Security Risk Category
Microsoft Security Risks — Page 3
Published vulnerability pages connected to Microsoft. Each page keeps one canonical URL and focused remediation guidance.
212 published Microsoft risks
Microsoft risks
Showing 73–108 of 212 published risks.
CVE-2026-55133 365 apps vulnerability
Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.
Updated Jul 17, 2026
CVE-2026-55134 365 apps vulnerability
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Updated Jul 17, 2026
CVE-2026-55139 365 apps vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-55140 365 apps vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Updated Jul 17, 2026
CVE-2026-55142 365 apps vulnerability
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-56192 365 apps vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-56195 365 apps vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-57101 visual studio code vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Updated Jul 17, 2026
CVE-2026-57102 visual studio code vulnerability
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Updated Jul 17, 2026
CVE-2026-58617 365 copilot vulnerability
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
Updated Jul 17, 2026
CVE-2026-58629 windows 10 1607 vulnerability
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-47305 visual studio 2022 vulnerability
Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.
Updated Jul 17, 2026
CVE-2026-50675 in Microsoft 365 Apps
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-50678 in Microsoft 365 Apps
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Updated Jul 16, 2026
CVE-2026-50697 in Microsoft Windows
Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Updated Jul 16, 2026
CVE-2026-54107 in Microsoft Windows
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.
Updated Jul 16, 2026
CVE-2026-54109 in Microsoft Windows
Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-54111 in Microsoft Windows
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
Updated Jul 16, 2026
CVE-2026-54112 in Microsoft Windows
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.
Updated Jul 16, 2026
CVE-2026-48580 in Microsoft 365 Apps
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Updated Jul 16, 2026
CVE-2026-50408 in Microsoft 365 Apps
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Updated Jul 16, 2026
CVE-2026-54131 in Microsoft 365 Apps
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55024 in Microsoft 365 Apps
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55025 in Microsoft 365 Apps
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55029 in Microsoft 365 Apps
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55031 in Microsoft 365 Apps
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55040 in Microsoft SharePoint Server
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
Updated Jul 16, 2026
CVE-2026-55048 in Microsoft 365 Apps
Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55053 in Microsoft 365 Apps
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55058 in Microsoft 365 Apps
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55120 in Microsoft 365 Apps
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55121 in Microsoft 365 Apps
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Updated Jul 16, 2026
CVE-2026-55122 in Microsoft 365 Apps
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Updated Jul 16, 2026
CVE-2026-55130 in Microsoft 365 Apps
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55131 in Microsoft 365 Apps
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55136 in Microsoft 365 Apps
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
