CVE-2026-66308 Skype for Business and Lync Denial of Service Vulnerability
Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66804.
EPSS 0.05 CVSS 7.8 CVE-2026-66804 Microsoft US 2 zdrojů
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.
EPSS 0.00 CVSS 7.8 CVE-2026-62712 Microsoft US 2 zdrojů
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Authentication is not required to exploit this vulnerability, but only systems with specific IPsec configurations are vulnerable. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-50696.
EPSS 0.01 CVSS 8.1 CVE-2026-50696 Microsoft US 2 zdrojů
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-62916 Microsoft US
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
EPSS 0.00 CVE-2026-65818 US
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-69857 US
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-83711 Microsoft US
Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.00 CVE-2026-80098 US
Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-70352 US
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
EPSS 0.00 CVE-2026-70178 Microsoft US
Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-62906 Microsoft US
Microsoft 11. srpna 2026 vydal opravu zranitelnosti CVE-2026-62911 (CVSS 8,0), přesto téměř 22 000 veřejně dostupných Exchange serverů zůstává zranitelných. V Česku Shadowserver eviduje přibližně 300 unikátních IP adres Exchange serverů, které vyhodnocuje jako zranitelné (na jednu či více zranitelností). Zranitelnost postihuje Exchange Server 2016, 2019 a Subscription Edition a může vést až k převzetí uživatelských e-mailových schránek. Exploit je již veřejně dostupný. Verze 2016 a 2019 jsou…
EPSS 0.01 CVSS 8.8 CVE-2026-62911 Microsoft finance veřejná správa CZ NL US 4 zdrojů
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
EPSS 0.00 CVE-2026-70309 Microsoft US
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-72984 Microsoft US
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-66798 Microsoft US
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-66324 Microsoft US
Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-66323 Microsoft US
Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
EPSS 0.00 CVE-2026-62904 Microsoft US
Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.
EPSS 0.00 CVE-2026-58616 Microsoft US
Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-70331 Microsoft US
Americká CISA upozornila na aktivní zneužívání zranitelnosti CVE-2026-33824 (CVSS 9,8) ve Windows Internet Key Exchange (IKE). Ke zneužití této zranitelnosti stačí na neaktualizovaný počítač se systémem Windows odeslat speciálně upravené síťové pakety přes UDP porty 500 nebo 4 500. Zranitelnost se týká podporovaných verzí Windows 10, Windows 11 a Windows Serveru. Microsoft opravu vydal již v dubnu, takže je nezbytné neprodleně aktualizovat. Pokud to z nějakého důvodu není možné, doporučuje se…
KEV ✓ EPSS 0.73 CVSS 9.8 CVE-2026-33824 Microsoft veřejná správa CZ US 5 zdrojů
EPSS 0.03 CVE-2026-63520 Microsoft US 2 zdrojů
This vulnerability allows remote attackers to disclose NTLM responses on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-50508.
EPSS 0.09 CVSS 3.3 CVE-2026-50508 Microsoft US 2 zdrojů
Classification: Critical, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv3.1: 10.0, CVEs: CVE-2026-69836, Summary: Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.
EPSS 0.02 CVSS 10.0 CVE-2026-69836 Microsoft veřejná správa FI IT US FR 5 zdrojů
Une vulnérabilité a été découverte dans Microsoft Office. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données.
EPSS 0.01 CVSS 6.5 CVE-2026-70105 Microsoft FR US 2 zdrojů
Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.
EPSS 0.00 CVE-2026-69855 Microsoft US
Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.
EPSS 0.00 CVE-2026-69543 US
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69558 Microsoft US
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.00 CVE-2026-69555 US
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69400 US
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69502 finance US
Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-69419 energetika US
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-68782 US
Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-66800 US
Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
EPSS 0.00 CVE-2026-66309 US
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-65816 US
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-63509 Microsoft US
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-65770 US
Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.
EPSS 0.00 CVE-2026-55013 US
Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.
EPSS 0.00 CVE-2026-55015 Microsoft US
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
EPSS 0.00 CVE-2026-69851 Microsoft US
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69519 US
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-68789 US
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-65801 Microsoft US
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.00 CVE-2026-62834 US
Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation. Installing the patch alone does not complete remediation, as the fix replaces a kernel driver and requires…
KEV ✓ EPSS 0.06 CVSS 7.0 CVE-2026-68820 Microsoft US FR 5 zdrojů
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
EPSS 0.02 CVE-2026-24301 Microsoft US
CISA added CVE-2026-55040 to the Known Exploited Vulnerabilities catalog. Affected product: Microsoft SharePoint. Remediation due date: 2026-08-21.
KEV ✓ EPSS 0.40 CVE-2026-55040 Microsoft US 3 zdrojů
CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been. [...]
EPSS 0.02 CVE-2026-54121 veřejná správa US 2 zdrojů
Serial Number: AV26-822Date: August 17, 2026 As of August 14, 2026, Microsoft is affected by a vulnerability in the following product: Microsoft Edge (Chromium-based) Prior to 151.0.4129.86 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Microsoft Edge Stable Channel Release Notes Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability CVE-2026-72970 (en anglais seulement)
EPSS 0.01 CVE-2026-72970 Microsoft CA US 2 zdrojů
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Clam AntiVirus. Interaction with this product is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 8.4. The following CVEs are assigned: CVE-2026-20215.
EPSS 0.01 CVSS 8.4 CVE-2026-20215 Clam AntiVirus ClamAV US 2 zdrojů
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of dnsmasq. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-4890.
EPSS 0.09 CVSS 7.5 CVE-2026-4890 dnsmasq US 2 zdrojů
CVSSv3 Score: 5.8 CVE-2026-49975Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. Revised on 2026-08-12 00:00:00
EPSS 0.31 CVSS 5.8 CVE-2026-49975 Apache US 2 zdrojů