| | CVE-2026-69813 | Microsoft | high | 8.1 | 0.7%
| | Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | Sep 8, 2026 | Sep 10, 2026 |
| | CVE-2026-69710 | Microsoft | high | 7.5 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69858 | Microsoft | high | 8.1 | 0.7%
| | Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | Sep 8, 2026 | Sep 10, 2026 |
| | CVE-2026-69874 | Microsoft | high | 8.2 | — | | Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges lo… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69725 | Microsoft | high | 7.8 | — | | Double free in Windows Hello allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69864 | Microsoft | high | 7.8 | — | | Use after free in Windows Hello allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69820 | Microsoft | high | 8.2 | — | | Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges loca… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69784 | Microsoft | high | 8.8 | — | | Use after free in Windows Hello allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-70569 | Microsoft | high | 7.8 | — | | Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to elevate privileges loca… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-70578 | Microsoft | high | 7.0 | — | | Heap-based buffer overflow in Windows Credential Guard allows an authorized attacker to elevate priv… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-70583 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privil… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-71342 | Microsoft | high | 7.0 | — | | Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-71352 | Microsoft | high | 8.8 | — | | Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authori… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72927 | Microsoft | medium | 6.7 | — | | Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72928 | Microsoft | high | 7.5 | 0.6%
| | Use after free in Windows DNS allows an authorized attacker to execute code over a network. | Sep 8, 2026 | Sep 10, 2026 |
| | CVE-2026-72936 | Microsoft | high | 8.1 | — | | Use after free in Windows SMB Client allows an unauthorized attacker to execute code over a network. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72933 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Microsoft WDAC OLE DB provider for SQL allows an unauthorized attacker… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72952 | Microsoft | high | 7.0 | — | | Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72957 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Deployment Services allows an authorized attacker to execute c… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72950 | Microsoft | high | 8.8 | — | | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72959 | Microsoft | high | 8.8 | — | | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72954 | Microsoft | high | 7.5 | — | | Use after free in Windows Deployment Services allows an authorized attacker to execute code over a n… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72960 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code o… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72961 | Microsoft | high | 8.2 | — | | Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69287 | Microsoft | high | 7.0 | — | | Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privilege… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69309 | Microsoft | high | 7.0 | — | | Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69290 | Microsoft | high | 7.8 | 0.2%
| | Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to el… | Sep 8, 2026 | Sep 10, 2026 |
| | CVE-2026-69311 | Microsoft | high | 7.0 | — | | Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69910 | Microsoft | critical | 9.8 | — | | Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69392 | Microsoft | high | 7.8 | — | | Use after free in Windows Shell allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69397 | Microsoft | high | 7.5 | — | | Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69560 | Microsoft | high | 7.0 | — | | Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges lo… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69564 | Microsoft | high | 7.0 | — | | Heap-based buffer overflow in Windows Online Certificate Status Protocol (OCSP) allows an authorized… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69575 | Microsoft | high | 7.0 | 0.3%
| | Use after free in Windows Storage Spaces Controller allows an authorized attacker to elevate privile… | Sep 8, 2026 | Sep 10, 2026 |
| | CVE-2026-69607 | Microsoft | high | 7.5 | — | | Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69590 | Microsoft | critical | 9.8 | — | | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69601 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69614 | Microsoft | high | 8.8 | — | | Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute co… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69477 | Microsoft | high | 7.3 | — | | Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-20293 | Cisco | high | 7.1 | — | | A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UC… | Sep 8, 2026 | Sep 8, 2026 |
| | CVE-2026-69439 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate priv… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69805 | Microsoft | high | 7.5 | — | | External control of file name or path in .NET allows an unauthorized attacker to elevate privileges … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69441 | Microsoft | high | 7.0 | — | | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69906 | Microsoft | high | 8.2 | — | | Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate pr… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-70203 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code o… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-70570 | Microsoft | high | 7.5 | — | | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72987 | Microsoft | high | 8.1 | 0.6%
| | Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | Sep 8, 2026 | Sep 10, 2026 |
| | CVE-2026-73024 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attack… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-73012 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate p… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-73009 | Microsoft | critical | 9.8 | — | | Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to… | Sep 8, 2026 | Sep 9, 2026 |