CVE-2026-68776
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-908
T1005
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68777
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-125
T1005
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68778
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-125
T1005
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68779
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-125
T1005
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68780
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-125
T1005
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68781
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-125
T1005
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68784
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-125
T1005
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68898
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Windows iSCSI allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69267
MEDIUM
CVSS: 6.5
EPSS: 0.4%
CWE-1220
Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69297
MEDIUM
CVSS: 6.5
EPSS: 0.8%
CWE-257
Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69361
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-918
T1190
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69374
MEDIUM
CVSS: 6.5
EPSS: 1.1%
CWE-770
T1499
Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69375
MEDIUM
CVSS: 6.5
EPSS: 0.6%
CWE-639
Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69395
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-134
T1203
Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69409
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-250
T1068
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69497
MEDIUM
CVSS: 6.5
EPSS: 1.1%
CWE-401
T1499
Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69562
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69624
MEDIUM
CVSS: 6.5
EPSS: 0.7%
CWE-184
Incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) allows an authorized attacker to perform tampering over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69626
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-126
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69636
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-89
T1190
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69642
MEDIUM
CVSS: 6.5
EPSS: 0.4%
CWE-79
T1189
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69683
MEDIUM
CVSS: 6.5
EPSS: 0.8%
CWE-918
T1190
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69719
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-126
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69734
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
CWE-190
T1005
T1203
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69739
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69781
MEDIUM
CVSS: 6.5
EPSS: 0.6%
CWE-401
T1499
Missing release of memory after effective lifetime in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69839
MEDIUM
CVSS: 6.5
EPSS: 1.1%
CWE-248
Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70019
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-65
Windows hard link in Windows Compressed Folder allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72938
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-822
CWE-843
Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72939
MEDIUM
CVSS: 6.5
EPSS: 1.1%
CWE-476
T1499
Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72942
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Windows Spaceport.sys allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72956
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-822
Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72974
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-126
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72975
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72977
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-20
CWE-125
T1005
T1190
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-73029
MEDIUM
CVSS: 6.5
EPSS: 1.0%
CWE-126
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77896
MEDIUM
CVSS: 6.5
EPSS: 0.7%
CWE-190
T1203
Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77911
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78441
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78453
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-191
Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78502
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78503
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78515
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78520
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78522
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-80073
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-80076
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-80078
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-80079
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-80082
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):