CVE-2026-58279 Azure CycleCloud Elevation of Privilege Vulnerability
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-58526 Windows Storage Elevation of Privilege Vulnerability
Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-58595 Microsoft Bing App for IOS Spoofing Vulnerability
Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-50522 Microsoft SharePoint Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-58601 Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-58602 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-58608 Windows Print Spooler Remote Code Execution Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-58609 Windows Graphics Component Remote Code Execution Vulnerability
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-58610 Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-58614 Windows Kernel Security Feature Bypass Vulnerability
Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.
Categories: Microsoft
CVE-2026-47301 Configuration Manager Elevation of Privilege Vulnerability
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-58618 Microsoft Excel Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-58631 Windows Admin Center (WAC) Remote Code Execution Vulnerability
Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-58635 Windows Narrator Braille Elevation of Privilege Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-58636 Microsoft PC Manager Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-58640 Windows NTFS Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-58644 Microsoft SharePoint Remote Code Execution Vulnerability
The Patch for this issue was released but the CVE was inadvertently left out of the Patch Tuesday June 2026 release
Categories: Microsoft
CVE-2026-58647 Microsoft PowerBI Report Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-50652 Azure Active Directory Denial of Service Vulnerability
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
Categories: Microsoft
CVE-2026-50653 Azure Active Directory Denial of Service Vulnerability
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
Categories: Microsoft


