CVE-2026-70130 Microsoft Office Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-70306 Microsoft Office SharePoint Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-70326 Microsoft SharePoint Server Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
Categories: Microsoft
CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-70354 .NET Core Remote Code Execution Vulnerability
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
Categories: Microsoft
CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability
Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-62738 Windows Management Instrumentation Information Disclosure Vulnerability
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
Categories: Microsoft
CVE-2026-62898 Microsoft QUIC Information Disclosure Vulnerability
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
Categories: Microsoft
CVE-2026-65767 Microsoft Teams for Android and iOS Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-58639 Microsoft SharePoint Server Spoofing Vulnerability
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-62839 Microsoft SharePoint Server Spoofing Vulnerability
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-62917 Microsoft SharePoint Server Spoofing Vulnerability
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-6727 MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability
[CVE-2026-6727](https://www.cve.org/CVERecord?id=CVE-2026-6727) is an Information Disclosure vulnerability in the TPM 2.0 reference implementation involving an RSA OAEP timing side channel. MITRE assigned this CVE on behalf of the Trusted Computing Group. This document incorporates updates to Microsoft Windows that address this vulnerability.
Please see [CVE-2026-6727](https://www.cve.org/CVERecord?id=CVE-2026-6727) for more information.
Categories: Microsoft
CVE-2026-6726 MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot Reuse
[CVE-2026-6726](https://www.cve.org/CVERecord?id=CVE-2026-6726) is a Spoofing vulnerability in the TPM 2.0 reference implementation involving improper object-slot reuse. MITRE assigned this CVE on behalf of the Trusted Computing Group. This document incorporates updates to Microsoft Windows that address this vulnerability.
Please see [CVE-2026-6726](https://www.cve.org/CVERecord?id=CVE-2026-6726) for more information.
Categories: Microsoft
CVE-2024-57888 workqueue: Do not warn when cancelling WQ_MEM_RECLAIM work from !WQ_MEM_RECLAIM worker
Information published.
Categories: Microsoft
CVE-2024-57795 RDMA/rxe: Remove the direct link to net_device
Information published.
Categories: Microsoft
CVE-2026-3087 shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
Information published.
Categories: Microsoft
CVE-2024-57899 wifi: mac80211: fix mbss changed flags corruption on 32 bit systems
Information published.
Categories: Microsoft
CVE-2025-21629 net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packets
Information published.
Categories: Microsoft


