CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2026-71339

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7
    High

    CVE-2026-71340

    Last Modified: 10 Sept 2026

    Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    6.4
    Medium

    CVE-2026-71338

    Last Modified: 10 Sept 2026

    Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-71334

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows NFS Portmapper allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7
    High

    CVE-2026-71332

    Last Modified: 10 Sept 2026

    Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-71337

    Last Modified: 10 Sept 2026

    Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7
    High

    CVE-2026-71333

    Last Modified: 10 Sept 2026

    Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-71330

    Last Modified: 8 Sept 2026

    Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-71336

    Last Modified: 10 Sept 2026

    Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network.

    Published: 8 Sept 2026
    6.8
    Medium

    CVE-2026-71329

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-70587

    Last Modified: 10 Sept 2026

    Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-70586

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network.

    Published: 8 Sept 2026
    7
    High

    CVE-2026-70585

    Last Modified: 9 Sept 2026

    Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-70584

    Last Modified: 10 Sept 2026

    Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    6.4
    Medium

    CVE-2026-70582

    Last Modified: 10 Sept 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-70564

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    8.1
    High

    CVE-2026-70563

    Last Modified: 10 Sept 2026

    Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-72923

    Last Modified: 8 Sept 2026

    In Microsoft.OpenApi.YamlReader from 2.0.0-preview.11 until 2.12.0 and from 3.0.0 until 3.10.0, and in Microsoft.OpenApi.Readers prior to 1.6.30, a small YAML OpenAPI document containing nested anchors and aliases can cause uncontrolled resource consumption when parsed through the public YAML reader APIs. YAML is parsed through SharpYaml, which represents aliases as shared nodes in a directed acyclic graph, so the parsed YAML graph stays small, but converting that graph to System.Text.Json.Nodes.JsonNode requires every alias to be materialized as an independent node because a JsonNode cannot be attached to multiple parents. Without a bound on that conversion work, a document with N nested anchors each referenced k times can require k^N materialized JSON nodes, leading to excessive memory allocation and process termination through out-of-memory conditions, a billion laughs style denial of service. The patched versions bound the YAML-to-JSON conversion by node count and nesting depth and report an OpenApiDiagnostic error instead of expanding without limit. This vulnerability is fixed in Microsoft.OpenApi.YamlReader 2.12.0 and 3.10.0, and Microsoft.OpenApi.Readers 1.6.30.

    Published: 8 Sept 2026
    7
    High

    CVE-2026-70562

    Last Modified: 10 Sept 2026

    Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-70351

    Last Modified: 9 Sept 2026

    Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-58600

    Last Modified: 9 Sept 2026

    Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    8.1
    High

    CVE-2026-70342

    Last Modified: 10 Sept 2026

    Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-70289

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-70334

    Last Modified: 11 Sept 2026

    Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-69890

    Last Modified: 10 Sept 2026

    Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-69740

    Last Modified: 10 Sept 2026

    Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-69676

    Last Modified: 10 Sept 2026

    Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute code over a network.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-69712

    Last Modified: 9 Sept 2026

    Use after free in Windows Key Distribution Center allows an authorized attacker to execute code over a network.

    Published: 8 Sept 2026
    9.8
    Critical

    CVE-2026-69730

    Last Modified: 10 Sept 2026

    Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-69860

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

    Published: 8 Sept 2026
    5.5
    Medium

    CVE-2026-69770

    Last Modified: 10 Sept 2026

    Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally.

    Published: 8 Sept 2026
    8.1
    High

    CVE-2026-69732

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an unauthorized attacker to execute code over a network.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-69822

    Last Modified: 10 Sept 2026

    Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    4.7
    Medium

    CVE-2026-69771

    Last Modified: 10 Sept 2026

    Improper link resolution before file access ('link following') in Windows Container Manager Service allows an authorized attacker to bypass a security feature locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-69758

    Last Modified: 8 Sept 2026

    Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.1
    High

    CVE-2026-69775

    Last Modified: 10 Sept 2026

    Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges over a network.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-69772

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Network File System allows an unauthorized attacker to execute code over a network.

    Published: 8 Sept 2026
    6.5
    Medium

    CVE-2026-69839

    Last Modified: 9 Sept 2026

    Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network.

    Published: 8 Sept 2026
    5.5
    Medium

    CVE-2026-69808

    Last Modified: 10 Sept 2026

    Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

    Published: 8 Sept 2026
    7
    High

    CVE-2026-69838

    Last Modified: 10 Sept 2026

    Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-69691

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    5.6
    Medium

    CVE-2026-69832

    Last Modified: 8 Sept 2026

    Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally.

    Published: 8 Sept 2026
    5.5
    Medium

    CVE-2026-69862

    Last Modified: 10 Sept 2026

    Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to disclose information locally.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-69744

    Last Modified: 10 Sept 2026

    Null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over a network.

    Published: 8 Sept 2026
    9.8
    Critical

    CVE-2026-69819

    Last Modified: 10 Sept 2026

    Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network.

    Published: 8 Sept 2026
    8
    High

    CVE-2026-69762

    Last Modified: 11 Sept 2026

    Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.

    Published: 8 Sept 2026
    5.5
    Medium

    CVE-2026-69741

    Last Modified: 10 Sept 2026

    Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.

    Published: 8 Sept 2026
    7
    High

    CVE-2026-69735

    Last Modified: 10 Sept 2026

    Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7
    High

    CVE-2026-69896

    Last Modified: 10 Sept 2026

    Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    8
    High

    CVE-2026-69681

    Last Modified: 11 Sept 2026

    Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges over a network.

    Published: 8 Sept 2026
    Items Per Page