CVE-2026-55132
Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVSS
7.8
Alto
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Publicado: 14 jul 2026 · Última mod.: 16 jul 2026 · CWE-415
0.4%EPSS · 30 días0.4%
2026-07-152026-07-21
Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-646217.3 ALT14.5%
——4FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field of a .rdp connection file. The MonitorIds array is allocated through the settings object, and a raw non-owning pointer to it is freed on the strtoul error path without clearing settings->MonitorIds, leaving it dangling; at teardown freerdp_settings_free() frees the same buffer again. An attacker who convinces a victim to open a crafted .rdp file with oversized monitor tokens can trigger a size-controlled double-free in any FreeRDP CLI client (xfreerdp/sdl-freerdp/wlfreerdp) in the default configuration.1dCVE-2026-137136.2 MED3.9%
——1YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack.
In the bundled libsyck, when an anchor name is redefined or removed, syck_hdlr_add_anchor and syck_hdlr_remove_anchor free the node stored under that name with syck_free_node. That node can still be live on the parser's value stack, so syck_hdlr_add_node reaches it again and frees it a second time. On a normal build the 48-byte node chunk is freed twice and the interpreter aborts. Anchors need no special flags, so this is reached on the default Load path, and a 7-byte document that redefines an anchor triggers it.
Any caller that runs Load or LoadFile on an untrusted document that redefines an anchor mid-parse crashes the interpreter, a denial of service.4dCVE-2026-506857.5 ALT45.7%
——14Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.7dCVE-2026-503617.8 ALT8.2%
——2Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.1dCVE-2026-550047.8 ALT15.8%
——5Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.6dCVE-2026-12659—16.7%
——5A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent to the adapter. A power cycle is required to recover the module and associated I/O.7d