Microsoft Windows
Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability — Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feat
2026 continues the year-over-year growth trend in confirmed disclosures. The list below updates as new breaches are reported by Verizon DBIR partners and major security news outlets.
Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability — Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feat
Microsoft Windows NULL Pointer Dereference Vulnerability — Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.
Microsoft Windows Shell Protection Mechanism Failure Vulnerability — Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature ov
Microsoft Windows Improper Privilege Management Vulnerability — Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privile
Microsoft Windows Type Confusion Vulnerability — Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.
Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability — Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized
670K mining operational records exposed in targeted espionage
3.1M customer records accessed via compromised customer service platform
450K customer records exposed in credential harvesting
280K patient records exposed
340K customer utility records exposed via compromised billing system vendor
340K employee and supply records exposed
210K client records compromised via vendor
2.8M customer trading records and SSNs exposed via social engineering attack on support staff
SecurityScorecard has identified over 40,000 OpenClaw deployments exposed to potential attack
640K Skywards member records including travel history and contact data compromised
The services of Florida-based payments platform BridgePay are offline due to a ransomware attack
340K defense and aerospace employee records exposed via LockBit 3.0 ransomware
440K patient records exposed in spear-phishing attack on Massachusetts health system
1.1M taxpayer records exposed via zero-day in myGov authentication system
620K enterprise workflow configurations exposed via compromised instance admin accounts
680K shopper and customer records exposed via third-party payment processor compromise
9.4M passenger records re-exposed as 2018 breach data reappears on new dark web marketplace
380K student and staff records compromised in targeted phishing campaign