Security Risk Category

Microsoft Security Risks — Page 3

Published vulnerability pages connected to Microsoft. Each page keeps one canonical URL and focused remediation guidance.

212 published Microsoft risks

Microsoft risks

Showing 73–108 of 212 published risks.

highEPSS 0.003

CVE-2026-55133 365 apps vulnerability

Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.

CVE-2026-55133microsoftmemory-corruption

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55134 365 apps vulnerability

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-55134microsoftmemory-corruption

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-55139 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55139microsoftinformation-disclosure

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55140 365 apps vulnerability

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-55140microsoftmemory-corruption

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-55142 365 apps vulnerability

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-55142microsoft

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-56192 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-56192microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-56195 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-56195microsoftinformation-disclosure

Updated Jul 17, 2026

highEPSS 0.004

CVE-2026-57101 visual studio code vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-57101microsoftxss

Updated Jul 17, 2026

highEPSS 0.008

CVE-2026-57102 visual studio code vulnerability

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-57102microsoftsupply-chaininformation-disclosure

Updated Jul 17, 2026

highEPSS 0.007

CVE-2026-58617 365 copilot vulnerability

Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-58617microsoftauthorization-bypass

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-58629 windows 10 1607 vulnerability

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

CVE-2026-58629windowsmicrosoftmemory-corruption

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-47305 visual studio 2022 vulnerability

Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.

CVE-2026-47305microsoft

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-50675 in Microsoft 365 Apps

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-50675microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-50678 in Microsoft 365 Apps

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-50678microsoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-50697 in Microsoft Windows

Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-50697windowsmicrosoftinformation-disclosureprivilege-escalation

Updated Jul 16, 2026

highEPSS 0.002

CVE-2026-54107 in Microsoft Windows

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-54107windowsmicrosoftprivilege-escalationrace-condition

Updated Jul 16, 2026

highEPSS 0.002

CVE-2026-54109 in Microsoft Windows

Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

CVE-2026-54109windowsmicrosoftremote-code-executioninput-validation

Updated Jul 16, 2026

highEPSS 0.002

CVE-2026-54111 in Microsoft Windows

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-54111windowsmicrosoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

highEPSS 0.002

CVE-2026-54112 in Microsoft Windows

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-54112windowsmicrosoftmemory-corruptionprivilege-escalation

Updated Jul 16, 2026

mediumEPSS 0.005

CVE-2026-48580 in Microsoft 365 Apps

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-48580microsoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

mediumEPSS 0.004

CVE-2026-50408 in Microsoft 365 Apps

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-50408microsoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-54131 in Microsoft 365 Apps

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-54131microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.004

CVE-2026-55024 in Microsoft 365 Apps

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55024microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55025 in Microsoft 365 Apps

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55025microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55029 in Microsoft 365 Apps

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55029microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.004

CVE-2026-55031 in Microsoft 365 Apps

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55031microsoftremote-code-executioninformation-disclosurememory-corruption

Updated Jul 16, 2026

criticalEPSS 0.007

CVE-2026-55040 in Microsoft SharePoint Server

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-55040microsoftweb-applicationauthentication-bypassauthorization-bypass

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55048 in Microsoft 365 Apps

Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55048microsoftremote-code-executioninput-validationmemory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55053 in Microsoft 365 Apps

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55053microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55058 in Microsoft 365 Apps

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55058microsoftremote-code-executioninformation-disclosurememory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55120 in Microsoft 365 Apps

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

CVE-2026-55120microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

mediumEPSS 0.004

CVE-2026-55121 in Microsoft 365 Apps

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55121microsoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55122 in Microsoft 365 Apps

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-55122microsoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55130 in Microsoft 365 Apps

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-55130microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55131 in Microsoft 365 Apps

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55131microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55136 in Microsoft 365 Apps

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55136microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026