CVE-2026-64909
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS
7.8
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 11, 2026 · Last modified: Aug 11, 2026 · CWE-122 · CWE-125 · CWE-191
Not enough EPSS history yet.
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-713896.2 MED—
———CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.5hCVE-2026-713318.1 HIG—
———Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.5hCVE-2026-703477.8 HIG—
———Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.5hCVE-2026-703457.8 HIG—
———Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.5hCVE-2026-703306.7 MED—
———Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.5hCVE-2026-703286.5 MED—
———Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.5h