CVE-2026-58641
Last Modified: 3 Sept 2026Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2026-54981
Last Modified: 17 Aug 2026Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-42976
Last Modified: 14 Aug 2026Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.
CVE-2026-72971
Last Modified: 14 Aug 2026Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
CVE-2026-70355
Last Modified: 14 Aug 2026Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2026-70348
Last Modified: 14 Aug 2026Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
CVE-2026-70347
Last Modified: 14 Aug 2026Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-73089
Last Modified: 14 Aug 2026Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCache without a size cap, TTL, or eviction, allowing an attacker who can influence repeated browserslist() query values, including valid since `<year>-<month>-<day>` queries, to bypass the caller-controlled BROWSERSLIST_DISABLE_CACHE mitigation and cause linear memory growth followed by an out-of-memory process crash. This issue is fixed in version 4.28.7.
CVE-2026-70346
Last Modified: 14 Aug 2026Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-70345
Last Modified: 14 Aug 2026Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-70344
Last Modified: 14 Aug 2026Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-66804
Last Modified: 14 Aug 2026Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
CVE-2026-65783
Last Modified: 13 Aug 2026Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
CVE-2026-61352
Last Modified: 14 Aug 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-65806
Last Modified: 12 Aug 2026Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.
CVE-2026-70340
Last Modified: 12 Aug 2026Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
CVE-2026-57104
Last Modified: 12 Aug 2026Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-70336
Last Modified: 12 Aug 2026Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
CVE-2026-70335
Last Modified: 11 Aug 2026Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
CVE-2026-70330
Last Modified: 18 Aug 2026Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-70304
Last Modified: 17 Aug 2026Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-70329
Last Modified: 14 Aug 2026Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2026-70328
Last Modified: 13 Aug 2026Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-70327
Last Modified: 13 Aug 2026Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-70324
Last Modified: 13 Aug 2026Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2026-70322
Last Modified: 14 Aug 2026Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-70323
Last Modified: 14 Aug 2026Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-70320
Last Modified: 14 Aug 2026Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-70319
Last Modified: 14 Aug 2026Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-70325
Last Modified: 14 Aug 2026Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-70317
Last Modified: 17 Aug 2026Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-70314
Last Modified: 14 Aug 2026Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-70318
Last Modified: 17 Aug 2026Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-70321
Last Modified: 13 Aug 2026Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-70315
Last Modified: 14 Aug 2026Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-70316
Last Modified: 14 Aug 2026Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-70310
Last Modified: 14 Aug 2026Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-70313
Last Modified: 14 Aug 2026Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-70311
Last Modified: 14 Aug 2026Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-70312
Last Modified: 14 Aug 2026Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-66301
Last Modified: 11 Aug 2026Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network.
CVE-2026-65769
Last Modified: 11 Aug 2026Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.
CVE-2026-70307
Last Modified: 14 Aug 2026Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-69306
Last Modified: 11 Aug 2026Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-69278
Last Modified: 12 Aug 2026Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-69320
Last Modified: 12 Aug 2026Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
CVE-2026-68821
Last Modified: 12 Aug 2026Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-68820
Last Modified: 14 Aug 2026Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-68819
Last Modified: 14 Aug 2026Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.
CVE-2026-68816
Last Modified: 13 Aug 2026Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
