CVEs have been published or revised in the Security Update Guide
April 2, 2026
These common vulnerabilities and exposures (CVEs) were recently published or revised in the Microsoft Security Update Guide:
- Title: Azure Custom Locations Resource Provider (RP) Elevation of Privilege Vulnerability
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating: Critical
- Customer action required: No
- Title: Azure SRE Agent Information Disclosure Vulnerability
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating: Critical
- Customer action required: No
- Title: Microsoft Bing Elevation of Privilege Vulnerability
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating: Critical
- Customer action required: No
- Title: Azure MCP Server Information Disclosure Vulnerability
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating: Critical
- Customer action required: No
- Title: Azure AI Foundry Elevation of Privilege Vulnerability
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating: Critical
- Customer action required: No
- Title: Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating: Critical
- Customer action required: No
- Title: Azure Databricks Elevation of Privilege Vulnerability
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating: Critical
- Customer action required: No
- Title: Chromium: CVE-2026-5272 Heap buffer overflow in GPU
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2026-5273 Use after free in CSS
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2026-5274 Integer overflow in Codecs
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2026-5275 Heap buffer overflow in ANGLE
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2026-5276 Insufficient policy enforcement in WebUSB
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2026-5277 Integer overflow in ANGLE
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2026-5279 Object corruption in V8
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2026-5280 Use after free in WebCodecs
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2026-5281 Use after free in Dawn
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2026-5283 Inappropriate implementation in ANGLE
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2026-5284 Use after free in Dawn
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2026-5285 Use after free in WebGL
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2026-5286 Use after free in Dawn
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2026-5287 Use after free in PDF
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2026-5289 Use after free in Navigation
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2026-5290 Use after free in Compositing
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2026-5291 Inappropriate implementation in WebGL
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2026-5292 Out of bounds read in WebCodecs
- Version: 1.0
- Reason for revision: Information published.
- Originally released: April 2, 2026
- Last updated: April 2, 2026
- Aggregate CVE severity rating:
Customer action required: Yes
