CVE Notify
19.6K subscribers
4 photos
310K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-62915
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.

🎖@cveNotify
🚨 CVE-2026-63531
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-64899
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-65660
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

🎖@cveNotify
🚨 CVE-2026-65769
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.

🎖@cveNotify
🚨 CVE-2026-65777
Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.

🎖@cveNotify
🚨 CVE-2026-65794
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

🎖@cveNotify
🚨 CVE-2026-68799
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-68809
Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-70316
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-18687
MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed request that leads to a server crash or excessive internal writes, resulting in resource exhaustion and corruption of encrypted index data.

🎖@cveNotify
🚨 CVE-2026-18688
An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain aggregation pipeline stage. This could result in a server crash (denial of service) and may potentially expose a limited amount of memory contents.

🎖@cveNotify
🚨 CVE-2026-18690
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not permit. This could result in critical system collections being dropped and recreated without proper authorization.

🎖@cveNotify
🚨 CVE-2026-18691
An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another. Under certain conditions, this could cause the cluster's shared internal credential to be transmitted in a less-protected form, potentially allowing that credential to be recovered. If recovered, the credential could be used to authenticate as the internal superuser to nodes in the deployment.

🎖@cveNotify
🚨 CVE-2026-18692
An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed. Subsequent operations could then result in a server crash or, potentially, execution of unintended code.

🎖@cveNotify
🚨 CVE-2026-18693
An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges to cause an internal data structure to become inconsistent through certain document insertions. A subsequent insert into the affected bucket could then result in the server accessing memory outside its intended bounds, potentially causing a server crash (denial of service), exposure of limited memory contents, or memory corruption.

🎖@cveNotify
🚨 CVE-2026-18694
An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry data to be stored and later processed without proper validation. Subsequent queries against this data could then result in the server accessing memory outside its intended bounds. This could result in a server crash (denial of service) and may expose a limited amount of server process memory.

🎖@cveNotify
🚨 CVE-2026-18695
An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could allow an authenticated user with write access to cause the server process to terminate unexpectedly, resulting in a denial of service.

🎖@cveNotify
🚨 CVE-2026-18696
An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.

🎖@cveNotify
🚨 CVE-2026-18697
An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service, disrupting client connections routed through the affected mongos instance.

🎖@cveNotify
🚨 CVE-2026-18698
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges. This could result in exposure of collection metadata and, on certain deployment configurations, unauthorized modification of system collection data.

🎖@cveNotify