CVE-2026-83951 Microsoft Office Word Information Disclosure Vulnerability
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-83951 Microsoft US
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-83951 Microsoft US
Improper neutralization of special elements used in a command ('command injection') in Microsoft Azure CLI allows an authorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-83948 Microsoft US
Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-77897 Microsoft US
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-57099 US
Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-83939 US
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-83940 US
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-77906 US
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-81948 Microsoft US
Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-81950 Microsoft US
Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-81949 Microsoft US
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-81953 Microsoft US
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-81959 Microsoft US
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-81952 Microsoft US
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-81951 Microsoft US
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-81955 Microsoft US
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-81388 Microsoft US
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-81957 Microsoft US
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-81395 Microsoft US
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-81960 Microsoft US
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-81394 Microsoft US
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-81389 Microsoft US
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-81400 Microsoft US
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-81393 Microsoft US
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-81956 Microsoft US
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-81397 Microsoft US
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-81392 Microsoft US
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-81396 Microsoft US
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-81958 Microsoft US
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-81401 Microsoft US
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-81391 Microsoft US
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-81399 Microsoft US
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-81390 Microsoft US
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-81954 Microsoft US
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-81387 Microsoft US
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-81947 Microsoft US
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-81386 Microsoft US
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-81398 Microsoft US
Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-81385 Microsoft US
Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-81383 US
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-81354 US
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-81353 Microsoft US
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-81352 Microsoft US
Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-80096 US
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-80082 Microsoft US
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-80081 Microsoft US
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-80090 Microsoft US
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-80089 Microsoft US
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-80091 Microsoft US
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-80088 Microsoft US
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-80085 Microsoft US
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-80087 Microsoft US
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-80080 Microsoft US
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-80086 Microsoft US
Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78525 Microsoft US
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-80084 Microsoft US
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78526 Microsoft US
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-80076 Microsoft US
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-80078 Microsoft US
Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78524 Microsoft US
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78520 Microsoft US