CVE-2026-55018 Microsoft Office Remote Code Execution Vulnerability
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Continue reading CVE-2026-55018 Microsoft Office Remote Code Execution Vulnerability
Opinions, tips, and news orbiting Microsoft
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Continue reading CVE-2026-55018 Microsoft Office Remote Code Execution Vulnerability
Concurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Runtime allows an authorized attacker to elevate privileges locally. Continue reading CVE-2026-50385 Windows Runtime Elevation of Privilege Vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. Continue reading CVE-2026-55035 Microsoft Office Information Disclosure Vulnerability
Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. Continue reading CVE-2026-58534 Windows Input Method Editor (IME) Elevation of Privilege Vulnerability
Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally. Continue reading CVE-2026-50401 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack. Continue reading CVE-2026-50492 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally. Continue reading CVE-2026-57095 Win32k Elevation of Privilege Vulnerability
Improper neutralization of input during web page generation (‘cross-site scripting’) in Power BI allows an authorized attacker to perform spoofing over a network. Continue reading CVE-2026-58647 Microsoft PowerBI Report Server Spoofing Vulnerability