Common Vulnerabilities and Exposures (CVE)

CVE-2026-44820

Jun 19, 2026 20:27:53 UTC

Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-44819

Jun 19, 2026 20:27:52 UTC

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-44818

Jun 19, 2026 20:27:52 UTC

Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-44817

Jun 19, 2026 20:27:51 UTC

Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-42902

Jun 19, 2026 20:27:51 UTC

Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.

CVE-2026-34335

Jun 19, 2026 20:27:50 UTC

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-33828

Jun 19, 2026 20:27:50 UTC

Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.

CVE-2026-40404

Jun 19, 2026 20:27:49 UTC

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

CVE-2026-40409

Jun 19, 2026 20:27:49 UTC

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

CVE-2026-48584

Jun 19, 2026 20:27:48 UTC

Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.

CVE-2026-47647

Jun 19, 2026 20:27:47 UTC

Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.

CVE-2026-54130

Jun 19, 2026 20:27:47 UTC

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2026-42895

Jun 19, 2026 20:27:46 UTC

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

CVE-2026-45480

Jun 19, 2026 20:27:46 UTC

Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-32174

Jun 19, 2026 20:27:45 UTC

Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.