| CVE-2026-45602 | No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. | critical | |
| CVE-2026-45471 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | high | |
| CVE-2026-45607 | Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. | high | |
| CVE-2026-45458 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | high | |
| CVE-2026-45475 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | high | |
| CVE-2026-45654 | Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | high | |
| CVE-2026-45479 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | medium | |
| CVE-2026-45588 | Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | high | |
| CVE-2026-47641 | Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | medium | |
| CVE-2026-47634 | Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | medium | |
| CVE-2026-6338 | A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series. The vulnerability is caused by a parsing flaw in Kong’s HTTP request processing pipeline when handling untrusted HTTP/1.1 traffic. | high | |
| CVE-2026-26164 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | high | |
| CVE-2026-35430 | Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network. | high | |
| CVE-2026-40411 | Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network. | high | |
| CVE-2026-23663 | Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. | high | |
| CVE-2026-40412 | Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network. | critical | |
| CVE-2026-45494 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | medium | |
| CVE-2026-42822 | Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. | critical | |
| CVE-2026-36828 | A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including v7.7. The CGI component allows authenticated users to execute arbitrary shell commands with root privileges via the action=runcmd parameter. | high | |
| CVE-2026-57084 | Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally. | medium | |
| CVE-2026-56189 | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. | high | |
| CVE-2026-55140 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | high | |
| CVE-2026-56187 | Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | high | |
| CVE-2026-56157 | Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | medium | |
| CVE-2026-55136 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | high | |
| CVE-2026-55125 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | high | |
| CVE-2026-55056 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | high | |
| CVE-2026-55047 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | medium | |
| CVE-2026-55127 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | high | |
| CVE-2026-55048 | Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | high | |
| CVE-2026-55043 | Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | high | |
| CVE-2026-55041 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | high | |
| CVE-2026-55034 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | high | |
| CVE-2026-55051 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | medium | |
| CVE-2026-54125 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. | high | |
| CVE-2026-55018 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | high | |
| CVE-2026-50687 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | high | |
| CVE-2026-55033 | Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally. | high | |
| CVE-2026-54115 | Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally. | high | |
| CVE-2026-50686 | Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network. | high | |
| CVE-2026-55027 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | medium | |
| CVE-2026-50306 | Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | high | |
| CVE-2026-50301 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | high | |
| CVE-2026-50309 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | high | |
| CVE-2026-50310 | Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally. | medium | |
| CVE-2026-50330 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network. | critical | |
| CVE-2026-47290 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | high | |
| CVE-2026-50358 | Use after free in Windows Media allows an authorized attacker to elevate privileges locally. | high | |
| CVE-2026-50363 | Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | high | |
| CVE-2026-50498 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | high | |