CVE-2026-66806
published 2026-08-11CVE-2026-66806: Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
PriorityP428medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.42%
34.7th percentile
Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2024 | >= 16.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_word_2016 | >= 16.0.1 < 16.0.5565.1000 | 16.0.5565.1000 |
| microsoft | word | — | — |
| multicluster-engine | console-mce-rhel9 | — | — |
| rhacm2 | console-rhel9 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
console: console: TLS verification disabled when sending hub pull-secret to console.redhat.com
vendor_redhat·2026-08-10·CVSS 7.4
CVE-2026-66806 [HIGH] CWE-295 console: console: TLS verification disabled when sending hub pull-secret to console.redhat.com
console: console: TLS verification disabled when sending hub pull-secret to console.redhat.com
A flaw was found in console. When the `HTTPS_PROXY` environment variable is not configured, the console component fails to verify Transport Layer Security (TLS) certificates for outbound connections. A network-positioned attacker (Man-in-the-Middle) can exploit this vulnerability to intercept the cluster pull-secret while it is being sent to console.redhat.com. This pull-secret is a critical credential that provides access to Red Hat container registries and cloud services, potentially leading to unauthorized access and sensitive information disclosure.
Statement: Important: The console component in Multicluster Engine for Kubernetes and Red Hat Advanced Cluster Management for Kubernetes disabl
GHSA
Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
ghsa_unreviewed·2026-08-11
CVE-2026-66806 [MEDIUM] CWE-125 Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
VulDB
Red Hat Console certificate validation
vuldb·2026-08-11
CVE-2026-66806 [LOW] Red Hat Console certificate validation
A vulnerability identified as problematic has been detected in Red Hat Console. Affected by this issue is some unknown functionality. This manipulation causes improper certificate validation.
The identification of this vulnerability is CVE-2026-66806. It is possible to initiate the attack remotely. There is no exploit available.
No detection rules found.
No public exploits indexed.
Rapid7
Patch Tuesday - August 2026
blogs_rapid7·2026-08-11·CVSS 7.2
CVE-2026-68821 [HIGH] Patch Tuesday - August 2026
Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday , including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for one of the vulnerabilities published today, as well as public disclosure for two others, although the Notable CVEs section of the Security Update Guide omits one of these. As usual, browser vulns are not included in the Patch Tuesday count above, but unusually, Microsoft does not appear to have published any desktop browser security patches so far this month.
## Summary charts
## Summary tables
#
Sans Isc
Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)
blogs_sans_isc·2026-08-11·CVSS 7.8
CVE-2026-68820 [HIGH] Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)
Microsoft Patch Tuesday August 2026
Published: 2026-08-11. Last Updated: 2026-08-11 17:54:49 UTC
by Renato Marinho (Version: 1)
0 comment(s)
This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execution bugs.
A few vulnerabilities worth mentioning:
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820)
This Important-severity elevation of privilege vulnerability is listed by Microsoft as exploited in the wild but not publicly disclosed, and it has a CVSS score of 7.0. The flaw is a use-after-free issue in the Windows Ancil
Bugzilla
CVE-2026-66806 console: console: TLS verification disabled when sending hub pull-secret to console.redhat.com
bugzilla·2026-07-29
CVE-2026-66806 [HIGH] CVE-2026-66806 console: console: TLS verification disabled when sending hub pull-secret to console.redhat.com
CVE-2026-66806 console: console: TLS verification disabled when sending hub pull-secret to console.redhat.com
The jsonPost function in json-request.ts uses a module-level https.Agent({ rejectUnauthorized: false }) for all calls where no HttpsProxyAgent is supplied. The upgrade-risks-prediction.ts module reads the cluster pull-secret (openshift-config/pull-secret) with the SA token, extracts auths['cloud.openshift.com'].auth, and POSTs it as a Bearer token to https://console.redhat.com/api/insights-results-aggregator/v2/upgrade-risks-prediction. When HTTPS_PROXY is unset, this outbound internet request runs with server certificate validation disabled.
A network-positioned attacker (MITM) can intercept the pull-secret credential in transit between the hub and console.redhat.com. The pull-s
2026-08-11
Published