CVE-2026-18687
MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the c
CVSS
7.1
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 11 ago 2026 · Última mod.: 11 ago 2026 · CWE-191
Sin historial EPSS suficiente todavía.
MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed request that leads to a server crash or excessive internal writes, resulting in resource exhaustion and corruption of encrypted index data.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-713896.2 MED—
———CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.12hCVE-2026-649097.8 ALT—
———Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.10hCVE-2026-635157.8 ALT—
———Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.10hCVE-2026-628146.5 MED—
———Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.7hCVE-2026-627456.5 MED—
———Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.7hCVE-2026-627426.5 MED—
———Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.7h