Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.7) | 0.84% | — | Microsoft 365 Copilot | 17/9/2026 | 28/9/2026 | Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.72% | — | Microsoft 365 Copilot | 17/9/2026 | 25/9/2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network. | |
| Pendiente de análisis | Alta (7.4) | 0.89% | — | Microsoft 365 CopilotAI | 17/9/2026 | 18/9/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.9) | 1.7% | — | Microsoft 365 Copilot | 24/7/2026 | 29/7/2026 | Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. | |
| Analizada | Crítica (9.8) | 0.79% | — | Microsoft 365 Copilot | 14/7/2026 | 16/7/2026 | Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft 365 CopilotMicrosoft 365Microsoft Office 2021Microsoft Office 2024+12 | 14/7/2026 | 22/7/2026 | Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally. | |
| Modificada | Crítica (9.6) | 0.86% | — | Microsoft 365 Copilot | 14/7/2026 | 26/7/2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network. | |
| Analizada | Crítica (9.3) | 0.72% | — | Microsoft 365 Copilot | 2/7/2026 | 7/7/2026 | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.76% | — | Microsoft 365 Copilot | 19/6/2026 | 26/6/2026 | Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.71% | — | Microsoft 365 Copilot | 19/6/2026 | 26/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. | |
| Analizada | Alta (7.5) | 1.1% | — | Microsoft 365 Copilot | 18/6/2026 | 25/6/2026 | Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Modificada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft 365Microsoft Office 2016+3 | 9/6/2026 | 23/7/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft 365Microsoft Office 2016+3 | 9/6/2026 | 23/7/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft 365Microsoft Office 2016+3 | 9/6/2026 | 23/7/2026 | Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft 365Microsoft Office 2016+3 | 9/6/2026 | 23/7/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Media (4.7) | 0.42% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft 365Microsoft Office 2019+2 | 9/6/2026 | 23/7/2026 | Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.5) | 0.92% | — | Microsoft 365 Copilot | 22/5/2026 | 23/7/2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.3) | 0.76% | — | Microsoft 365 Copilot | 22/5/2026 | 23/7/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 12/5/2026 | 17/6/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (6.2) | 0.40% | — | Microsoft 365 Copilot | 12/5/2026 | 17/6/2026 | Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally. | |
| Analizada | Media (4.4) | 0.26% | — | Microsoft 365 Copilot | 12/5/2026 | 17/6/2026 | Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally. | |
| Analizada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 12/5/2026 | 17/6/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (7.5) | 1.0% | — | Microsoft 365 Copilot Chat | 7/5/2026 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Modificada | Alta (7.5) | 1.0% | — | Microsoft 365 Copilot Chat | 7/5/2026 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.3) | 0.72% | — | Microsoft 365 Copilot | 23/4/2026 | 17/6/2026 | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. |