| | CVE-2026-69712 | Microsoft | high | 8.8 | — | | Use after free in Windows Key Distribution Center allows an authorized attacker to execute code over… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69676 | Microsoft | high | 8.8 | — | | Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69740 | Microsoft | high | 8.8 | — | | Use after free in Windows Hello allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69890 | Microsoft | high | 7.5 | — | | Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate p… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-70334 | Microsoft | high | 7.8 | — | | Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-70289 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevat… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-70342 | Microsoft | high | 8.1 | — | | Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to e… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-70562 | Microsoft | high | 7.0 | — | | Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-70563 | Microsoft | high | 8.1 | — | | Improper link resolution before file access ('link following') in Windows Shell allows an unauthoriz… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-70564 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elev… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-70584 | Microsoft | high | 7.8 | — | | Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an au… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-70585 | Microsoft | high | 7.0 | — | | Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execut… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-70586 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a n… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-71336 | Microsoft | high | 8.8 | — | | Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execu… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-71333 | Microsoft | high | 7.0 | — | | Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-71332 | Microsoft | high | 7.0 | — | | Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to e… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-71334 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows NFS Portmapper allows an authorized attacker to elevate privil… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-71340 | Microsoft | high | 7.0 | — | | Use after free in Windows File History Service allows an authorized attacker to elevate privileges l… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-71339 | Microsoft | medium | 6.7 | — | | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72926 | Microsoft | high | 7.0 | — | | Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-71343 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-71353 | Microsoft | high | 7.0 | — | | Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to ele… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-71345 | Microsoft | high | 7.8 | — | | Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72929 | Microsoft | high | 7.8 | — | | Improper validation of integrity check value in Windows Installer allows an authorized attacker to e… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-71351 | Microsoft | high | 7.0 | — | | Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to ele… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72930 | Microsoft | high | 7.0 | — | | Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to e… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72935 | Microsoft | medium | 6.7 | — | | Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72944 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privilege… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72943 | Microsoft | high | 7.5 | — | | Use after free in Windows Deployment Services allows an authorized attacker to execute code over a n… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72958 | Microsoft | high | 8.2 | — | | Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72963 | Microsoft | high | 7.0 | 0.3%
| | Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privilege… | Sep 8, 2026 | Sep 10, 2026 |
| | CVE-2026-68825 | Microsoft | high | 7.0 | — | | Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges loc… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-68837 | Microsoft | high | 7.0 | — | | Use after free in Windows File History Service allows an authorized attacker to elevate privileges l… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-68844 | Microsoft | high | 7.8 | 0.3%
| | Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to exe… | Sep 8, 2026 | Sep 10, 2026 |
| | CVE-2026-68877 | Microsoft | high | 7.8 | 0.2%
| | Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to exe… | Sep 8, 2026 | Sep 10, 2026 |
| | CVE-2026-69355 | Microsoft | high | 8.8 | — | | External control of file name or path in Microsoft Exchange Server allows an authorized attacker to … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69380 | Microsoft | high | 8.1 | — | | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileg… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69383 | Microsoft | high | 7.0 | — | | External control of file name or path in Windows Shell allows an authorized attacker to elevate priv… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69394 | Microsoft | high | 7.0 | — | | Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privile… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69501 | Microsoft | high | 7.0 | — | | Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69518 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69544 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69604 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privile… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69603 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69641 | Microsoft | critical | 9.1 | — | | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileg… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69649 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Windows Raw Image Extension allows an unauthorized attacker to execute… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69529 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute cod… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69764 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69778 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute cod… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69846 | Microsoft | high | 8.2 | — | | Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevat… | Sep 8, 2026 | Sep 9, 2026 |