Security Risk Category

Remote Code Execution Security Risks — Page 3

Published vulnerability pages connected to Remote Code Execution. Each page keeps one canonical URL and focused remediation guidance.

303 published Remote Code Execution risks

Remote Code Execution risks

Showing 73–108 of 303 published risks.

highEPSS 0.002

CVE-2026-48342 bridge vulnerability

Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48342remote-code-executioninput-validation

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48343 bridge vulnerability

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48343remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48344 creative cloud desktop application vulnerability

Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48344remote-code-executionrace-condition

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48366 media encoder vulnerability

Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48366remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48367 after effects vulnerability

After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48367remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48369 premiere pro vulnerability

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48369remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48370 media encoder vulnerability

Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48370remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-48275 illustrator vulnerability

Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-48275supply-chainremote-code-execution

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48287 c2pa vulnerability

CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

CVE-2026-48287supply-chainremote-code-execution

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-48290 c2pa vulnerability

CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

CVE-2026-48290remote-code-executionssrf

Updated Jul 17, 2026

criticalEPSS 0.004

CVE-2026-48334 illustrator vulnerability

Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-48334remote-code-executioninput-validation

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48335 illustrator vulnerability

Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48335remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48336 illustrator vulnerability

Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48336remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48337 illustrator vulnerability

Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48337remote-code-executionmemory-corruption

Updated Jul 17, 2026

criticalEPSS 0.003

CVE-2026-56400 open webui vulnerability

open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary code on the openwebui instance by crafting malicious cross-site requests from attacker-controlled websites when an admin user visits them.

CVE-2026-56400api-securityweb-applicationremote-code-execution

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-50675 in Microsoft 365 Apps

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-50675microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.002

CVE-2026-54109 in Microsoft Windows

Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

CVE-2026-54109windowsmicrosoftremote-code-executioninput-validation

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-54131 in Microsoft 365 Apps

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-54131microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.004

CVE-2026-55024 in Microsoft 365 Apps

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55024microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55025 in Microsoft 365 Apps

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55025microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55029 in Microsoft 365 Apps

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55029microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.004

CVE-2026-55031 in Microsoft 365 Apps

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55031microsoftremote-code-executioninformation-disclosurememory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55048 in Microsoft 365 Apps

Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55048microsoftremote-code-executioninput-validationmemory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55053 in Microsoft 365 Apps

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55053microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55058 in Microsoft 365 Apps

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55058microsoftremote-code-executioninformation-disclosurememory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55120 in Microsoft 365 Apps

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

CVE-2026-55120microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55130 in Microsoft 365 Apps

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-55130microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55131 in Microsoft 365 Apps

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55131microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55136 in Microsoft 365 Apps

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55136microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55137 in Microsoft 365 Apps

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55137microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55141 in Microsoft 365 Apps

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55141microsoftremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-15767 in Google Chrome

Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High)

CVE-2026-15767browserwindowsremote-code-executionmemory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-15776 in Google Chrome

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15776browserremote-code-executionmemory-corruption

Updated Jul 16, 2026

criticalEPSS 0.022

CVE-2026-48284 in Adobe ColdFusion

ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48284web-applicationremote-code-executioninput-validation

Updated Jul 16, 2026

criticalEPSS 0.009

CVE-2026-48319 in Adobe ColdFusion

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48319web-applicationremote-code-executionpath-traversal

Updated Jul 16, 2026

criticalEPSS 0.004

CVE-2026-48322 in Adobe ColdFusion

ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48322web-applicationremote-code-execution

Updated Jul 16, 2026