Only two 0days this month for MS? Bummer. https:// msrc.microsoft.com/update-guid e/vulnerability/CVE-2026-81963 https:// msrc.microsoft.com/update-guid e/vulnerability/CVE-2026-85880

Only two 0days this month for MS? Bummer.

4 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

I explicitly don't want to complain about MSRC here, this is a bigger topic, but I am a bit confused here: Compare these two: https:// msrc.microsoft.com/update-guid e/vulnerability/CVE-2026-81954 - A

mastodon:infosec-exchangeother21d ago kagi ↗

I explicitly don't want to complain about MSRC here, this is a bigger topic, but I am a bit confused here: Compare these two: https:// msrc.microsoft.com/update-guid e/vulnerability/CVE-2026-81954 - AV:L,UI:R Q: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? A: An attacker must send a user a malicious Office file and convince them to

I'm also quickly going to mention this, explicitly not as a complaint but as a good case study of a well chosen "SHOULD" & why should is better than must here: https://www. cve.org/ResourcesSupport/Al

mastodon:infosec-exchangeother21d ago kagi ↗

I'm also quickly going to mention this, explicitly not as a complaint but as a good case study of a well chosen "SHOULD" & why should is better than must here: https://www. cve.org/ResourcesSupport/AllRe sources/CNARules#section_5-1_Required_CVE_Record_Content 5.1.1 SHOULD contain sufficient information to uniquely identify the Vulnerability and distinguish it from similar Vulnerabilities. This, u