Common Vulnerabilities and Exposures (CVE)

CVE-2026-40367

Jun 9, 2026 19:33:29 UTC

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-40365

Jun 9, 2026 19:33:29 UTC

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVE-2026-40362

Jun 9, 2026 19:33:28 UTC

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-40361

Jun 9, 2026 19:33:27 UTC

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-40359

Jun 9, 2026 19:33:26 UTC

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-40358

Jun 9, 2026 19:33:25 UTC

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-40357

Jun 9, 2026 19:33:24 UTC

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVE-2026-34341

Jun 9, 2026 19:33:24 UTC

Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.

CVE-2026-34340

Jun 9, 2026 19:33:23 UTC

Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

CVE-2026-34339

Jun 9, 2026 19:33:23 UTC

Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally.

CVE-2026-34338

Jun 9, 2026 19:33:22 UTC

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

CVE-2026-34337

Jun 9, 2026 19:33:21 UTC

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-34336

Jun 9, 2026 19:33:21 UTC

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-34334

Jun 9, 2026 19:33:20 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

CVE-2026-34332

Jun 9, 2026 19:33:20 UTC

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.