CVE-2026-70351
Microsoft · Published September 8, 2026
8.8
CVSS v3.1
HIGHPatch availableGet patch
Description
Microsoft WebP Image Extension Remote Code Execution Vulnerability. Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.
Affected Products
- WebP Image Extension
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C