CVE-2026-69285 Microsoft Office Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69285 Microsoft US
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69285 Microsoft US
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69268 Microsoft US
Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-77896 US
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-77895 US
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-77894 US
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-77893 US
No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack.
EPSS 0.00 CVE-2026-77892 US
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.
EPSS 0.00 CVE-2026-77891 US
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-77889 US
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-77890 US
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-77886 US
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-77888 US
Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-77505 US
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-77504 Microsoft US
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.
EPSS 0.00 CVE-2026-77887 US
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-77503 US
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-77502 US
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-77501 US
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-77499 US
Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-77500 US
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-77498 US
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-77494 US
Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-77493 Microsoft US
Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-77492 US
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-77491 US
Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-77489 US
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69579 US
Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-72986 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69787 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69476 US
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-72982 US
Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-72983 US
Use after free in IP Helper allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-72981 US
Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-72980 US
Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-72979 US
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-77495 US
Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-72978 US
Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-70283 US
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-70124 US
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69930 US
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69929 US
Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69846 US
Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69804 Microsoft US
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69797 Microsoft US
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69767 Microsoft US
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69778 Microsoft US
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69764 Microsoft US
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69759 Microsoft US
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69529 Microsoft US
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69683 Microsoft US
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69739 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-69690 Microsoft US
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69719 Microsoft US
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69724 Microsoft US
Integer overflow or wraparound in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69742 Microsoft US
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69734 Microsoft US
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69716 Microsoft US
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69722 Microsoft US
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69686 Microsoft US
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69678 Microsoft US