Common Vulnerabilities and Exposures (CVE)

CVE-2026-56169

Jul 20, 2026 23:08:43 UTC

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

CVE-2026-56164

Jul 20, 2026 23:08:43 UTC

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-56155

Jul 20, 2026 23:08:42 UTC

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

CVE-2026-55948

Jul 20, 2026 23:08:42 UTC

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55945

Jul 20, 2026 23:08:41 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

CVE-2026-55899

Jul 20, 2026 23:08:41 UTC

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-54988

Jul 20, 2026 23:08:40 UTC

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-50678

Jul 20, 2026 23:08:39 UTC

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-50675

Jul 20, 2026 23:08:39 UTC

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-54108

Jul 20, 2026 23:08:38 UTC

External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-50520

Jul 20, 2026 23:08:38 UTC

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.

CVE-2026-55144

Jul 20, 2026 23:08:37 UTC

Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.

CVE-2026-55002

Jul 20, 2026 23:08:37 UTC

External control of file name or path in SQL Server allows an authorized attacker to elevate privileges locally.

CVE-2026-54118

Jul 20, 2026 23:08:36 UTC

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.

CVE-2026-54117

Jul 20, 2026 23:08:35 UTC

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.