CVE-2026-69654
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69682
HIGH
CVSS: 7.0
EPSS: 0.2%
CWE-362
CWE-416
T1068
T1203
Use after free in Windows Host Guardian Service allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69692
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69693
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69694
HIGH
CVSS: 7.0
EPSS: 2.8%
CWE-502
T1203
Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69708
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Web Platform Storage allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69711
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69735
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69779
HIGH
CVSS: 7.0
EPSS: 0.2%
CWE-367
Time-of-check time-of-use (toctou) race condition in Windows Win32K allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69791
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69806
HIGH
CVSS: 7.0
EPSS: 1.9%
CWE-94
CWE-200
T1005
T1059
T1083
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69814
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Credential Providers allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69816
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69817
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69818
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69834
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows ALPC allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69838
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69859
HIGH
CVSS: 7.0
EPSS: 0.2%
CWE-191
CWE-367
Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69866
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69889
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69891
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69896
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69911
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70283
HIGH
CVSS: 7.0
EPSS: 0.2%
CWE-863
T1078
Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70562
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-415
T1203
Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70565
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70567
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-415
T1203
Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70568
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-122
T1203
Heap-based buffer overflow in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70573
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-20
CWE-122
T1190
T1203
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70577
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70578
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-122
T1203
Heap-based buffer overflow in Windows Credential Guard allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70585
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-71332
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-71333
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-71340
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-71342
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-71351
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-415
T1203
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-71353
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-415
T1203
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72926
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72930
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72952
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-125
T1005
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72963
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-73003
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-73005
HIGH
CVSS: 7.0
EPSS: 0.2%
CWE-362
CWE-416
T1068
T1203
Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-73022
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77485
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in SQL Server allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77894
HIGH
CVSS: 7.0
EPSS: 0.2%
CWE-362
CWE-416
T1068
T1203
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77897
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-23
Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77899
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Security Center allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77905
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):