| | CVE-2026-69906 | Microsoft | high | 8.2 | — | | Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate pr… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-70203 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code o… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-70570 | Microsoft | high | 7.5 | — | | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-72987 | Microsoft | high | 8.1 | 0.6%
| | Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | Sep 8, 2026 | Sep 10, 2026 |
| | CVE-2026-73024 | Microsoft | high | 7.8 | — | | Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attack… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-73012 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate p… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-73009 | Microsoft | critical | 9.8 | — | | Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-73006 | Microsoft | high | 8.8 | — | | Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execu… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-73025 | Microsoft | critical | 9.8 | — | | Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature ov… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-73016 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execut… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-71328 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a n… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-73028 | Microsoft | high | 8.8 | — | | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a net… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-77480 | Microsoft | high | 8.8 | — | | Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate pr… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-77483 | Microsoft | high | 8.8 | — | | Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-77484 | Microsoft | high | 8.8 | — | | Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-77487 | Microsoft | high | 8.8 | — | | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a net… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-77485 | Microsoft | high | 7.0 | — | | Use after free in SQL Server allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-77486 | Microsoft | high | 8.8 | — | | Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-77901 | Microsoft | high | 8.8 | — | | Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code ov… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-78442 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-78445 | Microsoft | critical | 9.8 | — | | Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to exec… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-78450 | Microsoft | high | 8.1 | — | | Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to ex… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-78456 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a networ… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-78462 | Microsoft | high | 8.8 | — | | Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attack… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69595 | Microsoft | critical | 9.8 | — | | Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to exec… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-78464 | Microsoft | high | 7.0 | — | | Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorize… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-66819 | Microsoft | high | 8.8 | — | | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-77481 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a networ… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-80096 | Microsoft | high | 8.8 | — | | Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privi… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-81352 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to ex… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-81353 | Microsoft | high | 7.8 | 0.4%
| | Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to ex… | Sep 8, 2026 | Sep 11, 2026 |
| | CVE-2026-81354 | Microsoft | high | 8.2 | — | | Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges loca… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-81955 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execut… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-77906 | Microsoft | high | 8.8 | — | | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a n… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-83939 | Microsoft | high | 8.2 | — | | Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-57099 | Red Hat | high | 7.5 | — | | A flaw was found in ASP.NET Core. This vulnerability allows an unauthorized remote attacker to cause… | Sep 8, 2026 | Sep 8, 2026 |
| | CVE-2026-81963 | Microsoft | high | 7.8 | — | ⚠ KEV | Improper link resolution before file access ('link following') in Windows Update Stack allows an aut… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69530 | Microsoft | high | 8.1 | — | | Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to ex… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-62804 | Microsoft | high | 7.8 | — | | External control of file name or path in Microsoft Office Word allows an unauthorized attacker to ex… | Sep 8, 2026 | Sep 8, 2026 |
| | CVE-2026-64918 | Microsoft | medium | 6.5 | 0.5%
| | Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69268 | Microsoft | high | 8.8 | 0.7%
| | Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69273 | Microsoft | high | 8.8 | 0.5%
| | Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69282 | Microsoft | high | 8.8 | 0.5%
| | Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69285 | Microsoft | high | 8.8 | 0.6%
| | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69402 | Microsoft | high | 7.3 | 0.4%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Sep 8, 2026 | Sep 10, 2026 |
| | CVE-2026-69409 | Microsoft | medium | 6.5 | 1.0%
| | Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker t… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69417 | Microsoft | high | 7.3 | 0.7%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69442 | Microsoft | high | 8.8 | 0.8%
| | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over … | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69464 | Microsoft | high | 8.8 | 0.9%
| | Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker t… | Sep 8, 2026 | Sep 9, 2026 |
| | CVE-2026-69465 | Microsoft | high | 8.8 | 0.8%
| | Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code o… | Sep 8, 2026 | Sep 9, 2026 |