CVE Notify
19.6K subscribers
4 photos
310K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-62730
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-62775
Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-62798
Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-62837
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

🎖@cveNotify
🚨 CVE-2026-62887
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-62893
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-62900
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.

🎖@cveNotify
🚨 CVE-2026-62915
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.

🎖@cveNotify
🚨 CVE-2026-63531
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-64899
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-65660
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

🎖@cveNotify
🚨 CVE-2026-65769
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.

🎖@cveNotify
🚨 CVE-2026-65777
Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.

🎖@cveNotify
🚨 CVE-2026-65794
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

🎖@cveNotify
🚨 CVE-2026-68799
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-68809
Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-70316
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-18687
MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed request that leads to a server crash or excessive internal writes, resulting in resource exhaustion and corruption of encrypted index data.

🎖@cveNotify
🚨 CVE-2026-18688
An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain aggregation pipeline stage. This could result in a server crash (denial of service) and may potentially expose a limited amount of memory contents.

🎖@cveNotify
🚨 CVE-2026-18690
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not permit. This could result in critical system collections being dropped and recreated without proper authorization.

🎖@cveNotify
🚨 CVE-2026-18691
An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another. Under certain conditions, this could cause the cluster's shared internal credential to be transmitted in a less-protected form, potentially allowing that credential to be recovered. If recovered, the credential could be used to authenticate as the internal superuser to nodes in the deployment.

🎖@cveNotify