Security Risk Category
Remote Code Execution Security Risks — Page 3
Published vulnerability pages connected to Remote Code Execution. Each page keeps one canonical URL and focused remediation guidance.
303 published Remote Code Execution risks
Remote Code Execution risks
Showing 73–108 of 303 published risks.
CVE-2026-48342 bridge vulnerability
Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Updated Jul 17, 2026
CVE-2026-48343 bridge vulnerability
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Updated Jul 17, 2026
CVE-2026-48344 creative cloud desktop application vulnerability
Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.
Updated Jul 17, 2026
CVE-2026-48366 media encoder vulnerability
Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Updated Jul 17, 2026
CVE-2026-48367 after effects vulnerability
After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Updated Jul 17, 2026
CVE-2026-48369 premiere pro vulnerability
Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Updated Jul 17, 2026
CVE-2026-48370 media encoder vulnerability
Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Updated Jul 17, 2026
CVE-2026-48275 illustrator vulnerability
Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Updated Jul 17, 2026
CVE-2026-48287 c2pa vulnerability
CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Updated Jul 17, 2026
CVE-2026-48290 c2pa vulnerability
CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Updated Jul 17, 2026
CVE-2026-48334 illustrator vulnerability
Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Updated Jul 17, 2026
CVE-2026-48335 illustrator vulnerability
Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Updated Jul 17, 2026
CVE-2026-48336 illustrator vulnerability
Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Updated Jul 17, 2026
CVE-2026-48337 illustrator vulnerability
Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Updated Jul 17, 2026
CVE-2026-56400 open webui vulnerability
open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary code on the openwebui instance by crafting malicious cross-site requests from attacker-controlled websites when an admin user visits them.
Updated Jul 17, 2026
CVE-2026-50675 in Microsoft 365 Apps
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-54109 in Microsoft Windows
Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-54131 in Microsoft 365 Apps
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55024 in Microsoft 365 Apps
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55025 in Microsoft 365 Apps
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55029 in Microsoft 365 Apps
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55031 in Microsoft 365 Apps
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55048 in Microsoft 365 Apps
Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55053 in Microsoft 365 Apps
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55058 in Microsoft 365 Apps
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55120 in Microsoft 365 Apps
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55130 in Microsoft 365 Apps
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55131 in Microsoft 365 Apps
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55136 in Microsoft 365 Apps
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55137 in Microsoft 365 Apps
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-55141 in Microsoft 365 Apps
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 16, 2026
CVE-2026-15767 in Google Chrome
Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High)
Updated Jul 16, 2026
CVE-2026-15776 in Google Chrome
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Updated Jul 16, 2026
CVE-2026-48284 in Adobe ColdFusion
ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Updated Jul 16, 2026
CVE-2026-48319 in Adobe ColdFusion
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Updated Jul 16, 2026
CVE-2026-48322 in Adobe ColdFusion
ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Updated Jul 16, 2026
