Where
-Infinity
0

Vendor Risk Score

See how microsoft compares to other vendors in security performance

View Risk Score →

Software

microsoft windows operating system
6621
microsoft windows
6421
microsoft windows server 2016
6303
microsoft windows server 2019
5959
microsoft windows 10
4412
microsoft windows server 2022
4238
microsoft windows server
3594
microsoft edge
3570
microsoft windows 7
3093
microsoft edge (chromium-based)
3058
microsoft windows 11
3038
microsoft windows server 2012 r2
3020
microsoft windows server 2012
2632
microsoft windows server 2025
2632
microsoft windows 10 1809
2556
microsoft windows 10 21h2
2485
microsoft windows 10 22h2
2481
microsoft windows 11 24h2
2429
microsoft windows 10 1607
2211
microsoft windows 11 23h2
2144
microsoft windows rt
1870
microsoft windows 11 25h2
1762
microsoft windows server 2022 23h2
1724
microsoft windows server 2008
1624
microsoft windows 11 26h1
1479
microsoft windows server 2022, 23h2 edition
1464
microsoft windows xp
1356
microsoft windows vista
1353
microsoft windows 8.1
1198
microsoft windows 11 22h2
1093
microsoft office
1077
microsoft edge beta
1007
microsoft internet explorer
923
microsoft windows server 2008 r2
902
microsoft windows 10 1507
881
microsoft windows server 2008 r2 for itanium-based systems
751
microsoft 365 apps for enterprise
738
microsoft 365 apps
663
microsoft windows rt 8.1
643
microsoft windows 2000
635
microsoft cbl2 kernel 5.15.186.1-1
574
microsoft office ltsc 2021 for 64-bit editions
570
microsoft office ltsc 2021 for 32-bit editions
569
microsoft office 2019 for 64-bit editions
564
microsoft office 2019 for 32-bit editions
563
microsoft office ltsc 2024 for 32-bit editions
510
microsoft office ltsc 2024 for 64-bit editions
510
microsoft windows server 2003
491
microsoft windows 11 21h2
460
microsoft office ltsc for mac 2021
451
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Insertion of sensitive information into log file in Microsoft Office allows an authorized attacker to disclose information over a network.

1 / 2
Source: Microsoft
First published (updated )
Severity
7.5
Integer Overflow
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

1 / 2
Source: Microsoft
First published (updated )

Three technical stories from today’s recap:

Ubuntu container escape: DepthFirst released an exploit for CVE-2026-80521 that reaches host root from a container on Ubuntu 26.04. The AF\UNIX flaw was fixed upstream, but affected distribution kernels still need the patch.

F5 BIG-IP APM RCE: CVE-2026-94127 is being exploited against vulnerable OAuth authorization-server configurations. Management-interface access is not required. Hotfixes are available.

Process Parameter Poisoning: Flashpoint tested Windows code injection through process initialization structures, avoiding common memory-writing APIs. The technique produced no alerts from the EDR controls tested in its lab.

More technical details and source links in today’s recap on CyberRecaps, and have an amazing day :)

First published (updated )
Social
reddit
Severity
8.8
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Microsoft Office Outlook Remote Code Execution Vulnerability

1 / 2
Source: Microsoft
First published (updated )
Severity
9.3
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

First published (updated )
Severity
7.5
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue does not require user interaction.

First published (updated )
Severity
8.6
Path Traversal
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Adobe Connect is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

First published (updated )
Severity
9.9
SQL Injection
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.

First published (updated )
Severity
9.3
Input Validation
AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Adobe Connect is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

First published (updated )
Severity
6.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

First published (updated )
Severity
9.3
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

First published (updated )
Severity
9.3
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

First published (updated )
Severity
9.3
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

First published (updated )
Severity
7.8
Buffer Overflow
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

First published (updated )
Severity
10
Code Injection
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

First published (updated )
Severity
10
Code Injection
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

First published (updated )
Severity
10
SSRF
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.

First published (updated )
Severity
9.9
Code Injection
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

First published (updated )
Severity
9.9
SSRF
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.

First published (updated )
Severity
9.1
SQL Injection
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary SQL commands. Exploitation of this issue does not require user interaction. Scope is changed.

First published (updated )
Severity
8.5
Input Validation
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

First published (updated )
Severity
10
Code Injection
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

First published (updated )
Severity
10
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

First published (updated )
Severity
10
Code Injection
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

First published (updated )
Severity
10
Code Injection
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

First published (updated )
Severity
9.9
SSRF
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.

First published (updated )
Severity
9.1
SQL Injection
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does not require user interaction. Scope is changed.

First published (updated )
Severity
9.9
Input Validation
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

First published (updated )
Severity
10
Code Injection
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

First published (updated )
Severity
9.1
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203