CVE-2026-77894 Windows Installer Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-77895 Windows DHCP Server Denial of Service Vulnerability
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2026-77896 Windows Remote Desktop Client Denial of Service Vulnerability
Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network.
CVE-2026-69268 Microsoft Office SharePoint Remote Code Execution Vulnerability
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-69285 Microsoft Office Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
CVE-2026-69273 Microsoft Office SharePoint Remote Code Execution Vulnerability
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-69282 Microsoft Office SharePoint Remote Code Execution Vulnerability
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-77898 Microsoft Office Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
CVE-2026-77899 Windows Security Center Elevation of Privilege Vulnerability
Use after free in Windows Security Center allows an authorized attacker to elevate privileges locally.
CVE-2026-77904 Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-77907 Visual Studio Remote Code Execution Vulnerability
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2026-77908 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
CVE-2026-77909 Azure CycleCloud Information Disclosure Vulnerability
Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network.
CVE-2026-78439 Microsoft Office Graphics Component Remote Code Execution Vulnerability
Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
CVE-2026-78461 Visual Studio Code Security Feature Bypass Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-67378 Microsoft SQL Server Remote Code Execution Vulnerability
Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-78463 Remote Desktop Client Remote Code Execution Vulnerability
Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-67376 Microsoft SQL Server Denial of Service Vulnerability
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.
CVE-2026-67379 Microsoft SQL Server Remote Code Execution Vulnerability
Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-67383 Microsoft SQL Server Information Disclosure Vulnerability
Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.


