CVE-2026-70328 Microsoft Excel Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
Categories: Microsoft
CVE-2026-70329 Microsoft Outlook Remote Code Execution Vulnerability
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-70304 Windows DNS Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-70330 Windows DNS Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-70336 Visual Studio Code Remote Code Execution Vulnerability
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-57104 Azure Storage Explorer Elevation of Privilege Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-70340 Azure CycleCloud Elevation of Privilege Vulnerability
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-65806 Azure CycleCloud Information Disclosure Vulnerability
Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.
Categories: Microsoft
CVE-2026-61352 Remote Desktop Client Remote Code Execution Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-65783 Windows Autopilot Elevation of Privilege Vulnerability
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-70344 Windows Installer Elevation of Privilege Vulnerability
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-70345 Windows Installer Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-70346 Windows Installer Elevation of Privilege Vulnerability
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-70347 Windows Installer Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Categories: Microsoft
CVE-2026-70348 Windows Management Services Denial of Service Vulnerability
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
Categories: Microsoft
CVE-2026-70355 Microsoft SharePoint Server Elevation of Privilege Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-72971 Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
Categories: Microsoft
CVE-2026-70339 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Categories: Microsoft


