Microsoft published security advisories for multiple vulnerabilities, including CVE-2026-40622, described as another "ghost domain names" attack variant, and CVE-2025-14524, which involves a bearer token leak on cross-protocol redirect. The disclosures indicate risks tied to identity, authentication, and trust boundaries, where attackers could potentially abuse domain-related conditions or redirect behavior to expose sensitive tokens.
The referenced advisories also include CVE-2022-21123, an Intel issue tracked by Microsoft as Shared Buffers Data Read (SBDR), highlighting continued visibility into hardware-level data exposure alongside software and cloud security flaws. Together, the notices show Microsoft updating customers on a mix of domain abuse, token leakage, and processor data-read vulnerabilities that could affect enterprise environments if left unpatched or unmitigated.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft published a Security Update Guide entry for CVE-2026-40622, describing it as another 'ghost domain names' attack variant.
Microsoft published a Security Update Guide entry for CVE-2025-14524, described as a bearer token leak on cross-protocol redirect.
Microsoft listed CVE-2022-21123 in its Security Update Guide, describing it as an Intel Shared Buffers Data Read (SBDR) issue.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.