Microsoft published security advisories for two vulnerabilities tracked as CVE-2026-23307 and CVE-2026-23370, both tied to Linux kernel driver code. CVE-2026-23307 affects the ems_usb component, where ems_usb_read_bulk_callback() was updated to properly validate message length, indicating a flaw that could stem from insufficient bounds checking during USB message handling.
The second issue, CVE-2026-23370, affects the platform/x86 dell-wmi-sysman driver, where plaintext password data could be exposed through hexadecimal dump output. The advisories point to fixes intended to prevent sensitive credential material from being logged or disclosed, highlighting risks from both memory-handling weaknesses and inadvertent exposure of authentication data in low-level system drivers.

See affected versions and whether adversaries are exploiting it.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.