CVE-2026-78517
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-122
T1203
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78518
HIGH
CVSS: 8.8
EPSS: 0.9%
CWE-20
CWE-125
T1005
T1190
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78519
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-908
T1005
Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78521
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-122
T1203
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78524
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-787
T1203
Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78525
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-416
T1203
Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78526
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-122
T1203
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-80074
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-122
T1203
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-80077
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-122
T1203
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-80080
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-415
T1203
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-80081
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-416
T1203
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-80083
HIGH
CVSS: 8.8
EPSS: 0.3%
CWE-822
Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-80085
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-122
T1203
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-80096
HIGH
CVSS: 8.8
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81352
HIGH
CVSS: 8.8
EPSS: 0.5%
CWE-122
T1203
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81385
HIGH
CVSS: 8.8
EPSS: 1.3%
CWE-502
T1203
Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81952
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-122
T1203
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81955
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-122
T1203
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-83992
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-122
T1203
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-83996
HIGH
CVSS: 8.8
EPSS: 0.3%
CWE-122
T1203
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-83998
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-122
T1203
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-85877
HIGH
CVSS: 8.8
EPSS: 0.8%
CWE-122
T1203
Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-80097
HIGH
CVSS: 8.6
EPSS: 0.4%
CWE-287
T1078
Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67379
HIGH
CVSS: 8.5
EPSS: 0.7%
CWE-121
Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69479
HIGH
CVSS: 8.4
EPSS: 0.4%
CWE-122
T1203
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69638
HIGH
CVSS: 8.4
EPSS: 0.4%
CWE-122
T1203
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77503
HIGH
CVSS: 8.4
EPSS: 0.3%
CWE-125
T1005
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78510
HIGH
CVSS: 8.4
EPSS: 0.3%
CWE-122
T1203
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69646
HIGH
CVSS: 8.3
EPSS: 0.3%
CWE-347
T1556
Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69820
HIGH
CVSS: 8.2
EPSS: 0.3%
CWE-122
T1203
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69846
HIGH
CVSS: 8.2
EPSS: 0.3%
CWE-190
T1203
Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69874
HIGH
CVSS: 8.2
EPSS: 0.3%
CWE-822
Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69906
HIGH
CVSS: 8.2
EPSS: 0.3%
CWE-122
T1203
Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72958
HIGH
CVSS: 8.2
EPSS: 0.3%
CWE-415
T1203
Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72961
HIGH
CVSS: 8.2
EPSS: 0.3%
CWE-122
T1203
Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72962
HIGH
CVSS: 8.2
EPSS: 0.3%
CWE-122
T1203
Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81354
HIGH
CVSS: 8.2
EPSS: 0.3%
CWE-122
T1203
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81356
HIGH
CVSS: 8.2
EPSS: 0.5%
CWE-444
Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81357
HIGH
CVSS: 8.2
EPSS: 0.5%
CWE-918
T1190
Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81378
HIGH
CVSS: 8.2
EPSS: 0.5%
CWE-436
Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81379
HIGH
CVSS: 8.2
EPSS: 0.5%
CWE-636
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-83939
HIGH
CVSS: 8.2
EPSS: 0.3%
CWE-822
Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-47297
HIGH
CVSS: 8.1
EPSS: 1.1%
CWE-502
T1203
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-55007
HIGH
CVSS: 8.1
EPSS: 0.7%
CWE-415
T1203
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69325
HIGH
CVSS: 8.1
EPSS: 0.7%
CWE-122
T1203
Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69380
HIGH
CVSS: 8.1
EPSS: 0.7%
CWE-862
T1078
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69438
HIGH
CVSS: 8.1
EPSS: 0.7%
CWE-681
Incorrect conversion between numeric types in Microsoft JScript allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69510
HIGH
CVSS: 8.1
EPSS: 0.7%
CWE-121
Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69524
HIGH
CVSS: 8.1
EPSS: 0.7%
CWE-416
T1203
Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69530
HIGH
CVSS: 8.1
EPSS: 0.7%
CWE-416
T1203
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):