CVE-2026-58618 Microsoft Excel Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-58631 Windows Admin Center (WAC) Remote Code Execution Vulnerability
Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-58635 Windows Narrator Braille Elevation of Privilege Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-58636 Microsoft PC Manager Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-58640 Windows NTFS Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-58644 Microsoft SharePoint Remote Code Execution Vulnerability
The Patch for this issue was released but the CVE was inadvertently left out of the Patch Tuesday June 2026 release
Categories: Microsoft
CVE-2026-58647 Microsoft PowerBI Report Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-50652 Azure Active Directory Denial of Service Vulnerability
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
Categories: Microsoft
CVE-2026-50653 Azure Active Directory Denial of Service Vulnerability
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
Categories: Microsoft
CVE-2026-33842 Windows File Explorer Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
Categories: Microsoft
CVE-2026-34328 Windows Audio Service Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.
Categories: Microsoft
CVE-2026-40422 Windows File Explorer Information Disclosure Vulnerability
Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.
Categories: Microsoft
CVE-2026-41087 Windows File Explorer Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
Categories: Microsoft
CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-34348 Windows Event Logging Service Information Disclosure Vulnerability
Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.
Categories: Microsoft
CVE-2026-44806 Windows Secure Channel Denial of Service Vulnerability
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.
Categories: Microsoft
CVE-2026-40378 Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
Categories: Microsoft
CVE-2026-47304 .NET Security Feature Bypass Vulnerability
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
Categories: Microsoft
CVE-2026-44800 Windows Push Notifications Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-47632 Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability
Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
Categories: Microsoft


