Skip to content
ThreatCluster

ReDoS Vulnerabilities in Microsoft Products Announced

First seen 18 Feb 2026, 15:24 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

Two vulnerabilities related to Regular Expression Denial of Service (ReDoS) have been reported. CVE-2020-28493, published on February 1, 2021, and CVE-2021-42836, published on October 22, 2021, both allow attackers to exploit regular expressions in software, potentially leading to denial of service. Affected products include those utilizing these specific CVEs.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 183d ago How this analysis works

Timeline

2021-02-01
CVE-2020-28493 published
2021-10-22
CVE-2021-42836 published
2026-02-18
Information published about both CVEs

More articles in this cluster (2)

Following this threat?

Track CVE-2020-28493 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed