Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-56165: Microsoft Account allows unauthorized code execution
CVE-2026-56165 · published 2 months ago
Summary
A vulnerability in Microsoft Account software allows attackers to execute malicious code remotely, which could lead to unauthorized access to sensitive information. This is a serious issue because it could allow attackers to take control of user accounts. To stay safe, ensure you have the latest security updates installed on your Microsoft Account system.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | microsoft account | - |
| microsoft | account |
All versions
cpe:2.3:a:microsoft:account:-:*:*:*:*:*:*:* |
Original advisory text
Microsoft Account Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56165 vendor-advisory patch
Severity
9.8
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published23 Jul 2026
Updated27 Sep 2026
First seen24 Jul 2026
Track software like this
Free during beta