CVEs have been published or revised in the Security Update Guide
February 5, 2026
These common vulnerabilities and exposures (CVEs) were recently published or revised in the Microsoft Security Update Guide:
- Title: Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
- Version: 1.0
- Reason for revision: Information published.
- Originally released: December 4, 2025
- Last updated: December 4, 2025
- Aggregate CVE severity rating: Moderate
- Customer action required: Yes
- Title: Chromium: CVE-2026-1861 Heap buffer overflow in libvpx
- Version: 1.0
- Reason for revision: Information published.
- Originally released: February 5, 2026
- Last updated: February 5, 2026
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Azure Function Information Disclosure Vulnerability
- Version: 1.0
- Reason for revision: Information published.
- Originally released: February 5, 2026
- Last updated: February 5, 2026
- Aggregate CVE severity rating: Critical
- Customer action required: No
- Title: Azure Front Door Elevation of Privilege Vulnerability
- Version: 1.0
- Reason for revision: Information published.
- Originally released: February 5, 2026
- Last updated: February 5, 2026
- Aggregate CVE severity rating: Critical
- Customer action required: No
- Title: Azure Arc Elevation of Privilege Vulnerability
- Version: 1.0
- Reason for revision: Information published.
- Originally released: February 5, 2026
- Last updated: February 5, 2026
- Aggregate CVE severity rating: Critical
Customer action required: No