CVE-2026-45463
- EPSS 0.36%
- Veröffentlicht 09.06.2026 17:17:20
- Zuletzt bearbeitet 23.07.2026 08:10:00
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45461
- EPSS 0.39%
- Veröffentlicht 09.06.2026 17:17:20
- Zuletzt bearbeitet 23.07.2026 08:10:00
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45460
- EPSS 0.36%
- Veröffentlicht 09.06.2026 17:17:20
- Zuletzt bearbeitet 23.07.2026 08:10:00
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-45497
- EPSS 0.45%
- Veröffentlicht 04.06.2026 22:00:49
- Zuletzt bearbeitet 23.07.2026 07:10:00
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network.
CVE-2026-42824
- EPSS 7.64%
- Veröffentlicht 04.06.2026 22:00:49
- Zuletzt bearbeitet 23.07.2026 07:10:00
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-41090
- EPSS 0.42%
- Veröffentlicht 22.05.2026 22:03:09
- Zuletzt bearbeitet 23.07.2026 11:10:00
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
CVE-2026-42827
- EPSS 0.5%
- Veröffentlicht 22.05.2026 22:03:08
- Zuletzt bearbeitet 23.07.2026 11:10:00
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-41614
- EPSS 0.36%
- Veröffentlicht 12.05.2026 16:58:57
- Zuletzt bearbeitet 14.05.2026 14:25:16
Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.
CVE-2026-41100
- EPSS 0.25%
- Veröffentlicht 12.05.2026 16:58:53
- Zuletzt bearbeitet 16.05.2026 01:49:18
Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.
CVE-2026-33102
- EPSS 0.4%
- Veröffentlicht 23.04.2026 21:35:48
- Zuletzt bearbeitet 29.04.2026 19:04:21
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.