2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-65789 — Use: after free in Windows DNS allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65789

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-65768 — Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65768

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 22TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-65767 — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65767

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 79TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-65679 — Heap: Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65679

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-65665 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65665

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-65663 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65663

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-65660 — Microsoft Sharepoint_server: Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65660

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH) · EPSS 52th percentile

CWECWE 94VNDMicrosoftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-65658 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65658

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-64921 — Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64921

Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 306TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-64901 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64901

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-63520 — Microsoft: Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63520

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 20VNDMicrosoftTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-63514 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63514

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-62913 — Heap: Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62913

Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-62911 — Authentication: bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62911

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 294TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-08-11
2026-08-11 17:18Z
CRIT

CVE-2026-62893 — Use: after free in Windows Deployment Services allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62893

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 416TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-62889 — Double: free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62889

Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 415VNDDoubleTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 17:18Z
CRIT

CVE-2026-62878 — Stack: Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62878

Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDStackTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-62872 — Incorrect: authorization in .NET Framework allows an authorized attacker to elevate privileges over a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62872

Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 863TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-62869 — Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62869

Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 345TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-62827 — Microsoft: Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62827

Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 287VNDMicrosoftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-62824 — Stack: Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62824

Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 121VNDStackTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-62823 — Heap: Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62823

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-62822 — Integer: overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62822

Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122CWECWE 190TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-62820 — Concurrent: execution using shared resource with improper synchronization ('race condition') in Windows DNS allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62820

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 362VNDConcurrentTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-62819 — Code: Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62819

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine CVSSv3.1 8.1 (HIGH)

CWECWE 416VNDCodeTYPVulnerability
8.1
CVSS v3.1
91
Edit Score