Known Vulnerabilities for Microsoft by Vendor
Listed below are 10 of the newest known vulnerabilities associated with "Microsoft" by "Vendor".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-62826 json | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an... | Not Provided | 2026-07-16 | 2026-07-21 |
| CVE-2026-61371 json | Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/overw... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-59864 json | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `... | Not Provided | 2026-07-16 | 2026-07-17 |
| CVE-2026-59162 json | Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses shar... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-59161 json | Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming worksh... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-58644 json | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a netwo... | Not Provided | 2026-07-14 | 2026-07-17 |
| CVE-2026-58618 json | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Not Provided | 2026-07-14 | 2026-07-15 |
| CVE-2026-58617 json | Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network... | Not Provided | 2026-07-14 | 2026-07-15 |
| CVE-2026-58610 json | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. | Not Provided | 2026-07-14 | 2026-07-22 |
| CVE-2026-58609 json | Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. | Not Provided | 2026-07-14 | 2026-07-22 |