CVE-2026-69804
HIGH
CVSS: 7.5
EPSS: 0.5%
CWE-367
Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69805
HIGH
CVSS: 7.5
EPSS: 0.6%
CWE-73
CWE-200
CWE-522
T1005
T1083
T1552
External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69809
HIGH
CVSS: 7.5
EPSS: 1.2%
CWE-401
T1499
Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69852
HIGH
CVSS: 7.5
EPSS: 0.7%
CWE-122
T1203
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69881
HIGH
CVSS: 7.5
EPSS: 1.2%
CWE-476
T1499
Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69890
HIGH
CVSS: 7.5
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70065
HIGH
CVSS: 7.5
EPSS: 1.2%
CWE-401
T1499
Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70570
HIGH
CVSS: 7.5
EPSS: 0.7%
CWE-416
T1203
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70579
HIGH
CVSS: 7.5
EPSS: 1.0%
CWE-125
T1005
Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70587
HIGH
CVSS: 7.5
EPSS: 1.0%
CWE-170
Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-71330
HIGH
CVSS: 7.5
EPSS: 1.0%
CWE-497
Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72928
HIGH
CVSS: 7.5
EPSS: 0.7%
CWE-416
T1203
Use after free in Windows DNS allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72932
HIGH
CVSS: 7.5
EPSS: 1.0%
CWE-126
Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72943
HIGH
CVSS: 7.5
EPSS: 0.7%
CWE-416
T1203
Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72949
HIGH
CVSS: 7.5
EPSS: 1.2%
CWE-476
T1499
Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72954
HIGH
CVSS: 7.5
EPSS: 0.7%
CWE-416
T1203
Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72989
HIGH
CVSS: 7.5
EPSS: 1.0%
CWE-908
T1005
Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-73017
HIGH
CVSS: 7.5
EPSS: 0.3%
CWE-122
T1203
Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77494
HIGH
CVSS: 7.5
EPSS: 1.2%
CWE-843
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77498
HIGH
CVSS: 7.5
EPSS: 1.2%
CWE-125
T1005
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77499
HIGH
CVSS: 7.5
EPSS: 1.2%
CWE-843
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77501
HIGH
CVSS: 7.5
EPSS: 1.2%
CWE-125
T1005
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77502
HIGH
CVSS: 7.5
EPSS: 1.2%
CWE-125
T1005
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77886
HIGH
CVSS: 7.5
EPSS: 1.2%
CWE-125
T1005
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77888
HIGH
CVSS: 7.5
EPSS: 1.2%
CWE-843
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77889
HIGH
CVSS: 7.5
EPSS: 1.2%
CWE-843
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77890
HIGH
CVSS: 7.5
EPSS: 1.2%
CWE-843
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77893
HIGH
CVSS: 7.5
EPSS: 1.2%
CWE-125
T1005
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77895
HIGH
CVSS: 7.5
EPSS: 1.2%
CWE-125
T1005
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77898
HIGH
CVSS: 7.5
EPSS: 0.6%
CWE-122
T1203
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81355
HIGH
CVSS: 7.5
EPSS: 0.2%
CWE-122
T1203
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to execute code locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-83989
HIGH
CVSS: 7.5
EPSS: 1.2%
CWE-125
T1005
Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-84001
HIGH
CVSS: 7.5
EPSS: 1.2%
CWE-125
T1005
Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69347
HIGH
CVSS: 7.4
EPSS: 0.3%
CWE-122
T1203
Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78461
HIGH
CVSS: 7.4
EPSS: 1.0%
CWE-22
T1083
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81383
HIGH
CVSS: 7.4
EPSS: 0.9%
CWE-706
Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-84003
HIGH
CVSS: 7.4
EPSS: 0.6%
CWE-294
Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69402
HIGH
CVSS: 7.3
EPSS: 0.4%
CWE-79
T1189
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69417
HIGH
CVSS: 7.3
EPSS: 0.4%
CWE-79
T1189
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69477
HIGH
CVSS: 7.3
EPSS: 0.4%
CWE-122
T1203
Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81349
HIGH
CVSS: 7.2
EPSS: 1.0%
CWE-78
T1059
Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-66305
HIGH
CVSS: 7.1
EPSS: 0.5%
CWE-603
Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68835
HIGH
CVSS: 7.1
EPSS: 0.6%
CWE-416
T1203
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68846
HIGH
CVSS: 7.1
EPSS: 0.6%
CWE-416
T1203
Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68889
HIGH
CVSS: 7.1
EPSS: 0.6%
CWE-122
CWE-190
T1203
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68893
HIGH
CVSS: 7.1
EPSS: 0.6%
CWE-416
T1203
Use after free in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69272
HIGH
CVSS: 7.1
EPSS: 0.6%
CWE-122
T1203
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69274
HIGH
CVSS: 7.1
EPSS: 0.6%
CWE-416
T1203
Use after free in Windows Win32K allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69296
HIGH
CVSS: 7.1
EPSS: 0.6%
CWE-416
T1203
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69305
HIGH
CVSS: 7.1
EPSS: 0.6%
CWE-416
T1203
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):