| | CVE-2026-70283 | Microsoft | high | 7.0 | — | | Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locall… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72983 | Microsoft | critical | 9.8 | — | | Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execu… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72982 | Microsoft | critical | 9.8 | — | | Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69579 | Microsoft | critical | 9.8 | 1.0%
| | Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a net… | Sep 8, 2026 | Sep 10, 2026 |
| | CVE-2026-77493 | Microsoft | critical | 9.8 | — | | Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a n… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-77503 | Microsoft | high | 8.4 | — | | Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-77504 | Microsoft | high | 8.8 | — | | Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-77505 | Microsoft | high | 8.1 | 0.5%
| | Use after free in DNS Server allows an unauthorized attacker to execute code over a network. | Sep 8, 2026 | Sep 10, 2026 |
| | CVE-2026-77894 | Microsoft | high | 7.0 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-77907 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a n… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-78439 | Microsoft | high | 8.8 | — | | Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execu… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-67378 | Microsoft | high | 8.5 | — | | Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a net… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-78463 | Microsoft | high | 8.8 | — | | Improper control of generation of code ('code injection') in Remote Desktop Client allows an unautho… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-67379 | Microsoft | high | 8.5 | — | | Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a netwo… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-67384 | Microsoft | high | 8.8 | — | | Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a ne… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-78517 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-67636 | Microsoft | high | 8.5 | — | | Out-of-bounds read in SQL Server allows an authorized attacker to execute code over a network. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-67643 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a networ… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-68786 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a networ… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-65669 | Microsoft | critical | 9.6 | — | | Improper neutralization of special elements in output used by a downstream component ('injection') i… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-80074 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-80077 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-80075 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileg… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-80083 | Microsoft | high | 8.8 | — | | Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code local… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-80093 | Microsoft | high | 7.0 | — | | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate pr… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-80097 | Microsoft | high | 8.6 | — | | Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privil… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-81349 | Microsoft | high | 7.2 | — | | Improper neutralization of special elements used in an os command ('os command injection') in Azure … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-81376 | Microsoft | critical | 9.6 | — | | Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-85880 | Microsoft | high | 7.8 | — | ⚠ KEV | Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges local… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-56177 | Microsoft | high | 7.8 | — | | Use after free in Windows Server allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-62810 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized att… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-62759 | Microsoft | high | 7.5 | — | | Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spo… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-62813 | Microsoft | high | 7.5 | — | | Use after free in Active Directory Domain Services allows an authorized attacker to execute code ove… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-62697 | Microsoft | high | 7.8 | — | | Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges loc… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-66814 | Microsoft | high | 8.8 | — | | Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate pr… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-66818 | Microsoft | high | 8.8 | — | | Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-66820 | Microsoft | high | 8.8 | — | | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-67380 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a networ… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-67381 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-67385 | Microsoft | high | 8.8 | — | | Use after free in SQL Server allows an authorized attacker to execute code over a network. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-67388 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a networ… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-67638 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a networ… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-67639 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a networ… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-67642 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a networ… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-68775 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a networ… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-68828 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-68827 | Microsoft | high | 8.0 | — | | Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate priv… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-68834 | Microsoft | high | 8.0 | — | | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-68838 | Microsoft | high | 8.0 | — | | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-68848 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elev… | Sep 8, 2026 | Sep 9, 2026 |