CVE-2026-63525 Microsoft
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +8 more
Updated August 11, 2026
CVE-2026-63526 Microsoft
Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated August 11, 2026
CVE-2026-64898 Microsoft
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +9 more
Updated August 11, 2026
CVE-2026-64907 Microsoft
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated August 11, 2026
CVE-2026-64909 Microsoft
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated August 11, 2026
CVE-2026-64910 Microsoft
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +9 more
Updated August 11, 2026
CVE-2026-64911 Microsoft
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +9 more
Updated August 11, 2026
CVE-2026-64921 Microsoft
Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft SharePoint Enterprise Server 2016 · Microsoft SharePoint Server 2019 · +1 more
Updated August 11, 2026
CVE-2026-65657 Microsoft
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +9 more
Updated August 11, 2026
CVE-2026-65664 Microsoft
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +9 more
Updated August 11, 2026
CVE-2026-65665 Microsoft
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft SharePoint Server 2019 · Microsoft SharePoint Server Subscription Edition
Updated August 11, 2026
CVE-2026-66799 Microsoft
Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated August 11, 2026
CVE-2026-68816 Microsoft
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +12 more
Updated August 11, 2026
CVE-2026-70130 Microsoft
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS 8.4
Update availability Patch status unknown Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +6 more
Updated August 11, 2026
CVE-2026-68364 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.150.1-1 on Azure Linux 3.0
Updated August 11, 2026
CVE-2026-64562 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.145.2-1 on Azure Linux 3.0
Updated August 9, 2026
CVE-2026-64565 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.145.2-1 on Azure Linux 3.0
Updated August 9, 2026
CVE-2026-64564 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.145.2-1 on Azure Linux 3.0
Updated August 9, 2026
CVE-2026-48144 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.1
Update availability Patch status unknown Affected: azl3 thrift 0.15.0-6 on Azure Linux 3.0
Updated August 7, 2026
CVE-2026-49163 Microsoft
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.
CVSS 8.8
Update availability Patch status unknown Affected: Application Insights Profiler
Updated August 6, 2026
CVE-2026-50481 Microsoft
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
CVSS 9.9
Update availability Patch status unknown Affected: Azure Active Directory
Updated August 6, 2026
CVE-2026-50515 Microsoft
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
CVSS 9.9
Update availability Patch status unknown Affected: Azure Service Bus
Updated August 6, 2026
CVE-2026-50516 Microsoft
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CVSS 9.4
Update availability Patch status unknown Affected: Azure Kubernetes Service
Updated August 6, 2026
CVE-2026-56161 Microsoft
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
CVSS 9.6
Update availability Patch status unknown Affected: Azure Logic Apps
Updated August 6, 2026