CVE-2026-54130
- EPSS 0.58%
- Veröffentlicht 18.06.2026 21:42:39
- Zuletzt bearbeitet 25.06.2026 18:59:48
Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-45474
- EPSS 0.36%
- Veröffentlicht 09.06.2026 17:17:21
- Zuletzt bearbeitet 23.07.2026 08:10:00
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45472
- EPSS 0.36%
- Veröffentlicht 09.06.2026 17:17:21
- Zuletzt bearbeitet 23.07.2026 08:10:00
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45460
- EPSS 0.36%
- Veröffentlicht 09.06.2026 17:17:20
- Zuletzt bearbeitet 23.07.2026 08:10:00
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-45463
- EPSS 0.36%
- Veröffentlicht 09.06.2026 17:17:20
- Zuletzt bearbeitet 23.07.2026 08:10:00
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45461
- EPSS 0.39%
- Veröffentlicht 09.06.2026 17:17:20
- Zuletzt bearbeitet 23.07.2026 08:10:00
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45497
- EPSS 0.45%
- Veröffentlicht 04.06.2026 22:00:49
- Zuletzt bearbeitet 23.07.2026 07:10:00
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network.
CVE-2026-42824
- EPSS 7.64%
- Veröffentlicht 04.06.2026 22:00:49
- Zuletzt bearbeitet 23.07.2026 07:10:00
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-41090
- EPSS 0.42%
- Veröffentlicht 22.05.2026 22:03:09
- Zuletzt bearbeitet 23.07.2026 11:10:00
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
CVE-2026-42827
- EPSS 0.5%
- Veröffentlicht 22.05.2026 22:03:08
- Zuletzt bearbeitet 23.07.2026 11:10:00
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.