Feed aggregator

CVE-2026-70130 Microsoft Office Remote Code Execution Vulnerability

Microsoft Security Center Center News - Tue, 08/11/2026 - 14:00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-70306 Microsoft Office SharePoint Spoofing Vulnerability

Microsoft Security Center Center News - Tue, 08/11/2026 - 14:00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-70326 Microsoft SharePoint Server Elevation of Privilege Vulnerability

Microsoft Security Center Center News - Tue, 08/11/2026 - 14:00
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability

Microsoft Security Center Center News - Tue, 08/11/2026 - 14:00
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
Categories: Microsoft

CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability

Microsoft Security Center Center News - Tue, 08/11/2026 - 14:00
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-70354 .NET Core Remote Code Execution Vulnerability

Microsoft Security Center Center News - Tue, 08/11/2026 - 14:00
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability

Microsoft Security Center Center News - Tue, 08/11/2026 - 14:00
Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-62738 Windows Management Instrumentation Information Disclosure Vulnerability

Microsoft Security Center Center News - Tue, 08/11/2026 - 14:00
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-62898 Microsoft QUIC Information Disclosure Vulnerability

Microsoft Security Center Center News - Tue, 08/11/2026 - 14:00
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
Categories: Microsoft

CVE-2026-65767 Microsoft Teams for Android and iOS Spoofing Vulnerability

Microsoft Security Center Center News - Tue, 08/11/2026 - 14:00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-58639 Microsoft SharePoint Server Spoofing Vulnerability

Microsoft Security Center Center News - Tue, 08/11/2026 - 14:00
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-62839 Microsoft SharePoint Server Spoofing Vulnerability

Microsoft Security Center Center News - Tue, 08/11/2026 - 14:00
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-62917 Microsoft SharePoint Server Spoofing Vulnerability

Microsoft Security Center Center News - Tue, 08/11/2026 - 14:00
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-6727 MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability

Microsoft Security Center Center News - Tue, 08/11/2026 - 14:00
[CVE-2026-6727](https://www.cve.org/CVERecord?id=CVE-2026-6727) is an Information Disclosure vulnerability in the TPM 2.0 reference implementation involving an RSA OAEP timing side channel. MITRE assigned this CVE on behalf of the Trusted Computing Group. This document incorporates updates to Microsoft Windows that address this vulnerability. Please see [CVE-2026-6727](https://www.cve.org/CVERecord?id=CVE-2026-6727) for more information.
Categories: Microsoft

CVE-2026-6726 MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot Reuse

Microsoft Security Center Center News - Tue, 08/11/2026 - 14:00
[CVE-2026-6726](https://www.cve.org/CVERecord?id=CVE-2026-6726) is a Spoofing vulnerability in the TPM 2.0 reference implementation involving improper object-slot reuse. MITRE assigned this CVE on behalf of the Trusted Computing Group. This document incorporates updates to Microsoft Windows that address this vulnerability. Please see [CVE-2026-6726](https://www.cve.org/CVERecord?id=CVE-2026-6726) for more information.
Categories: Microsoft

Pages

Subscribe to Geeksultant aggregator