Common Vulnerabilities and Exposures (CVE)

CVE-2026-19201

Sep 8, 2026 23:48:38 UTC

An uncontrolled recursion vulnerability in the Windows SIPA event log parser of Google go-attestation versions up to and including 0.6.1 allows an attacker to cause a denial of service (DoS). The (*WinEvents).readELAMAggregation function re...

CVE-2026-83711

Sep 8, 2026 23:42:34 UTC

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-80098

Sep 8, 2026 23:42:33 UTC

Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-70352

Sep 8, 2026 23:42:33 UTC

Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-62906

Sep 8, 2026 23:42:32 UTC

Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.

CVE-2026-62804

Sep 8, 2026 23:42:31 UTC

External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-66307

Sep 8, 2026 23:42:31 UTC

Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.

CVE-2026-66303

Sep 8, 2026 23:42:30 UTC

Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.

CVE-2026-84003

Sep 8, 2026 23:42:30 UTC

Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-83498

Sep 8, 2026 23:42:29 UTC

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

CVE-2026-83501

Sep 8, 2026 23:42:29 UTC

Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.

CVE-2026-85875

Sep 8, 2026 23:42:28 UTC

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-69806

Sep 8, 2026 23:42:28 UTC

Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.

CVE-2026-84000

Sep 8, 2026 23:42:27 UTC

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.

CVE-2026-83997

Sep 8, 2026 23:42:27 UTC

Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.