2026-08-11
2026-08-11 18:17Z
CRIT

CVE-2026-27302 — Adobe: Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27302

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 863VNDAdobeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-71387 — ColdFusion: is affected by an Incorrect Authorization vulnerability that could result in arbitrary code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71387

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDColdfusionTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-71386 — is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71386

is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.8 (HIGH)

CWECWE 79TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:19Z
CRIT

CVE-2026-71384 — Incorrect: is affected by an Incorrect Authorization vulnerability that could result in a Security feature

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71384

is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application denial-of-service condition. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 9.6 (CRITICAL)

CWECWE 863TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-71331 — Integer: overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71331

Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 122CWECWE 190TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-70340 — Azure: Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70340

Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDAzureTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-70337 — Relative: path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70337

Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 23VNDRelativeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-70336 — Improper control of generation of code ('code injection') in Visual Studio Code allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70336

Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 94TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-70329 — Integer: overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70329

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 190TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-70326 — Server: Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70326

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 918TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-70324 — Server: Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70324

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 918TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-70321 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70321

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:19Z
CRIT

CVE-2026-70306 — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70306

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. CVSSv3.1 9.3 (CRITICAL)

CWECWE 79TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-70130 — Heap: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70130

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-69320 — Improper neutralization of special elements used in an os command ('os command injection') in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69320

Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-69306 — Not: failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69306

Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. CVSSv3.1 8.2 (HIGH)

CWECWE 636VNDNotTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 17:19Z
CRIT

CVE-2026-69223 — Apache: Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69223

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue. CVSSv3.1 9.1 (CRITICAL)

CWECWE 918VNDApacheTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-68820 — Use: after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68820in the wild

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. CVSSv3.1 7.0 (HIGH)

CWECWE 416TYPVulnerabilitySTAitw exploited
7.0
CVSS v3.1
85
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-66808 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66808

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-66805 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66805

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-66802 — Concurrent: execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66802

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 416CWECWE 362VNDConcurrentTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-65815 — Deserialization: of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65815

Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-65811 — Power: Improper input validation in Power BI allows an authorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65811

Improper input validation in Power BI allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 20VNDPowerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-65807 — Access: of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65807

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDAccessTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-65796 — Microsoft Windows_10_1607: Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65796

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH) · EPSS 41th percentile

CWECWE 122VNDMicrosoftVNDHeapTYPVulnerability
8.1
CVSS v3.1
91
Edit Score