CVE-2026-69590
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-122
T1203
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69595
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-416
T1203
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69715
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-122
CWE-125
T1005
T1203
Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69730
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-416
T1203
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69768
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-122
T1203
Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69769
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-122
T1203
Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69819
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-787
T1203
Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69824
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-122
CWE-191
T1203
Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69829
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-122
T1203
Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69845
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-20
CWE-122
T1190
T1203
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69910
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-121
Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70296
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-787
T1203
Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72979
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-416
T1203
Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72982
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-121
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72983
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-416
T1203
Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-73009
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-416
T1203
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-73010
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-416
T1203
Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-73025
CRITICAL
CVSS: 9.8
EPSS: 0.9%
CWE-1390
Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77493
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-415
T1203
Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78445
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-416
T1203
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78509
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-122
T1203
Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-65669
CRITICAL
CVSS: 9.6
EPSS: 0.9%
CWE-74
Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81376
CRITICAL
CVSS: 9.6
EPSS: 0.8%
CWE-693
CWE-1023
Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69356
CRITICAL
CVSS: 9.3
EPSS: 0.8%
CWE-79
T1189
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69641
CRITICAL
CVSS: 9.1
EPSS: 0.9%
CWE-862
T1078
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67378
CRITICAL
CVSS: 9.0
EPSS: 0.7%
CWE-822
Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67636
CRITICAL
CVSS: 9.0
EPSS: 0.7%
CWE-125
T1005
Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69854
CRITICAL
CVSS: 9.0
EPSS: 0.7%
CWE-287
T1078
Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-62706
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-121
CWE-125
T1005
Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-62744
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-122
T1203
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-62895
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-89
CWE-942
CWE-1390
T1190
Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-65772
HIGH
CVSS: 8.8
EPSS: 1.7%
CWE-502
T1203
Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-66814
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-1220
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-66818
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-269
T1068
Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-66819
HIGH
CVSS: 8.8
EPSS: 1.0%
CWE-89
T1190
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-66820
HIGH
CVSS: 8.8
EPSS: 1.0%
CWE-89
T1190
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67368
HIGH
CVSS: 8.8
EPSS: 1.0%
CWE-59
T1083
Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67370
HIGH
CVSS: 8.8
EPSS: 1.0%
CWE-89
T1190
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67373
HIGH
CVSS: 8.8
EPSS: 0.9%
CWE-122
T1203
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67380
HIGH
CVSS: 8.8
EPSS: 0.9%
CWE-122
T1203
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67381
HIGH
CVSS: 8.8
EPSS: 0.9%
CWE-122
T1203
Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67384
HIGH
CVSS: 8.8
EPSS: 0.9%
CWE-122
CWE-190
T1203
Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67385
HIGH
CVSS: 8.8
EPSS: 0.9%
CWE-416
T1203
Use after free in SQL Server allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67388
HIGH
CVSS: 8.8
EPSS: 0.9%
CWE-122
T1203
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67638
HIGH
CVSS: 8.8
EPSS: 0.9%
CWE-122
T1203
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67639
HIGH
CVSS: 8.8
EPSS: 0.9%
CWE-122
T1203
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67642
HIGH
CVSS: 8.8
EPSS: 0.9%
CWE-122
T1203
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68775
HIGH
CVSS: 8.8
EPSS: 0.9%
CWE-122
T1203
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68786
HIGH
CVSS: 8.8
EPSS: 0.9%
CWE-122
T1203
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68828
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-122
T1203
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):