CVE-2026-55139 Microsoft Office Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Categories: Microsoft
CVE-2026-55043 Microsoft PowerPoint Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-55133 Microsoft OneNote Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-55123 Microsoft PowerPoint Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-55120 Microsoft PowerPoint Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-55052 Microsoft SharePoint Elevation of Privilege Vulnerability
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-55135 Microsoft SharePoint Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-50468 Microsoft SQL Server Information Disclosure Vulnerability
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Categories: Microsoft
CVE-2026-54116 Microsoft SQL Server Information Disclosure Vulnerability
Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.
Categories: Microsoft
CVE-2026-55145 Outlook Copilot Tampering Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network.
Categories: Microsoft
CVE-2026-54131 Microsoft Excel Remote Code Execution Vulnerability
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-55898 Microsoft Excel Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Categories: Microsoft
CVE-2026-55944 Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-55947 Microsoft Excel Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-55949 Microsoft Excel Remote Code Execution Vulnerability
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-56156 Microsoft Excel Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-56157 Microsoft SharePoint Server Spoofing Vulnerability
Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-41109 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.
Categories: Microsoft
CVE-2026-56159 DHCP Server Service Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-50359 Microsoft XML Core Services Elevation of Privilege Vulnerability
Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.
Categories: Microsoft


