Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.8 MEDIUM
CVE-2026-57097 — Microsoft XML Security Feature Bypass Vulnerability

Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.

Jul 14, 2026 Jul 22, 2026
Jul 14, 2026
Jul 22, 2026
7.1 HIGH
CVE-2026-56193 — Microsoft Office Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Jul 14, 2026 Jul 16, 2026
Jul 14, 2026
Jul 16, 2026
6.5 MEDIUM
CVE-2026-56185 — Windows Admin Center Information Disclosure Vulnerability

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

Jul 14, 2026 Jul 21, 2026
Jul 14, 2026
Jul 21, 2026
7.5 HIGH
CVE-2026-56170 — ASP.NET Core Denial of Service Vulnerability

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Jul 14, 2026 Jul 22, 2026
Jul 14, 2026
Jul 22, 2026
8.8 HIGH
CVE-2026-56169 — Windows Admin Center Elevation of Privilege Vulnerability

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

Jul 14, 2026 Jul 21, 2026
Jul 14, 2026
Jul 21, 2026
9.8 CRITICAL
CVE-2026-56164 — Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability - …

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
7.8 HIGH
CVE-2026-56155 — Microsoft Active Directory Federation Services Insufficient Granularity of Access Control…

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.8 HIGH
CVE-2026-55948 — Microsoft Excel Remote Code Execution Vulnerability

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026 Jul 16, 2026
Jul 14, 2026
Jul 16, 2026
7.8 HIGH
CVE-2026-55899 — Microsoft Excel Remote Code Execution Vulnerability

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026 Jul 16, 2026
Jul 14, 2026
Jul 16, 2026
7.1 HIGH
CVE-2026-55144 — Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability

Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.

Jul 14, 2026 Jul 21, 2026
Jul 14, 2026
Jul 21, 2026
7.8 HIGH
CVE-2026-55014 — Windows Remote Help Defense Elevation of Privilege Vulnerability

Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.

Jul 14, 2026 Jul 24, 2026
Jul 14, 2026
Jul 24, 2026
7.8 HIGH
CVE-2026-55012 — Microsoft Defender Remote Code Execution Vulnerability

Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.

Jul 14, 2026 Jul 24, 2026
Jul 14, 2026
Jul 24, 2026
7.8 HIGH
CVE-2026-55011 — Microsoft Defender Remote Code Execution Vulnerability

Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.

Jul 14, 2026 Jul 24, 2026
Jul 14, 2026
Jul 24, 2026
7.8 HIGH
CVE-2026-55009 — Microsoft Exchange Server Elevation of Privilege Vulnerability

Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

Jul 14, 2026 Jul 24, 2026
Jul 14, 2026
Jul 24, 2026
9.6 CRITICAL
CVE-2026-55008 — Microsoft Exchange Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Jul 14, 2026 Jul 24, 2026
Jul 14, 2026
Jul 24, 2026
7.8 HIGH
CVE-2026-55006 — Microsoft Exchange Server Elevation of Privilege Vulnerability

Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

Jul 14, 2026 Jul 24, 2026
Jul 14, 2026
Jul 24, 2026
8.8 HIGH
CVE-2026-55005 — Microsoft Exchange Server Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

Jul 14, 2026 Jul 24, 2026
Jul 14, 2026
Jul 24, 2026
7.8 HIGH
CVE-2026-55004 — Windows Print Configuration Elevation of Privilege Vulnerability

Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

Jul 14, 2026 Jul 24, 2026
Jul 14, 2026
Jul 24, 2026
6.5 MEDIUM
CVE-2026-55003 — Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

Jul 14, 2026 Jul 24, 2026
Jul 14, 2026
Jul 24, 2026
8.8 HIGH
CVE-2026-55002 — Microsoft SQL Server Elevation of Privilege Vulnerability

External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.

Jul 14, 2026 Aug 04, 2026
Jul 14, 2026
Aug 04, 2026
Showing 20 of 11267 Results