CVE-2026-65789 — Use: after free in Windows DNS allows an unauthorized attacker to execute code over
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network. CVSSv3.1 8.8 (HIGH)
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH) · EPSS 52th percentile
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)
Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.0 (HIGH)
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)
Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network. CVSSv3.1 8.8 (HIGH)
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)
Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. CVSSv3.1 8.8 (HIGH)
Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine CVSSv3.1 8.1 (HIGH)