Microsoft added three vulnerabilities to its Security Update Guide, including CVE-2026-5874 affecting Chromium and two flaws in jq. The Chromium issue is described as a use-after-free in PrivateAI, a class of memory-safety bug that can lead to crashes or potentially arbitrary code execution depending on exploitability and surrounding mitigations.
The two jq entries, CVE-2026-39979 and CVE-2026-33948, describe input-handling weaknesses in the JSON processor: an out-of-bounds read in jv_parse_sized() error formatting for non-NUL-terminated counted buffers, and an embedded-NUL truncation issue in the CLI JSON input path that can cause prefix-only validation of malformed input. Together, the disclosures highlight memory and parsing risks in widely used software components that may affect systems relying on Chromium-based software or jq for JSON processing.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft added CVE-2026-33948 to its Security Update Guide, describing an embedded-NUL truncation issue in jq CLI JSON input handling that can cause prefix-only validation of malformed input.
Microsoft added CVE-2026-39979 to its Security Update Guide, describing an out-of-bounds read in jq's jv_parse_sized() error formatting for non-NUL-terminated counted buffers.
Microsoft listed CVE-2026-5874 in its Security Update Guide as a Chromium vulnerability described as a use-after-free issue in PrivateAI.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.