Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.9) | 0.72% | — | Microsoft 365 Copilot Chat | 19/3/2026 | 17/6/2026 | Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.3) | 0.65% | — | Microsoft 365 Copilot | 19/3/2026 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Modificada | Alta (7.1) | 0.54% | — | Microsoft 365 CopilotMicrosoft EdgeMicrosoft ExcelMicrosoft Loop+6 | 16/3/2026 | 17/6/2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft 365 Copilot | 10/3/2026 | 17/6/2026 | Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.34% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 10/3/2026 | 17/6/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.5) | 0.66% | — | Microsoft 365 CopilotMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 10/3/2026 | 17/6/2026 | Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7) | 0.46% | — | Microsoft 365 CopilotMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+10 | 10/3/2026 | 17/6/2026 | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.5) | 0.92% | — | Microsoft 365 Copilot | 22/1/2026 | 17/6/2026 | Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.8) | 0.43% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 9/12/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.43% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 9/12/2025 | 30/9/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (7.8) | 0.76% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft ExcelMicrosoft Office Long Term Servicing Channel | 11/11/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Crítica (9.8) | 5.9% | — | Microsoft 365 CopilotMicrosoft Office Long Term Servicing ChannelMicrosoft Windows 10 1607Microsoft Windows 10 1809+12 | 11/11/2025 | 17/6/2026 | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.60% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.52% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Crítica (9.3) | 0.57% | — | Microsoft 365 Copilot Chat | 9/10/2025 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. | |
| Modificada | Crítica (9.3) | 0.57% | — | Microsoft 365 Copilot Chat | 9/10/2025 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally. | |
| Analizada | Media (5.5) | 0.78% | — | Microsoft 365 CopilotMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+12 | 9/9/2025 | 17/6/2026 | Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally. | |
| Analizada | Crítica (9.8) | 8.0% | — | Microsoft 365 CopilotMicrosoft OfficeMicrosoft Windows 10 1507Microsoft Windows 10 1607+13 | 12/8/2025 | 17/6/2026 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.48% | — | Microsoft 365 CopilotMicrosoft Office | 12/8/2025 | 17/6/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.5) | 0.71% | — | Microsoft 365 Copilot Chat | 7/8/2025 | 17/6/2026 | Microsoft 365 Copilot BizChat Information Disclosure Vulnerability | |
| Analizada | Alta (7.5) | 0.61% | — | Microsoft 365 Copilot Chat | 7/8/2025 | 17/6/2026 | Microsoft 365 Copilot BizChat Information Disclosure Vulnerability | |
| Analizada | Alta (7.8) | 0.63% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 8/7/2025 | 17/6/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.4) | 0.51% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 8/7/2025 | 17/6/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.4) | 0.61% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 8/7/2025 | 17/6/2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.4) | 0.66% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 8/7/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |