CVE-2026-62897 .NET Framework Remote Code Execution Vulnerability
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-62899 .NET Security Feature Bypass Vulnerability
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
Categories: Microsoft
CVE-2026-62900 .NET Information Disclosure Vulnerability
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
Categories: Microsoft
CVE-2026-62901 .NET Denial of Service Vulnerability
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
Categories: Microsoft
CVE-2026-62902 .NET Information Disclosure Vulnerability
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
Categories: Microsoft
CVE-2026-62908 Windows Backup Engine Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-62909 .NET Elevation of Privilege Vulnerability
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-62910 Microsoft Exchange Server Elevation of Privilege Vulnerability
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-62912 Microsoft Exchange Server Denial of Service Vulnerability
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
Categories: Microsoft
CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-62914 Microsoft Exchange Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-62915 Microsoft Exchange Server Security Feature Bypass Vulnerability
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
Categories: Microsoft
CVE-2026-54123 Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.
Categories: Microsoft
CVE-2026-63513 Microsoft Office Graphics Component Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-63515 Microsoft Office Remote Code Execution Vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-63517 Microsoft Office Graphics Component Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Categories: Microsoft
CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-63521 Microsoft Office Word Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Categories: Microsoft
CVE-2026-63519 Microsoft Office Graphics Component Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-64922 Microsoft SharePoint Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft


