CVE-2026-45463
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS
8.4
Alto
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Publicado: 9 jun 2026 · Última mod.: 23 jul 2026 · CWE-121 · CWE-191
0.4%EPSS · 30 días0.4%
2026-08-202026-09-17
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-908239.8 CRÍ—
——0FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass. An unauthenticated remote attacker with access to the affected management interface can submit a crafted authentication request that reaches an unchecked copy into a fixed-size stack buffer, potentially allowing arbitrary code execution as root.
The affected management interface is disabled by default and must be affirmatively enabled by the customer before the endpoint becomes reachable. FatPipe recommends restricting management access to trusted administrative networks and using WAN access control lists to limit access to trusted sources.1dCVE-2026-814807.2 ALT—
——0Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.1dCVE-2026-252838.8 ALT1.4%
——0Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.1dCVE-2026-815467.7 ALT1.4%
——0The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity document that when opened by a user in Affinity could result in arbitrary code execution.2dCVE-2026-91103—21.2%
——6HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.2dCVE-2026-863586.5 MED22.3%
——7Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execution.1d