Findings
A selection of the security vulnerabilities I’ve identified in widely used software. Each one was reported to the vendor first, and each is now fixed.
Microsoft
- CVE-2026-73014
Windows — Privilege escalation
- CVE-2026-20943
Microsoft Office — Privilege escalation
Bootloaders and firmware
- CVE-2026-29007
U-Boot — Out-of-bounds read
- CVE-2026-29008
U-Boot — Integer underflow
- CVE-2026-29009
U-Boot — Buffer overflow
- CVE-2026-34960
barebox — Out-of-bounds read
- CVE-2026-34961
barebox — Out-of-bounds read
- CVE-2026-34962
barebox — Infinite loop
- CVE-2026-34963
barebox — Memory-safety flaw
- CVE-2026-29004
BusyBox — Heap buffer overflow
Network and cryptography
- CVE-2026-25075
strongSwan — Integer underflow
Developer tools and libraries
- CVE-2026-5917
libgit2 — Command injection