CVE-2026-18687
MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the c
CVSS
7.1
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 11, 2026 · Last modified: Aug 11, 2026 · CWE-191
Not enough EPSS history yet.
MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed request that leads to a server crash or excessive internal writes, resulting in resource exhaustion and corruption of encrypted index data.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-713896.2 MED—
———CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.11hCVE-2026-649097.8 HIG—
———Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.9hCVE-2026-635157.8 HIG—
———Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.9hCVE-2026-628146.5 MED—
———Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.6hCVE-2026-627456.5 MED—
———Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.6hCVE-2026-627426.5 MED—
———Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.6h