Common Vulnerabilities and Exposures (CVE)

CVE-2026-57107

Aug 14, 2026 17:20:40 UTC

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.

CVE-2026-57097

Aug 14, 2026 17:20:40 UTC

Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-56179

Aug 14, 2026 17:20:40 UTC

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

CVE-2026-68817

Aug 14, 2026 17:20:39 UTC

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-56185

Aug 14, 2026 17:20:39 UTC

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

CVE-2026-56193

Aug 14, 2026 17:20:39 UTC

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-68814

Aug 14, 2026 17:20:38 UTC

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-54127

Aug 14, 2026 17:20:38 UTC

Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

CVE-2026-68812

Aug 14, 2026 17:20:38 UTC

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-50694

Aug 14, 2026 17:20:37 UTC

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

CVE-2026-68805

Aug 14, 2026 17:20:37 UTC

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-68804

Aug 14, 2026 17:20:37 UTC

Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-56170

Aug 14, 2026 17:20:37 UTC

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVE-2026-68803

Aug 14, 2026 17:20:36 UTC

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-56169

Aug 14, 2026 17:20:36 UTC

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.