CVE-2026-44819 Microsoft Office Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-44819 Microsoft US
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-44819 Microsoft US
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-44818 Microsoft US
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-44817 Microsoft US
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-45485 Microsoft US
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-45486 Microsoft US
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-45474 Microsoft US
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-45471 Microsoft US
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-45472 Microsoft US
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-45475 Microsoft US
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-45469 Microsoft US
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-45504 Microsoft US
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-45637 Microsoft US
Written by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan Introduction From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spider,” and "Silent Ransom Group") targeting dozens of organizations across professional, legal, and financial services in the United States. UNC3753 leverages voice phishing (vishing) and social engineering deception…
TeamPCP has leveraged a compromised GitHub account to inject malicious code into at least 42 repositories and 236 branches across the Azure, Azure-Samples and Microsoft GitHub organizations. They were published between 02:36 and 03:22 UTC on 5 June 2026. As of 14:00 UTC on 5 J...
Microsoft US
In September 2025, Volexity conducted an incident response engagement that began after suspicious network traffic was observed from a Linux-based virtual machine appliance on a customer’s network. The virtual machine was an Egnyte Storage Sync system, which is designed to facilitate syncing local on-premise files with the cloud. Volexity discovered that instead of connecting to a domain affiliated with Egnyte, the appliance was connecting to a threat-actor-controlled domain behind Cloudflare IP…
Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-48579 Microsoft US
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-47655 Microsoft US
Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-47644 Microsoft US
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-45497 Microsoft US
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
EPSS 0.01 CVSS 8.0 CVE-2026-47294 Microsoft US
Tycoon 2FA is currently the most prolific Phishing-as-a-Service (PhaaS) platform among AiTM phishing kits. First observed in August 2023 and attributed to Storm-1747 (per Microsoft Threat Intelligence), the kit provides turnkey adversary-in-the-middle (AiTM) capabilities that bypass multi-factor authentication and steal authenticated session tokens from Microsoft 365 and Google Workspace accounts. At its peak, Tycoon 2FA accounted for roughly 62% of phishing attempts blocked by Microsoft,…
Google omylem zveřejnil funkční exploit na dosud neopravenu zranitelnost v jádru Chromium, která existuje už zhruba tři a půl roku a ovlivňuje prohlížeče jako Google Chrome, Microsoft Edge, Brave či Opera. Útok lze spustit pouhou návštěvou škodlivé stránky a umožňuje vytvořit skryté trvalé spojení přes funkci Background Fetch (stahování na pozadí), čímž může zařízení sloužit jako proxy, součást botnetu nebo k omezenému sledování aktivity (bez přímého přístupu k datům v systému). Riziko spočívá…
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
KEV ✓ · ransomware EPSS 0.76 CVSS 8.8 CVE-2026-45659 Microsoft US
Three progressively compromised versions of a Microsoft-adjacent Python package deliver a full-featured infostealer that spreads through AWS and Kubernetes, exfiltrates every cloud credential it can find, and wipes disks on Israeli and Iranian systems Category: Vulnerabilities & Threats
Microsoft BE
Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVSS 8.1 CVE-2026-45584 Microsoft US
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
KEV ✓ EPSS 0.08 CVSS 7.8 CVE-2026-41091 Microsoft US
CWE added. Informational change only.
KEV ✓ EPSS 0.63 CVE-2026-45498 Microsoft US
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available.
EPSS 0.01 CVE-2026-45585 Microsoft US
Following two days of intense competition, Day Three of Pwn2Own Berlin 2026 brought the curtain down on an incredible event. Security researchers delivered their final exploits, pushing enterprise systems to the limit one last time as the race for Master of Pwn came to a close.Day Three added to an already historic event, bringing the final totals to $1,298,250 awarded for 47 unique 0-day vulnerabilities across three days of competition. DEVCORE claimed the title of Master of Pwn with a…
Acknowledgement added. This is an informational change only.
EPSS 0.00 CVE-2026-45494 Microsoft US
CWE added. Informational change only.
EPSS 0.01 CVE-2026-45495 Microsoft US
Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass traditional perimeter defenses and multi-factor authentication (MFA), UNC6671…
Day Two of Pwn2Own Berlin 2026 and the stakes continue to rise! Security researchers are back on the Pwn2Own stage, pushing enterprise systems to their limits as the competition heats up. More exploits, more surprises, and more standout moments are unfolding, so follow along here for live updates as the race for Master of Pwn intensifies. There were plenty of big targets on the schedule today, including SharePoint, Exchange, and Safari.Following an action-packed Day One where $523,000 was…
Tisztelt Ügyfelünk! A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet (NBSZ NKI) riasztást ad ki a Microsoft szoftvereket érintő kritikus kockázati besorolású sérülékenységek kapcsán, azok súlyossága, kihasználhatósága és a szoftverek széleskörű elterjedtsége miatt. A Microsoft tárgyhavi biztonsági csomagjában összesen 137 különböző biztonsági hibát javított, ugyanakkor a javítások között nem szerepelt olyan nulladik napi (zero-day) sebezhetőség, amelyet a […]
Microsoft HU
[Mise à jour du 11 juin 2026] Le 9 juin 2026, Microsoft a publié des versions correctives. [Publication initiale] Le 14 mai 2026, Microsoft a publié un avis de sécurité concernant la vulnérabilité CVE-2026-42897 affectant Exchange Server. Elle permet à un attaquant non authentifié de provoquer...
KEV ✓ EPSS 0.72 CVE-2026-42897 Microsoft FR US
Welcome to Day One of Pwn2Own Berlin 2026! Today, 22 entries took the Pwn2Own stage to target AI Databases, Coding Agents, Local Inferences, and a separate category for NVIDIA products, as the world’s top security researchers push technology to its limits. Exploits, surprises, and breakthrough discoveries are unfolding.After Day One, we awarded $523,000 for 24 unique 0-days! DEVCORE is currently in the lead for Master of Pwn, but a pack of teams are right on their heels. Stay tuned tomorrow for…
Willkommen! (Welcome!) Pwn2Own Berlin 2026 has arrived at OffensiveCon, and the world’s top security researchers are ready. This year’s enterprise-focused competition features AI Databases, Coding Agents, Local Inferences, and a separate category for NVIDIA products.Earlier today, we held the random draw to determine attempt order. Below is the official schedule. All times are Berlin local time (CET) and may change as the competition progresses. Check back for live updates.In case you missed it…
Microsoft JP
I’m currently in Berlin helping set up for Pwn2Own Berlin, but that doesn’t stop Patch Tuesday from coming, and it’s another big one. At least nothing is listed as being in the wild – for now. Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft. Due to technical difficulties, there will not be a video companion for this month.Adobe Patches for May 2026For May, Adobe released 10 bulletins addressing 52 unique CVEs in…
The security impact for this vulnerability has been revised from Critical to Important. In addition, the CVSS vector and FAQs were modified. This change does not affect the available security updates. Customers should continue to install the recommended updates to remain protected from this vulnerability.
EPSS 0.00 CVE-2026-40367 Microsoft US
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
EPSS 0.01 CVSS 9.9 CVE-2026-42898 Microsoft US
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
EPSS 0.01 CVSS 8.4 CVE-2026-40361 Microsoft US
Added Microsoft Excel for Android, Microsoft Word for Android, Microsoft Loop for Android, Microsoft PowerPoint for Android and Microsoft OneNote for Android softwares to the Security Updates table. Customers that are running supported version of these products are encouraged to update to the indicated versions to be protected from this vulnerability.
EPSS 0.00 CVE-2026-41100 Microsoft US
Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVSS 7.8 CVE-2026-40417 Microsoft US
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.00 CVSS 4.3 CVE-2026-35429 Microsoft US
A China-aligned threat group is exploiting unpatched Microsoft Exchange vulnerabilities to conduct cyberespionage against government and critical infrastructure targets across Asia and beyond.
Preamble In 2025 and 2026, we watched a pattern play out across the industry. Attackers stopped going after production servers directly and started targeting the automation that deploys to them. Compromised developer credentials, a modified workflow file, and suddenly every secret in a CI/CD environment is streaming to an attacker-controlled endpoint. We saw this play out across incidents involving major open-source projects, Fortune 500 companies, and critical infrastructure tooling. The…
Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim…
A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet (NBSZ NKI) riasztást ad ki a Microsoft szoftvereket érintő kritikus kockázati besorolású sérülékenységek kapcsán, azok súlyossága, kihasználhatósága és a szoftverek széleskörű elterjedtsége miatt.
Microsoft HU
Microsoft ha rilasciato gli aggiornamenti di sicurezza mensili che risolvono un totale di 165 nuove vulnerabilità, di cui due di tipo 0-day.
Microsoft IT
It’s time once again for Patch Tuesday, and this one is huge. We’ve also got multiple exploits in the wild, which adds another layer of urgency to this month’s release. Take a break from your regularly scheduled activities, and let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here: Adobe Patches for April 2026For April, Adobe released 12 bulletins addressing 61 unique CVEs in…
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVSS 7.8 CVE-2026-32153 Microsoft US
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.01 CVSS 4.3 CVE-2026-33118 Microsoft US
On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthenticated attacker. This vulnerability was added in the CISA's Known Exploited Vulnerabilities (KEV) catalogue on 18 March 2026. Additionally, three further RCE flaws affecting Microsoft SharePoint were…
Microsoft EU
Railway PaaS is being weaponized as a clean token replay engine in an active AiTM and device code phishing campaign impacting 268+ M365 organizations and 100+ MSPs.
Microsoft finance zdravotnictví veřejná správa telekomunikace US
If you just want to read the contest rules, click here. Willkommen zurück, meine Damen und Herren, zu unserem zweiten Wettbewerb in Berlin! That’s correct (if Google translate didn’t steer me wrong). After our inaugural competition last year, Pwn2Own returns to Berlin and OffensiveCon. Outside of our shipping troubles, we had an amazing time and can’t wait to get back.Last year, we added Artificial Intelligence as a category with great results. This year, we’re expanding this and splitting it…
I am back in the friendly confines of the Mid-South headquarters of TrendAI ZDI (a.k.a. my home office), and am all set for the third patch Tuesday of 2026. Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft.If you’d rather watch the full video recap covering the entire release, you can check it out here: Adobe Patches for March 2026For March, Adobe released eight bulletins addressing 80 unique CVEs in Adobe…
Intro Patch diffing has long fascinated me. I think part of it has to do with the race against the clock, reversing, exploiting, and trying to attain that “1day” exploit status. For advanced Windows targets, Valentina Palmiotti and Ruben Boonen proved that this was already possible nearly 3 years ago. But, they are some of the world's most talented exploit devs. Can LLMs raise the capability floor for us mere mortals? Fortunately, and maybe a bit alarmingly, the answer is yes. The Hunt When the…
Microsoft US
In this excerpt of a TrendAI Research Services vulnerability report, Nikolai Skliarenko and Yazhi Wang of the TrendAI Research team detail a recently patched command injection vulnerability in the Windows Notepad application. This bug was originally discovered by Cristian Papa and Alasdair Gorniak of Delta Obscura. Successful exploitation of this vulnerability could result in the execution of arbitrary commands in the security context of the victim's account. The following is a portion of their…
EPSS 0.12 CVE-2026-20841 Microsoft US
Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.
EPSS 0.01 CVSS 5.5 CVE-2025-29821 Microsoft US