Common Vulnerabilities and Exposures (CVE)

CVE-2026-57969

Jul 27, 2026 23:46:55 UTC

Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

CVE-2026-57107

Jul 27, 2026 23:46:54 UTC

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.

CVE-2026-57097

Jul 27, 2026 23:46:49 UTC

Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-56185

Jul 27, 2026 23:46:49 UTC

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

CVE-2026-56193

Jul 27, 2026 23:46:48 UTC

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-54127

Jul 27, 2026 23:46:48 UTC

Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

CVE-2026-50694

Jul 27, 2026 23:46:47 UTC

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

CVE-2026-56170

Jul 27, 2026 23:46:47 UTC

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVE-2026-56169

Jul 27, 2026 23:46:46 UTC

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

CVE-2026-56164

Jul 27, 2026 23:46:45 UTC

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-56155

Jul 27, 2026 23:46:45 UTC

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

CVE-2026-55948

Jul 27, 2026 23:46:44 UTC

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55945

Jul 27, 2026 23:46:44 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

CVE-2026-55899

Jul 27, 2026 23:46:43 UTC

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-54988

Jul 27, 2026 23:46:43 UTC

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.