CVE-2026-78522 Microsoft Office Word Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-78522 Microsoft US
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-78522 Microsoft US
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-80073 Microsoft US
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78521 Microsoft US
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-80079 Microsoft US
Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78519 Microsoft US
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-77481 Microsoft US
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-67645 Microsoft US
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-67624 Microsoft US
Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack.
EPSS 0.01 CVE-2026-78516 US
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-78503 Microsoft US
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78514 Microsoft US
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78512 Microsoft US
Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
EPSS 0.01 CVE-2026-78506 Microsoft US
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78507 Microsoft US
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-67369 Microsoft US
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-66819 Microsoft US
Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-78464 US
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69595 US
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
EPSS 0.01 CVE-2026-78462 US
Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-78457 US
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78456 US
Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-78454 US
Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack.
EPSS 0.00 CVE-2026-78452 Microsoft US
Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack.
EPSS 0.01 CVE-2026-78455 US
Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-78453 Microsoft US
Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.
EPSS 0.00 CVE-2026-78451 Microsoft US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-78448 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-78447 US
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78450 US
Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78444 Microsoft US
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78449 US
Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-78446 US
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78445 US
Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-78441 US
Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78442 US
Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69562 Microsoft US
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-77911 Microsoft US
Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-77905 US
Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69854 US
Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-77901 Microsoft US
Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-77488 Microsoft US
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-77486 Microsoft US
Use after free in SQL Server allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-77485 US
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-77487 US
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-77484 Microsoft US
Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-77483 US
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-77480 US
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-73028 US
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-71328 US
Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally.
EPSS 0.00 CVE-2026-73017 US
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-73016 Microsoft US
Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
EPSS 0.01 CVE-2026-73025 US
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-73013 US
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-73023 US
Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-73010 Microsoft US
Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-73006 Microsoft US
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-73009 US
Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-73012 US
Missing authentication for critical function in Windows Autopilot allows an authorized attacker to perform tampering locally.
EPSS 0.00 CVE-2026-73004 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-73026 US