CVE-2026-71339
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-71340
Last Modified: 10 Sept 2026Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.
CVE-2026-71338
Last Modified: 10 Sept 2026Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.
CVE-2026-71334
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows NFS Portmapper allows an authorized attacker to elevate privileges locally.
CVE-2026-71332
Last Modified: 10 Sept 2026Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.
CVE-2026-71337
Last Modified: 10 Sept 2026Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.
CVE-2026-71333
Last Modified: 10 Sept 2026Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-71330
Last Modified: 8 Sept 2026Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network.
CVE-2026-71336
Last Modified: 10 Sept 2026Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network.
CVE-2026-71329
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
CVE-2026-70587
Last Modified: 10 Sept 2026Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.
CVE-2026-70586
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network.
CVE-2026-70585
Last Modified: 9 Sept 2026Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally.
CVE-2026-70584
Last Modified: 10 Sept 2026Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.
CVE-2026-70582
Last Modified: 10 Sept 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.
CVE-2026-70564
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
CVE-2026-70563
Last Modified: 10 Sept 2026Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-72923
Last Modified: 8 Sept 2026In Microsoft.OpenApi.YamlReader from 2.0.0-preview.11 until 2.12.0 and from 3.0.0 until 3.10.0, and in Microsoft.OpenApi.Readers prior to 1.6.30, a small YAML OpenAPI document containing nested anchors and aliases can cause uncontrolled resource consumption when parsed through the public YAML reader APIs. YAML is parsed through SharpYaml, which represents aliases as shared nodes in a directed acyclic graph, so the parsed YAML graph stays small, but converting that graph to System.Text.Json.Nodes.JsonNode requires every alias to be materialized as an independent node because a JsonNode cannot be attached to multiple parents. Without a bound on that conversion work, a document with N nested anchors each referenced k times can require k^N materialized JSON nodes, leading to excessive memory allocation and process termination through out-of-memory conditions, a billion laughs style denial of service. The patched versions bound the YAML-to-JSON conversion by node count and nesting depth and report an OpenApiDiagnostic error instead of expanding without limit. This vulnerability is fixed in Microsoft.OpenApi.YamlReader 2.12.0 and 3.10.0, and Microsoft.OpenApi.Readers 1.6.30.
CVE-2026-70562
Last Modified: 10 Sept 2026Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.
CVE-2026-70351
Last Modified: 9 Sept 2026Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.
CVE-2026-58600
Last Modified: 9 Sept 2026Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.
CVE-2026-70342
Last Modified: 10 Sept 2026Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-70289
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
CVE-2026-70334
Last Modified: 11 Sept 2026Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-69890
Last Modified: 10 Sept 2026Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally.
CVE-2026-69740
Last Modified: 10 Sept 2026Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.
CVE-2026-69676
Last Modified: 10 Sept 2026Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute code over a network.
CVE-2026-69712
Last Modified: 9 Sept 2026Use after free in Windows Key Distribution Center allows an authorized attacker to execute code over a network.
CVE-2026-69730
Last Modified: 10 Sept 2026Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
CVE-2026-69860
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
CVE-2026-69770
Last Modified: 10 Sept 2026Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
CVE-2026-69732
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an unauthorized attacker to execute code over a network.
CVE-2026-69822
Last Modified: 10 Sept 2026Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.
CVE-2026-69771
Last Modified: 10 Sept 2026Improper link resolution before file access ('link following') in Windows Container Manager Service allows an authorized attacker to bypass a security feature locally.
CVE-2026-69758
Last Modified: 8 Sept 2026Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.
CVE-2026-69775
Last Modified: 10 Sept 2026Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges over a network.
CVE-2026-69772
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Network File System allows an unauthorized attacker to execute code over a network.
CVE-2026-69839
Last Modified: 9 Sept 2026Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network.
CVE-2026-69808
Last Modified: 10 Sept 2026Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-69838
Last Modified: 10 Sept 2026Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
CVE-2026-69691
Last Modified: 10 Sept 2026Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
CVE-2026-69832
Last Modified: 8 Sept 2026Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-69862
Last Modified: 10 Sept 2026Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to disclose information locally.
CVE-2026-69744
Last Modified: 10 Sept 2026Null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over a network.
CVE-2026-69819
Last Modified: 10 Sept 2026Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network.
CVE-2026-69762
Last Modified: 11 Sept 2026Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.
CVE-2026-69741
Last Modified: 10 Sept 2026Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
CVE-2026-69735
Last Modified: 10 Sept 2026Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69896
Last Modified: 10 Sept 2026Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
CVE-2026-69681
Last Modified: 11 Sept 2026Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges over a network.
