CVE-2026-62804
External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVSS
7.8
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 8, 2026 · Last modified: Sep 8, 2026 · CWE-73
Not enough EPSS history yet.
External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-698057.5 HIG—
———External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.3hCVE-2026-693837.0 HIG—
———External control of file name or path in Windows Shell allows an authorized attacker to elevate privileges locally.3hCVE-2026-693558.8 HIG—
———External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.3hCVE-2026-81830—1.2%
——0The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation2hCVE-2026-861899.8 CRI33.9%
——10WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext as a notifyCode token, which is decrypted but never validated, to bypass authentication and write files to the application root and subdirectories.3dCVE-2026-801197.8 HIG2.5%
——1PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump complete physical memory contents by supplying a caller-controlled file path to an exposed IOCTL. Attackers can issue a single IOCTL call to trigger the driver to iterate all physical memory ranges via MmGetPhysicalMemoryRanges and map each page through ZwMapViewOfSection on the PhysicalMemory section object, writing a full RAM image to an attacker-specified path in the SYSTEM context, bypassing user-mode ACLs and exposing LSASS working set, process memory, and cryptographic material from all running processes.4d