CVE-2026-80076 Microsoft Office Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-80076 Microsoft US
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-80076 Microsoft US
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-80078 Microsoft US
Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78524 Microsoft US
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78520 Microsoft US
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-78522 Microsoft US
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-80073 Microsoft US
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78521 Microsoft US
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-80079 Microsoft US
Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78519 Microsoft US
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-77481 Microsoft US
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-67645 Microsoft US
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-67624 Microsoft US
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-78503 Microsoft US
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78514 Microsoft US
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78512 Microsoft US
Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
EPSS 0.01 CVE-2026-78506 Microsoft US
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78507 Microsoft US
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-67369 Microsoft US
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-66819 Microsoft US
Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack.
EPSS 0.00 CVE-2026-78452 Microsoft US
Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-78453 Microsoft US
Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.
EPSS 0.00 CVE-2026-78451 Microsoft US
Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78444 Microsoft US
Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69562 Microsoft US
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-77911 Microsoft US
Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-77901 Microsoft US
Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-77488 Microsoft US
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-77486 Microsoft US
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-77484 Microsoft US
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-73016 Microsoft US
Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-73010 Microsoft US
Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-73006 Microsoft US
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69465 Microsoft US
Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
EPSS 0.00 CVE-2026-65812 Microsoft US
Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-65772 Microsoft US
Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-72976 Microsoft US
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-72975 Microsoft US
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-72977 Microsoft US
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-72974 Microsoft US
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-72973 Microsoft US
Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-72938 Microsoft US
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-72972 Microsoft US
Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-72956 Microsoft US
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69904 Microsoft US
Use after free in Microsoft Office allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69632 Microsoft US
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69626 Microsoft US
Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally.
EPSS 0.00 CVE-2026-69477 Microsoft US
Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69629 Microsoft US
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69636 Microsoft US
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69614 Microsoft US
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69464 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-69615 Microsoft US
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69442 Microsoft US
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69601 Microsoft US
Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
EPSS 0.00 CVE-2026-69559 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-69417 Microsoft US
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69409 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-69402 Microsoft US
Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69397 Microsoft US
Absolute path traversal in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-68896 Microsoft US