CVE-2026-80084
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-80086
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-80087
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-122
T1203
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-80088
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-80089
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-80090
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-80091
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-908
T1005
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81377
MEDIUM
CVSS: 6.5
EPSS: 0.8%
CWE-22
T1083
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81381
MEDIUM
CVSS: 6.5
EPSS: 0.9%
CWE-522
T1552
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69878
MEDIUM
CVSS: 6.4
EPSS: 0.3%
CWE-122
T1203
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70582
MEDIUM
CVSS: 6.4
EPSS: 0.2%
CWE-362
CWE-416
T1068
T1203
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-71338
MEDIUM
CVSS: 6.4
EPSS: 0.3%
CWE-415
T1203
Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72947
MEDIUM
CVSS: 6.4
EPSS: 0.3%
CWE-191
Integer underflow (wrap or wraparound) in Windows File History Service allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77887
MEDIUM
CVSS: 6.4
EPSS: 0.3%
CWE-125
T1005
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77891
MEDIUM
CVSS: 6.4
EPSS: 0.3%
CWE-125
T1005
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69304
MEDIUM
CVSS: 5.9
EPSS: 0.9%
CWE-409
Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69382
MEDIUM
CVSS: 5.9
EPSS: 0.5%
CWE-327
T1573
Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69803
MEDIUM
CVSS: 5.9
EPSS: 0.8%
CWE-125
T1005
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69929
MEDIUM
CVSS: 5.9
EPSS: 0.8%
CWE-125
T1005
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69930
MEDIUM
CVSS: 5.9
EPSS: 0.8%
CWE-125
T1005
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70091
MEDIUM
CVSS: 5.9
EPSS: 0.7%
CWE-362
T1068
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70124
MEDIUM
CVSS: 5.9
EPSS: 0.8%
CWE-125
T1005
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72978
MEDIUM
CVSS: 5.9
EPSS: 1.0%
CWE-770
T1499
Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78523
MEDIUM
CVSS: 5.9
EPSS: 1.0%
CWE-416
T1203
Use after free in Windows DNS allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69559
MEDIUM
CVSS: 5.8
EPSS: 0.3%
CWE-346
Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68874
MEDIUM
CVSS: 5.7
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69317
MEDIUM
CVSS: 5.7
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69349
MEDIUM
CVSS: 5.7
EPSS: 0.9%
CWE-908
T1005
Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69372
MEDIUM
CVSS: 5.7
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Windows Network File System allows an authorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69393
MEDIUM
CVSS: 5.7
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69405
MEDIUM
CVSS: 5.7
EPSS: 0.6%
CWE-401
T1499
Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69416
MEDIUM
CVSS: 5.7
EPSS: 0.6%
CWE-126
Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69507
MEDIUM
CVSS: 5.7
EPSS: 0.9%
CWE-538
Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69552
MEDIUM
CVSS: 5.7
EPSS: 0.9%
CWE-209
Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69569
MEDIUM
CVSS: 5.7
EPSS: 0.9%
CWE-822
Untrusted pointer dereference in Windows Print Spooler Components allows an authorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69572
MEDIUM
CVSS: 5.7
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69591
MEDIUM
CVSS: 5.7
EPSS: 0.9%
CWE-125
T1005
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69637
MEDIUM
CVSS: 5.7
EPSS: 0.6%
CWE-125
CWE-843
T1005
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69679
MEDIUM
CVSS: 5.7
EPSS: 0.6%
CWE-125
CWE-843
T1005
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69723
MEDIUM
CVSS: 5.7
EPSS: 0.9%
CWE-497
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69832
MEDIUM
CVSS: 5.6
EPSS: 0.4%
CWE-497
Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68830
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-59
CWE-269
T1068
T1083
Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68831
MEDIUM
CVSS: 5.5
EPSS: 0.6%
CWE-552
Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68842
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-497
Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68843
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-416
T1203
Use after free in Microsoft Office Word allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68851
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-126
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68852
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-200
CWE-908
T1005
T1083
Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68873
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-532
CWE-908
T1005
T1552
Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68881
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68886
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-209
CWE-416
T1203
Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):