CVE-2026-69550 Windows App for Mac Information Disclosure Vulnerability
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVSS 6.5 CVE-2026-69550 US
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVSS 6.5 CVE-2026-69550 US
[CVE-2026-6727](https://www.cve.org/CVERecord?id=CVE-2026-6727) is an Information Disclosure vulnerability in the TPM 2.0 reference implementation involving an RSA OAEP timing side channel. MITRE assigned this CVE on behalf of the Trusted Computing Group. This document incorporates updates to Microsoft Windows that address this vulnerability. Please see [CVE-2026-6727](https://www.cve.org/CVERecord?id=CVE-2026-6727) for more information.
EPSS 0.00 CVE-2026-6727 Microsoft US
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-62917 Microsoft US
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-62839 Microsoft US
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-58639 Microsoft US
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-62738 US
Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-71331 Microsoft US
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-70326 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-70306 Microsoft US
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-70130 Microsoft US
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
EPSS 0.00 CVE-2026-56179 US
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-68817 Microsoft US
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-68814 Microsoft US
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-68812 Microsoft US
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-68805 Microsoft US
Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-68804 Microsoft US
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-68803 Microsoft US
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-68801 Microsoft US
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-68799 Microsoft US
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-68798 Microsoft US
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-68797 Microsoft US
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-66809 Microsoft US
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-66810 Microsoft US
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-66808 Microsoft US
Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-66806 Microsoft US
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
EPSS 0.02 CVE-2026-66805 Microsoft US
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-66802 Microsoft US
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-65810 US
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-65798 US
Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-65799 US
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-65797 US
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-65794 US
No cwe for this issue in Windows DNS allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-65795 US
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-65791 US
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-65790 US
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-65781 US
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-65782 US
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-65778 US
Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-65780 veřejná správa US
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-65779 US
Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.
EPSS 0.00 CVE-2026-65777 US
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVSS 6.5 CVE-2026-65776 Microsoft US 2 zdrojů
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
EPSS 0.03 CVSS 8.8 CVE-2026-65775 Microsoft US 2 zdrojů
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-65774 US
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVSS 7.8 CVE-2026-65773 Microsoft US 2 zdrojů
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-65679 US
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-65680 Microsoft US
Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVSS 7.5 CVE-2026-65681 US
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVSS 7.8 CVE-2026-65673 Microsoft US
Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-62882 Microsoft US
Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-64921 Microsoft US
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-64919 Microsoft US
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-64917 Microsoft US
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-64920 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-64916 Microsoft US
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-64915 Microsoft US
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-64914 Microsoft US
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-64908 Microsoft US
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-64911 Microsoft US
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-64912 Microsoft US