Common Vulnerabilities and Exposures (CVE)

CVE-2026-50650

Aug 17, 2026 17:45:44 UTC

Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.

CVE-2026-65660

Aug 17, 2026 17:45:44 UTC

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-50649

Aug 17, 2026 17:45:44 UTC

Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.

CVE-2026-65663

Aug 17, 2026 17:45:44 UTC

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVE-2026-50648

Aug 17, 2026 17:45:43 UTC

Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.

CVE-2026-65661

Aug 17, 2026 17:45:43 UTC

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-50647

Aug 17, 2026 17:45:43 UTC

Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

CVE-2026-65658

Aug 17, 2026 17:45:42 UTC

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVE-2026-50646

Aug 17, 2026 17:45:42 UTC

Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.

CVE-2026-65656

Aug 17, 2026 17:45:42 UTC

Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-50528

Aug 17, 2026 17:45:42 UTC

Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-65657

Aug 17, 2026 17:45:41 UTC

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-50527

Aug 17, 2026 17:45:41 UTC

Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.

CVE-2026-64922

Aug 17, 2026 17:45:41 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-50526

Aug 17, 2026 17:45:40 UTC

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.