Вторник обновлений
май 2026 г.
Во второй вторник месяца Microsoft, Adobe, SAP, Siemens и Schneider Electric публикуют пакетно; Oracle — в третий вторник января, апреля, июля и октября. Здесь записи того дня из нашей базы, по баллу действия: сначала KEV и зрелые эксплойты.
Как считается: метка CNA + дата публикации (окно два дня, UTC). Полного соответствия бюллетеню производителя не утверждается; внеплановые обновления выходят в другие дни.
записей: 197 · KEV: 0
Затрагивают ваш стек
Записи этого месяца, совпадающие с продуктами и версиями вашего стека.
Войдите, чтобы увидеть совпадения со стеком; записи и уведомления бесплатны. →
Microsoft · 12 мая
125 · KEV: 0 · критических: 9| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2026-33821Эксплойта нет | Microsoft Dynamics 365 Customer Insights Elevation of Privilege Vulnerabilitymicrosoft · dynamics 365 customer insights · CWE-269 | Критическая9,9 | — | 0,8 % | 12 мая 2026 г. |
39Наблюдать | CVE-2026-41089Proof of concept | Windows Netlogon Remote Code Execution Vulnerabilitymicrosoft · windows server 2012 · CWE-121 | Критическая9,8 | — | 1,0 % | 12 мая 2026 г. |
39Наблюдать | CVE-2026-41096Proof of concept | Windows DNS Client Remote Code Execution Vulnerabilitymicrosoft · windows 11 23h2 · CWE-122 | Критическая9,8 | — | 1,0 % | 12 мая 2026 г. |
39Наблюдать | CVE-2026-42823Эксплойта нет | Azure Logic Apps Elevation of Privilege Vulnerabilitymicrosoft · azure logic apps · CWE-284 | Критическая9,9 | — | 0,8 % | 12 мая 2026 г. |
39Наблюдать | CVE-2026-42898Эксплойта нет | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerabilitymicrosoft · dynamics 365 · CWE-94 | Критическая9,9 | — | 1,0 % | 12 мая 2026 г. |
37Наблюдать | CVE-2026-40402Эксплойта нет | Windows Hyper-V Elevation of Privilege Vulnerabilitymicrosoft · windows 11 23h2 · CWE-416 | Критическая9,3 | — | 0,4 % | 12 мая 2026 г. |
36Наблюдать | CVE-2026-33110Эксплойта нет | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-502 | Высокая8,8 | — | 2,3 % | 12 мая 2026 г. |
36Наблюдать | CVE-2026-33112Эксплойта нет | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-502 | Высокая8,8 | — | 2,3 % | 12 мая 2026 г. |
36Наблюдать | CVE-2026-33117Эксплойта нет | Azure SDK for Java Security Feature Bypass Vulnerabilitymicrosoft · azure sdk for java · CWE-287 | Критическая9,1 | — | 0,5 % | 12 мая 2026 г. |
36Наблюдать | CVE-2026-35439Эксплойта нет | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-502 | Высокая8,8 | — | 2,3 % | 12 мая 2026 г. |
36Наблюдать | CVE-2026-40357Эксплойта нет | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-502 | Высокая8,8 | — | 2,3 % | 12 мая 2026 г. |
36Наблюдать | CVE-2026-41103Эксплойта нет | Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerabilitymicrosoft · confluence saml sso · CWE-303 | Критическая9,1 | — | 0,8 % | 12 мая 2026 г. |
- CVE-2026-3382139Наблюдать
Microsoft Dynamics 365 Customer Insights Elevation of Privilege Vulnerability
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %microsoft · dynamics 365 customer insights12 мая 2026 г.
- CVE-2026-4108939Наблюдать
Windows Netlogon Remote Code Execution Vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 1 %microsoft · windows server 201212 мая 2026 г.
- CVE-2026-4109639Наблюдать
Windows DNS Client Remote Code Execution Vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 1 %microsoft · windows 11 23h212 мая 2026 г.
- CVE-2026-4282339Наблюдать
Azure Logic Apps Elevation of Privilege Vulnerability
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %microsoft · azure logic apps12 мая 2026 г.
- CVE-2026-4289839Наблюдать
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %microsoft · dynamics 36512 мая 2026 г.
- CVE-2026-4040237Наблюдать
Windows Hyper-V Elevation of Privilege Vulnerability
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %microsoft · windows 11 23h212 мая 2026 г.
- CVE-2026-3311036Наблюдать
Microsoft SharePoint Server Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %microsoft · sharepoint server12 мая 2026 г.
- CVE-2026-3311236Наблюдать
Microsoft SharePoint Server Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %microsoft · sharepoint server12 мая 2026 г.
- CVE-2026-3311736Наблюдать
Azure SDK for Java Security Feature Bypass Vulnerability
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %microsoft · azure sdk for java12 мая 2026 г.
- CVE-2026-3543936Наблюдать
Microsoft SharePoint Server Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %microsoft · sharepoint server12 мая 2026 г.
- CVE-2026-4035736Наблюдать
Microsoft SharePoint Server Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %microsoft · sharepoint server12 мая 2026 г.
- CVE-2026-4110336Наблюдать
Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %microsoft · confluence saml sso12 мая 2026 г.
+113 ещёВсе записи производителя
Adobe · 12 мая
51 · KEV: 0 · критических: 2| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2026-34659Эксплойта нет | Adobe Connect | Deserialization of Untrusted Data (CWE-502)adobe · connect desktop application · CWE-502 | Критическая9,6 | — | 1,9 % | 12 мая 2026 г. |
37Наблюдать | CVE-2026-34660Эксплойта нет | Adobe Connect | Incorrect Authorization (CWE-863)adobe · connect desktop application · CWE-863 | Критическая9,3 | — | 1,0 % | 12 мая 2026 г. |
34Наблюдать | CVE-2026-34653Эксплойта нет | Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)adobe · commerce · CWE-22 | Высокая8,7 | — | 1,0 % | 12 мая 2026 г. |
34Наблюдать | CVE-2026-34686Эксплойта нет | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)adobe · commerce · CWE-79 | Высокая8,7 | — | 0,7 % | 12 мая 2026 г. |
31Наблюдать | CVE-2026-34636Эксплойта нет | Premiere Pro | Out-of-bounds Write (CWE-787)adobe · premiere pro · CWE-787 | Высокая7,8 | — | 0,3 % | 12 мая 2026 г. |
31Наблюдать | CVE-2026-34637Эксплойта нет | Premiere Pro | Out-of-bounds Write (CWE-787)adobe · premiere pro · CWE-787 | Высокая7,8 | — | 0,3 % | 12 мая 2026 г. |
31Наблюдать | CVE-2026-34638Эксплойта нет | Premiere Pro | Use After Free (CWE-416)adobe · premiere pro · CWE-416 | Высокая7,8 | — | 0,4 % | 12 мая 2026 г. |
31Наблюдать | CVE-2026-34639Эксплойта нет | Media Encoder | Out-of-bounds Write (CWE-787)adobe · media encoder · CWE-787 | Высокая7,8 | — | 0,3 % | 12 мая 2026 г. |
31Наблюдать | CVE-2026-34640Эксплойта нет | Media Encoder | Integer Overflow or Wraparound (CWE-190)adobe · media encoder · CWE-190 | Высокая7,8 | — | 0,3 % | 12 мая 2026 г. |
31Наблюдать | CVE-2026-34642Эксплойта нет | After Effects | Heap-based Buffer Overflow (CWE-122)adobe · after effects · CWE-122 | Высокая7,8 | — | 0,3 % | 12 мая 2026 г. |
31Наблюдать | CVE-2026-34643Эксплойта нет | After Effects | Out-of-bounds Write (CWE-787)adobe · after effects · CWE-787 | Высокая7,8 | — | 0,3 % | 12 мая 2026 г. |
31Наблюдать | CVE-2026-34644Эксплойта нет | After Effects | Integer Overflow or Wraparound (CWE-190)adobe · after effects · CWE-190 | Высокая7,8 | — | 0,3 % | 12 мая 2026 г. |
- CVE-2026-3465939Наблюдать
Adobe Connect | Deserialization of Untrusted Data (CWE-502)
КритическаяCVSS 9,6Эксплойта нетEPSS 2 %adobe · connect desktop application12 мая 2026 г.
- CVE-2026-3466037Наблюдать
Adobe Connect | Incorrect Authorization (CWE-863)
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %adobe · connect desktop application12 мая 2026 г.
- CVE-2026-3465334Наблюдать
Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %adobe · commerce12 мая 2026 г.
- CVE-2026-3468634Наблюдать
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %adobe · commerce12 мая 2026 г.
- CVE-2026-3463631Наблюдать
Premiere Pro | Out-of-bounds Write (CWE-787)
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %adobe · premiere pro12 мая 2026 г.
- CVE-2026-3463731Наблюдать
Premiere Pro | Out-of-bounds Write (CWE-787)
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %adobe · premiere pro12 мая 2026 г.
- CVE-2026-3463831Наблюдать
Premiere Pro | Use After Free (CWE-416)
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %adobe · premiere pro12 мая 2026 г.
- CVE-2026-3463931Наблюдать
Media Encoder | Out-of-bounds Write (CWE-787)
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %adobe · media encoder12 мая 2026 г.
- CVE-2026-3464031Наблюдать
Media Encoder | Integer Overflow or Wraparound (CWE-190)
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %adobe · media encoder12 мая 2026 г.
- CVE-2026-3464231Наблюдать
After Effects | Heap-based Buffer Overflow (CWE-122)
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %adobe · after effects12 мая 2026 г.
- CVE-2026-3464331Наблюдать
After Effects | Out-of-bounds Write (CWE-787)
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %adobe · after effects12 мая 2026 г.
- CVE-2026-3464431Наблюдать
After Effects | Integer Overflow or Wraparound (CWE-190)
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %adobe · after effects12 мая 2026 г.
+39 ещёВсе записи производителя
SAP · 12 мая
0 · KEV: 0 · критических: 0В этом окне записей нет.
Siemens · 12 мая
18 · KEV: 0 · критических: 3| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
37Наблюдать | CVE-2026-25786Эксплойта нет | Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interfacesiemens · simatic drive controller cpu 1504d tf · CWE-79 | Критическая9,3 | — | 0,5 % | 12 мая 2026 г. |
37Наблюдать | CVE-2026-25787Эксплойта нет | Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the siemens · simatic drive controller cpu 1504d tf · CWE-79 | Критическая9,3 | — | 0,5 % | 12 мая 2026 г. |
37Наблюдать | CVE-2026-41551Proof of concept | A vulnerability has been identified in ROS# (All versions < V2.2.2).siemens · ros# · CWE-23 | Критическая9,3 | — | 0,6 % | 12 мая 2026 г. |
35Наблюдать | CVE-2025-40949Эксплойта нет | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEsiemens · ruggedcom rox mx5000 firmware · CWE-78 | Высокая8,9 | — | 0,7 % | 12 мая 2026 г. |
35Наблюдать | CVE-2026-22924Эксплойта нет | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0).siemens · simatic cn 4100 firmware · CWE-306 | Высокая8,8 | — | 0,3 % | 12 мая 2026 г. |
34Наблюдать | CVE-2025-40833Эксплойта нет | The affected devices contain a null pointer dereference vulnerability while processing specially crafted IPv4 requests.siemens · ie/pb link ha · CWE-476 | Высокая8,7 | — | 0,3 % | 12 мая 2026 г. |
34Наблюдать | CVE-2026-22925Эксплойта нет | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0).siemens · simatic cn 4100 firmware · CWE-770 | Высокая8,7 | — | 0,3 % | 12 мая 2026 г. |
34Наблюдать | CVE-2026-33862Эксплойта нет | A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcentesiemens · teamcenter · CWE-79 | Высокая8,5 | — | 0,3 % | 12 мая 2026 г. |
34Наблюдать | CVE-2026-33893Эксплойта нет | A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcentesiemens · teamcenter · CWE-798 | Высокая8,7 | — | 0,4 % | 12 мая 2026 г. |
30Наблюдать | CVE-2025-40947Эксплойта нет | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEsiemens · ruggedcom rox mx5000 firmware · CWE-78 | Высокая7,7 | — | 0,5 % | 12 мая 2026 г. |
29Наблюдать | CVE-2026-44411Эксплойта нет | A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5).siemens · solid edge se2026 · CWE-824 | Высокая7,3 | — | 0,2 % | 12 мая 2026 г. |
29Наблюдать | CVE-2026-44412Эксплойта нет | A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5).siemens · solid edge se2026 · CWE-121 | Высокая7,3 | — | 0,2 % | 12 мая 2026 г. |
- CVE-2026-2578637Наблюдать
Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interface
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %siemens · simatic drive controller cpu 1504d tf12 мая 2026 г.
- CVE-2026-2578737Наблюдать
Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %siemens · simatic drive controller cpu 1504d tf12 мая 2026 г.
- CVE-2026-4155137Наблюдать
A vulnerability has been identified in ROS# (All versions < V2.2.2).
КритическаяCVSS 9,3Proof of conceptEPSS 1 %siemens · ros#12 мая 2026 г.
- CVE-2025-4094935Наблюдать
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGE
ВысокаяCVSS 8,9Эксплойта нетEPSS 1 %siemens · ruggedcom rox mx5000 firmware12 мая 2026 г.
- CVE-2026-2292435Наблюдать
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0).
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %siemens · simatic cn 4100 firmware12 мая 2026 г.
- CVE-2025-4083334Наблюдать
The affected devices contain a null pointer dereference vulnerability while processing specially crafted IPv4 requests.
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %siemens · ie/pb link ha12 мая 2026 г.
- CVE-2026-2292534Наблюдать
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0).
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %siemens · simatic cn 4100 firmware12 мая 2026 г.
- CVE-2026-3386234Наблюдать
A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcente
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %siemens · teamcenter12 мая 2026 г.
- CVE-2026-3389334Наблюдать
A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcente
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %siemens · teamcenter12 мая 2026 г.
- CVE-2025-4094730Наблюдать
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGE
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %siemens · ruggedcom rox mx5000 firmware12 мая 2026 г.
- CVE-2026-4441129Наблюдать
A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5).
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %siemens · solid edge se202612 мая 2026 г.
- CVE-2026-4441229Наблюдать
A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5).
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %siemens · solid edge se202612 мая 2026 г.
+6 ещёВсе записи производителя
Schneider Electric · 12 мая
3 · KEV: 0 · критических: 0| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2026-4827Эксплойта нет | Insufficient Entropy vulnerability on Multiple Productsschneider electric · easergy micom c264 · CWE-331 | Высокая8,7 | — | 0,4 % | 12 мая 2026 г. |
32Наблюдать | CVE-2026-6866Эксплойта нет | Initialization of a Resource with an Insecure Default vulnerability on EcoStruxure™ Panel Serverschneider-electric · ecostruxure panel server pas400 firmware · CWE-1188 | Высокая8,2 | — | 0,5 % | 12 мая 2026 г. |
28Наблюдать | CVE-2026-6865Эксплойта нет | Improper Limitation of a Pathname to a Restricted Directory Vulnerability on Multiple Productsschneider electric · easylogic t150 (formerly saitel dr) remote terminal unit & controller · CWE-22 | Высокая7,1 | — | 0,4 % | 12 мая 2026 г. |
- CVE-2026-482734Наблюдать
Insufficient Entropy vulnerability on Multiple Products
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %schneider electric · easergy micom c26412 мая 2026 г.
- CVE-2026-686632Наблюдать
Initialization of a Resource with an Insecure Default vulnerability on EcoStruxure™ Panel Server
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %schneider-electric · ecostruxure panel server pas400 firmware12 мая 2026 г.
- CVE-2026-686528Наблюдать
Improper Limitation of a Pathname to a Restricted Directory Vulnerability on Multiple Products
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %schneider electric · easylogic t150 (formerly saitel dr) remote terminal unit & controller12 мая 2026 г.