Common Vulnerabilities and Exposures (CVE)

CVE-2026-87875

Sep 11, 2026 23:55:37 UTC

The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/s...

CVE-2026-89266

Sep 11, 2026 23:23:26 UTC

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions v...

CVE-2026-86169

Sep 11, 2026 23:18:44 UTC

Axolotl before 0.19.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python co...

CVE-2026-83711

Sep 11, 2026 22:18:30 UTC

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-80098

Sep 11, 2026 22:18:29 UTC

Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-70352

Sep 11, 2026 22:18:29 UTC

Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-62906

Sep 11, 2026 22:18:28 UTC

Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.

CVE-2026-62804

Sep 11, 2026 22:18:27 UTC

External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-66307

Sep 11, 2026 22:18:27 UTC

Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.

CVE-2026-66303

Sep 11, 2026 22:18:26 UTC

Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.

CVE-2026-84003

Sep 11, 2026 22:18:26 UTC

Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-83498

Sep 11, 2026 22:18:25 UTC

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

CVE-2026-83501

Sep 11, 2026 22:18:24 UTC

Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.

CVE-2026-85875

Sep 11, 2026 22:18:24 UTC

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-69806

Sep 11, 2026 22:18:23 UTC

Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.