CVE-2026-18688
An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a
CVSS
7.1
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 11, 2026 · Last modified: Aug 11, 2026 · CWE-125
Not enough EPSS history yet.
An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain aggregation pipeline stage. This could result in a server crash (denial of service) and may potentially expose a limited amount of memory contents.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-186947.1 HIG—
———An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry data to be stored and later processed without proper validation. Subsequent queries against this data could then result in the server accessing memory outside its intended bounds. This could result in a server crash (denial of service) and may expose a limited amount of server process memory.5hCVE-2026-703286.5 MED—
———Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.8hCVE-2026-703276.5 MED—
———Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.8hCVE-2026-703155.5 MED—
———Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.4hCVE-2026-703105.5 MED—
———Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.4hCVE-2026-688147.8 HIG—
———Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.7h