CVE-2026-78457
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78464
HIGH
CVSS: 7.0
EPSS: 0.2%
CWE-367
Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-80093
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81389
HIGH
CVSS: 7.0
EPSS: 0.4%
CWE-122
T1203
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-83940
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-83999
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-59
T1083
Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-85360
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-416
T1203
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-65812
MEDIUM
CVSS: 6.8
EPSS: 0.9%
CWE-201
Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68833
MEDIUM
CVSS: 6.8
EPSS: 0.4%
CWE-122
T1203
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69415
MEDIUM
CVSS: 6.8
EPSS: 0.7%
CWE-306
T1078
Missing authentication for critical function in Windows DHCP Server allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69490
MEDIUM
CVSS: 6.8
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a physical attack.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69566
MEDIUM
CVSS: 6.8
EPSS: 0.4%
CWE-122
T1203
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-71329
MEDIUM
CVSS: 6.8
EPSS: 0.4%
CWE-122
T1203
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-71348
MEDIUM
CVSS: 6.8
EPSS: 0.4%
CWE-122
T1203
Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-71349
MEDIUM
CVSS: 6.8
EPSS: 0.4%
CWE-122
T1203
Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-71350
MEDIUM
CVSS: 6.8
EPSS: 0.4%
CWE-122
T1203
Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72985
MEDIUM
CVSS: 6.8
EPSS: 0.4%
CWE-122
T1203
Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72999
MEDIUM
CVSS: 6.8
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77892
MEDIUM
CVSS: 6.8
EPSS: 0.4%
CWE-693
No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78451
MEDIUM
CVSS: 6.8
EPSS: 0.4%
CWE-822
Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69350
MEDIUM
CVSS: 6.7
EPSS: 0.3%
CWE-122
T1203
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69373
MEDIUM
CVSS: 6.7
EPSS: 0.3%
CWE-125
CWE-190
T1005
T1203
Integer overflow or wraparound in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69449
MEDIUM
CVSS: 6.7
EPSS: 0.3%
CWE-122
T1203
Heap-based buffer overflow in Windows BitLocker allows an authorized attacker to execute code locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-71339
MEDIUM
CVSS: 6.7
EPSS: 0.3%
CWE-122
T1203
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72927
MEDIUM
CVSS: 6.7
EPSS: 0.2%
CWE-122
T1203
Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72935
MEDIUM
CVSS: 6.7
EPSS: 0.3%
CWE-125
T1005
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72948
MEDIUM
CVSS: 6.7
EPSS: 0.4%
CWE-23
Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69469
MEDIUM
CVSS: 6.6
EPSS: 0.5%
CWE-122
CWE-190
T1203
Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to elevate privileges with a physical attack.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-58649
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-346
Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-62762
MEDIUM
CVSS: 6.5
EPSS: 1.1%
CWE-476
T1499
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-62801
MEDIUM
CVSS: 6.5
EPSS: 0.8%
CWE-22
T1083
Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-63523
MEDIUM
CVSS: 6.5
EPSS: 0.6%
CWE-79
T1189
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-64918
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-522
T1552
Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-66303
MEDIUM
CVSS: 6.5
EPSS: 1.1%
CWE-476
T1499
Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-66306
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-209
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-66308
MEDIUM
CVSS: 6.5
EPSS: 1.1%
CWE-125
T1005
Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-66816
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-778
Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67369
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-125
T1005
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67383
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-209
Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67386
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-908
T1005
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67389
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-125
T1005
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67390
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-126
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67393
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-126
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67624
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-125
T1005
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67629
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-125
T1005
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67630
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-125
T1005
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67633
MEDIUM
CVSS: 6.5
EPSS: 1.1%
CWE-125
T1005
Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67641
MEDIUM
CVSS: 6.5
EPSS: 1.1%
CWE-190
T1203
Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67645
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-125
T1005
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67648
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-908
T1005
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):