CVE-2026-72973
Last Modified: 9 Sept 2026Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-72938
Last Modified: 9 Sept 2026Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
CVE-2026-72972
Last Modified: 9 Sept 2026Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-72956
Last Modified: 10 Sept 2026Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
CVE-2026-70570
Last Modified: 10 Sept 2026Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
CVE-2026-70296
Last Modified: 10 Sept 2026Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
CVE-2026-70203
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.
CVE-2026-69906
Last Modified: 9 Sept 2026Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVE-2026-69904
Last Modified: 8 Sept 2026Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
CVE-2026-69441
Last Modified: 10 Sept 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-69805
Last Modified: 9 Sept 2026External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69439
Last Modified: 10 Sept 2026Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69632
Last Modified: 9 Sept 2026Use after free in Microsoft Office allows an unauthorized attacker to execute code over a network.
CVE-2026-69626
Last Modified: 9 Sept 2026Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
CVE-2026-69477
Last Modified: 10 Sept 2026Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally.
CVE-2026-69629
Last Modified: 9 Sept 2026Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2026-69636
Last Modified: 8 Sept 2026Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
CVE-2026-69614
Last Modified: 10 Sept 2026Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
CVE-2026-69464
Last Modified: 10 Sept 2026Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2026-69615
Last Modified: 11 Sept 2026Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-69442
Last Modified: 9 Sept 2026Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
CVE-2026-69601
Last Modified: 10 Sept 2026Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
CVE-2026-69590
Last Modified: 10 Sept 2026Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
CVE-2026-69607
Last Modified: 10 Sept 2026Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
CVE-2026-69575
Last Modified: 10 Sept 2026Use after free in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
CVE-2026-69568
Last Modified: 10 Sept 2026Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to disclose information locally.
CVE-2026-69593
Last Modified: 11 Sept 2026Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69564
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Online Certificate Status Protocol (OCSP) allows an authorized attacker to elevate privileges locally.
CVE-2026-69560
Last Modified: 10 Sept 2026Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69559
Last Modified: 8 Sept 2026Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
CVE-2026-69510
Last Modified: 10 Sept 2026Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-69499
Last Modified: 10 Sept 2026Integer overflow or wraparound in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
CVE-2026-69490
Last Modified: 11 Sept 2026Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-69489
Last Modified: 11 Sept 2026Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69426
Last Modified: 11 Sept 2026Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to execute code locally.
CVE-2026-69417
Last Modified: 9 Sept 2026Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-69409
Last Modified: 8 Sept 2026Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
CVE-2026-69402
Last Modified: 10 Sept 2026Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-69397
Last Modified: 10 Sept 2026Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network.
CVE-2026-69395
Last Modified: 10 Sept 2026Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network.
CVE-2026-69392
Last Modified: 10 Sept 2026Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
CVE-2026-69910
Last Modified: 9 Sept 2026Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.
CVE-2026-69352
Last Modified: 11 Sept 2026Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69311
Last Modified: 10 Sept 2026Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69298
Last Modified: 10 Sept 2026Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69323
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69334
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.
CVE-2026-69291
Last Modified: 11 Sept 2026Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.
CVE-2026-69290
Last Modified: 10 Sept 2026Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
CVE-2026-69309
Last Modified: 10 Sept 2026Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
