Microsoft released security guidance for CVE-2026-23359, a flaw in bpf described as a stack out-of-bounds write in devmap, indicating a memory corruption issue in low-level packet processing components. The company also published an advisory for CVE-2026-5283, a Chromium vulnerability in ANGLE caused by an inappropriate implementation, extending the scope of affected software from kernel-adjacent networking code to browser graphics infrastructure.
The advisories were issued through Microsoft's Security Update Guide and identify two distinct vulnerability classes that could affect system and browser security depending on product exposure and patch status. Organizations using Microsoft products that incorporate Linux kernel bpf functionality or Chromium-based components should review the relevant updates for CVE-2026-23359 and CVE-2026-5283 and prioritize remediation based on asset exposure and dependency on those technologies.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft published a Security Update Guide entry for CVE-2026-23359, describing the issue as a bpf stack out-of-bounds write in devmap.
Microsoft added CVE-2026-5283 to its Security Update Guide, identifying the issue as an inappropriate implementation flaw in Chromium's ANGLE component.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
9 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.