CVE-2026-69734 Microsoft Office Word Information Disclosure Vulnerability
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69734 Microsoft US
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69734 Microsoft US
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69716 Microsoft US
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69722 Microsoft US
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69686 Microsoft US
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69678 Microsoft US
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69671 Microsoft US
Heap-based buffer overflow in Windows Raw Image Extension allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69649 US
Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.
EPSS 0.00 CVE-2026-69646 US
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-69642 US
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69641 Microsoft US
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
EPSS 0.00 CVE-2026-69603 US
Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69604 US
Use after free in Graphic Fonts allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69576 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69580 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69589 US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69583 US
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69556 Microsoft US
Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical attack.
EPSS 0.00 CVE-2026-69548 US
Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69544 US
Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69518 US
Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69501 US
Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to elevate privileges with a physical attack.
EPSS 0.00 CVE-2026-69469 US
Out-of-bounds read in Windows Device Health Attestation (DHA) allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69443 US
Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69394 US
External control of file name or path in Windows Shell allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69383 US
Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
EPSS 0.00 CVE-2026-69382 Microsoft US
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69380 Microsoft US
Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-69378 Microsoft US
Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
EPSS 0.01 CVE-2026-69375 Microsoft US
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-69361 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-69356 Microsoft US
External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69355 Microsoft US
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69293 US
Out-of-bounds read in Windows Message Queuing Queue Manager allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-68887 US
Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
EPSS 0.00 CVE-2026-68877 US
Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
EPSS 0.00 CVE-2026-68844 US
Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-68837 US
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-68825 US
Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-72963 US
Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-72962 US
Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-72958 US
Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-72948 US
Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-72945 US
Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-72943 US
Heap-based buffer overflow in Storage Port Driver allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-72946 Microsoft US
Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-72944 US
Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-72939 US
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-72935 US
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally.
EPSS 0.00 CVE-2026-72930 US
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-71351 US
Improper validation of integrity check value in Windows Installer allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-72929 US
Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally.
EPSS 0.00 CVE-2026-71345 US
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-71353 US
Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-71341 US
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to execute code locally.
EPSS 0.00 CVE-2026-71343 US
Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-72926 US
Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.
EPSS 0.00 CVE-2026-71348 US
Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.
EPSS 0.00 CVE-2026-71350 US
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-71339 US
Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-71340 US