PatchSiren

Microsoft CVE debriefs · Page 4

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Microsoft CVE published 2026-09-08

CVE-2026-80080

A double free vulnerability in Microsoft Office Word could allow an unauthorized attacker to execute code over a network. This CVE was published on 2026-09-08T18:20:50.233Z and was last modified on 2026-09-17T20:18:34.770Z. The NVD entry is currently Analyzed. Defenders responsible for Microsoft Office Word installations, especially in network-connected environments, should assess exposure and prioritize [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-80078

Microsoft Office vulnerability CVE-2026-80078 allows unauthorized information disclosure over a network via an out-of-bounds read. Defenders should assess exposure of managed Office installations, prioritize remediation based on network exposure, and verify patching for affected Office versions according to vendor guidance. This medium-severity vulnerability requires defenders to review compensating contr [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-80077

CVE-2026-80077 debrief based on the supplied source corpus. The vulnerability is a heap-based buffer overflow in Remote Desktop Client, allowing unauthorized attackers to execute code over a network. Defenders should assess exposure and potential code execution risks. The CVE record and NVD entry provide details on this vulnerability, which has a CVSS score of 8.8 and is considered HIGH severity. The debr [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-80076

Microsoft Office vulnerability CVE-2026-80076 allows unauthorized information disclosure over a network due to an out-of-bounds read issue. Defenders should assess exposure, particularly for roles managing Microsoft Office deployments, and prioritize verification of affected versions and remediation. This vulnerability impacts Microsoft Office users who may be exposed to information disclosure attacks. Th [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-80075

CVE-2026-80075 is a heap-based buffer overflow vulnerability in Windows Work Folders that allows an authorized attacker to elevate privileges locally. The CVE record was published on 2026-09-08T18:20:49.443Z and has not been modified since then. The NVD entry is currently Analyzed. Defenders responsible for Windows systems with Work Folders enabled should prioritize patching this vulnerability to prevent [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-80074

CVE-2026-80074 is a high-severity heap-based buffer overflow vulnerability in Remote Desktop Client for Windows Desktop. An unauthorized attacker can exploit this vulnerability to execute code over a network. Defenders responsible for Remote Desktop Client deployments should assess exposure, verify versions, and prioritize patching or mitigation. This vulnerability has a CVSS score of 8.8 and is considere [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78526

Microsoft Office Word has a heap-based buffer overflow vulnerability that allows unauthorized attackers to execute code over a network. This vulnerability affects various versions of Microsoft Office, including Microsoft 365 Apps, Office 2016, Office 2019, Office 2021, and Office 2024. Defenders should prioritize patching vulnerable installations, especially those exposed to untrusted networks, to prevent [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78525

A use-after-free vulnerability in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. This CVE was published on 2026-09-08T18:20:48.227Z and was last modified on 2026-09-17T20:18:33.263Z. The NVD entry is currently Analyzed. The vulnerability affects Microsoft Office Outlook deployments, which defenders should assess for exposure and prioritize patching to prevent unau [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78524

Microsoft Office vulnerability CVE-2026-78524 allows unauthorized attackers to execute code over a network. Defenders should assess exposure, prioritize remediation, and verify affected systems. This high-severity vulnerability requires immediate attention to prevent potential code execution. Affected systems and configurations must be verified against official advisories. The CVE record and NVD entry pro [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78521

Microsoft Office Word is vulnerable to a heap-based buffer overflow, which could allow an unauthorized attacker to execute code over a network. This vulnerability affects Microsoft Office Word deployments and requires immediate attention from defenders. The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and vector. Microsoft has released a patch for the vulnerabili [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-78520

Microsoft Office Outlook vulnerability allows unauthorized attackers to execute code over a network via an out-of-bounds read. This medium-severity vulnerability, tracked as CVE-2026-78520, affects Microsoft Office Outlook and could allow attackers to execute code remotely. Defenders should prioritize verifying exposure in Microsoft Office Outlook deployments and applying patches from Microsoft. The CVE r [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78518

Microsoft Office Excel vulnerability allows unauthorized attackers to execute code over a network via an out-of-bounds read. This high-severity vulnerability, tracked as CVE-2026-78518, affects Microsoft Office Excel installations and requires immediate attention from defenders. The vulnerability enables attackers to execute code remotely, potentially leading to significant operational impacts. Defenders [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78517

A heap-based buffer overflow vulnerability exists in Microsoft Office Word, potentially allowing an unauthorized attacker to execute code over a network. This vulnerability, classified as CWE-122, has a CVSS score of 8.8, indicating high severity. Defenders should assess exposure, particularly in networked environments, and apply patches provided by Microsoft for the affected Office versions. The CVE reco [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-78516

CVE-2026-78516 is an insertion of sensitive information into an externally-accessible file or directory vulnerability in Windows Storage. An authorized attacker can disclose information locally. Microsoft has released a patch for this vulnerability. The vulnerability affects Windows Storage, allowing local information disclosure. Defenders should assess exposure and apply patches. Review local access cont [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-78515

Microsoft Office Excel is vulnerable to an out-of-bounds read, allowing unauthorized attackers to disclose information over a network. The CVE record was published on 2026-09-08T18:20:46.850Z. Defenders should assess exposure and prioritize patching. The NVD entry is currently Analyzed. A detailed review of the vulnerability indicates that it is a Medium-severity issue that requires verification of affect [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78514

A use-after-free vulnerability in Microsoft Office Word allows an unauthorized attacker to execute code over a network. This CVE was published on 2026-09-08T18:20:46.720Z and was last modified on 2026-09-17T20:18:32.057Z. The NVD entry is currently Analyzed. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. Defenders should prioritize verifying exposure of Microsoft Office Word in [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-78513

Microsoft Office PowerPoint is vulnerable to an out-of-bounds read, allowing local information disclosure. The CVE record was published on 2026-09-08T18:20:46.590Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Microsoft Office PowerPoint installations, which defenders should assess for exposure and prioritize patching for high-risk systems, consideri [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78512

CVE-2026-78512 is a numeric truncation error in Microsoft Office Word that allows an unauthorized attacker to execute code over a network. The CVE record was published on 2026-09-08T18:20:46.453Z and has not been modified since then. The NVD entry is currently Analyzed. Defenders should assess exposure and prioritize patching or mitigation in network-connected environments. This vulnerability has signific [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78511

A heap-based buffer overflow vulnerability exists in Microsoft Office Word, potentially allowing an unauthorized attacker to execute code over a network. The CVE record was published on 2026-09-08T18:20:46.327Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability, with a CVSS score of 8.8, indicates high severity and is associated with CWE-122. Defenders should ass [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78510

A critical vulnerability in Microsoft Office allows an unauthorized attacker to execute code over a network. The vulnerability is a heap-based buffer overflow, which can be exploited without requiring user interaction or privileges. This vulnerability affects Microsoft Office installations, and defenders should assess exposure and prioritize patching. The vulnerability has a CVSS score of 9.8 and is consi [truncated]

CRITICAL Microsoft CVE published 2026-09-08

CVE-2026-78509

A critical vulnerability in Microsoft Office Outlook could allow an unauthorized attacker to execute code over a network. This CVE was published on 2026-09-08T18:20:46.070Z and was last modified on 2026-09-17T20:18:31.397Z. The vulnerability is a heap-based buffer overflow, which could lead to unauthorized access to sensitive data and disruption of email services and business operations. Defenders respons [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78507

Microsoft Office Word has a high-severity vulnerability (CVE-2026-78507) that allows unauthorized code execution over a network due to a use-after-free issue. This vulnerability requires immediate attention from defenders, particularly those responsible for Microsoft Office Word deployments. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. Affected products include Microsoft 365 [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-78506

Microsoft Office Word Improper Null Termination Information Disclosure. The CVE-2026-78506 vulnerability in Microsoft Office Word is caused by improper null termination, allowing unauthorized attackers to disclose information locally. This medium-severity vulnerability, with a CVSS score of 5.5, requires assessment and mitigation. Defenders and IT administrators responsible for Microsoft Office Word insta [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78505

Microsoft Office has a heap-based buffer overflow vulnerability, classified as CWE-122, that allows unauthorized attackers to execute code over a network. This CVE was published on 2026-09-08T18:20:45.487Z and was last modified on 2026-09-17T20:18:30.867Z. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. Defenders responsible for Microsoft Office installations, particularly in en [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78504

A stack-based buffer overflow vulnerability exists in Microsoft Office Word, which could allow an unauthorized attacker to execute code over a network. The CVE record was published on 2026-09-08T18:20:45.360Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Microsoft Office Word and can be exploited over a network, potentially leading to unauthorized co [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-78503

Microsoft Office Word has a vulnerability that allows unauthorized information disclosure over a network via an out-of-bounds read. Defenders should assess exposure, prioritize remediation, and verify affected systems, configurations, and inventory. This vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. The CVE record and NVD entry provide details on the vulnerability, but specif [truncated]

MEDIUM Microsoft CVE published 2026-09-08

CVE-2026-78502

Microsoft Office Word vulnerability allows unauthorized information disclosure over a network via an out-of-bounds read. This Medium-severity vulnerability, tracked as CVE-2026-78502, affects Microsoft Office Word installations. Defenders should assess exposure, prioritize patching, and monitor for potential disclosure attempts. The vulnerability has a CVSS score of 6.5 and is considered Medium severity. [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78463

CVE-2026-78463 is a high-severity code injection vulnerability in Remote Desktop Client, allowing unauthorized attackers to execute code over a network. This vulnerability affects Remote Desktop Client users and administrators, who should assess exposure and prioritize remediation to prevent potential code execution, unauthorized access, and disruption of critical services. The vulnerability has a CVSS sc [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78462

CVE-2026-78462 is an authorization bypass vulnerability in Visual Studio Code that allows an unauthorized attacker to bypass a security feature over a network. The CVE record was published on 2026-09-08T18:20:44.670Z and was last modified on 2026-09-11T21:11:03.717Z. The NVD entry is currently Analyzed. Defenders should verify exposure, assess potential impact, and apply the vendor advisory and patch. The [truncated]

HIGH Microsoft CVE published 2026-09-08

CVE-2026-78461

Microsoft Visual Studio Code vulnerability allows unauthorized attackers to bypass security features over a network via path traversal, potentially impacting defenders who need to assess exposure and prioritize patching to prevent security feature bypass. This vulnerability requires defenders to verify exposure of Visual Studio Code installations, prioritize patching to prevent security feature bypass, an [truncated]