Microsoft added Security Update Guide entries for multiple third-party vulnerabilities, including Chromium flaws CVE-2026-8574 and CVE-2025-13223 and an Adobe Systems Incorporated issue tracked as CVE-2024-20721. The Chromium advisories identify a use-after-free in Core and a type confusion in V8, both bug classes commonly associated with browser instability and potential code-execution risk depending on exploit conditions.
Microsoft also listed CVE-2024-20721 as an improper input validation vulnerability that can cause denial of service in Adobe software. The entries appear in Microsoft's Security Update Guide as vendor-linked advisories, giving defenders a consolidated reference point to track affected third-party components and prioritize patch validation across browsers and Adobe-dependent environments.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft's Security Update Guide publishes CVE-2026-8574, a Chromium use-after-free vulnerability in Core. The advisory was published on 2026-05-16.
Microsoft's Security Update Guide lists CVE-2025-13223, a Chromium type confusion vulnerability in V8. The advisory was published on 2025-11-18.
Microsoft's Security Update Guide lists CVE-2024-20721, an Adobe Systems Incorporated improper input validation denial-of-service vulnerability. The advisory was published on 2024-11-01.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.