CyberICT

CVE-2026-70351

Microsoft · Published September 8, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Microsoft WebP Image Extension Remote Code Execution Vulnerability. Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.

Affected Products

  • WebP Image Extension

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C