| CVE-2026-55038 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55037 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55036 | Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55035 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | low | 2026-07-16 |
| CVE-2026-55034 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | high | 2026-07-15 |
| CVE-2026-55033 | Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55032 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55031 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | high | 2026-07-15 |
| CVE-2026-55030 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | medium | 2026-07-15 |
| CVE-2026-55029 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | high | 2026-07-15 |
| CVE-2026-55028 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | medium | 2026-07-16 |
| CVE-2026-55027 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | medium | 2026-07-16 |
| CVE-2026-55026 | Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally. | medium | 2026-07-16 |
| CVE-2026-55025 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | high | 2026-07-15 |
| CVE-2026-55024 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | high | 2026-07-15 |
| CVE-2026-55023 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | medium | 2026-07-16 |
| CVE-2026-55022 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55021 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | high | 2026-07-15 |
| CVE-2026-55020 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | medium | 2026-07-16 |
| CVE-2026-55019 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | medium | 2026-07-15 |
| CVE-2026-55018 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55017 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55016 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | medium | 2026-07-15 |
| CVE-2026-55010 | Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network. | critical | 2026-07-22 |
| CVE-2026-54131 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | high | 2026-07-15 |
| CVE-2026-54128 | Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally. | high | 2026-07-22 |
| CVE-2026-54126 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | medium | 2026-07-22 |
| CVE-2026-54125 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. | high | 2026-07-21 |
| CVE-2026-54124 | Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally. | high | 2026-07-22 |
| CVE-2026-54121 | Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network. | high | 2026-07-21 |
| CVE-2026-54116 | Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network. | medium | 2026-07-22 |
| CVE-2026-54115 | Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally. | high | 2026-07-21 |
| CVE-2026-50692 | Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | high | 2026-07-22 |
| CVE-2026-50690 | Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. | medium | 2026-07-22 |
| CVE-2026-50689 | Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally. | high | 2026-07-22 |
| CVE-2026-50688 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | high | 2026-07-16 |
| CVE-2026-50687 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | high | 2026-07-22 |
| CVE-2026-50686 | Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network. | high | 2026-07-23 |
| CVE-2026-50685 | Double free in Windows DHCP Server allows an authorized attacker to execute code over a network. | high | 2026-07-21 |
| CVE-2026-50684 | Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network. | medium | 2026-07-21 |
| CVE-2026-50683 | Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network. | high | 2026-07-21 |
| CVE-2026-50682 | Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network. | high | 2026-07-22 |
| CVE-2026-50681 | Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally. | medium | 2026-07-22 |
| CVE-2026-50680 | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | high | 2026-07-22 |
| CVE-2026-50679 | Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. | high | 2026-07-22 |
| CVE-2026-50677 | Use after free in Windows Media allows an authorized attacker to elevate privileges locally. | high | 2026-07-22 |
| CVE-2026-50676 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally. | high | 2026-07-22 |
| CVE-2026-50674 | Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | high | 2026-07-22 |
| CVE-2026-50673 | Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. | high | 2026-07-16 |
| CVE-2026-50672 | Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. | high | 2026-07-22 |