Reading view
Chromium: CVE-2026-4450 Out of bounds write in V8
CVE-2026-70125 Microsoft Outlook Remote Code Execution Vulnerability
CISA outlines improvement plan for CVE program
The Cybersecurity and Infrastructure Security Agency published a paper Wednesday that lays out its plan for improving the Common Vulnerabilities and Exposures (CVE) program, a contract for which nearly ended last year before a last-minute reprieve.
The white paper outlines the components of a βQuality Eraβ for the program, widely used as the definitive clearinghouse for data on vulnerabilities in software and other products, even as the number of CVEs surges.Β
βCISA remains committed to leading, growing and sustaining the CVE Program into the foreseeable future, just as weβve done for more than 25 years without fail,β said Chris Butera, acting executive assistant director for cybersecurity. βInformed by CVE community feedback, this whitepaper communicates CISAβs effort to support and enable stronger participation and governance, a program-wide maturation effort.β
The CVE program has been in a βGrowth Era,β according to CISA. Over 67,000 new CVEs have been published in 2026 as of last week, and the National Institute of Standards and Technology National Vulnerability Database program has seen a 263% increase in CVE submissions between 2020 and 2025. Artificial intelligence has furthered the rise.
βThese pressures intensify quality challenges across the CVE ecosystem,β the white paper states. βWhile faster discovery and reporting can improve the value of vulnerability information when records are complete, consistent, timely, and actionable, the same acceleration can expose gaps in processes, tooling, coordination, and accountability β especially when the quality of the submissions is uneven.βΒ
The plan calls for advancing data quality across four key dimensions: transparent and effective program governance, broad and active participation across the global software community, data infrastructure that supports CVE operational functions and reliable CVE record content.
Some vulnerability experts have questioned whether other organizations should take over CISAβs stewardship, given budget cuts at the agency.
Butera invited further feedback from the CVE community on the white paper, which stems from an earlier strategy document on the future of the program.
Some CVE experts that CyberScoop spoke to were supportive of what CISA wants to achieve, but skeptical about elements of the white paper.
βWeβve been working around long-standing quality issues in CVE reports for decades. Incomplete or inconsistent records create real downstream work for the security tools, developers, and organizations trying to determine whether theyβre actually affected and what to do next,β said Sonatypeβs co-founder and chief technology officer Brian Fox. βSo itβs good to see CISA acknowledge that quality has to extend beyond the record itself to governance, infrastructure, and participation across the ecosystem.β
But, he added, βIβll believe weβve entered a βQuality Eraβ when we can see the improvement in the actual data and in the decisions that data enables.β
Tom Alrich, who leads the OWASP PURL Expansion Working Group thatβs focused on establishing a protocol for creating Product URLs for commercial software, said CISAβs white paper ignores a particularly important and growing issue.
βI support everything mentioned. I also support the flag, motherhood and apple pie,β he said.Β βHowever, nothing in there is going to affect the CVE programβs most important problem: that a huge and growing percentage of new CVE records donβt contain a machine-readable software identifier.β
Caitlin Condon, VulnCheckβs vice president of security research, said that βCISA and the CVE program are well-positioned to both observe challenges in this space and to create (and enforce) standards that explicitly state what βqualityβ means in CVE records.β
But she said the white paper was more the basis for a future framework than a full-fledged framework in itself.
βMany of the potential success metrics suggested in the document can be measured today, but simply arenβt shared publicly,β Condon said. βIn future iterations on the framework, Iβd hope to see more transparency on CVE metrics as they stand today, along with reasoning on why those metrics are the right ones (versus simply the things that are easiest to measure qualitatively or quantitatively).β
The post CISA outlines improvement plan for CVE program appeared first on CyberScoop.
Chromium CVE-2026-87536: Use after free in V8
CVE-2026-88097 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
Chromium: CVE-2026-0899 Out of bounds memory access in V8
CVE-2026-55946 Microsoft Copilot Information Disclosure Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-70009 Azure Arc Elevation of Privilege Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69865 Microsoft Container Registry Elevation of Privilege Vulnerability
Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-77903 Microsoft Dataverse Elevation of Privilege Vulnerability
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69399 Azure Arc Elevation of Privilege Vulnerability
CVE-2026-68791 Azure Machine Learning Information Disclosure Vulnerability
Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.
CVE-2026-85885 Microsoft 365 Copilot Elevation of Privilege Vulnerability
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.
CVE-2026-83944 Azure Logic Apps Elevation of Privilege Vulnerability
Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-78501 Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.
CVE-2026-87701 Azure Cosmos DB Elevation of Privilege Vulnerability
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
CVE-2026-70200 Azure Logic Apps Elevation of Privilege Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-85889 Azure AI Foundry Elevation of Privilege Vulnerability
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-85917 Azure AI Foundry Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.