CVE-2026-66816
Last Modified: 8 Sept 2026Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.
CVE-2026-66814
Last Modified: 9 Sept 2026Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-56172
Last Modified: 8 Sept 2026Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.
CVE-2026-62697
Last Modified: 8 Sept 2026Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CVE-2026-62813
Last Modified: 9 Sept 2026Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.
CVE-2026-62762
Last Modified: 8 Sept 2026Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
CVE-2026-62759
Last Modified: 9 Sept 2026Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.
CVE-2026-62810
Last Modified: 9 Sept 2026Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.
CVE-2026-58611
Last Modified: 9 Sept 2026Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.
CVE-2026-56198
Last Modified: 9 Sept 2026Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.
CVE-2026-56177
Last Modified: 9 Sept 2026Use after free in Windows Server allows an authorized attacker to elevate privileges locally.
CVE-2026-85880
Last Modified: 8 Sept 2026Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-85877
Last Modified: 9 Sept 2026Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.
CVE-2026-84001
Last Modified: 10 Sept 2026Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network.
CVE-2026-83999
Last Modified: 11 Sept 2026Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83998
Last Modified: 9 Sept 2026Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-83996
Last Modified: 9 Sept 2026Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
CVE-2026-83991
Last Modified: 9 Sept 2026Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.
CVE-2026-70290
Last Modified: 10 Sept 2026Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.
CVE-2026-83976
Last Modified: 11 Sept 2026Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83975
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83974
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83979
Last Modified: 10 Sept 2026Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83988
Last Modified: 11 Sept 2026Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83969
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83986
Last Modified: 9 Sept 2026Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83955
Last Modified: 11 Sept 2026Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69492
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-72937
Last Modified: 10 Sept 2026Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.
CVE-2026-69573
Last Modified: 11 Sept 2026Use after free in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.
CVE-2026-72940
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Schannel allows an unauthorized attacker to execute code over a network.
CVE-2026-70019
Last Modified: 10 Sept 2026Windows hard link in Windows Compressed Folder allows an unauthorized attacker to disclose information over a network.
CVE-2026-72949
Last Modified: 10 Sept 2026Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network.
CVE-2026-72947
Last Modified: 10 Sept 2026Integer underflow (wrap or wraparound) in Windows File History Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69827
Last Modified: 11 Sept 2026Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.
CVE-2026-69989
Last Modified: 10 Sept 2026Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
CVE-2026-83952
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
CVE-2026-83942
Last Modified: 10 Sept 2026Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-70065
Last Modified: 10 Sept 2026Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2026-81381
Last Modified: 8 Sept 2026Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
CVE-2026-81380
Last Modified: 8 Sept 2026Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
CVE-2026-81379
Last Modified: 11 Sept 2026Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-81378
Last Modified: 11 Sept 2026Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-81377
Last Modified: 11 Sept 2026Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
CVE-2026-81376
Last Modified: 11 Sept 2026Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-81357
Last Modified: 11 Sept 2026Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-81356
Last Modified: 11 Sept 2026Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-81355
Last Modified: 10 Sept 2026Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to execute code locally.
CVE-2026-81349
Last Modified: 9 Sept 2026Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.
CVE-2026-80097
Last Modified: 10 Sept 2026Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally.
