE-2026-26148: Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability https://patchapalooza.com/cve/CVE-2026-26148 2026-03-11T06:00:00.000Z Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability CVE-2026-26144: Microsoft Excel Information Disclosure Vulnerability https://patchapalooza.com/cve/CVE-2026-26144 2026-03-10T06:00:00.000Z Microsoft Excel Information Disclosure Vulnerability CVE-2026-26141: Hybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege Vulnerability https://patchapalooza.com/cve/CVE-2026-26141 2026-03-10T06:00:00.000Z Hybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege Vulnerability CVE-2026-26139: Microsoft Purview Elevation of Privilege Vulnerability https://patchapalooza.com/cve/CVE-2026-26139 2026-03-19T06:00:00.000Z Microsoft Purview Elevation of Privilege Vulnerability CVE-2026-26138: Microsoft Purview Elevation of Privilege Vulnerability https://patchapalooza.com/cve/CVE-2026-26138 2026-03-19T06:00:00.000Z Microsoft Purview Elevation of Privilege Vulnerability CVE-2026-26137: Microsoft 365 Copilot BizChat Elevation of Privilege Vulnerability https://patchapalooza.com/cve/CVE-2026-26137 2026-03-19T06:00:00.000Z Microsoft 365 Copilot BizChat Elevation of Privilege Vulnerability CVE-2026-26136: Microsoft Copilot Information Disclosure Vulnerability https://patchapalooza.com/cve/CVE-2026-26136 2026-03-19T06:00:00.000Z Microsoft Copilot Information Disclosure Vulnerability CVE-2026-26134: Microsoft Office Elevation of Privilege Vulnerability https://patchapalooza.com/cve/CVE-2026-26134 2026-03-10T06:00:00.000Z Microsoft Office Elevation of Privilege Vulnerability CVE-2026-26133: M365 Copilot Information Disclosure Vulnerability https://patchapalooza.com/cve/CVE-2026-26133 2026-03-12T06:00:00.000Z M365 Copilot Information Disclosure Vulnerability CVE-2026-26132: Windows Kernel Elevation of Privilege Vulnerability https://patchapalooza.com/cve/CVE-2026-26132 2026-03-10T06:00:00.000Z Windows Kernel Elevation of Privilege Vulnerability CVE-2026-26131: .NET Elevation of Privilege Vulnerability https://patchapalooza.com/cve/CVE-2026-26131 2026-03-10T06:00:00.000Z .NET Elevation of Privilege Vulnerability CVE-2026-26130: ASP.NET Core Denial of Service Vulnerability https://patchapalooza.com/cve/CVE-2026-26130 2026-03-10T06:00:00.000Z ASP.NET Core Denial of Service Vulnerability CVE-2026-26128: Windows SMB Server Elevation of Privilege Vulnerability https://patchapalooza.com/cve/CVE-2026-26128 2026-03-10T06:00:00.000Z Windows SMB Server Elevation of Privilege Vulnerability CVE-2026-26127: .NET Denial of Service Vulnerability https://patchapalooza.com/cve/CVE-2026-26127 2026-03-10T06:00:00.000Z .NET Denial of Service Vulnerability CVE-2026-26125: Payment Orchestrator Service Elevation of Privilege Vulnerability https://patchapalooza.com/cve/CVE-2026-26125 2026-03-05T07:00:00.000Z Payment Orchestrator Service Elevation of Privilege Vulnerability CVE-2026-26124: Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability https://patchapalooza.com/cve/CVE-2026-26124 2026-03-06T07:00:00.000Z Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability CVE-2026-26123: Microsoft Authenticator Information Disclosure Vulnerability https://patchapalooza.com/cve/CVE-2026-26123 2026-03-10T06:00:00.000Z Microsoft Authenticator Information Disclosure Vulnerability CVE-2026-26122: Microsoft ACI Confidential Containers Information Disclosure Vulnerability https://patchapalooza.com/cve/CVE-2026-26122 2026-03-06T07:00:00.000Z Microsoft ACI Confidential Containers Information Disclosure Vulnerability CVE-2026-26121: Azure IOT Explorer Spoofing Vulnerability https://patchapalooza.com/cve/CVE-2026-26121 2026-03-10T06:00:00.000Z Azure IOT Explorer Spoofing Vulnerability CVE-2026-26120: Microsoft Bing Tampering Vulnerability https://patchapalooza.com/cve/CVE-2026-26120 2026-03-19T06:00:00.000Z Microsoft Bing Tampering Vulnerability