Common Vulnerabilities and Exposures (CVE)

CVE-2026-65784

Aug 11, 2026 23:59:05 UTC

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

CVE-2026-65785

Aug 11, 2026 23:59:04 UTC

Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.

CVE-2026-65675

Aug 11, 2026 23:59:03 UTC

No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-65672

Aug 11, 2026 23:59:03 UTC

Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.

CVE-2026-65671

Aug 11, 2026 23:59:02 UTC

Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.

CVE-2026-65662

Aug 11, 2026 23:59:01 UTC

Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.

CVE-2026-65660

Aug 11, 2026 23:59:00 UTC

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-64922

Aug 11, 2026 23:58:56 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-63521

Aug 11, 2026 23:58:55 UTC

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-63517

Aug 11, 2026 23:58:54 UTC

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-54123

Aug 11, 2026 23:58:53 UTC

Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.

CVE-2026-62915

Aug 11, 2026 23:58:52 UTC

Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.

CVE-2026-62914

Aug 11, 2026 23:58:51 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

CVE-2026-62912

Aug 11, 2026 23:58:50 UTC

Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.

CVE-2026-62908

Aug 11, 2026 23:58:49 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.