Common Vulnerabilities and Exposures (CVE)

CVE-2026-62904

Aug 31, 2026 20:06:27 UTC

Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

CVE-2026-58616

Aug 31, 2026 20:06:27 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.

CVE-2026-55013

Aug 31, 2026 20:06:26 UTC

Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.

CVE-2026-55015

Aug 31, 2026 20:06:26 UTC

Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.

CVE-2026-69550

Aug 31, 2026 20:06:25 UTC

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

CVE-2026-24301

Aug 31, 2026 20:06:24 UTC

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2026-69414

Aug 31, 2026 20:06:24 UTC

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this ...

CVE-2026-50523

Aug 31, 2026 20:06:23 UTC

Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.

CVE-2026-70339

Aug 31, 2026 20:06:23 UTC

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-72971

Aug 31, 2026 20:06:22 UTC

Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.

CVE-2026-70355

Aug 31, 2026 20:06:22 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

CVE-2026-70348

Aug 31, 2026 20:06:21 UTC

Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.

CVE-2026-70347

Aug 31, 2026 20:06:21 UTC

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-70346

Aug 31, 2026 20:06:20 UTC

Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-70345

Aug 31, 2026 20:06:20 UTC

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.