2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-41613 — Session: fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41613

Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 78CWECWE 384TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-41109 — Improper neutralization of special elements in output used by a downstream component ('injection') in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41109

Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 74TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-41103 — Incorrect: implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41103

Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 9.1 (CRITICAL)

CWECWE 303TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-41096 — Heap: Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41096

Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDHeapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-41094 — Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41094

Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 94TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-41089 — Stack: Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41089

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDStackTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-41086 — Windows: Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41086

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 284TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-40420 — Microsoft: Improper access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40420

Improper access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. CVSSv3.1 8.8 (HIGH)

CWECWE 284VNDMicrosoftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-40415 — Use: after free in Windows TCP/IP allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40415

Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-40403 — Heap: Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40403

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-40402 — Use: after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40402

Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. CVSSv3.1 9.3 (CRITICAL)

CWECWE 416TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-05-12
2026-05-12 18:17Z
CRIT

CVE-2026-40379 — Exposure: of sensitive information to an unauthorized actor in Azure Entra ID allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40379

Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network. CVSSv3.1 9.3 (CRITICAL)

CWECWE 200TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-40370 — External: control of file name or path in SQL Server allows an authorized attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40370

External control of file name or path in SQL Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 73TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-40368 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40368

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 502TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-40367 — Untrusted: pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40367

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 822VNDUntrustedTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-40366 — Use: after free in Microsoft Office Word allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40366

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 416TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-40365 — Insufficient granularity of access control in Microsoft Office SharePoint allows an authorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40365

Insufficient granularity of access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 1220TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-40364 — Access: of resource using incompatible type ('type confusion') in Microsoft Office Word allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40364

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 122CWECWE 843CWECWE 908VNDAccessTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-40363 — Heap: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40363

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-40361 — Use: after free in Microsoft Office Word allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40361

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 416TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-40358 — Use: after free in Microsoft Office allows an unauthorized attacker to execute code locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40358

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 416TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-40357 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40357

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-35439 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35439

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-35438 — Windows: Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35438

Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.3 (HIGH)

CWECWE 862TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-12
2026-05-12 18:17Z
HIGH

CVE-2026-35436 — Insufficient granularity of access control in Microsoft Office Click-To-Run allows an authorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35436

Insufficient granularity of access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. CVSSv3.1 8.8 (HIGH)

CWECWE 1220TYPVulnerability
8.8
CVSS v3.1
94
Edit Score