CVE-2026-69687
Last Modified: 10 Sept 2026Integer underflow (wrap or wraparound) in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
CVE-2026-69643
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.
CVE-2026-69803
Last Modified: 10 Sept 2026Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.
CVE-2026-69685
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.
CVE-2026-69682
Last Modified: 9 Sept 2026Use after free in Windows Host Guardian Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69637
Last Modified: 10 Sept 2026Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.
CVE-2026-69715
Last Modified: 10 Sept 2026Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network.
CVE-2026-69821
Last Modified: 10 Sept 2026Improper encoding or escaping of output in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.
CVE-2026-69720
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-69620
Last Modified: 11 Sept 2026Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-69619
Last Modified: 10 Sept 2026Out-of-bounds read in Windows exFAT File System allows an authorized attacker to elevate privileges over a network.
CVE-2026-69817
Last Modified: 10 Sept 2026Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-69680
Last Modified: 10 Sept 2026Origin validation error in Windows DNS allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-69881
Last Modified: 10 Sept 2026Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.
CVE-2026-69669
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to execute code over a network.
CVE-2026-54611
Last Modified: 9 Sept 2026InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component installer. It is possible to upload a malicious component into the server, however, it won't be installed, but upload files will be executed. Normally all php files in upload folder are not executed, however, by uploading custom .htaccess it becomes possible. Version 2.18.2 contains a fix.
CVE-2026-69613
Last Modified: 9 Sept 2026Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.
CVE-2026-69610
Last Modified: 10 Sept 2026Buffer over-read in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-69630
Last Modified: 9 Sept 2026Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-69616
Last Modified: 10 Sept 2026Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to disclose information locally.
CVE-2026-69617
Last Modified: 10 Sept 2026Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
CVE-2026-69611
Last Modified: 10 Sept 2026Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-69602
Last Modified: 10 Sept 2026Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges over a network.
CVE-2026-69597
Last Modified: 10 Sept 2026Use after free in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
CVE-2026-69624
Last Modified: 10 Sept 2026Incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) allows an authorized attacker to perform tampering over a network.
CVE-2026-69618
Last Modified: 10 Sept 2026Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally.
CVE-2026-69625
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges over a network.
CVE-2026-69606
Last Modified: 10 Sept 2026Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
CVE-2026-69600
Last Modified: 11 Sept 2026Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
CVE-2026-69584
Last Modified: 11 Sept 2026Integer overflow or wraparound in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-69592
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.
CVE-2026-69567
Last Modified: 10 Sept 2026Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-69566
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
CVE-2026-69612
Last Modified: 10 Sept 2026Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
CVE-2026-69586
Last Modified: 10 Sept 2026Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.
CVE-2026-69581
Last Modified: 10 Sept 2026Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69569
Last Modified: 10 Sept 2026Untrusted pointer dereference in Windows Print Spooler Components allows an authorized attacker to deny service over a network.
CVE-2026-69591
Last Modified: 10 Sept 2026Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information over a network.
CVE-2026-69542
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Camera Frame Server Monitor allows an authorized attacker to elevate privileges locally.
CVE-2026-69538
Last Modified: 9 Sept 2026Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally.
CVE-2026-69535
Last Modified: 10 Sept 2026Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
CVE-2026-69571
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
CVE-2026-69546
Last Modified: 10 Sept 2026Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
CVE-2026-69536
Last Modified: 10 Sept 2026Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
CVE-2026-69547
Last Modified: 11 Sept 2026Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
CVE-2026-69599
Last Modified: 10 Sept 2026Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
CVE-2026-69509
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69508
Last Modified: 10 Sept 2026Stack-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-69503
Last Modified: 10 Sept 2026Stack-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges over a network.
CVE-2026-69498
Last Modified: 10 Sept 2026Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
