CVE-2026-68489 CVE-2026-68489 — Static Code Injection in Plesk extensions "Ruby" befo... · 2 days ago CVE-2026-19583 [CRITICAL] CVE-2026-19583 — Velociraptor allows some sensitive artifacts to be ga... · 6 days ago CVE-2026-67277 [CRITICAL] CVE-2026-67277 — MikroTik RouterOS Missing Authentication for Critical... · 1 week ago CVE-2026-86060 [CRITICAL] CVE-2026-86060 — MikroTik RouterOS Improper Neutralization of Argument... · 1 week ago CVE-2025-25249 [CRITICAL] CVE-2025-25249 — Fortinet Multiple Products Heap-based Buffer Overflow... · 1 week ago CVE-2026-69412 CVE-2026-69412 — Stack-based buffer overflow in Windows DHCP Server al... · 1 week ago CVE-2026-69266 CVE-2026-69266 — Integer overflow or wraparound in Windows DHCP Server... · 1 week ago CVE-2026-85880 [CRITICAL] CVE-2026-85880 — Microsoft Windows Heap-Based Buffer Overflow Vulnerab... · 1 week ago CVE-2026-81963 [CRITICAL] CVE-2026-81963 — Microsoft Windows Link Following Vulnerability · 1 week ago ZTNA Portal Improper Certificate Validation · 1 week ago CVE-2026-68489 CVE-2026-68489 — Static Code Injection in Plesk extensions "Ruby" befo... · 2 days ago CVE-2026-19583 [CRITICAL] CVE-2026-19583 — Velociraptor allows some sensitive artifacts to be ga... · 6 days ago CVE-2026-67277 [CRITICAL] CVE-2026-67277 — MikroTik RouterOS Missing Authentication for Critical... · 1 week ago CVE-2026-86060 [CRITICAL] CVE-2026-86060 — MikroTik RouterOS Improper Neutralization of Argument... · 1 week ago CVE-2025-25249 [CRITICAL] CVE-2025-25249 — Fortinet Multiple Products Heap-based Buffer Overflow... · 1 week ago CVE-2026-69412 CVE-2026-69412 — Stack-based buffer overflow in Windows DHCP Server al... · 1 week ago CVE-2026-69266 CVE-2026-69266 — Integer overflow or wraparound in Windows DHCP Server... · 1 week ago CVE-2026-85880 [CRITICAL] CVE-2026-85880 — Microsoft Windows Heap-Based Buffer Overflow Vulnerab... · 1 week ago CVE-2026-81963 [CRITICAL] CVE-2026-81963 — Microsoft Windows Link Following Vulnerability · 1 week ago ZTNA Portal Improper Certificate Validation · 1 week ago
İdeal Çözümler // Infrastructure Security Intelligence

RADAR

Security intelligence for your infrastructure.
Ubuntu Server, Windows Server, Proxmox VE, Plesk, FortiGate / FortiOS and 6 more platforms — track vulnerabilities, critical patches and release news on a single screen. Stay a step ahead with verified, prioritised and actionable intelligence.

Active Advisories
0
Critical
0
Last 30 Days
0
Views
0
Search

Windows Server Feed

RESET FILTERS ↺
Windows Server 06 Jul 2026
Critical · 9.8

CVE-2026-9182 — Esri ArcGIS Server contains an unrestricted file upload vulnerability.

Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload, potentially allowing for other attacks. This issue impacts all versions of ArcGIS Server on Windows and Linux 12.0 and prior. This issue does not impact ArcGIS Enterprise for Kubernetes.

CVE-2026-9182 Vulnerability 44
Windows Server 22 Jun 2026
High · 8.7

CVE-2026-53779 — WebP Server Go through 0.14.4 contains a path traversal vulnerability on Windows that allows unauthenticated attackers t

WebP Server Go through 0.14.4 contains a path traversal vulnerability on Windows that allows unauthenticated attackers to read files outside the configured IMG_PATH directory by sending requests with percent-encoded backslashes (%5C) that bypass the path.Clean() sanitization in handler/router.go. Attackers can exploit the discrepancy between Go's forward-slash-only path normalization and Windows file system APIs that treat backslashes and forward slashes as equivalent to acce

CVE-2026-53779 Vulnerability 38
Windows Server 22 Jun 2026
High · 8.2

CVE-2026-53571 — Vite is a frontend tooling framework for JavaScript.

Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive files through server.fs.deny, including entries such as .env, .env.*, and *.{crt,pem}. However, on Windows, the deny logic does not correctly normalize NTFS ADS path forms before access checks are applied. Because of this, requests such a

CVE-2026-53571 Vulnerability 40
Windows Server 22 Jun 2026
High · 8.3

CVE-2026-54100 — A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform.

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can capture WICD and kubelet bootstrap credentials transferred during node configuration, enabling compromise of Windows node identities in the cluster.

CVE-2026-54100 Vulnerability 36
Windows Server 19 Jun 2026
High · 8.8

CVE-2026-49357 — Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly o

Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly operate the LINE Desktop application on Windows or Mac via MCP. `line-desktop-mcp` supports a `--http-mode` Streamable HTTP transport for use with clients such as n8n. In this mode the server binds to `0.0.0.0` and exposes the MCP `/mcp` endpoint without an MCP-layer authentication check. Prior to version 1.1.2, any network client that can reach the port can

CVE-2026-49357 Vulnerability 37
Windows Server 17 Jun 2026
High · 8.9

CVE-2026-48989 — Windows-MCP is an open-source project that integrates AI agents with Windows.

Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP modes exposed the MCP control plane without authentication while enabling wildcard CORS (allow_origins=*, allow_methods=*, allow_headers=*). Because the same server also exposed a PowerShell tool that executes caller-controlled commands as the Windows user running Windows-MCP, attackers could reach the control plane from arbitrary origins or non-browser clien

CVE-2026-48989 Vulnerability 37
Windows Server 20 May 2026
Critical

CVE-2008-4250 — Microsoft Windows Buffer Overflow Vulnerability

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.

CVE-2008-4250 CISA-KEV Vulnerability 40
Windows Server 17 Feb 2026
Critical

CVE-2008-0015 — Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability

Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.

CVE-2008-0015 CISA-KEV Vulnerability 29

From the agenda

See all →