CVE-2026-69304
Last Modified: 8 Sept 2026Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-69465
Last Modified: 8 Sept 2026Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-65812
Last Modified: 8 Sept 2026Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
CVE-2026-65772
Last Modified: 8 Sept 2026Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
CVE-2026-72985
Last Modified: 8 Sept 2026Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-72976
Last Modified: 8 Sept 2026Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally.
CVE-2026-72975
Last Modified: 8 Sept 2026Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
CVE-2026-72977
Last Modified: 8 Sept 2026Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
CVE-2026-72974
Last Modified: 8 Sept 2026Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-72973
Last Modified: 8 Sept 2026Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-72938
Last Modified: 8 Sept 2026Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
CVE-2026-72972
Last Modified: 8 Sept 2026Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-72956
Last Modified: 8 Sept 2026Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
CVE-2026-70570
Last Modified: 8 Sept 2026Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
CVE-2026-70296
Last Modified: 8 Sept 2026Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
CVE-2026-70203
Last Modified: 8 Sept 2026Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.
CVE-2026-69906
Last Modified: 8 Sept 2026Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVE-2026-69904
Last Modified: 8 Sept 2026Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
CVE-2026-69441
Last Modified: 8 Sept 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-58649
Last Modified: 8 Sept 2026Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-69805
Last Modified: 8 Sept 2026External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69439
Last Modified: 8 Sept 2026Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69632
Last Modified: 8 Sept 2026Use after free in Microsoft Office allows an unauthorized attacker to execute code over a network.
CVE-2026-69626
Last Modified: 8 Sept 2026Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
CVE-2026-69477
Last Modified: 8 Sept 2026Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally.
CVE-2026-69629
Last Modified: 8 Sept 2026Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2026-69636
Last Modified: 8 Sept 2026Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
CVE-2026-69614
Last Modified: 8 Sept 2026Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
CVE-2026-69464
Last Modified: 8 Sept 2026Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2026-69615
Last Modified: 8 Sept 2026Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-69442
Last Modified: 8 Sept 2026Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
CVE-2026-69601
Last Modified: 8 Sept 2026Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
CVE-2026-69590
Last Modified: 8 Sept 2026Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
CVE-2026-69607
Last Modified: 8 Sept 2026Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
CVE-2026-69575
Last Modified: 8 Sept 2026Use after free in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
CVE-2026-69568
Last Modified: 8 Sept 2026Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to disclose information locally.
CVE-2026-69593
Last Modified: 8 Sept 2026Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69564
Last Modified: 8 Sept 2026Heap-based buffer overflow in Windows Online Certificate Status Protocol (OCSP) allows an authorized attacker to elevate privileges locally.
CVE-2026-69560
Last Modified: 8 Sept 2026Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69559
Last Modified: 8 Sept 2026Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
CVE-2026-69510
Last Modified: 8 Sept 2026Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-69499
Last Modified: 8 Sept 2026Integer overflow or wraparound in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
CVE-2026-69490
Last Modified: 8 Sept 2026Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-69489
Last Modified: 8 Sept 2026Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69426
Last Modified: 8 Sept 2026Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to execute code locally.
CVE-2026-69417
Last Modified: 8 Sept 2026Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-69409
Last Modified: 8 Sept 2026Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
CVE-2026-69402
Last Modified: 8 Sept 2026Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-69397
Last Modified: 8 Sept 2026Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network.
CVE-2026-69395
Last Modified: 8 Sept 2026Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network.
