CVE-2026-68809
Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVSS
5.5
Medio
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 11 ago 2026 · Última mod.: 11 ago 2026 · CWE-459
Sin historial EPSS suficiente todavía.
Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-20712——
——0Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.8hCVE-2026-190194.8 MED22.9%
——7A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_session_persistence of the file executor/app/core/workspace.py of the component Claude File Handler. The manipulation results in incomplete cleanup. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks.8hCVE-2026-635452.4 BAJ4.8%
——1Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users.9dCVE-2026-673343.8 BAJ9.9%
——3better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is false. Attackers can reuse deleted user session tokens to maintain authentication for up to seven days after account deletion.9dCVE-2026-424927.5 ALT38.9%
——12Xenstore, to have an up-to-date picture of the entire system, wants to
know of domains appearing and disappearing. To make this more robust, a
new XEN_DOMCTL_get_domain_state was introduced. The management of the
bitmap underlying that operation is tied into the binding of the
VIRQ_DOM_EXC virtual IRQ. Unfortunately an error path there would tear
down the bitmap even in cases when it wasn't set up. Unprivileged domains
can trigger that error path.15dCVE-2026-76397.8 ALT2.4%
——1Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilitating unprivileged memory access from a shader code.
Triggering failure path in the MMU mapping logic by a malicious code could lead to incomplete cleanup of an internal driver state, allowing for future unauthorized access to the contents of the physical memory.11h