Ad

CVE Vulnerability Database

Complete database of CVE vulnerabilities. Track critical security threats, exploits and patches. Updated daily from NVD NIST.

CVE-2026-26117

7.8

Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.

Microsoft
Details

CVE-2026-26116

8.8

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Microsoft
Details

CVE-2026-26115

8.8

Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.

Microsoft
Details

CVE-2026-26114

8.8

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Microsoft
Details

CVE-2026-26113

7.8

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

Microsoft
Details

CVE-2026-26112

7.8

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Microsoft
Details

CVE-2026-26111

8.0

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

Microsoft
Details

CVE-2026-26110

7.8

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Microsoft
Details

CVE-2026-26109

7.8

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Microsoft
Details

CVE-2026-26108

7.8

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Microsoft
Details
744/3864