on January 20, 2026 at 8:00 am — CVE-2026-20943 Microsoft Office Click-To-Run Remote Code Execution Vulnerability
Corrected the affected product name in the CVE title and in the FAQs. This is an informational change only.
Protecting Privacy Build Trust
Corrected the affected product name in the CVE title and in the FAQs. This is an informational change only.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.
on January 16, 2026 at 8:08 pm — Chromium: CVE-2026-0906 Incorrect security UI Read More »
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.