CVE-2026-69649
Last Modified: 9 Sept 2026Heap-based buffer overflow in Windows Raw Image Extension allows an unauthorized attacker to execute code over a network.
CVE-2026-69641
Last Modified: 9 Sept 2026Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-69603
Last Modified: 9 Sept 2026Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
CVE-2026-69604
Last Modified: 9 Sept 2026Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69576
Last Modified: 9 Sept 2026Use after free in Graphic Fonts allows an authorized attacker to elevate privileges locally.
CVE-2026-69580
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69589
Last Modified: 11 Sept 2026Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69583
Last Modified: 11 Sept 2026Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69556
Last Modified: 9 Sept 2026Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-69548
Last Modified: 8 Sept 2026Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-69544
Last Modified: 9 Sept 2026Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.
CVE-2026-69518
Last Modified: 9 Sept 2026Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
CVE-2026-69501
Last Modified: 8 Sept 2026Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVE-2026-69469
Last Modified: 9 Sept 2026Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-69443
Last Modified: 8 Sept 2026Out-of-bounds read in Windows Device Health Attestation (DHA) allows an unauthorized attacker to disclose information over a network.
CVE-2026-69394
Last Modified: 9 Sept 2026Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69383
Last Modified: 9 Sept 2026External control of file name or path in Windows Shell allows an authorized attacker to elevate privileges locally.
CVE-2026-69382
Last Modified: 8 Sept 2026Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
CVE-2026-69380
Last Modified: 9 Sept 2026Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-69378
Last Modified: 8 Sept 2026Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.
CVE-2026-69375
Last Modified: 11 Sept 2026Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
CVE-2026-69361
Last Modified: 9 Sept 2026Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
CVE-2026-69356
Last Modified: 10 Sept 2026Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-69355
Last Modified: 9 Sept 2026External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-69293
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-68887
Last Modified: 10 Sept 2026Out-of-bounds read in Windows Message Queuing Queue Manager allows an unauthorized attacker to deny service over a network.
CVE-2026-68877
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
CVE-2026-68844
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
CVE-2026-68837
Last Modified: 10 Sept 2026Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.
CVE-2026-68825
Last Modified: 10 Sept 2026Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-72963
Last Modified: 10 Sept 2026Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally.
CVE-2026-72962
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-72958
Last Modified: 10 Sept 2026Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.
CVE-2026-72948
Last Modified: 10 Sept 2026Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-72945
Last Modified: 10 Sept 2026Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally.
CVE-2026-72943
Last Modified: 10 Sept 2026Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.
CVE-2026-72946
Last Modified: 11 Sept 2026Heap-based buffer overflow in Storage Port Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-72944
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.
CVE-2026-72939
Last Modified: 10 Sept 2026Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network.
CVE-2026-72935
Last Modified: 10 Sept 2026Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-72930
Last Modified: 10 Sept 2026Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally.
CVE-2026-71351
Last Modified: 10 Sept 2026Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
CVE-2026-72929
Last Modified: 10 Sept 2026Improper validation of integrity check value in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-71345
Last Modified: 11 Sept 2026Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally.
CVE-2026-71353
Last Modified: 10 Sept 2026Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
CVE-2026-71341
Last Modified: 10 Sept 2026Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally.
CVE-2026-71343
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to execute code locally.
CVE-2026-72926
Last Modified: 10 Sept 2026Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally.
CVE-2026-71348
Last Modified: 11 Sept 2026Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.
CVE-2026-71350
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.
