Latest Microsoft CVEs
Every organization faces unique cybersecurity challenges, but successful outcomes require more than technology alone. Our case studies highlight how Gilliam Security works alongside executives, security leaders, and stakeholders to build practical security programs, strengthen governance, manage risk, and achieve critical compliance objectives in complex business environments.From guiding organizations through leadership transitions and regulatory audits to establishing governance functions for global enterprises and preparing government contractors for CMMC requirements, these engagements demonstrate our commitment to delivering measurable results, sustainable security practices, and long-term business value.
Provided below are the Microsoft CVEs from the last 30 days:
Chromium: CVE-2025-1920 Type Confusion in V8 Published on: September 11, 2026 Information published. Read Details
Chromium: CVE-2025-2137 Out of bounds read in V8 Published on: September 11, 2026 Information published. Read Details
Chromium: CVE-2026-85046 Type confusion in V8 Published on: September 09, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Google is aware that an exploit for CVE-2026-85046 exists in the wild. Read Details
CVE-2026-69777 Windows DHCP Client Elevation of Privilege Vulnerability Published on: September 09, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-69508 Windows MIDI Service Module Elevation of Privileges Vulnerability Published on: September 09, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-68877 Windows Storage Spaces Controller Remote Code Execution Vulnerability Published on: September 09, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-69334 Windows Volume Manager Extension Driver Remote Code Execution Vulnerability Published on: September 09, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-69492 Windows Partition Management Driver Elevation of Privilege Vulnerability Published on: September 09, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-73024 Windows Services for NFS ONCRPC XDR Driver Elevation of Privilege Vulnerability Published on: September 09, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-45499 Azure OpenAI Elevation of Privilege Vulnerability Published on: September 09, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62693 Windows MIDI Service Module Elevation of Privileges Vulnerability Published on: September 09, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62706 Microsoft Windows Media Foundation Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-62694 Windows Installer Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-62744 Microsoft Windows Media Foundation Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-66304 Skype for Business Information Disclosure Vulnerability Published on: September 08, 2026 <p>Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-66302 Skype for Business Remote Code Execution Vulnerability Published on: September 08, 2026 <p>External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-66306 Skype for Business Information Disclosure Vulnerability Published on: September 08, 2026 <p>Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-66308 Skype for Business and Lync Denial of Service Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.</p> Read Details
CVE-2026-62895 Azure Arc SQL Server Extension Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69341 Windows Image Acquisition Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69522 .NET and Visual Studio Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-70091 Windows DNS Denial of Service Vulnerability Published on: September 08, 2026 <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-69782 Windows DNS Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-62916 Microsoft Entra ID Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-65818 Power Automate Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69857 Azure Cosmos DB Spoofing Vulnerability Published on: September 08, 2026 <p>Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.</p> Read Details
CVE-2026-70178 Microsoft Fabric Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-83941 Entra ID Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-85360 Windows Kernel Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-77482 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-57098 Microsoft Remote Desktop App for Windows Information Disclosure Vulnerability Published on: September 08, 2026 <p>Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-62801 Microsoft PowerShell Security Feature Bypass Vulnerability Published on: September 08, 2026 <p>Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network.</p> Read Details
CVE-2026-55007 Microsoft Exchange Server Remote Code Execution Vulnerability Published on: September 08, 2026 Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-50349 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Published on: September 08, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-67368 Microsoft SQL Server Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-67370 Microsoft SQL Server Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-67373 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-67629 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-67630 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-67631 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. Read Details
CVE-2026-67633 Microsoft SQL Server Denial of Service Vulnerability Published on: September 08, 2026 Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network. Read Details
CVE-2026-68781 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-68784 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-68785 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-68787 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.</p> Read Details
CVE-2026-68824 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-68830 Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability Published on: September 08, 2026 Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally. Read Details
CVE-2026-68832 Windows NTFS Elevation of Privilege Vulnerability Published on: September 08, 2026 Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-68833 Windows NTFS Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.</p> Read Details
CVE-2026-68835 Windows Print Spooler Components Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-68841 Windows NTFS Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-68847 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-68849 Windows Bluetooth Port Driver Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows Bluetooth Port Driver allows an authorized attacker to disclose information locally. Read Details
CVE-2026-68845 Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-68846 Windows Kernel Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-68851 Windows NTFS Information Disclosure Vulnerability Published on: September 08, 2026 <p>Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-68875 Windows NTFS Remote Code Execution Vulnerability Published on: September 08, 2026 Buffer over-read in Windows NTFS allows an authorized attacker to execute code locally. Read Details
CVE-2026-68897 Microsoft Standard XPS Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-68878 Windows Fast FAT Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Windows Fast FAT Driver allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-68884 Windows Kernel Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-68881 Microsoft Standard XPS Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-68890 Microsoft Standard XPS Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69271 Microsoft Standard XPS Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-68892 Microsoft Standard XPS Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-68893 Remote Desktop Licensing Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69281 Windows License Manager Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows License Manager allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69267 Windows Connected User Experiences and Telemetry Information Disclosure Vulnerability Published on: September 08, 2026 Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69276 Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69292 Remote Desktop Gateway Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69307 Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69279 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69296 Windows Device Association Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69325 Microsoft JScript Remote Code Execution Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-69336 Microsoft Standard XPS Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69310 Windows DNS Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows DNS allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69366 Windows Kernel Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69337 Windows Registry Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Double free in Windows Registry allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69333 Windows Win32k Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69339 Windows MIDI Service Module Information Disclosure Vulnerability Published on: September 08, 2026 <p>Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-69338 Remote Desktop Gateway Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69347 Windows Fast FAT Driver Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.</p> Read Details
CVE-2026-69345 Microsoft Standard XPS Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69377 Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Missing authorization in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69349 Windows Management Instrumentation Information Disclosure Vulnerability Published on: September 08, 2026 Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network. Read Details
CVE-2026-69362 Windows Error Reporting Elevation of Privilege Vulnerability Published on: September 08, 2026 Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69359 Active Directory Domain Services Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69367 Microsoft Standard XPS Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69389 Windows Storage Management Provider Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69368 Windows Overlay Filter Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69371 Windows Overlay Filter Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-69379 Windows NTFS Elevation of Privilege Vulnerability Published on: September 08, 2026 Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69391 Windows Broker Infrastructure Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Windows Broker Infrastructure Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69404 Windows TCP/IP Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69390 Windows Spaceport.sys Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69406 Windows Kernel Information Disclosure Vulnerability Published on: September 08, 2026 <p>Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-69401 Audio Video Control Transport Protocol Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Audio Video Control Transport Protocol allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69413 Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability Published on: September 08, 2026 Use after free in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69418 Volume Manager Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69408 Microsoft Windows Media Foundation Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69457 Windows USB Driver Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69412 Windows DHCP Server Remote Code Execution Vulnerability Published on: September 08, 2026 Stack-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network. Read Details
CVE-2026-69415 Windows DHCP Server Elevation of Privilege Vulnerability Published on: September 08, 2026 Missing authentication for critical function in Windows DHCP Server allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-69420 Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69436 Windows Error Reporting Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69423 Windows USB Video Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-69429 Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows IKE Extension allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69458 Windows BitLocker Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows BitLocker allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69448 Windows Bluetooth Service Elevation of Privilege Vulnerability Published on: September 08, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69432 Volume Manager Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69431 Telnet Client Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69491 Microsoft DirectMusic Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69513 Windows Error Reporting Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69455 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69532 Windows NTFS Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69451 Windows Management Instrumentation Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69450 Windows Error Reporting Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Error Reporting allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69485 Remote Desktop Client Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69461 Windows NTFS Remote Code Execution Vulnerability Published on: September 08, 2026 Stack-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-69463 Windows NTFS Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69472 Windows Devices Human Interface Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Devices Human Interface allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69468 Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69470 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69473 Windows Kernel Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69479 Windows NTFS Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.</p> Read Details
CVE-2026-69481 Windows Enterprise App Management Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Enterprise App Management allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69494 Windows Event Logging Service Remote Code Execution Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-69495 Windows Event Logging Service Remote Code Execution Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows Event Logging Service allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-69496 Windows Compressed Folder Remote Code Execution Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-69531 Microsoft Windows Speech Tampering Vulnerability Published on: September 08, 2026 <p>Unintended proxy or intermediary ('confused deputy') in Microsoft Windows Speech allows an authorized attacker to perform tampering locally.</p> Read Details
CVE-2026-69517 Windows Wireless Networking Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69500 Windows Image Acquisition Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69505 Windows NTFS Elevation of Privilege Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-69504 Windows NTFS Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69507 Microsoft Windows Search Component Information Disclosure Vulnerability Published on: September 08, 2026 Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component allows an authorized attacker to disclose information over a network. Read Details
CVE-2026-69551 Windows DNS Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows DNS allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69514 Remote Desktop Services Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69516 Connected Devices Platform Service (Cdpsvc) Elevation of Privilege Vulnerability Published on: September 08, 2026 Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69621 Role: Windows Fax Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69527 Windows USB Mass Storage Class Driver Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows USB Mass Storage Class Driver allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69525 Remote Desktop Services Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69539 Remote Desktop Services Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69582 Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Buffer over-read in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69524 Windows Active Directory Domain Services Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69528 Windows Shell Elevation of Privilege Vulnerability Published on: September 08, 2026 Missing authentication for critical function in Windows Shell allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69534 Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper neutralization of special elements used in a command ('command injection') in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69574 Windows Device Association Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69540 Windows Audio Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69549 Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability Published on: September 08, 2026 Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69541 Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability Published on: September 08, 2026 <p>Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69563 Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69553 Windows Hyper-V Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Missing authorization in Windows Hyper-V allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69552 Windows Print Spooler Components Information Disclosure Vulnerability Published on: September 08, 2026 Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a network. Read Details
CVE-2026-69554 Microsoft Windows Search Component Tampering Vulnerability Published on: September 08, 2026 Missing authentication for critical function in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally. Read Details
CVE-2026-69572 Windows SMB Client Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information over a network. Read Details
CVE-2026-69585 Microsoft Windows Search Component Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Incorrect type conversion or cast in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69608 Microsoft Windows Search Component Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69588 Windows TCP/IP Denial of Service Vulnerability Published on: September 08, 2026 Missing release of memory after effective lifetime in Windows TCP/IP allows an unauthorized attacker to deny service over a network. Read Details
CVE-2026-69587 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Published on: September 08, 2026 <p>Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-69609 Win32k Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69594 Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69605 Microsoft Install Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Microsoft Install Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69645 Windows Message Queuing Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69648 Windows Notification Elevation of Privilege Vulnerability Published on: September 08, 2026 Use after free in Windows Notification allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69684 Windows Error Reporting Information Disclosure Vulnerability Published on: September 08, 2026 Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69623 Windows HTTP Print Provider Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows HTTP Print Provider allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69689 Windows Win32k Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69627 Windows Remote Desktop Licensing Service Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69628 Windows iSCSI Remote Code Execution Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows iSCSI allows an authorized attacker to execute code over a network. Read Details
CVE-2026-69790 Windows Credential Providers Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69631 Windows DNS Denial of Service Vulnerability Published on: September 08, 2026 Integer overflow or wraparound in Windows DNS allows an unauthorized attacker to deny service over a network. Read Details
CVE-2026-69638 Windows NTFS Remote Code Execution Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-69859 Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability Published on: September 08, 2026 Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69693 Windows Device Association Broker Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69729 Windows Credential Providers Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69717 Windows Group Policy Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69711 Windows Device Association Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69694 Windows IP Address Management (IPAM) Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69875 Windows NTFS Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69723 Windows Kernel Information Disclosure Vulnerability Published on: September 08, 2026 <p>Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69889 Windows Bluetooth Service Elevation of Privilege Vulnerability Published on: September 08, 2026 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69757 Windows TCP/IP Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69681 Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability Published on: September 08, 2026 <p>Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69896 Windows Error Reporting Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69735 Windows Broadcast DVR User Service Elevation of Privilege Vulnerability Published on: September 08, 2026 Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69741 Windows Spaceport.sys Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69762 Windows Win32k Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69819 RPC Runtime Library Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69744 Windows Kerberos Denial of Service Vulnerability Published on: September 08, 2026 <p>Null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-69862 Windows Wireless Wide Area Network Service Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69832 Win32k Information Disclosure Vulnerability Published on: September 08, 2026 <p>Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-69691 Windows Spaceport.sys Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69838 Windows Print Spooler Components Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69808 Win32k Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-69839 Windows iSCSI Target Service Denial of Service Vulnerability Published on: September 08, 2026 <p>Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network.</p> Read Details
CVE-2026-69772 Windows Network File System Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Network File System allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69775 Windows DWM Core Library Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69758 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69771 Windows Container Manager Service Security Feature Bypass Vulnerability Published on: September 08, 2026 <p>Improper link resolution before file access ('link following') in Windows Container Manager Service allows an authorized attacker to bypass a security feature locally.</p> Read Details
CVE-2026-69822 Windows Kerberos Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69732 Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69770 Windows Spaceport.sys Information Disclosure Vulnerability Published on: September 08, 2026 Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69860 Windows Imaging Component Remote Code Execution Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-69730 Windows DNS Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69712 Windows Key Distribution Center Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Key Distribution Center allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69676 Windows Kerberos Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69740 Windows Hello Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69890 Windows Virtual Trusted Platform Module Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-63523 Skype for Business Spoofing Vulnerability Published on: September 08, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. Read Details
CVE-2026-66305 Skype for Business Spoofing Vulnerability Published on: September 08, 2026 Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-70334 Visual Studio Code Security Feature Bypass Vulnerability Published on: September 08, 2026 <p>Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.</p> Read Details
CVE-2026-70289 Windows Win32k Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-70342 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-58600 HEVC Video Extensions Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally. Read Details
CVE-2026-70351 Microsoft WebP Image Extension Remote Code Execution Vulnerability Published on: September 08, 2026 Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-70562 Windows Audio Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-70563 Windows Shell Spoofing Vulnerability Published on: September 08, 2026 <p>Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.</p> Read Details
CVE-2026-70564 Windows Print Spooler Components Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-70582 Windows Management Instrumentation Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-70584 Windows Core Messaging Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-70585 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally.</p> Read Details
CVE-2026-70586 Windows Paint Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-70587 Windows Remote Desktop Protocol Information Disclosure Vulnerability Published on: September 08, 2026 <p>Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-71329 Windows NTFS Remote Code Execution Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. Read Details
CVE-2026-71336 Windows Work Folder Service Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-71330 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability Published on: September 08, 2026 <p>Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-71333 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-71337 Windows Storage Management Provider Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-71332 Windows Secure Socket Tunneling Protocol (SSTP) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-71334 Windows NFS Portmapper Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows NFS Portmapper allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-71338 Windows Failover Cluster Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-71340 Windows File History Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-71339 Windows Installer Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-71350 Windows Spaceport.sys Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.</p> Read Details
CVE-2026-71348 Windows Spaceport.sys Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.</p> Read Details
CVE-2026-72926 Windows Internet Connection Sharing (ICS) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-71343 Windows Remote Access Connection Manager Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to execute code locally.</p> Read Details
CVE-2026-71341 Windows Partition Management Driver Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-71353 Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-71345 Windows Spaceport.sys Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally.</p> Read Details
CVE-2026-72929 Windows Installer Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper validation of integrity check value in Windows Installer allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-71351 Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72930 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally.</p> Read Details
CVE-2026-72935 Windows NTFS Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72939 Windows Routing and Remote Access Service (RRAS) Denial of Service Vulnerability Published on: September 08, 2026 <p>Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network.</p> Read Details
CVE-2026-72944 Role: Windows Fax Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72946 Microsoft Storage Port Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Storage Port Driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72943 Windows Deployment Services Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-72945 Windows Task Scheduler Information Disclosure Vulnerability Published on: September 08, 2026 <p>Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-72948 Windows DNS Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72958 Windows Credential Guard Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72962 Windows USB Video Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72963 Windows Modern Execution Server Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-68825 Windows Bind Filter Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-68837 Windows File History Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-68844 Windows Storage Spaces Controller Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.</p> Read Details
CVE-2026-68877 Windows Storage Spaces Controller Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.</p> Read Details
CVE-2026-68887 Windows Message Queuing Queue Manager Denial of Service Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Message Queuing Queue Manager allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-69293 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69355 Microsoft Exchange Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69356 Microsoft Exchange Server Spoofing Vulnerability Published on: September 08, 2026 <p>Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.</p> Read Details
CVE-2026-69361 Microsoft Exchange Server Spoofing Vulnerability Published on: September 08, 2026 Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-69375 Microsoft Exchange Server Tampering Vulnerability Published on: September 08, 2026 <p>Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.</p> Read Details
CVE-2026-69378 Microsoft Exchange Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-69380 Microsoft Exchange Server Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69382 Microsoft Exchange Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69383 Windows Shell Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>External control of file name or path in Windows Shell allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69394 Windows Audio Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69443 Windows Device Health Attestation (DHA) Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Device Health Attestation (DHA) allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69469 Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to elevate privileges with a physical attack.</p> Read Details
CVE-2026-69501 Windows Secure Kernel Mode Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69518 Windows Remote Desktop Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69544 Windows SMB Client Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69548 Windows RNDIS Information Disclosure Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical attack.</p> Read Details
CVE-2026-69556 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69583 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69589 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69580 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69576 Graphic Fonts Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Graphic Fonts allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69604 Windows Audio Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69603 Windows Hyper-V Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.</p> Read Details
CVE-2026-69641 Microsoft Exchange Server Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69642 Skype for Business Spoofing Vulnerability Published on: September 08, 2026 <p>Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.</p> Read Details
CVE-2026-69646 Skype for Business Spoofing Vulnerability Published on: September 08, 2026 <p>Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.</p> Read Details
CVE-2026-69649 Raw Image Extension Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Raw Image Extension allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69671 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69678 Microsoft Office PowerPoint Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69686 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69722 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69716 Microsoft Office SharePoint Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69734 Microsoft Office Word Information Disclosure Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69742 Microsoft Office Publisher Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69724 Microsoft Office SharePoint Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69719 Microsoft Office Word Information Disclosure Vulnerability Published on: September 08, 2026 <p>Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69690 Microsoft Office SharePoint Spoofing Vulnerability Published on: September 08, 2026 <p>Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.</p> Read Details
CVE-2026-69739 Microsoft Office Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69683 Microsoft Office SharePoint Information Disclosure Vulnerability Published on: September 08, 2026 <p>Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69529 Microsoft Office Access Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69759 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69764 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69778 Microsoft Office Access Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69767 Microsoft Office PowerPoint Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69797 Microsoft Office PowerPoint Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69804 Microsoft Office SharePoint Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69846 Windows Secure Kernel Mode Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69929 Windows DHCP Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69930 Windows DHCP Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-70124 Windows DHCP Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-70283 Windows Win32k Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72978 Active Directory Federation Services (AD FS) Denial of Service Vulnerability Published on: September 08, 2026 <p>Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-77495 Windows Imaging Component Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-72979 Windows DHCP Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-72980 Windows Hello Security Feature Bypass Vulnerability Published on: September 08, 2026 <p>Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.</p> Read Details
CVE-2026-72981 IP Helper Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in IP Helper allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-72983 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-72982 Windows Netlogon Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69476 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69787 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72986 Graphic Fonts Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69579 Windows Message Queuing Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-77489 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-77491 Windows GDI Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.</p> Read Details
CVE-2026-77492 Windows Storage Port Driver Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-77493 Windows Graphics Component Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-77494 Windows DHCP Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-77498 Windows DHCP Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-77500 Windows Device Association Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-77499 Windows DHCP Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-77501 Windows DHCP Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-77502 Windows DHCP Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-77503 Windows NTFS Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-77887 Windows DHCP Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.</p> Read Details
CVE-2026-77504 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-77505 Windows DNS Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in DNS Server allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-77888 Windows DHCP Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-77886 Windows DHCP Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-77890 Windows DHCP Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-77889 Windows DHCP Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-77891 Windows DHCP Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.</p> Read Details
CVE-2026-77892 Windows Boot Manager Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack.</p> Read Details
CVE-2026-77893 Windows DHCP Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-77894 Windows Installer Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-77895 Windows DHCP Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-77896 Windows Remote Desktop Client Denial of Service Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-69268 Microsoft Office SharePoint Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69285 Microsoft Office Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69273 Microsoft Office SharePoint Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69282 Microsoft Office SharePoint Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-77898 Microsoft Office Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-77899 Windows Security Center Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Security Center allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-77904 Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-77907 Visual Studio Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-77908 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-77909 Azure CycleCloud Information Disclosure Vulnerability Published on: September 08, 2026 <p>Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-78439 Microsoft Office Graphics Component Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-78461 Visual Studio Code Security Feature Bypass Vulnerability Published on: September 08, 2026 <p>Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.</p> Read Details
CVE-2026-67378 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-78463 Remote Desktop Client Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-67376 Microsoft SQL Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-67379 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-67383 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-67384 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-78511 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-78502 Microsoft Office Word Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-78515 Microsoft Office Excel Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-78505 Microsoft Office Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-78510 Microsoft Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-78508 Windows CD-ROM Driver Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack.</p> Read Details
CVE-2026-78513 Microsoft Office PowerPoint Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.</p> Read Details
CVE-2026-78504 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-78517 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-78509 Microsoft Office Outlook Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-67389 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-78518 Microsoft Office Excel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-67636 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in SQL Server allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-67643 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-68786 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-73029 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-65669 Microsoft SQL Server Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-78523 Windows DNS Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Use after free in Windows DNS allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-80074 Remote Desktop Client Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-80077 Remote Desktop Client Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-80075 Windows Work Folders Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-80083 Windows Hyper-V Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code locally.</p> Read Details
CVE-2026-80093 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-80097 Microsoft Authenticator Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-81349 Azure HDInsight Ambari Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-81355 Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to execute code locally.</p> Read Details
CVE-2026-81356 Visual Studio Code Security Feature Bypass Vulnerability Published on: September 08, 2026 <p>Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.</p> Read Details
CVE-2026-81357 Visual Studio Code Security Feature Bypass Vulnerability Published on: September 08, 2026 <p>Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.</p> Read Details
CVE-2026-81376 Visual Studio Code Security Feature Bypass Vulnerability Published on: September 08, 2026 <p>Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.</p> Read Details
CVE-2026-81377 Visual Studio Code Tampering Vulnerability Published on: September 08, 2026 <p>Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.</p> Read Details
CVE-2026-81378 Visual Studio Code Security Feature Bypass Vulnerability Published on: September 08, 2026 <p>Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.</p> Read Details
CVE-2026-81379 Visual Studio Code Security Feature Bypass Vulnerability Published on: September 08, 2026 <p>Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.</p> Read Details
CVE-2026-81380 GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability Published on: September 08, 2026 <p>Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-81381 GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability Published on: September 08, 2026 <p>Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-70065 Windows DHCP Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-83942 Windows Kernel Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83952 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69989 Windows DNS Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in DNS Server allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69827 Windows DNS Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-72947 Windows File History Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Integer underflow (wrap or wraparound) in Windows File History Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72949 Windows SMB Server Network Transport Driver (srvnet.sys) Denial of Service Vulnerability Published on: September 08, 2026 <p>Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-70019 Windows Compressed Folder Information Disclosure Vulnerability Published on: September 08, 2026 <p>Windows hard link in Windows Compressed Folder allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-72940 Windows Schannel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Schannel allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69573 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72937 Windows Storage Port Driver Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-69492 Windows Partition Management Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83955 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83986 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83969 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83988 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83979 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83974 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83975 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83976 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-70290 Win32k Information Disclosure Vulnerability Published on: September 08, 2026 <p>Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-83991 Windows Cloud Files Mini Filter Driver Tampering Vulnerability Published on: September 08, 2026 <p>Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.</p> Read Details
CVE-2026-83996 Windows Error Reporting Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.</p> Read Details
Chromium: CVE-2026-84323 Missing authorization in FileSystem Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-84329 Confused deputy in CredentialProvider Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-84331 Incorrect authorization in Actor Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-84334 Incorrect authorization in Chromoting Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-84335 Incorrect authorization in TabStrip Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-84348 Information leak in MediaCapture Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-84350 Use after free in TabStrip Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-84351 Buffer overflow in GPU Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-84353 Use after free in Shared Tab Groups Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
CVE-2026-83998 Remote Desktop Client Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.</p> Read Details
Chromium: CVE-2026-84354 Incorrect authorization in FileSystem Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-84357 Improper input validation in Omnibox Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
CVE-2026-83999 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-84001 Windows Key Distribution Center Denial of Service Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-85877 Windows Print Spooler Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-85880 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-56177 Windows Server Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Server allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-56198 Microsoft Trace Data Helper Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-58611 Xbox Gaming Services Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-62810 Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62759 Windows Netlogon Spoofing Vulnerability Published on: September 08, 2026 <p>Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.</p> Read Details
CVE-2026-62762 Windows Active Directory Domain Services Denial of Service Vulnerability Published on: September 08, 2026 Information published. Read Details
CVE-2026-62813 Windows Active Directory Domain Services Remote Code Execution Vulnerability Published on: September 08, 2026 Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network. Read Details
CVE-2026-62697 Windows Push Notifications Elevation of Privilege Vulnerability Published on: September 08, 2026 Acknowledgement Updated Read Details
CVE-2026-56172 Windows VHD miniport driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-66814 Microsoft SQL Server Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-66816 Microsoft SQL Server Security Feature Bypass Vulnerability Published on: September 08, 2026 <p>Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.</p> Read Details
CVE-2026-66818 Microsoft SQL Server Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-66820 SQL Server Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-67380 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-67381 Microsoft SQL Server Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-67385 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in SQL Server allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-67386 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-67388 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-67390 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-67393 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-67638 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. Read Details
CVE-2026-67639 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-67641 Microsoft SQL Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.</p> Read Details
CVE-2026-67642 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-67648 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-68775 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. Read Details
CVE-2026-68776 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. Read Details
CVE-2026-68777 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-68778 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-68779 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-68780 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-68828 Remote Desktop Client Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-68831 Windows Defender Firewall Service Information Disclosure Vulnerability Published on: September 08, 2026 Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. Read Details
CVE-2026-68827 Windows GDI+ Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-68834 Windows NTFS Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-68843 Microsoft Office Word Information Disclosure Vulnerability Published on: September 08, 2026 Use after free in Microsoft Office Word allows an authorized attacker to disclose information locally. Read Details
CVE-2026-68838 Windows NTFS Elevation of Privilege Vulnerability Published on: September 08, 2026 Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-68839 Windows USB Mass Storage Class Driver Remote Code Execution Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-68840 Windows USB Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-68848 Windows Print Spooler Components Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-68842 Windows MIDI Service Module Information Disclosure Vulnerability Published on: September 08, 2026 <p>Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-68880 Windows Win32k Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-68876 Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-68874 Windows Program Compatibility Assistant Service Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information over a network. Read Details
CVE-2026-68850 Microsoft Account Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Microsoft Account allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-68852 Microsoft Account Information Disclosure Vulnerability Published on: September 08, 2026 Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69265 Windows NTFS Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-68873 Windows Program Compatibility Assistant Service Information Disclosure Vulnerability Published on: September 08, 2026 Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally. Read Details
CVE-2026-68885 Microsoft Standard XPS Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-68898 Windows iSCSI Denial of Service Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows iSCSI allows an unauthorized attacker to deny service over a network. Read Details
CVE-2026-68886 Windows Network Connection Broker Information Disclosure Vulnerability Published on: September 08, 2026 Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally. Read Details
CVE-2026-68888 Microsoft Standard XPS Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-68889 Microsoft Standard XPS Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-68891 Microsoft Standard XPS Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69272 Microsoft Standard XPS Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-69274 Windows Win32k Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Win32K allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69288 Windows GDI+ Information Disclosure Vulnerability Published on: September 08, 2026 Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69266 Windows DHCP Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in Windows DHCP Server allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-68894 Windows Error Reporting Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-68895 Internet Storage Name Service Information Disclosure Vulnerability Published on: September 08, 2026 <p>Numeric truncation error in Internet Storage Name Service allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-69280 Windows Push Notifications Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69269 Microsoft Standard XPS Elevation of Privilege Vulnerability Published on: September 08, 2026 Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69270 Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69277 Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69305 Microsoft Windows Search Component Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69286 Windows USB Audio Class Driver Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69284 Windows DCOM Server Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows DCOM Server allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69275 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69299 Microsoft COM for Windows Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Microsoft COM for Windows allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69295 Windows USB Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69283 Windows CD-ROM Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69297 Windows DHCP Server Information Disclosure Vulnerability Published on: September 08, 2026 Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network. Read Details
CVE-2026-69289 Windows Setup Files Cleanup Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69294 Microsoft COM for Windows Information Disclosure Vulnerability Published on: September 08, 2026 <p>Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-69314 Windows Device Association Broker Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69300 Windows Push Notifications Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69321 Windows Power Dependency Coordinator Tampering Vulnerability Published on: September 08, 2026 <p>Missing authentication for critical function in Windows Power Dependency Coordinator allows an authorized attacker to perform tampering locally.</p> Read Details
CVE-2026-69301 Windows Win32k Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69303 Push Message Routing Service Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69313 Microsoft Standard XPS Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-69315 Windows License Manager Information Disclosure Vulnerability Published on: September 08, 2026 <p>Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-69312 Windows NTFS Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69308 Microsoft Standard XPS Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69318 Windows Imaging Component Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69317 Windows Remote Desktop Client Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information over a network. Read Details
CVE-2026-69316 Windows Overlay Filter Information Disclosure Vulnerability Published on: September 08, 2026 Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69319 Windows USB Video Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69322 Microsoft Windows Search Component Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69324 Windows Performance Monitor Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Access of resource using incompatible type ('type confusion') in Windows Performance Monitor allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69351 Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability Published on: September 08, 2026 Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69329 BranchCache Denial of Service Vulnerability Published on: September 08, 2026 Out-of-bounds read in BranchCache allows an unauthorized attacker to deny service over a network. Read Details
CVE-2026-69328 Windows Storage Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69331 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Published on: September 08, 2026 Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69332 Windows NTFS Elevation of Privilege Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-69335 Windows Win32k Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69340 Windows NTFS Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69342 Windows DHCP Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-69343 Windows Overlay Filter Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows Overlay Filter allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69344 Windows Print Spooler Components Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69346 Windows Print Spooler Components Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-69348 Windows Win32k Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69350 Windows Overlay Filter Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69353 Windows Text Shaping Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69358 Remote Desktop Client Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69357 Windows NDIS Elevation of Privilege Vulnerability Published on: September 08, 2026 Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-69376 Microsoft Standard XPS Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69384 Virtual Hard Disk (VHD) Miniport Driver Denial of Service Vulnerability Published on: September 08, 2026 Information published. Read Details
CVE-2026-69372 Windows Network File System Denial of Service Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Network File System allows an authorized attacker to deny service over a network.</p> Read Details
CVE-2026-69360 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-69365 Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability Published on: September 08, 2026 Out-of-bounds read in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-69364 Windows Print Spooler Components Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69369 Windows DNS Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows DNS allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69403 Windows SMB Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Missing authorization in Windows SMB Server allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-69373 Windows Overlay Filter Elevation of Privilege Vulnerability Published on: September 08, 2026 Integer overflow or wraparound in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69374 Windows SMB Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service over a network.</p> Read Details
CVE-2026-69385 Windows TCP/IP Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69386 Microsoft Windows Media Foundation Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69388 Windows Bluetooth Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69393 Windows Spaceport.sys Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information over a network. Read Details
CVE-2026-69396 Windows NDIS Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69410 Windows Win32k Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69398 Windows Bluetooth Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69421 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Integer underflow (wrap or wraparound) in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69405 Windows DHCP Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.</p> Read Details
CVE-2026-69407 Volume Manager Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 Integer overflow or wraparound in Volume Manager Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69416 Windows DHCP Server Denial of Service Vulnerability Published on: September 08, 2026 Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. Read Details
CVE-2026-69424 Windows Distributed File System (DFS) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Distributed File System (DFS) allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69428 Windows LDAP - Lightweight Directory Access Protocol Denial of Service Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. Read Details
CVE-2026-69422 Windows USB Video Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 Use after free in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69438 Microsoft JScript Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Incorrect conversion between numeric types in Microsoft JScript allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69425 Windows NTFS Tampering Vulnerability Published on: September 08, 2026 Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to perform tampering locally. Read Details
CVE-2026-69427 Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-69475 Windows Remote Desktop Services Elevation of Privilege Vulnerability Published on: September 08, 2026 Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69430 Windows Embedded Mode Service Elevation of Privilege Vulnerability Published on: September 08, 2026 Use after free in Windows Embedded Mode Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69449 Windows BitLocker Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows BitLocker allows an authorized attacker to execute code locally.</p> Read Details
CVE-2026-69447 Windows Audio Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69433 Windows Error Reporting Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69434 Windows URL Moniker Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows URL Moniker allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69440 Windows MIDI Service Module Elevation of Privileges Vulnerability Published on: September 08, 2026 <p>Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69444 Microsoft Windows Speech Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69466 Windows Kernel Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Time-of-check time-of-use (toctou) race condition in Windows Kernel allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69445 Windows Compressed Folder Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper limitation of a pathname to a restricted directory ('path traversal') in Windows Compressed Folder allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69462 Windows Error Reporting Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69453 Microsoft Windows Search Component Tampering Vulnerability Published on: September 08, 2026 <p>Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.</p> Read Details
CVE-2026-69456 Microsoft Windows Speech Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69459 Windows Power Dependency Coordinator Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Power Dependency Coordinator allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69460 Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69467 Microsoft Graphics Component Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69474 Windows Overlay Filter Information Disclosure Vulnerability Published on: September 08, 2026 Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network. Read Details
CVE-2026-69482 Windows Error Reporting Tampering Vulnerability Published on: September 08, 2026 <p>Creation of temporary file in directory with insecure permissions in Windows Error Reporting allows an authorized attacker to perform tampering locally.</p> Read Details
CVE-2026-69478 Windows Device Association Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69561 Windows CD-ROM Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69480 Windows Partition Management Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69483 Windows Image Acquisition Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows Image Acquisition allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69578 Windows Kernel Elevation of Privilege Vulnerability Published on: September 08, 2026 Numeric truncation error in Windows Kernel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69488 Windows Device Association Service Elevation of Privilege Vulnerability Published on: September 08, 2026 Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69493 Windows Event Logging Service Remote Code Execution Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-69511 Microsoft Windows Media Foundation Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69497 Windows DHCP Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over a network.</p> Read Details
CVE-2026-69512 Windows Spaceport.sys Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-69498 Windows Win32k Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69503 Windows USB Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 Stack-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-69508 Windows MIDI Service Module Elevation of Privileges Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69509 Role: Windows Fax Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69599 Remote Desktop Services Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69547 Windows DHCP Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69536 Remote Desktop Services Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69546 Windows Active Directory Domain Services Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69571 Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69535 Windows Spaceport.sys Elevation of Privilege Vulnerability Published on: September 08, 2026 Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69538 Windows Spaceport.sys Remote Code Execution Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally. Read Details
CVE-2026-69542 Windows Camera Frame Server Monitor Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows Camera Frame Server Monitor allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69591 Windows NTFS Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69569 Windows Print Spooler Components Denial of Service Vulnerability Published on: September 08, 2026 Untrusted pointer dereference in Windows Print Spooler Components allows an authorized attacker to deny service over a network. Read Details
CVE-2026-69581 Windows Device Association Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69586 Microsoft Windows PDF Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69612 Windows Error Reporting Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69566 Windows NTFS Remote Code Execution Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. Read Details
CVE-2026-69567 Windows NTFS Elevation of Privilege Vulnerability Published on: September 08, 2026 Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69592 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69584 Windows USB Video Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 Integer overflow or wraparound in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69600 Microsoft Windows Search Component Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69606 Windows Shell Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69625 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69618 Windows SMB Client Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69624 Active Directory Certificate Services (AD CS) Tampering Vulnerability Published on: September 08, 2026 Incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) allows an authorized attacker to perform tampering over a network. Read Details
CVE-2026-69597 Windows HTTP.sys Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69602 Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69611 Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability Published on: September 08, 2026 <p>Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69617 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69616 Windows Remote Desktop Services Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69630 Windows Win32k Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69610 Windows Win32k Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Buffer over-read in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69613 Windows Image Acquisition Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69669 Windows Kernel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69881 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Published on: September 08, 2026 Information published. Read Details
CVE-2026-69680 Windows DNS Spoofing Vulnerability Published on: September 08, 2026 Origin validation error in Windows DNS allows an unauthorized attacker to perform spoofing over a network. Read Details
CVE-2026-69817 Windows Bluetooth Port Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69619 Windows exFAT File System Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows exFAT File System allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69620 Windows DHCP Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69720 Windows MIDI Service Module Elevation of Privileges Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69821 Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper encoding or escaping of output in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69715 Windows Direct Show Remote Code Execution Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-69637 Windows DHCP Server Denial of Service Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. Read Details
CVE-2026-69682 Windows Host Guardian Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Host Guardian Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69685 Windows Kerberos Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69803 Windows DHCP Server Information Disclosure Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-69643 Windows Spaceport.sys Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-69687 Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability Published on: September 08, 2026 Integer underflow (wrap or wraparound) in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69791 Windows Device Association Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69707 Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability Published on: September 08, 2026 Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69652 Windows Win32k Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69834 Windows ALPC Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows ALPC allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69654 Windows Accounts Control Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69816 Windows Accounts Control Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69714 Windows Device Association Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69709 Windows NTFS Remote Code Execution Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. Read Details
CVE-2026-69844 Windows Win32k Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69679 Windows DHCP Server Denial of Service Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.</p> Read Details
CVE-2026-69866 Windows Device Association Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69674 Windows Modern Device Management (MDM) Security Feature Bypass Vulnerability Published on: September 08, 2026 Missing authentication for critical function in Windows Modern Device Management (MDM) allows an authorized attacker to bypass a security feature locally. Read Details
CVE-2026-69688 Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-69841 Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69727 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69826 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-69738 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69801 Windows Audio Service Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69692 Windows Audio Service Elevation of Privilege Vulnerability Published on: September 08, 2026 Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69814 Windows Credential Providers Elevation of Privilege Vulnerability Published on: September 08, 2026 Use after free in Windows Credential Providers allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69731 HID Class Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in HID class driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69773 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-69794 Windows Encrypting File System (EFS) Information Disclosure Vulnerability Published on: September 08, 2026 Buffer over-read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69706 Windows Win32k Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Win32K allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69768 Windows RNDIS Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69713 Windows Secure Boot Security Feature Bypass Vulnerability Published on: September 08, 2026 <p>Dependency on vulnerable third-party component in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.</p> Read Details
CVE-2026-69793 Windows TCP/IP Security Feature Bypass Vulnerability Published on: September 08, 2026 Improper validation of consistency within input in Windows TCP/IP allows an unauthorized attacker to bypass a security feature over a network. Read Details
CVE-2026-69921 Windows Print Spooler Components Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69779 Windows Win32k Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Time-of-check time-of-use (toctou) race condition in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69895 Windows Spaceport.sys Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-69672 Windows DNS Information Disclosure Vulnerability Published on: September 08, 2026 Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally. Read Details
CVE-2026-69809 Windows Active Directory Domain Services Denial of Service Vulnerability Published on: September 08, 2026 Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network. Read Details
CVE-2026-69792 Windows Win32K Security Feature Bypass Vulnerability Published on: September 08, 2026 <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to bypass a security feature locally.</p> Read Details
CVE-2026-69853 Win32k Information Disclosure Vulnerability Published on: September 08, 2026 <p>Use of uninitialized resource in Windows Win32K allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-69761 Windows TCP/IP Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69708 Windows Web Platform Storage Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Web Platform Storage allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69878 Windows DHCP Server Remote Code Execution Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code locally. Read Details
CVE-2026-69785 Windows Smart Card Elevation of Privilege Vulnerability Published on: September 08, 2026 Untrusted search path in Windows Smart Card allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69907 Windows Enterprise App Management Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69818 Windows Win32k Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69900 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69891 Windows Media Elevation of Privilege Vulnerability Published on: September 08, 2026 Use after free in Windows Media allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69847 Windows DHCP Server Remote Code Execution Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network. Read Details
CVE-2026-69911 Microsoft Windows Search Component Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69824 Microsoft Standard XPS Remote Code Execution Vulnerability Published on: September 08, 2026 Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-69760 Windows Kerberos Denial of Service Vulnerability Published on: September 08, 2026 Out-of-bounds read in Windows Kerberos allows an unauthorized attacker to deny service over a network. Read Details
CVE-2026-69777 Windows DHCP Client Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges over an adjacent network.</p> Read Details
CVE-2026-69807 PowerShell Elevation of Privilege Vulnerability Published on: September 08, 2026 Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-69781 Windows DHCP Client Denial of Service Vulnerability Published on: September 08, 2026 <p>Missing release of memory after effective lifetime in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.</p> Read Details
CVE-2026-69876 Windows DHCP Server Remote Code Execution Vulnerability Published on: September 08, 2026 Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network. Read Details
CVE-2026-69845 Windows DHCP Server Remote Code Execution Vulnerability Published on: September 08, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-69829 Windows Shell Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69769 Windows HTTP Print Provider Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69852 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Published on: September 08, 2026 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine Read Details
CVE-2026-69786 Windows Text Shaping Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Text Shaping allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69799 Windows Hello Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69813 Windows DNS Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69710 Windows Hello Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69858 Windows DNS Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69874 Windows ALPC Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69725 Windows Hello Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Double free in Windows Hello allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69864 Windows Hello Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69820 Windows Hello Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69784 Windows Hello Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-58599 HEVC Video Extensions Remote Code Execution Vulnerability Published on: September 08, 2026 Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64918 Microsoft Office Spoofing Vulnerability Published on: September 08, 2026 Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network. Read Details
CVE-2026-47297 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-70565 Windows AF_UNIX Socket Provider Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-70574 Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability Published on: September 08, 2026 <p>Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-70567 Windows Display Enhancement Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-70568 Windows Defender Firewall Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-70569 Windows Spaceport.sys Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-70573 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-70572 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-70575 Windows Schannel Denial of Service Vulnerability Published on: September 08, 2026 <p>Null pointer dereference in Windows Schannel allows an authorized attacker to deny service over a network.</p> Read Details
CVE-2026-70581 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-70577 Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-70578 Windows Credential Guard Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Credential Guard allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-70579 Windows Mobile Broadband Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-70583 Windows Core Messaging Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-71349 Windows Spaceport.sys Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.</p> Read Details
CVE-2026-71342 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-71352 Windows Remote Access Connection Manager Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-72927 Winsock Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72928 Windows DNS Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows DNS allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-72931 Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability Published on: September 08, 2026 <p>Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally.</p> Read Details
CVE-2026-72936 Windows SMB Client Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows SMB Client allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-72933 Microsoft WDAC OLE DB provider for SQL Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft WDAC OLE DB provider for SQL allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-72932 Windows Message Queuing Queue Manager Information Disclosure Vulnerability Published on: September 08, 2026 <p>Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-72952 Windows Spaceport.sys Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally.</p> Read Details
CVE-2026-72953 Windows USB Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72941 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72942 Windows Spaceport.sys Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Spaceport.sys allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-72957 Windows Deployment Services Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Deployment Services allows an authorized attacker to execute code locally.</p> Read Details
CVE-2026-72950 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Published on: September 08, 2026 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine Read Details
CVE-2026-72959 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Published on: September 08, 2026 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine Read Details
CVE-2026-72954 Windows Deployment Services Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-72960 Windows Media Player Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-72961 Windows Hyper-V Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72964 Windows Internet Connection Sharing (ICS) Tampering Vulnerability Published on: September 08, 2026 <p>Missing authentication for critical function in Windows Internet Connection Sharing (ICS) allows an authorized attacker to perform tampering locally.</p> Read Details
CVE-2026-72966 Windows Remote Access Connection Manager Tampering Vulnerability Published on: September 08, 2026 <p>Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.</p> Read Details
CVE-2026-72967 Windows Network Connection Broker Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-68896 Microsoft Windows Search Component Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Absolute path traversal in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69287 Windows Remote Desktop Services Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69309 Windows Print Spooler Components Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69290 Windows Storage Spaces Controller Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69291 Windows Volume Manager Extension Driver Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69334 Windows Volume Manager Extension Driver Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69323 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69298 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69311 Windows Audio Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69352 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69910 Windows Hyper-V Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69392 Windows Shell Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69395 Active Directory Certificate Services (AD CS) Information Disclosure Vulnerability Published on: September 08, 2026 <p>Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69397 Microsoft OpenSSH for Windows Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69402 Microsoft Office SharePoint Spoofing Vulnerability Published on: September 08, 2026 <p>Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.</p> Read Details
CVE-2026-69409 Microsoft Office SharePoint Information Disclosure Vulnerability Published on: September 08, 2026 <p>Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69417 Microsoft Office SharePoint Spoofing Vulnerability Published on: September 08, 2026 <p>Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.</p> Read Details
CVE-2026-69426 Windows VOLSNAP.SYS Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to execute code locally.</p> Read Details
CVE-2026-69489 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69490 Windows USB Mass Storage Class Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a physical attack.</p> Read Details
CVE-2026-69499 Windows Imaging Component Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in Windows Imaging Component allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69510 Windows DHCP Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69559 Microsoft Teams for Android Information Disclosure Vulnerability Published on: September 08, 2026 <p>Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69560 Windows Work Folder Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69564 Windows Online Certificate Status Protocol (OCSP) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Online Certificate Status Protocol (OCSP) allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69593 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69568 Storage Spaces Controller Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-69575 Windows Storage Spaces Controller Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69607 Windows Deployment Services Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69590 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Published on: September 08, 2026 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine Read Details
CVE-2026-69601 Microsoft Windows Media Foundation Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69442 Microsoft Office Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69615 Microsoft Office SharePoint Spoofing Vulnerability Published on: September 08, 2026 <p>Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.</p> Read Details
CVE-2026-69464 Microsoft Office SharePoint Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69614 Microsoft Office Access Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69636 Microsoft Office SharePoint Information Disclosure Vulnerability Published on: September 08, 2026 <p>Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69629 Microsoft Office Outlook Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69477 Microsoft Office Access Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally.</p> Read Details
CVE-2026-69626 Microsoft Office Information Disclosure Vulnerability Published on: September 08, 2026 <p>Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69632 Microsoft Office Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Microsoft Office allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69439 .NET and Visual Studio Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69805 .NET Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-58649 .NET Information Disclosure Vulnerability Published on: September 08, 2026 <p>Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69441 Windows Installer Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69904 Microsoft Office SharePoint Information Disclosure Vulnerability Published on: September 08, 2026 <p>Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69906 Windows Secure Kernel Mode Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-70203 Windows Media Player Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-70296 Windows Imaging Component Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-70570 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Published on: September 08, 2026 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine Read Details
CVE-2026-72956 Microsoft Office PowerPoint Information Disclosure Vulnerability Published on: September 08, 2026 <p>Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-72972 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-72938 Microsoft Office PowerPoint Information Disclosure Vulnerability Published on: September 08, 2026 <p>Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-72973 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-72974 Microsoft Office Excel Information Disclosure Vulnerability Published on: September 08, 2026 <p>Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-72977 Microsoft Office PowerPoint Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-72975 Microsoft Office PowerPoint Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-72976 Microsoft Office Word Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-72985 Volume Shadow Copy Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack.</p> Read Details
CVE-2026-65772 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-65812 Microsoft Teams for Android Information Disclosure Vulnerability Published on: September 08, 2026 <p>Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69465 Microsoft Office SharePoint Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69304 ASP.NET Core Denial of Service Vulnerability Published on: September 08, 2026 <p>Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-72989 Windows Failover Cluster Information Disclosure Vulnerability Published on: September 08, 2026 <p>Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-72987 Windows DNS Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-72995 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72988 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72990 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72991 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72992 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72993 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72994 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72996 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-72997 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-73018 Graphic Fonts Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-73019 Windows URL Moniker Security Feature Bypass Vulnerability Published on: September 08, 2026 <p>Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network.</p> Read Details
CVE-2026-72999 Windows USB Hub Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack.</p> Read Details
CVE-2026-73002 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-73020 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-73000 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-73001 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-73021 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-73015 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-73003 Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-73022 Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-73011 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-73014 Data Sharing Service Client Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-73008 Windows Biometric Service Information Disclosure Vulnerability Published on: September 08, 2026 <p>Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-73005 Windows Authentication Methods Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-73024 Windows Services for NFS ONCRPC XDR Driver Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-73007 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-73026 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-73004 Windows Autopilot Tampering Vulnerability Published on: September 08, 2026 <p>Missing authentication for critical function in Windows Autopilot allows an authorized attacker to perform tampering locally.</p> Read Details
CVE-2026-73012 Windows Management Services Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-73009 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-73006 DirectWrite Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-73010 Microsoft Failover Cluster Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-73023 Windows Imaging Component Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-73013 Windows Imaging Component Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-73025 Windows iSCSI Security Feature Bypass Vulnerability Published on: September 08, 2026 <p>Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.</p> Read Details
CVE-2026-73016 DirectWrite Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-73017 Graphics Kernel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally.</p> Read Details
CVE-2026-71328 .NET and Visual Studio Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-73028 SQL Server Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-77480 SQL Server Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-77483 SQL Server Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-77484 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-77487 SQL Server Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-77485 SQL Server Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in SQL Server allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-77486 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-77488 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-77901 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69854 Spring Cloud Azure Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-77905 Windows Management Instrumentation Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-77911 Microsoft Office Word Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69562 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-78442 Windows OLE DB Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-78441 Windows OLE DB Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-78445 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-78446 Windows Distributed File System (DFS) Denial of Service Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network.</p> Read Details
CVE-2026-78449 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-78444 Microsoft Failover Cluster Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-78450 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-78447 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-78448 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-78451 Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.</p> Read Details
CVE-2026-78453 Microsoft Windows SCSI Class System File Information Disclosure Vulnerability Published on: September 08, 2026 <p>Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-78455 Xbox Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack.</p> Read Details
CVE-2026-78452 Microsoft Windows SCSI Class System File Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack.</p> Read Details
CVE-2026-78454 Windows CD-ROM Driver Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-78456 SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-78457 Windows Security Health Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-78462 Visual Studio Code Security Feature Bypass Vulnerability Published on: September 08, 2026 <p>Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.</p> Read Details
CVE-2026-69595 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-78464 Windows MIDI Service Module Elevation of Privileges Vulnerability Published on: September 08, 2026 <p>Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-66819 Microsoft SQL Server Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-67369 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-78507 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-78506 Microsoft Office Word Information Disclosure Vulnerability Published on: September 08, 2026 <p>Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally.</p> Read Details
CVE-2026-78512 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-78514 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-78503 Microsoft Office Word Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-78516 Windows Storage Information Disclosure Vulnerability Published on: September 08, 2026 <p>Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack.</p> Read Details
CVE-2026-67624 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-67645 Microsoft SQL Server Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-77481 Microsoft SQL Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-78519 Microsoft Office Outlook Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-80079 Microsoft Office Word Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-78521 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-80073 Microsoft Office Outlook Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-78522 Microsoft Office Word Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-78520 Microsoft Office Outlook Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-78524 Microsoft Office Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-80078 Microsoft Office Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-80076 Microsoft Office Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-78526 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-80084 Microsoft Office Outlook Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-78525 Microsoft Office Outlook Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-80086 Microsoft Office PowerPoint Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-80080 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-80087 Microsoft Office Information Disclosure Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-80085 Microsoft Office Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-80088 Microsoft Office Word Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-80091 Microsoft Office Information Disclosure Vulnerability Published on: September 08, 2026 <p>Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-80089 Microsoft Office Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-80090 Microsoft Office Word Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-80081 Microsoft Office PowerPoint Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-80082 Microsoft Office Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-80096 Windows Remote Desktop Services Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-81352 Web Media Extensions Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-81353 HEIF Image Extensions Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.</p> Read Details
CVE-2026-81354 Windows Hello Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-81383 Visual Studio Code Information Disclosure Vulnerability Published on: September 08, 2026 <p>Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-81385 Microsoft Office Publisher Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-81398 Microsoft Excel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p> Read Details
CVE-2026-81386 Microsoft Excel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p> Read Details
CVE-2026-81947 Microsoft Excel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p> Read Details
CVE-2026-81387 Microsoft Excel Information Disclosure Vulnerability Published on: September 08, 2026 <p>Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.</p> Read Details
CVE-2026-81954 Microsoft Excel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p> Read Details
CVE-2026-81390 Microsoft Excel Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.</p> Read Details
CVE-2026-81399 Microsoft Excel Information Disclosure Vulnerability Published on: September 08, 2026 <p>Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.</p> Read Details
CVE-2026-81391 Microsoft Excel Information Disclosure Vulnerability Published on: September 08, 2026 <p>Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.</p> Read Details
CVE-2026-81401 Microsoft Excel Information Disclosure Vulnerability Published on: September 08, 2026 <p>Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.</p> Read Details
CVE-2026-81958 Microsoft Excel Information Disclosure Vulnerability Published on: September 08, 2026 <p>Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.</p> Read Details
CVE-2026-81396 Microsoft Excel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p> Read Details
CVE-2026-81392 Microsoft Excel Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.</p> Read Details
CVE-2026-81397 Microsoft Excel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p> Read Details
CVE-2026-81956 Microsoft Excel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p> Read Details
CVE-2026-81393 Microsoft Excel Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.</p> Read Details
CVE-2026-81400 Microsoft Excel Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.</p> Read Details
CVE-2026-81389 Microsoft Excel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p> Read Details
CVE-2026-81394 Microsoft Excel Information Disclosure Vulnerability Published on: September 08, 2026 <p>Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.</p> Read Details
CVE-2026-81960 Microsoft Excel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p> Read Details
CVE-2026-81395 Microsoft Excel Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.</p> Read Details
CVE-2026-81957 Microsoft Excel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p> Read Details
CVE-2026-81388 Microsoft Excel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p> Read Details
CVE-2026-81955 Windows Graphics Component Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-81951 Microsoft Excel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p> Read Details
CVE-2026-81952 Microsoft Word Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-81959 Microsoft Excel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p> Read Details
CVE-2026-81953 Microsoft Excel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p> Read Details
CVE-2026-81949 Microsoft Excel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p> Read Details
CVE-2026-81950 Microsoft Excel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p> Read Details
CVE-2026-81948 Microsoft Excel Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p> Read Details
CVE-2026-77906 Visual Studio Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-83940 Windows Device Association Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83939 Windows Secure Kernel Mode Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-57099 ASP.NET Core Denial of Service Vulnerability Published on: September 08, 2026 <p>Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-77897 Microsoft Power Automate Desktop Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83948 Microsoft Azure CLI Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Improper neutralization of special elements used in a command ('command injection') in Microsoft Azure CLI allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-81963 Windows Update Stack Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83951 Microsoft Office Word Information Disclosure Vulnerability Published on: September 08, 2026 <p>Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.</p> Read Details
CVE-2026-83949 Microsoft Office Word Information Disclosure Vulnerability Published on: September 08, 2026 <p>Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.</p> Read Details
CVE-2026-69530 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-69381 Windows Storage Port Driver Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physical attack.</p> Read Details
CVE-2026-72965 Windows WebClient Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-69598 Windows iSCSI Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-83971 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83954 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83967 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83970 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83972 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83968 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-70145 Microsoft Windows Search Component Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-83973 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83981 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83977 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83978 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83982 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83980 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83987 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83983 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83985 Windows Biometric Service Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83989 Windows Services for NFS ONCRPC XDR Driver Denial of Service Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-83990 Microsoft Graphics Component Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83992 Windows Imaging Component Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-83995 Windows NTFS Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-83997 Windows Message Queuing Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.</p> Read Details
Chromium: CVE-2026-84324 Use after free in Proxy Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-84325 Improper input validation in DataTransfer Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-84326 Uninitialized resource in V8 Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-84327 Incorrect authorization in Autofill Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-84328 Missing authorization in FileSystem Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-84332 Incorrect authorization in SiteSettings Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-84347 Use after free in WebRTC Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-84349 Use after free in Browser Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-84355 Incorrect authorization in Navigation Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-84356 UI misrepresentation in FullScreen Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
CVE-2026-84000 Microsoft Graphics Component Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.</p> Read Details
Chromium: CVE-2026-84358 Improper privilege management in Downloads Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-84359 Information leak in Skia Published on: September 08, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
CVE-2026-69806 .NET Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-85875 Microsoft Office Excel Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.</p> Read Details
ADV990001 Latest Servicing Stack Updates Published on: September 08, 2026 Advisory updated to announce new versions of Servicing Stack Updates are available. Please see the FAQ for details. Read Details
CVE-2026-83501 Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability Published on: September 08, 2026 <p>Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.</p> Read Details
CVE-2026-83498 Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.</p> Read Details
CVE-2026-84003 Microsoft Authentication Library (MSAL) for Node.js Spoofing Vulnerability Published on: September 08, 2026 <p>Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.</p> Read Details
CVE-2026-66303 Skype for Business and Lync Denial of Service Vulnerability Published on: September 08, 2026 <p>Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.</p> Read Details
CVE-2026-66307 Skype for Business and Lync Denial of Service Vulnerability Published on: September 08, 2026 <p>Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.</p> Read Details
CVE-2026-62804 Microsoft Word Remote Code Execution Vulnerability Published on: September 08, 2026 External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-62906 Microsoft Discovery Studio Information Disclosure Vulnerability Published on: September 08, 2026 <p>Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-70352 Azure AI Language Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-80098 Copilot Studio Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-83711 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability Published on: September 08, 2026 <p>Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-50696 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability Published on: September 08, 2026 Acknowledgement Updated Read Details
CVE-2026-54990 Remote Desktop Client Remote Code Execution Vulnerability Published on: September 08, 2026 Acknowledgement Updated Read Details
CVE-2026-50453 Windows USB Audio Class Driver Information Disclosure Vulnerability Published on: September 08, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-57085 Windows Print Spooler Information Disclosure Vulnerability Published on: September 08, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62718 Windows DHCP Server Information Disclosure Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-62715 Windows DHCP Server Information Disclosure Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-62716 Windows DHCP Server Information Disclosure Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-62742 Windows DHCP Server Information Disclosure Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-62745 Windows DHCP Server Information Disclosure Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-62787 Windows DNS Server Remote Code Execution Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-62812 Windows DHCP Server Elevation of Privilege Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-62817 Windows DNS Server Remote Code Execution Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-62820 Windows DNS Server Remote Code Execution Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-62878 Windows DNS Server Remote Code Execution Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-62893 Windows Deployment Services TFTP Server Remote Code Execution Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-65789 Windows DNS Server Remote Code Execution Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-61920 Windows DNS Server Remote Code Execution Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-62720 Windows DHCP Server Information Disclosure Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-62714 Windows DHCP Server Information Disclosure Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-62761 Windows DHCP Server Elevation of Privilege Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-62776 Windows DHCP Server Elevation of Privilege Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-62803 Windows DHCP Server Elevation of Privilege Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-62807 Windows DHCP Server Elevation of Privilege Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-62814 Windows DHCP Server Information Disclosure Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-62823 Windows DHCP Server Remote Code Execution Vulnerability Published on: September 08, 2026 Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. Read Details
CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability Published on: September 08, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-42914 Windows Kerberos Denial of Service Vulnerability Published on: September 08, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-44814 Windows DWM Core Library Information Disclosure Vulnerability Published on: September 08, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-69845 Windows DHCP Server Remote Code Execution Vulnerability Published on: September 08, 2026 <p>Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-50376 Windows Remote Desktop Client Information Disclosure Vulnerability Published on: September 04, 2026 Acknowledgment updated Read Details
CVE-2026-58641 .NET Elevation of Privilege Vulnerability Published on: September 03, 2026 Added SkiaSharp 4.151.2 to the affected software table. Read Details
CVE-2026-58612 PowerShell Information Disclosure Vulnerability Published on: September 03, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62815 Microsoft QUIC Remote Code Execution Vulnerability Published on: September 03, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-69414 Microsoft Defender Elevation of Privilege Vulnerability Published on: September 03, 2026 Microsoft has released an update to the Microsoft Malware Protection Engine that addresses the vulnerability identified by CVE-2026-69414. Please see the FAQ for more information on how to check if the new version has been installed. Read Details
CVE-2026-58650 Visual Studio Code Security Feature Bypass Vulnerability Published on: September 02, 2026 Affected software updated with new package information. Read Details
CVE-2026-59113 Visual Studio Code Remote Code Execution Vulnerability Published on: September 02, 2026 Affected software updated with new package information. Read Details
CVE-2026-47285 Visual Studio Code Information Disclosure Vulnerability Published on: September 02, 2026 Affected software updated with new package information. Read Details
CVE-2026-65675 CoPilot Chat Security Feature Bypass Vulnerability Published on: September 02, 2026 Affected software updated with new package information. Read Details
CVE-2026-69320 Visual Studio Code Remote Code Execution Vulnerability Published on: September 02, 2026 Affected software updated with new package information. Read Details
CVE-2026-69278 Visual Studio Code Security Feature Bypass Vulnerability Published on: September 02, 2026 Affected software updated with new package information. Read Details
CVE-2026-69306 Visual Studio Code Security Feature Bypass Vulnerability Published on: September 02, 2026 Affected software updated with new package information. Read Details
CVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability Published on: September 02, 2026 Affected software updated with new package information. Read Details
CVE-2026-70336 Visual Studio Code Remote Code Execution Vulnerability Published on: September 02, 2026 Affected software updated with new package information. Read Details
CVE-2026-62768 Windows Installer Elevation of Privilege Vulnerability Published on: September 02, 2026 Acknowledgement added. This is an informational change only. Read Details
CVE-2026-62880 Windows NTFS Elevation of Privilege Vulnerability Published on: September 02, 2026 Acknowledgement Updated Read Details
CVE-2026-50376 Windows Remote Desktop Client Information Disclosure Vulnerability Published on: September 02, 2026 Acknowledgement added. This is an informational change only. Read Details
CVE-2026-64899 Microsoft Office Information Disclosure Vulnerability Published on: August 31, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-65775 Windows Win32k Elevation of Privilege Vulnerability Published on: August 31, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-65776 Windows Win32k Elevation of Privilege Vulnerability Published on: August 31, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62823 Windows DHCP Server Remote Code Execution Vulnerability Published on: August 31, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62889 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Published on: August 31, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-59134 Remote Desktop Client Remote Code Execution Vulnerability Published on: August 31, 2026 Acknowledgement Updated Read Details
CVE-2026-49177 Windows TCP/IP Information Disclosure Vulnerability Published on: August 31, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-55134 Microsoft Word Remote Code Execution Vulnerability Published on: August 31, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-50448 Windows NTFS Remote Code Execution Vulnerability Published on: August 31, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-50344 Windows OLE Elevation of Privilege Vulnerability Published on: August 31, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-50462 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Published on: August 31, 2026 Acknowledgement Updated Read Details
CVE-2026-26174 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability Published on: August 31, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-68821 Windows Package Manager Elevation of Privilege Vulnerability Published on: August 29, 2026 Changes made to the security updates links and information. This is an informational change only. Read Details
CVE-2026-70331 Microsoft Edge for iOS Spoofing Vulnerability Published on: August 28, 2026 <p>Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.</p> Read Details
CVE-2026-58616 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability Published on: August 28, 2026 <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-62904 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability Published on: August 28, 2026 <p>Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-66323 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Published on: August 28, 2026 <p>Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-66324 Microsoft Edge (Chromium-based) Spoofing Vulnerability Published on: August 28, 2026 <p>External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.</p> Read Details
CVE-2026-66798 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Published on: August 28, 2026 <p>Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-70341 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Published on: August 28, 2026 <p>Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-72984 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Published on: August 28, 2026 <p>Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.</p> Read Details
Chromium: CVE-2026-78891 Buffer overflow in WebRTC Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78892 Incorrect authorization in Chromoting Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78893 Information leak in QUIC Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78894 Race condition in Payments Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78895 Information leak in Paint Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78896 Information leak in StorageAccessAPI Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78897 Missing authorization in BrowserTag Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78898 Incorrect authorization in Downloads Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78899 Use after free in V8 Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78900 Improper input validation in Media Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78901 Race condition in V8 Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78903 Incomplete cleanup in SiteIsolation Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78904 Type confusion in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78905 Type confusion in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78906 Race condition in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78907 Incorrect authorization in WebProtect Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78908 Information leak in Canvas Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78909 Use after free in Views Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78910 Buffer overflow in V8 Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78911 Incorrect authorization in USB Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78912 UI misrepresentation in Browser Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78913 Use after free in Chromoting Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78914 Uninitialized resource in Skia Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78915 Race condition in Enterprise Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78934 Race condition in ReadAloud Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78938 Type confusion in V8 Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78939 Use after free in Chromecast Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78940 Improper initialization in Network Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78941 Information leak in Core Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78942 Incorrect reference resolution in Loader Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78943 Improper input validation in Editing Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78944 Use after free in DevTools Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78945 Use after free in Views Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78946 Incorrect authorization in Select Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78947 Incomplete cleanup in Chromium Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78948 Buffer overflow in WebGL Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78950 Integer overflow in WebRTC Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78951 Use after free in ServiceWorker Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78952 Out of bounds write in Crashpad Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78953 Missing authorization in SiteIsolation Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78954 Incorrect authorization in Extensions Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78955 Observable discrepancy in PerformanceAPIs Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78956 Type confusion in V8 Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78958 Uninitialized resource in Skia Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78959 Improper handling of case sensitivity in FileSystem Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78960 Information leak in Extensions Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78961 Incorrect authorization in Core Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78962 Uninitialized resource in WebXR Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78963 Improper input validation in Media Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78964 Use after free in Sync Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78965 Uninitialized resource in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78966 Externally controlled reference in QUIC Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78967 Missing authorization in BFCache Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78968 Missing authorization in Core Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78969 Uninitialized resource in Video Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78974 UI misrepresentation in Linux Toolkit Theming Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78975 Incorrect authorization in DOM Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78976 Improper input validation in StorageAccessAPI Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78977 Uninitialized resource in GPU Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78978 Out of bounds read in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78979 Race condition in Core Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78980 Improper input validation in ReaderMode Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78983 Use after free in Views Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78984 Uninitialized resource in GPU Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78985 Incorrect reference resolution in FileSystem Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78986 Uninitialized resource in GPU Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78987 Information leak in Canvas Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78989 Out of bounds read in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78990 Use after free in Compositing Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78991 Race condition in WebProtect Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-78999 Improper privilege management in Navigation Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79000 Improper input validation in DeviceBoundSessionCredentials Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79001 Information leak in Bluetooth Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79002 Incorrect authorization in SiteIsolation Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79003 Incorrect authorization in Device Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79004 Out of bounds read in Media Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79005 Incorrect authorization in StorageAccessAPI Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79006 Protection mechanism failure in HttpsUpgrades Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79007 Uninitialized resource in GPU Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79009 UI misrepresentation in UI Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79010 Operation on a resource after expiration or release in Network Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79011 UI misrepresentation in Browser Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79012 Use after free in Safebrowsing Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79013 Improper input validation in Sync Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79014 Race condition in Autofill Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79015 Improper input validation in ServiceWorker Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79016 Observable discrepancy in SVG Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79017 Race condition in Extensions Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79018 Information leak in FoldableAPIs Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79019 Out of bounds write in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79020 Out of bounds read in Skia Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79021 Missing authorization in InterestGroups Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79022 UI misrepresentation in Transactions Platform Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79023 Incorrect authorization in Editing Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79024 Information leak in ServiceWorker Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79025 Improper input validation in Workers Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79026 Use after free in Extensions Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79027 Use after free in WebRTC Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79028 Observable discrepancy in Network Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79030 Observable discrepancy in Autofill Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79031 Improper resource exposure in Preload Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79032 Improper input validation in Network Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79033 Insufficient control flow management in DevTools Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79034 Information leak in CORS Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79038 Incorrect authorization in WebProtect Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79040 Uninitialized resource in GPU Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79041 Missing authorization in Browser Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79042 Missing authorization in Payments Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79043 Out of bounds write in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79045 Type confusion in V8 Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79047 Use after free in Views Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79048 Out of bounds write in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79049 Incorrect reference resolution in Passwords Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79050 Incorrect authorization in Network Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79051 Incorrect authorization in Loader Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79052 Use after free in Aura Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79053 Missing authorization in Lighthouse Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79054 Use after free in Chromecast Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79055 Information leak in Sharing Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79056 Use after free in ServiceWorker Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79058 Missing authorization in Passwords Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79059 Information leak in BFCache Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79060 Incorrect authorization in StorageAccessAPI Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79064 Use after free in Network Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79065 Improper input validation in Network Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79066 Improper input validation in Navigation Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79067 Missing authorization in Network Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79068 Improper resource exposure in StreamsAPI Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79069 Memory corruption in Tint Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79070 Incorrect reference resolution in Cache Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79071 Race condition in GPU Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79072 Improper state validation in Performance Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79073 Improper state validation in Parser Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79074 Information leak in Network Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79075 Information leak in Geolocation Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79076 Improper input validation in Sync Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79077 Incorrect authorization in WebProtect Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79078 Use after free in FedCM Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79082 Incorrect authorization in Transactions Platform Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79083 Improper enforcement of behavioral workflow in Media Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79084 Inadequate encryption strength in Notifications Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79085 Missing authorization in Network Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79087 Injection in Chrome Tabs Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79088 Incorrect authorization in FileSystem Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79089 Race condition in Transactions Platform Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79090 Improper privilege management in Actor Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79091 Use after free in Bluetooth Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79093 Incorrect authorization in Paint Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79094 Race condition in Workers Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79095 Information leak in Payments Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79097 Use after free in V8 Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79098 UI misrepresentation in PermissionElement Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79099 Missing authorization in Network Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79103 Incorrect reference resolution in Speech Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79104 Missing authorization in Sensor Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79106 Improper input validation in Input Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79107 Incorrect authorization in TabGroups Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79108 UI misrepresentation in Web Authentication (Passkeys & Security Keys) Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79109 Improper input validation in Printing Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79110 Missing authorization in Preload Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79111 Improper input validation in Dawn Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79112 Out of bounds read in Skia Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79116 Missing authorization in Viz Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79118 Uninitialized resource in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79119 Use after free in PDF Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79120 Uninitialized resource in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79121 Improper input validation in Chromecast Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79122 Information leak in SignIn Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79123 Improper input validation in NTP Footer Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79124 Information leak in Intents Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79125 Information leak in XR Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79126 Incorrect provision of specified functionality in Proxy Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79127 Out of bounds write in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79128 Use after free in Views Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79130 Buffer overflow in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79131 Out of bounds write in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79133 Incorrect authorization in Forms Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79134 Incorrect authorization in GetUserMedia Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79136 Incorrect authorization in ServiceWorker Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79137 Incorrect authorization in Extensions Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79138 Out of bounds write in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79139 Improper input validation in Media Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79140 Use after free in Views Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79141 Incorrect authorization in Browser Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79142 Buffer overflow in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79143 Incorrect authorization in FileSystem Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79144 Information leak in Skia Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79147 Information leak in Skia Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79148 Off-by-one error in DevTools Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79149 Use after free in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79150 Use after free in Views Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79151 Improper input validation in Safebrowsing Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79154 Missing authorization in DevTools Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79155 Race condition in FileSystem Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79173 UI misrepresentation in WebAppInstalls Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79174 Incorrect authorization in Extensions Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79175 Type confusion in Accessibility Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79176 UI misrepresentation in Extensions Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79177 Incorrect authorization in Media Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79178 Incorrect authorization in Web Authentication (Passkeys & Security Keys) Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79179 Incorrect authorization in DOM Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79181 Observable discrepancy in Glic Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79182 Improper input validation in Media Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79183 Use after free in Accessibility Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79184 Missing authorization in Preload Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79185 Information leak in DOM Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79186 Incorrect authorization in Network Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79187 Use after free in WebRTC Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79188 Out of bounds write in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79189 Out of bounds write in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79190 Incorrect authorization in Extensions Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79191 Incorrect authorization in SiteIsolation Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79192 Improper input validation in Variations Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79193 Information leak in Canvas Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79194 Use after free in Chromoting Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79195 Use after free in Script Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79196 Race condition in Editing Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79197 Use after free in V8 Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79198 Use after free in Platform Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79199 Incorrect authorization in Network Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79200 Use after free in Aura Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79201 Improper access control in Workers Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79202 Use after free in Chromecast Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79203 Improper input validation in DevTools Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79204 UI misrepresentation in Input Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79205 Incorrect authorization in Network Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79206 Out of bounds read in FileSystem Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79208 Missing authorization in HTTP2 Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79209 Type confusion in Animation Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79211 Incorrect authorization in USB Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79212 Missing authorization in Passwords Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79214 Improper input validation in Preload Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79215 Integer overflow in WebGL Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79216 Buffer overflow in Blink Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79218 Incorrect authorization in Sandbox Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79219 Use after free in Bluetooth Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79220 Information leak in Network Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79221 Uninitialized resource in Dawn Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79223 Integer overflow in Chromium Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79224 Use after free in Chromecast Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79225 Incorrect authorization in Browser Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79226 Improper privilege management in Regional Capabilities Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79227 Type confusion in DevTools Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79228 Incorrect authorization in SiteIsolation Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79229 Uninitialized resource in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79230 Improper input validation in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79231 Buffer overflow in Media Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79232 Use after free in Aura Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79234 Injection in CSS Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79235 Use after free in WebGL Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79236 Type confusion in V8 Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79237 Incorrect authorization in Navigation Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79238 Incorrect authorization in ServiceWorker Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79239 Out of bounds read in Tint Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79240 Out of bounds write in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79242 Observable discrepancy in HTML Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79243 Improper input validation in ReadingList Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79244 Use after free in Animation Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79245 Use after free in UI Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79246 Information leak in DataTransfer Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79247 Use after free in Chromoting Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79248 Incorrect authorization in Input Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79249 Code injection in Bisection Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79250 UI misrepresentation in Navigation Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79251 Improper input validation in Network Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79252 Information leak in ServiceWorker Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79253 Improper input validation in Network Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79255 Improper input validation in WebRTC Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79257 Use after free in Views Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79258 Incorrect authorization in WebXR Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79259 Improper input validation in Safebrowsing Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79260 Improper input validation in Cookies Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79261 Incorrect authorization in Controls Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79262 Incorrect authorization in Network Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79263 Race condition in Extensions Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79264 Incorrect reference resolution in Preload Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79265 Incomplete cleanup in GetUserMedia Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79266 Use after free in DevTools Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79267 Race condition in Workers Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79269 Uninitialized resource in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79270 Uninitialized resource in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79271 Information leak in DOM Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79272 Improper input validation in FindInPage Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79274 Information leak in GPU Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79275 Use after free in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79276 Improper privilege management in FileSystem Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79283 UI misrepresentation in Geometry Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79284 UI misrepresentation in Core Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79285 Uninitialized resource in ANGLE Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79287 Observable discrepancy in Forms Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79289 Improper control of a resource through its lifetime in Workers Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79290 Use after free in Aura Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79291 Information leak in CSS Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79292 Integer overflow in Chromecast Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
Chromium: CVE-2026-79293 Information leak in Animation Published on: August 28, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Read Details
CVE-2026-70309 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability Published on: August 28, 2026 <p>Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.</p> Read Details
CVE-2026-65813 Microsoft Exchange Server Elevation of Privilege Vulnerability Published on: August 28, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability Published on: August 28, 2026 Acknowledgement Updated Read Details
CVE-2026-69550 Windows App for Mac Information Disclosure Vulnerability Published on: August 27, 2026 Updated CWE value. This is an informational change only. Read Details
CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability Published on: August 27, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-65779 Windows Autopilot Elevation of Privilege Vulnerability Published on: August 27, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-68817 Microsoft Excel Remote Code Execution Vulnerability Published on: August 27, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-65660 Microsoft SharePoint Server Remote Code Execution Vulnerability Published on: August 27, 2026 Updated Impact in the Security Updates table, CVE Title, and FAQs. This is an informational change only. Read Details
CVE-2026-70329 Microsoft Outlook Remote Code Execution Vulnerability Published on: August 27, 2026 Acknowledgement Updated Read Details
CVE-2026-50435 Windows Overlay Filter Elevation of Privilege Vulnerability Published on: August 27, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-50351 Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability Published on: August 27, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-42993 Remote Desktop Client Remote Code Execution Vulnerability Published on: August 27, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62890 Windows GDI+ Elevation of Privilege Vulnerability Published on: August 26, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-68819 Windows Network File System Denial of Service Vulnerability Published on: August 26, 2026 Acknowledgement Updated Read Details
CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability Published on: August 25, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-61939 Winlogon Elevation of Privilege Vulnerability Published on: August 25, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62728 Windows Common Log File System Driver Elevation of Privilege Vulnerability Published on: August 25, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability Published on: August 25, 2026 Acknowledgement Updated Read Details
CVE-2026-59127 Windows Installer Elevation of Privilege Vulnerability Published on: August 25, 2026 Acknowledgement Updated Read Details
CVE-2026-59130 AMD Zen Information Disclosure Vulnerability Published on: August 25, 2026 Updated CWE value. This is an informational change only. Read Details
CVE-2026-59131 AMD Zen Information Disclosure Vulnerability Published on: August 25, 2026 Updated CWE value. This is an informational change only. Read Details
CVE-2026-24301 Microsoft Copilot Information Disclosure Vulnerability Published on: August 25, 2026 Acknowledgement Updated Read Details
CVE-2026-45639 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability Published on: August 25, 2026 Acknowledgement Updated Read Details
CVE-2026-55137 Microsoft Excel Remote Code Execution Vulnerability Published on: August 25, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-50448 Windows NTFS Remote Code Execution Vulnerability Published on: August 25, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-49183 Windows Clipboard Server Elevation of Privilege Vulnerability Published on: August 25, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-50333 Windows Spaceport.sys Elevation of Privilege Vulnerability Published on: August 25, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-50661 Windows BitLocker Security Feature Bypass Vulnerability Published on: August 24, 2026 Acknowledgement Updated Read Details
CVE-2026-65787 Desktop Window Manager Elevation of Privilege Vulnerability Published on: August 24, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-47292 Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability Published on: August 24, 2026 Affected software updated with new package information. Read Details
CVE-2026-68801 Microsoft Excel Remote Code Execution Vulnerability Published on: August 21, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-64903 Microsoft Office Remote Code Execution Vulnerability Published on: August 21, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-64899 Microsoft Office Information Disclosure Vulnerability Published on: August 21, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability Published on: August 21, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability Published on: August 21, 2026 Corrected **Exploited** to **No**. This vulnerability was not exploited in the wild. This is an informational change only. Read Details
CVE-2026-54981 Visual Studio Code Python Extension Security Feature Bypass Vulnerability Published on: August 21, 2026 Affected software updated with new package information. Read Details
CVE-2026-58547 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability Published on: August 21, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-49183 Windows Clipboard Server Elevation of Privilege Vulnerability Published on: August 21, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-55134 Microsoft Word Remote Code Execution Vulnerability Published on: August 21, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-50466 Microsoft Brokering File System Elevation of Privilege Vulnerability Published on: August 21, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-32202 Windows Shell Spoofing Vulnerability Published on: August 21, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62834 Azure Data Factory Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-65801 Microsoft Exchange Online Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-68789 Azure SQL Database Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69519 Azure Stack HCI Information Disclosure Vulnerability Published on: August 20, 2026 <p>Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69851 Microsoft Entra ID Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability Published on: August 20, 2026 <p>Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-62703 Windows DWM Core Library Information Disclosure Vulnerability Published on: August 20, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability Published on: August 20, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62754 Windows Kerberos Elevation of Privilege Vulnerability Published on: August 20, 2026 Updated links to security updates. This is an informational change only. Read Details
CVE-2026-62755 Windows DHCP Client Elevation of Privilege Vulnerability Published on: August 20, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-65786 Desktop Window Manager Elevation of Privilege Vulnerability Published on: August 20, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-55015 Microsoft Remote Help Denial of Service Vulnerability Published on: August 20, 2026 <p>Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.</p> Read Details
CVE-2026-55013 Windows Remote Help Defense Spoofing Vulnerability Published on: August 20, 2026 <p>Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.</p> Read Details
CVE-2026-61363 Remote Desktop Client Remote Code Execution Vulnerability Published on: August 20, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62728 Windows Common Log File System Driver Elevation of Privilege Vulnerability Published on: August 20, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-66802 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability Published on: August 20, 2026 Corrected the Executive Summary to clarify that the vulnerability affects Windows Device Health Attestation (DHA), not Microsoft Azure Attestation. This is an informational change only. Read Details
CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability Published on: August 20, 2026 Updated links to security updates. This is an informational change only. Read Details
CVE-2026-70105 Microsoft Word Information Disclosure Vulnerability Published on: August 20, 2026 Information published. This CVE was addressed by updates that were released in August 2026, but the CVE was inadvertently omitted from the August 2026 Security Updates. This is an informational change only. Customers who have already installed the August 2026 updates do not need to take any further action. Read Details
CVE-2026-65770 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability Published on: August 20, 2026 <p>Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-63509 Microsoft Fabric Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-65816 Azure Arc Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-66309 Azure SQL Database Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-66800 Azure Data Factory Information Disclosure Vulnerability Published on: August 20, 2026 <p>Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-68782 Azure SQL Database Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69419 Azure Data Manager for Energy Remote Code Execution Vulnerability Published on: August 20, 2026 <p>Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.</p> Read Details
CVE-2026-69502 Azure SQL Database Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69400 Azure Logic Apps Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69555 Azure Arc Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69558 Microsoft Partner Center Information Disclosure Vulnerability Published on: August 20, 2026 <p>Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-69543 Azure Virtual Machines Elevation of Privilege Vulnerability Published on: August 20, 2026 <p>Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.</p> Read Details
CVE-2026-69855 Microsoft Copilot in Azure Information Disclosure Vulnerability Published on: August 20, 2026 <p>Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.</p> Read Details
CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability Published on: August 20, 2026 Added clarifying information to the mitigation. This is an informational change only. Read Details
CVE-2026-54118 Microsoft SQL Server Remote Code Execution Vulnerability Published on: August 20, 2026 The CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only. Read Details
CVE-2026-54117 Microsoft SQL Server Remote Code Execution Vulnerability Published on: August 20, 2026 The CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only. Read Details
CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability Published on: August 20, 2026 Updated links to security updates. This is an informational change only. Read Details
CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability Published on: August 20, 2026 Corrected the Executive Summary to clarify that the vulnerability affects Windows Device Health Attestation (DHA), not Microsoft Azure Attestation. This is an informational change only. Read Details
CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability Published on: August 19, 2026 Acknowledgement Updated Read Details
CVE-2026-62705 Microsoft Brokering File System Elevation of Privilege Vulnerability Published on: August 19, 2026 Corrected the CVE title from **Windows Bind Filter Driver Elevation of Privilege Vulnerability** to **Microsoft Brokering File System Elevation of Privilege Vulnerability** and updated the acknowledgement. These are informational changes only. Read Details
CVE-2026-69414 Microsoft Defender Elevation of Privilege Vulnerability Published on: August 19, 2026 CWE added. Informational change only. Read Details
CVE-2026-65811 Power BI Remote Code Execution Vulnerability Published on: August 19, 2026 Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. Read Details
CVE-2026-65675 CoPilot Chat Security Feature Bypass Vulnerability Published on: August 19, 2026 CWE added. Informational change only. Read Details
CVE-2020-1173 Microsoft Power BI Report Server Spoofing Vulnerability Published on: August 19, 2026 Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. Read Details
CVE-2021-26859 Microsoft Power BI Information Disclosure Vulnerability Published on: August 19, 2026 Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. Read Details
CVE-2021-41372 Power BI Report Server Spoofing Vulnerability Published on: August 19, 2026 Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. Read Details
CVE-2023-21806 Power BI Report Server Spoofing Vulnerability Published on: August 19, 2026 Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. Read Details
CVE-2024-43612 Power BI Report Server Spoofing Vulnerability Published on: August 19, 2026 Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. Read Details
CVE-2024-43481 Power BI Report Server Spoofing Vulnerability Published on: August 19, 2026 Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. Read Details
CVE-2026-50383 Windows Print Spooler Information Disclosure Vulnerability Published on: August 19, 2026 Acknowledgement Updated Read Details
CVE-2026-49798 Windows Kernel Elevation of Privilege Vulnerability Published on: August 19, 2026 Acknowledgement Updated Read Details
CVE-2026-58647 Microsoft PowerBI Report Server Spoofing Vulnerability Published on: August 19, 2026 Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. Read Details
CVE-2026-42912 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 19, 2026 Acknowledgement Updated Read Details
CVE-2026-24301 Microsoft Copilot Information Disclosure Vulnerability Published on: August 18, 2026 <p>Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.</p> Read Details
CVE-2026-65791 Windows iSCSI Target Service Remote Code Execution Vulnerability Published on: August 18, 2026 Acknowledgement Updated Read Details
CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability Published on: August 18, 2026 Acknowledgement Updated Read Details
CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability Published on: August 18, 2026 Acknowledgement Updated Read Details
CVE-2026-47632 Azure Connected Machine Agent Elevation of Privilege Vulnerability Published on: August 18, 2026 Corrected the affected product from **Azure Monitor Agent Metrics Extension** to **Azure Connected Machine Agent** and updated the Security Updates table. This is an informational change only. Read Details
CVE-2026-50419 Windows Kernel Information Disclosure Vulnerability Published on: August 18, 2026 Acknowledgement Updated Read Details
CVE-2026-56642 Microsoft Fabric Data Warehouse Remote Code Execution Vulnerability Published on: August 18, 2026 Updated the Security Updates table by removing an affected software entry. No user action is required. This is an informational change only. Read Details
CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability Published on: August 17, 2026 Acknowledgement Updated Read Details
CVE-2026-56188 Windows Server Network driver Remote Code Execution Vulnerability Published on: August 17, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62722 Microsoft Brokering File System Elevation of Privilege Vulnerability Published on: August 17, 2026 Corrected the CVE description and title. This is an informational change only. Read Details
CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability Published on: August 17, 2026 Acknowledgement Updated Read Details
CVE-2026-63519 Microsoft Office Graphics Component Remote Code Execution Vulnerability Published on: August 17, 2026 Acknowledgement Updated Read Details
CVE-2026-63513 Microsoft Office Graphics Component Remote Code Execution Vulnerability Published on: August 17, 2026 Acknowledgement Updated Read Details
CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability Published on: August 17, 2026 Acknowledgement Updated Read Details
CVE-2026-58612 PowerShell Information Disclosure Vulnerability Published on: August 17, 2026 Acknowledgement Updated Read Details
CVE-2026-62886 .NET Elevation of Privilege Vulnerability Published on: August 17, 2026 Acknowledgement Updated Read Details
CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability Published on: August 17, 2026 Acknowledgement Updated Read Details
CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability Published on: August 16, 2026 Corrected build number for the security update. This in an informational change only. Read Details
CVE-2026-65769 Microsoft Teams iOS Information Disclosure Vulnerability Published on: August 16, 2026 Corrected build number for the security update. This in an informational change only. Read Details
CVE-2026-57104 Azure Storage Explorer Elevation of Privilege Vulnerability Published on: August 16, 2026 Corrected build number for the security update. This in an informational change only. Read Details
CVE-2026-65767 Microsoft Teams for Android Spoofing Vulnerability Published on: August 16, 2026 Corrected build number for the security update. This in an informational change only. Read Details
CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability Published on: August 16, 2026 Corrected the listed software in the Security Updates table. Microsoft recommends installing the security update as soon as possible. Read Details
CVE-2026-72970 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Published on: August 14, 2026 <p>Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.</p> Read Details
CVE-2026-61347 Windows Event Logging Service Information Disclosure Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-62746 Win32k Information Disclosure Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-62755 Windows DHCP Client Elevation of Privilege Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-62777 Windows License Manager Elevation of Privilege Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-65671 Remote Access API Elevation of Privilege Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-68821 Windows Package Manager Elevation of Privilege Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
Chromium: CVE-2026-19560 Use after free in Blink Published on: August 14, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
Chromium: CVE-2026-19559 Use after free in HTML Published on: August 14, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
Chromium: CVE-2026-19558 Use after free in Extensions Published on: August 14, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
Chromium: CVE-2026-19557 Use after free in TabStrip Published on: August 14, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
Chromium: CVE-2026-19556 Use after free in V8 Published on: August 14, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-59126 Windows Event Logging Service Elevation of Privilege Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-58612 PowerShell Information Disclosure Vulnerability Published on: August 14, 2026 The security updates for Powershell have been updated. Read Details
CVE-2026-59119 PowerShell Elevation of Privilege Vulnerability Published on: August 14, 2026 The security updates for Powershell have been updated. Read Details
CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability Published on: August 14, 2026 The security updates for Powershell have been updated. Read Details
CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability Published on: August 14, 2026 The security updates for Powershell have been updated. Read Details
CVE-2026-50523 Microsoft PowerShell Remote Code Execution Vulnerability Published on: August 14, 2026 The security updates for Powershell have been updated. Read Details
CVE-2026-69414 Microsoft Defender Elevation of Privilege Vulnerability Published on: August 14, 2026 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available. Read Details
CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-49162 Microsoft Brokering File System Elevation of Privilege Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-50313 Windows NTFS Remote Code Execution Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-32153 Windows Speech Runtime Elevation of Privilege Vulnerability Published on: August 14, 2026 Acknowledgement Updated Read Details
CVE-2026-48566 Windows DWM Core Library Information Disclosure Vulnerability Published on: August 14, 2026 This CVE has been discovered to be an Elevation of Privilege and not an Information Disclosure. The CVE's Impact has been updated. Read Details
CVE-2026-49162 Microsoft Brokering File System Elevation of Privilege Vulnerability Published on: August 13, 2026 Added acknowledgements. This is an informational change only. Read Details
CVE-2026-49798 Windows Kernel Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-50342 Windows MIDI Service Module Elevation of Privileges Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-50298 Windows Spaceport.sys Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-50309 Windows NTFS Remote Code Execution Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-50387 Windows GDI Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-50383 Windows Print Spooler Information Disclosure Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-50461 Windows NTFS Remote Code Execution Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-45592 Windows Internet (wininet.dll) Elevation of Privilege Vulnerability Published on: August 13, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-45593 Windows SDK Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-45597 Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-45638 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-45637 Microsoft DWM Core Library Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-44814 Windows DWM Core Library Information Disclosure Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-61346 Windows Graphics Kernel Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-62695 Windows Storage Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-61359 Windows Storage Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability Published on: August 13, 2026 Added acknowledgements. This is an informational change only. Read Details
CVE-2026-62688 Windows MIDI Service Module Elevation of Privileges Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-62897 .NET Framework Remote Code Execution Vulnerability Published on: August 13, 2026 Removed Linux and macOS products from the Affected Software table. This is an informational change only. Read Details
CVE-2026-62902 .NET Information Disclosure Vulnerability Published on: August 13, 2026 Removed Linux and macOS products from the Affected Software table. This is an informational change only. Read Details
CVE-2026-70354 .NET Core Remote Code Execution Vulnerability Published on: August 13, 2026 Removed Linux and macOS products from the Affected Software table. This is an informational change only. Read Details
CVE-2026-62871 .NET Elevation of Privilege Vulnerability Published on: August 13, 2026 Removed Linux and macOS products from the Affected Software table. This is an informational change only. Read Details
CVE-2026-62886 .NET Elevation of Privilege Vulnerability Published on: August 13, 2026 Removed Linux and macOS products from the Affected Software table. This is an informational change only. Read Details
CVE-2026-62898 Microsoft QUIC Information Disclosure Vulnerability Published on: August 13, 2026 Removed Linux and macOS products from the Affected Software table. This is an informational change only. Read Details
CVE-2026-64906 Microsoft Access Remote Code Execution Vulnerability Published on: August 13, 2026 Acknowledgement Updated Read Details
CVE-2026-65796 Windows iSCSI Target Service Remote Code Execution Vulnerability Published on: August 13, 2026 Updated the CVE title, changed the security impact from Denial of Service to Remote Code Execution, changed the severity from Important to Critical, updated the CVSS score from 5.9 to 8.1, and corrected the severity and impact entries in the Security Updates table. These are informational changes only. Customers who have successfully installed the update do not need to take any further action. Read Details
CVE-2026-62696 Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability Published on: August 12, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability Published on: August 12, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability Published on: August 12, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-68815 Microsoft Excel Remote Code Execution Vulnerability Published on: August 12, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-70348 Windows Management Services Denial of Service Vulnerability Published on: August 12, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-42976 Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability Published on: August 12, 2026 Updated product information in the Software Update table. This is an informational change only. Read Details
CVE-2026-50687 Windows Win32k Elevation of Privilege Vulnerability Published on: August 12, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-58538 Windows Bluetooth Service Elevation of Privilege Vulnerability Published on: August 12, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-50655 Microsoft Windows Media Foundation Remote Code Execution Vulnerability Published on: August 12, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-58643 Windows Admin Center Spoofing Vulnerability Published on: August 12, 2026 Corrected Build Number in the Security Updates table. This is an informational change only. Read Details
CVE-2026-50476 Windows Network Connections Service Elevation of Privilege Vulnerability Published on: August 12, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2022-41127 Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability Published on: August 12, 2026 Updated the build numbers. This is an informational update only. Read Details
CVE-2026-45637 Microsoft DWM Core Library Elevation of Privilege Vulnerability Published on: August 12, 2026 Updated an acknowledgement. This is an informational change only. Read Details
CVE-2026-50472 Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-56174 Windows Narrator Braille Elevation of Privilege Vulnerability Published on: August 11, 2026 Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-58650 Visual Studio Code Security Feature Bypass Vulnerability Published on: August 11, 2026 Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. Read Details
CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability Published on: August 11, 2026 Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-57105 Microsoft Office SharePoint Spoofing Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-62829 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-62827 Microsoft SharePoint Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-62837 Microsoft SharePoint Server Information Disclosure Vulnerability Published on: August 11, 2026 Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. Read Details
CVE-2026-63514 Microsoft SharePoint Server Remote Code Execution Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Read Details
CVE-2026-63512 Microsoft SharePoint Server Tampering Vulnerability Published on: August 11, 2026 Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network. Read Details
CVE-2026-63516 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-63520 Microsoft SharePoint Server Remote Code Execution Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-40375 Microsoft Dynamics Business Central Information Disclosure Vulnerability Published on: August 11, 2026 Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network. Read Details
CVE-2026-54113 Remote Procedure Call Denial of Service Vulnerability Published on: August 11, 2026 Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network. Read Details
CVE-2026-54984 Windows Imaging Component Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-49179 Windows Active Directory Domain Services Remote Code Execution Vulnerability Published on: August 11, 2026 Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-58612 PowerShell Information Disclosure Vulnerability Published on: August 11, 2026 Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-59113 Visual Studio Code Remote Code Execution Vulnerability Published on: August 11, 2026 Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-47299 Azure Monitor Agent Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-47285 Visual Studio Code Information Disclosure Vulnerability Published on: August 11, 2026 Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-59127 Windows Installer Elevation of Privilege Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-59128 Windows Encrypting File System (EFS) Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. Read Details
CVE-2026-59133 Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability Published on: August 11, 2026 Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-59130 AMD Zen Information Disclosure Vulnerability Published on: August 11, 2026 No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. Read Details
CVE-2026-59132 Windows TCP/IP Denial of Service Vulnerability Published on: August 11, 2026 Information published. Read Details
CVE-2026-59135 Microsoft Windows Search Component Information Disclosure Vulnerability Published on: August 11, 2026 Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. Read Details
CVE-2026-59134 Remote Desktop Client Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-59136 Microsoft COM for Windows Information Disclosure Vulnerability Published on: August 11, 2026 Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally. Read Details
CVE-2026-59137 Windows Event Logging Service Information Disclosure Vulnerability Published on: August 11, 2026 Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally. Read Details
CVE-2026-59138 Microsoft Remote Registry Service Denial of Service Vulnerability Published on: August 11, 2026 Information published. Read Details
CVE-2026-61345 Microsoft Remote Registry Service Denial of Service Vulnerability Published on: August 11, 2026 Information published. Read Details
CVE-2026-61346 Windows Graphics Kernel Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61353 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61347 Windows Event Logging Service Information Disclosure Vulnerability Published on: August 11, 2026 Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally. Read Details
CVE-2026-61361 Windows DHCP Client Remote Code Execution Vulnerability Published on: August 11, 2026 Use after free in Windows DHCP Client allows an authorized attacker to execute code locally. Read Details
CVE-2026-61348 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61350 Windows NTFS Information Disclosure Vulnerability Published on: August 11, 2026 Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. Read Details
CVE-2026-61356 Windows Remote Desktop Services Elevation of Privilege Vulnerability Published on: August 11, 2026 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61367 Windows Remote Desktop Services Elevation of Privilege Vulnerability Published on: August 11, 2026 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61923 Windows Display Enhancement Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61366 Windows Network Connection Broker Elevation of Privilege Vulnerability Published on: August 11, 2026 Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61368 Windows Hyper-V Information Disclosure Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally. Read Details
CVE-2026-61924 Windows Remote Desktop Client Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-61925 Windows Installer Elevation of Privilege Vulnerability Published on: August 11, 2026 Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61927 Windows Bind Filter Driver Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61928 Windows Hello Tampering Vulnerability Published on: August 11, 2026 Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. Read Details
CVE-2026-61930 Windows Kernel Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61937 Windows HTTP.sys Elevation of Privilege Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62692 Windows Remote Desktop Services Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61932 Windows DWM Core Library Elevation of Privilege Vulnerability Published on: August 11, 2026 Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61933 Windows DWM Core Library Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. Read Details
CVE-2026-61934 Windows Bind Filter Driver Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61936 Windows Defender Firewall Service Security Feature Bypass Vulnerability Published on: August 11, 2026 Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally. Read Details
CVE-2026-61939 Winlogon Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Winlogon allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62695 Windows Storage Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62688 Windows MIDI Service Module Elevation of Privileges Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62690 Windows Push Notifications Elevation of Privilege Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62693 Windows MIDI Service Module Elevation of Privileges Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62696 Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62702 Windows Graphics Kernel Denial of Service Vulnerability Published on: August 11, 2026 Information published. Read Details
CVE-2026-62699 Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack. Read Details
CVE-2026-62703 Windows DWM Core Library Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62705 Windows Bind Filter Driver Elevation of Privilege Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62707 Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62713 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62712 Windows Win32k Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62718 Windows DHCP Server Information Disclosure Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. Read Details
CVE-2026-62715 Windows DHCP Server Information Disclosure Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. Read Details
CVE-2026-62716 Windows DHCP Server Information Disclosure Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. Read Details
CVE-2026-62719 Windows Message Queuing Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62722 Windows Bind Filter Driver Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62723 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62724 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62748 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62729 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62746 Win32k Information Disclosure Vulnerability Published on: August 11, 2026 Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62740 Windows Imaging Component Information Disclosure Vulnerability Published on: August 11, 2026 Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62753 Windows HTTP.sys Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62735 Windows HTTP.sys Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62737 Windows Kernel Elevation of Privilege Vulnerability Published on: August 11, 2026 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62739 Windows HTTP.sys Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62742 Windows DHCP Server Information Disclosure Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. Read Details
CVE-2026-62745 Windows DHCP Server Information Disclosure Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. Read Details
CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62750 Windows HTTP Protocol Stack Tampering Vulnerability Published on: August 11, 2026 Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network. Read Details
CVE-2026-62754 Windows Kerberos Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62783 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62755 Windows DHCP Client Elevation of Privilege Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62758 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62766 Windows Kerberos Elevation of Privilege Vulnerability Published on: August 11, 2026 Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62773 Windows Kerberos Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62772 Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62774 Windows Graphics Kernel Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62785 Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62777 Windows License Manager Elevation of Privilege Vulnerability Published on: August 11, 2026 Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62779 Windows Schannel Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62792 Windows TCP/IP Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62784 Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network. Read Details
CVE-2026-62787 Windows DNS Server Remote Code Execution Vulnerability Published on: August 11, 2026 Use after free in Windows DNS allows an authorized attacker to execute code over a network. Read Details
CVE-2026-62798 Win32k Information Disclosure Vulnerability Published on: August 11, 2026 Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62795 Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability Published on: August 11, 2026 Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62796 Windows NTFS Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62797 Windows NTFS Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62812 Windows DHCP Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62815 Microsoft QUIC Remote Code Execution Vulnerability Published on: August 11, 2026 Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62816 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. Read Details
CVE-2026-62817 Windows DNS Server Remote Code Execution Vulnerability Published on: August 11, 2026 Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network. Read Details
CVE-2026-62818 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability Published on: August 11, 2026 Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network. Read Details
CVE-2026-62819 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Published on: August 11, 2026 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine Read Details
CVE-2026-62820 Windows DNS Server Remote Code Execution Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62876 Windows Win32k Elevation of Privilege Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62877 Windows Win32k Elevation of Privilege Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62878 Windows DNS Server Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62889 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Published on: August 11, 2026 Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62890 Windows GDI+ Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally. Read Details
CVE-2026-62892 Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62893 Windows Deployment Services TFTP Server Remote Code Execution Vulnerability Published on: August 11, 2026 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62894 Windows DWM Core Library Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62897 .NET Framework Remote Code Execution Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-62899 .NET Security Feature Bypass Vulnerability Published on: August 11, 2026 Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. Read Details
CVE-2026-62900 .NET Information Disclosure Vulnerability Published on: August 11, 2026 Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-62901 .NET Denial of Service Vulnerability Published on: August 11, 2026 Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. Read Details
CVE-2026-62902 .NET Information Disclosure Vulnerability Published on: August 11, 2026 Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-62908 Windows Backup Engine Elevation of Privilege Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62909 .NET Elevation of Privilege Vulnerability Published on: August 11, 2026 Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62910 Microsoft Exchange Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-62912 Microsoft Exchange Server Denial of Service Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network. Read Details
CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. Read Details
CVE-2026-62914 Microsoft Exchange Server Spoofing Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-62915 Microsoft Exchange Server Security Feature Bypass Vulnerability Published on: August 11, 2026 Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. Read Details
CVE-2026-54123 Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability Published on: August 11, 2026 Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally. Read Details
CVE-2026-63513 Microsoft Office Graphics Component Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-63515 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-63517 Microsoft Office Graphics Component Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-63521 Microsoft Office Word Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-63519 Microsoft Office Graphics Component Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64922 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-65657 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-65656 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-65658 Microsoft SharePoint Server Remote Code Execution Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Read Details
CVE-2026-65661 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-65663 Microsoft SharePoint Server Remote Code Execution Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Read Details
CVE-2026-65660 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-65664 Microsoft Office Graphics Component Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-65665 Microsoft SharePoint Server Remote Code Execution Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Read Details
CVE-2026-65662 Windows GDI Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally. Read Details
CVE-2026-65671 Remote Access API Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65672 Remote Access API Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65675 CoPilot Chat Security Feature Bypass Vulnerability Published on: August 11, 2026 No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network. Read Details
CVE-2026-65678 Windows Win32k Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65785 Windows DHCP Client Denial of Service Vulnerability Published on: August 11, 2026 Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network. Read Details
CVE-2026-65784 Windows NTFS Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. Read Details
CVE-2026-65786 Desktop Window Manager Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65789 Windows DNS Server Remote Code Execution Vulnerability Published on: August 11, 2026 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-65787 Desktop Window Manager Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65788 Desktop Window Manager Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65807 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-65811 Power BI Remote Code Execution Vulnerability Published on: August 11, 2026 Improper input validation in Power BI allows an authorized attacker to execute code over a network. Read Details
CVE-2026-65813 Microsoft Exchange Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-65814 Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65815 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. Read Details
CVE-2026-66799 Windows Key Guard Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-68792 Microsoft Office Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-68793 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68794 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68795 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68796 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68800 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68802 Microsoft Excel Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-68807 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68806 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68808 Microsoft Excel Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-68809 Powerpoint Information Disclosure Vulnerability Published on: August 11, 2026 Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-68810 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68811 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68813 Microsoft Excel Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-68815 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68816 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68819 Windows Network File System Denial of Service Vulnerability Published on: August 11, 2026 Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network. Read Details
CVE-2026-68820 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-68821 Windows Package Manager Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-69320 Visual Studio Code Remote Code Execution Vulnerability Published on: August 11, 2026 Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-69278 Visual Studio Code Security Feature Bypass Vulnerability Published on: August 11, 2026 Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. Read Details
CVE-2026-69306 Visual Studio Code Security Feature Bypass Vulnerability Published on: August 11, 2026 Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. Read Details
CVE-2026-70307 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65769 Microsoft Teams iOS Information Disclosure Vulnerability Published on: August 11, 2026 Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-66301 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability Published on: August 11, 2026 Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network. Read Details
CVE-2026-70312 Powerpoint Information Disclosure Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70311 Microsoft Office Word Remote Code Execution Vulnerability Published on: August 11, 2026 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-70313 Microsoft PowerPoint Remote Code Execution Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70310 Microsoft Word Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70316 Powerpoint Information Disclosure Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70315 Microsoft Office Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70321 Microsoft SharePoint Remote Code Execution Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Read Details
CVE-2026-70318 Microsoft Excel Information Disclosure Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70314 Microsoft Office Information Disclosure Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70317 Microsoft Office Information Disclosure Vulnerability Published on: August 11, 2026 Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70325 Powerpoint Information Disclosure Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70319 Microsoft Office Word Information Disclosure Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70320 Powerpoint Information Disclosure Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70323 Microsoft Office Information Disclosure Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70322 Powerpoint Information Disclosure Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-70324 Microsoft SharePoint Elevation of Privilege Vulnerability Published on: August 11, 2026 Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-70327 Microsoft Excel Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-70328 Microsoft Excel Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-70329 Microsoft Outlook Remote Code Execution Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-70304 Windows DNS Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-70330 Windows DNS Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally. Read Details
CVE-2026-70336 Visual Studio Code Remote Code Execution Vulnerability Published on: August 11, 2026 Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-57104 Azure Storage Explorer Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network. Read Details
CVE-2026-70340 Azure CycleCloud Elevation of Privilege Vulnerability Published on: August 11, 2026 Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-65806 Azure CycleCloud Information Disclosure Vulnerability Published on: August 11, 2026 Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network. Read Details
CVE-2026-61352 Remote Desktop Client Remote Code Execution Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-65783 Windows Autopilot Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-70344 Windows Installer Elevation of Privilege Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-70345 Windows Installer Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-70346 Windows Installer Elevation of Privilege Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-70347 Windows Installer Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-70348 Windows Management Services Denial of Service Vulnerability Published on: August 11, 2026 Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally. Read Details
CVE-2026-70355 Microsoft SharePoint Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-72971 Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability Published on: August 11, 2026 Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally. Read Details
CVE-2026-19137 Use after free in WebGL Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-70339 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Published on: August 11, 2026 Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-19140 Use after free in GPU Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19138 Heap buffer overflow in CrashReporting Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19139 Race in CredentialProvider Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19145 Use after free in Translate Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19142 Use after free in Views Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19144 Use after free in HTML Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19146 Uninitialized Use in GPU Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19147 Use after free in Aura Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19149 Use after free in Aura Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19148 Out of bounds write in GPU Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19151 Use after free in V8 Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19153 Insufficient validation of untrusted input in Workers Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19152 Inappropriate implementation in Navigation Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19155 Use after free in Payments Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19158 Use after free in Views Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19157 Out of bounds write in ANGLE Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19156 Heap buffer overflow in Base Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19150 Inappropriate implementation in V8 Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19161 Uninitialized Use in Skia Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19162 Out of bounds write in V8 Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19160 Uninitialized Use in Skia Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19163 Use after free in Media Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19159 Use after free in Views Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19164 Insufficient validation of untrusted input in Codecs Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19165 Use after free in Extensions Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19167 Integer overflow in GPU Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19166 Use after free in Web Authentication Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19170 Use after free in WebGL Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19169 Insufficient validation of untrusted input in Contextual Tasks Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19173 Out of bounds write in Skia Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19172 Use after free in Views Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19168 Inappropriate implementation in V8 Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19174 Integer overflow in V8 Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19176 Use after free in Skia Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19171 Use after free in Media Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19175 Use after free in Payments Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-19177 Insufficient validation of untrusted input in UI Published on: August 11, 2026 This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Read Details
CVE-2026-42976 Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability Published on: August 11, 2026 Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-54981 Visual Studio Code Python Extension Security Feature Bypass Vulnerability Published on: August 11, 2026 Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally. Read Details
CVE-2026-58641 .NET Elevation of Privilege Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. Read Details
CVE-2026-58651 Microsoft Word Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-59119 PowerShell Elevation of Privilege Vulnerability Published on: August 11, 2026 Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-59122 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-59125 Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability Published on: August 11, 2026 Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-59126 Windows Event Logging Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-59131 AMD Zen Information Disclosure Vulnerability Published on: August 11, 2026 No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. Read Details
CVE-2026-61349 Windows Work Folder Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61363 Remote Desktop Client Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-61359 Windows Storage Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61355 Windows Sensor Data Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61364 Windows Remote Desktop Services Elevation of Privilege Vulnerability Published on: August 11, 2026 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61365 Windows Remote Desktop Services Elevation of Privilege Vulnerability Published on: August 11, 2026 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61357 Application Information Services Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Application Information Services allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61358 Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61360 Windows GDI Information Disclosure Vulnerability Published on: August 11, 2026 Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. Read Details
CVE-2026-61920 Windows DNS Server Remote Code Execution Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network. Read Details
CVE-2026-61926 Windows USB Driver Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61918 Windows Remote Desktop Client Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-61921 Windows Remote Desktop Client Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-61929 Windows Kernel Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-61938 Windows Installer Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62698 Microsoft Digest Authentication Elevation of Privilege Vulnerability Published on: August 11, 2026 Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62700 Windows NTFS Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62701 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62708 Windows Kernel Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. Read Details
CVE-2026-62709 Windows GDI+ Information Disclosure Vulnerability Published on: August 11, 2026 Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62710 Windows Device Association Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62711 Windows Win32k Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62720 Windows DHCP Server Information Disclosure Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. Read Details
CVE-2026-62714 Windows DHCP Server Information Disclosure Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. Read Details
CVE-2026-62717 Windows Message Queuing Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62721 Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability Published on: August 11, 2026 Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62725 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62726 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62728 Windows Common Log File System Driver Elevation of Privilege Vulnerability Published on: August 11, 2026 Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62733 Windows Win32k Elevation of Privilege Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62743 Win32k Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62730 Windows Wired AutoConfig Service Information Disclosure Vulnerability Published on: August 11, 2026 Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62732 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62734 Windows Telephony Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62736 Windows DHCP Client Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62757 Windows Schannel Security Feature Bypass Vulnerability Published on: August 11, 2026 Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network. Read Details
CVE-2026-62741 Windows HTTP.sys Elevation of Privilege Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62749 Windows Kernel Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62751 Windows Projected File System Elevation of Privilege Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62752 Windows Kerberos Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62769 Windows DNS Elevation of Privilege Vulnerability Published on: August 11, 2026 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62771 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62761 Windows DHCP Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62768 Windows Installer Elevation of Privilege Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62770 Windows Shell Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62775 Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability Published on: August 11, 2026 Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62799 Windows SMB Client Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62776 Windows DHCP Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62778 Windows DNS Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network. Read Details
CVE-2026-62780 Windows Kernel Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62782 Windows SMB Client Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-62781 RPC Runtime Library Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62800 Windows SMBv3 Server Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. Read Details
CVE-2026-62786 Win32k Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62788 Windows Kernel Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62790 Windows SMBv3 Server Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. Read Details
CVE-2026-62793 Windows NTFS Information Disclosure Vulnerability Published on: August 11, 2026 Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62803 Windows DHCP Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62807 Windows DHCP Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62811 Windows HTTP.sys Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62814 Windows DHCP Server Information Disclosure Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. Read Details
CVE-2026-62823 Windows DHCP Server Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. Read Details
CVE-2026-62824 Remote Desktop Client Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62822 Windows GDI+ Remote Code Execution Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62832 Windows User Profile Service Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62871 .NET Elevation of Privilege Vulnerability Published on: August 11, 2026 Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-62872 .NET Framework Elevation of Privilege Vulnerability Published on: August 11, 2026 Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-62880 Windows NTFS Elevation of Privilege Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62881 Windows DNS Elevation of Privilege Vulnerability Published on: August 11, 2026 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62883 Windows DNS Elevation of Privilege Vulnerability Published on: August 11, 2026 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62885 Windows Win32k Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62886 .NET Elevation of Privilege Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. Read Details
CVE-2026-62887 Windows NTFS Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62888 Windows DWM Core Library Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-62911 Microsoft Exchange Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-62842 Microsoft Office Graphics Component Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-63524 Microsoft Office Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-63525 Microsoft Office Word Remote Code Execution Vulnerability Published on: August 11, 2026 Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-63526 Microsoft Office Graphics Component Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-63528 Microsoft Office Word Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-63527 Microsoft Office Word Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-63529 Microsoft Office Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-63530 Microsoft Office Word Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-63531 Microsoft Office Word Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-63532 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-63533 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64897 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-64898 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64900 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-64902 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-64899 Microsoft Office Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-64903 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64901 Microsoft SharePoint Server Remote Code Execution Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Read Details
CVE-2026-64904 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64905 Microsoft Office Word Remote Code Execution Vulnerability Published on: August 11, 2026 Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64907 Microsoft Office Word Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64906 Microsoft Access Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64909 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64910 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64912 Microsoft Access Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64911 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64908 Microsoft Access Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64914 Microsoft Access Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64915 Microsoft Office Word Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64916 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-64920 Microsoft Access Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64917 Microsoft Office Word Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-64919 Microsoft Access Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-64921 Microsoft SharePoint Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-62882 Microsoft Outlook Spoofing Vulnerability Published on: August 11, 2026 Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. Read Details
CVE-2026-65673 Microsoft Entra Connect Elevation of Privilege Vulnerability Published on: August 11, 2026 CVET-EOP Read Details
CVE-2026-65681 Windows iSCSI Target Service Denial of Service Vulnerability Published on: August 11, 2026 Information published. Read Details
CVE-2026-65680 Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65679 Windows iSCSI Target Service Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-65773 Windows Kernel Elevation of Privilege Vulnerability Published on: August 11, 2026 Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65774 Windows Installer Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65775 Windows Win32k Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65776 Windows Win32k Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65777 Active Directory Security Feature Bypass Vulnerability Published on: August 11, 2026 Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network. Read Details
CVE-2026-65779 Windows Autopilot Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65780 Windows Autopilot Elevation of Privilege Vulnerability Published on: August 11, 2026 Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65778 Windows Autopilot Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65782 Windows Autopilot Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65781 Windows Autopilot Elevation of Privilege Vulnerability Published on: August 11, 2026 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65790 Windows Message Queuing Elevation of Privilege Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65791 Windows iSCSI Target Service Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-65795 Windows DNS Elevation of Privilege Vulnerability Published on: August 11, 2026 No cwe for this issue in Windows DNS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65794 Windows SMB Client Information Disclosure Vulnerability Published on: August 11, 2026 Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-65797 Windows DNS Elevation of Privilege Vulnerability Published on: August 11, 2026 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65799 Windows DNS Elevation of Privilege Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65798 Windows DNS Elevation of Privilege Vulnerability Published on: August 11, 2026 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. Read Details
CVE-2026-65796 Windows iSCSI Target Service Denial of Service Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network. Read Details
CVE-2026-65810 .NET Framework Elevation of Privilege Vulnerability Published on: August 11, 2026 Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. Read Details
CVE-2026-66802 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability Published on: August 11, 2026 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-66805 Microsoft SharePoint Server Remote Code Execution Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Read Details
CVE-2026-66806 Microsoft Office Word Information Disclosure Vulnerability Published on: August 11, 2026 Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-66808 Microsoft SharePoint Server Remote Code Execution Vulnerability Published on: August 11, 2026 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Read Details
CVE-2026-66810 Microsoft Office Word Information Disclosure Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-66809 Microsoft Office Graphics Component Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-68797 Microsoft Excel Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-68798 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68799 Microsoft Excel Information Disclosure Vulnerability Published on: August 11, 2026 Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. Read Details
CVE-2026-68801 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68803 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68804 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68805 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68812 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68814 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-68817 Microsoft Excel Remote Code Execution Vulnerability Published on: August 11, 2026 Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-56179 Windows Network Address Translation (NAT) Spoofing Vulnerability Published on: August 11, 2026 Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. Read Details
CVE-2026-70130 Microsoft Office Remote Code Execution Vulnerability Published on: August 11, 2026 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-70306 Microsoft Office SharePoint Spoofing Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Read Details
CVE-2026-70326 Microsoft SharePoint Server Elevation of Privilege Vulnerability Published on: August 11, 2026 Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Read Details
CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability Published on: August 11, 2026 Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally. Read Details
CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability Published on: August 11, 2026 Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-70354 .NET Core Remote Code Execution Vulnerability Published on: August 11, 2026 Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. Read Details
CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability Published on: August 11, 2026 Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network. Read Details
CVE-2026-62738 Windows Management Instrumentation Information Disclosure Vulnerability Published on: August 11, 2026 Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally. Read Details
CVE-2026-62898 Microsoft QUIC Information Disclosure Vulnerability Published on: August 11, 2026 Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. Read Details
CVE-2026-65767 Microsoft Teams for Android and iOS Spoofing Vulnerability Published on: August 11, 2026 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-58639 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-62839 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-62917 Microsoft SharePoint Server Spoofing Vulnerability Published on: August 11, 2026 Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Read Details
CVE-2026-59118 Copilot Cowork Elevation of Privilege Vulnerability Published on: August 11, 2026 Corrected CVE title. This is an informational change only. Read Details
CVE-2026-6727 MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability Published on: August 11, 2026 [CVE-2026-6727](https://www.cve.org/CVERecord?id=CVE-2026-6727) is an Information Disclosure vulnerability in the TPM 2.0 reference implementation involving an RSA OAEP timing side channel. MITRE assigned this CVE on behalf of the Trusted Computing Group. This document incorporates updates to Microsoft Windows that address this vulnerability. Please see [CVE-2026-6727](https://www.cve.org/CVERecord?id=CVE-2026-6727) for more information. Read Details
CVE-2026-6726 MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot Reuse Published on: August 11, 2026 [CVE-2026-6726](https://www.cve.org/CVERecord?id=CVE-2026-6726) is a Spoofing vulnerability in the TPM 2.0 reference implementation involving improper object-slot reuse. MITRE assigned this CVE on behalf of the Trusted Computing Group. This document incorporates updates to Microsoft Windows that address this vulnerability. Please see [CVE-2026-6726](https://www.cve.org/CVERecord?id=CVE-2026-6726) for more information. Read Details