CVE-2026-44823
Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVSS
7.8
Alto
EPSS
0.4%
p31
KEV
—
Exploit Today
9
0-100
Publicado: 9 jun 2026 · Última mod.: 23 jul 2026 · CWE-197 · CWE-416
0.4%EPSS · 30 días0.4%
2026-08-222026-09-19
Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-940553.7 BAJ—
———Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.3hCVE-2026-880978.1 ALT12.7%
——4Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.12hCVE-2026-634493.7 BAJ16.1%
——5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SIP parser in rust/src/sip/parser.rs stores request and response body lengths in 16-bit fields. A SIP body larger than 65,536 bytes can truncate the length and prevent frame:request.body or frame:response.body from exposing the complete body to inspection, allowing content in the omitted portion to evade frame-based detection. This issue is fixed in version 8.0.6.1dCVE-2026-935862.9 BAJ1.7%
——1ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may result in a limited availability impact (e.g., a crash of the affected process). The issue is fixed in versions 7.1.2-31 and 6.9.13-56.1dCVE-2026-933828.8 ALT31.2%
——9Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)22hCVE-2026-933749.6 CRÍ29.2%
——9Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)22h