CVE-2026-78505 Microsoft
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated September 17, 2026
CVE-2026-78509 Microsoft
Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVSS 9.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated September 17, 2026
CVE-2026-78520 Microsoft
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVSS 6.5
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated September 17, 2026
CVE-2026-78525 Microsoft
Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated September 17, 2026
CVE-2026-81948 Microsoft
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +13 more
Updated September 17, 2026
CVE-2026-81949 Microsoft
Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +13 more
Updated September 17, 2026
CVE-2026-81950 Microsoft
Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +13 more
Updated September 17, 2026
CVE-2026-81952 Microsoft
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated September 17, 2026
CVE-2026-81953 Microsoft
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +13 more
Updated September 17, 2026
CVE-2026-81955 Microsoft
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +41 more
Updated September 17, 2026
CVE-2026-81959 Microsoft
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +13 more
Updated September 17, 2026
CVE-2026-83944 Microsoft
Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
Update availability Patch status unknown Affected: Azure Logic Apps
Updated September 17, 2026
CVE-2026-83946 Microsoft
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.
CVSS 8.2
Update availability Patch status unknown Affected: Azure Portal
Updated September 17, 2026
CVE-2026-85878 Microsoft
Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.
CVSS 9.9
Update availability Patch status unknown Affected: Azure HorizonDB
Updated September 17, 2026
CVE-2026-85885 Microsoft
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.
CVSS 9.9
Update availability Patch status unknown Affected: Microsoft 365 Copilot
Updated September 17, 2026
CVE-2026-85887 Microsoft
Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.
CVSS 7.7
Update availability Patch status unknown Affected: Microsoft 365 Copilot
Updated September 17, 2026
CVE-2026-85889 Microsoft
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
Update availability Patch status unknown Affected: Azure AI Foundry
Updated September 17, 2026
CVE-2026-85917 Microsoft
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVSS 7.5
Update availability Patch status unknown Affected: Azure AI Foundry
Updated September 17, 2026
CVE-2026-87701 Microsoft
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
CVSS 9.6
Update availability Patch status unknown Affected: Azure Cosmos DB
Updated September 17, 2026
CVE-2026-63508 Microsoft
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
Update availability Patch status unknown Affected: Microsoft Planetary Computer Pro (GeoCatalog)
Updated September 15, 2026
CVE-2026-73006 Microsoft
Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 15, 2026
CVE-2026-69860 Microsoft
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 11, 2026
CVE-2026-85507 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Security update available Affected: azl3 freeipmi 1.6.18-1 on Azure Linux 3.0
Updated September 10, 2026
CVE-2026-85506 Microsoft
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).
CVSS 9.8
Update availability Security update available Affected: azl3 freeipmi 1.6.18-1 on Azure Linux 3.0
Updated September 10, 2026