Protecting Privacy Build Trust

Protecting Privacy Build Trust
  • Contact Us

Privacy Trust

on June 16, 2026 at 2:00 pm — CVE-2026-40371 Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability 

Updated the fixed version information and download link. The fix was previously believed to be included in Dynamics 365 Server (on-premises) version 6.2; however, it has been confirmed that the fix is included in Dynamics 365 Server v9.1 (on-premises) Update 1.45 (version 9.1.0045.0011). The download link, release notes, and build number has been updated accordingly

on June 16, 2026 at 2:00 pm — CVE-2026-40371 Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability  Read More »

on June 16, 2026 at 2:00 pm — CVE-2026-50656 Microsoft Defender Elevation of Privilege Vulnerability 

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as “RoguePlanet “. We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available. 

on June 16, 2026 at 2:00 pm — CVE-2026-50656 Microsoft Defender Elevation of Privilege Vulnerability  Read More »

on June 16, 2026 at 8:01 am — CVE-2026-54411 Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module’s plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate’s length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext. 

Information published. 

on June 16, 2026 at 8:01 am — CVE-2026-54411 Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module’s plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate’s length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.  Read More »

on June 15, 2026 at 2:00 pm — Chromium: CVE-2026-12016 Insufficient validation of untrusted input  DevTools 

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information. 

on June 15, 2026 at 2:00 pm — Chromium: CVE-2026-12016 Insufficient validation of untrusted input  DevTools  Read More »