CVE-2026-68895
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-197
Numeric truncation error in Internet Storage Name Service allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69286
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-20
CWE-125
T1005
T1190
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69288
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-908
T1005
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69294
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-209
Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69303
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
CWE-191
T1005
Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69308
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
CWE-843
T1005
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69315
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-497
Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69318
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69321
MEDIUM
CVSS: 5.5
EPSS: 0.3%
CWE-306
T1078
Missing authentication for critical function in Windows Power Dependency Coordinator allows an authorized attacker to perform tampering locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69339
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-497
Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69343
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows Overlay Filter allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69344
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69345
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69351
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-359
Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69353
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69367
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69369
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows DNS allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69376
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69390
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69403
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-862
T1078
Missing authorization in Windows SMB Server allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69406
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-497
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69453
MEDIUM
CVSS: 5.5
EPSS: 0.3%
CWE-862
T1078
Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69457
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69504
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69527
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows USB Mass Storage Class Driver allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69531
MEDIUM
CVSS: 5.5
EPSS: 0.3%
CWE-441
Unintended proxy or intermediary ('confused deputy') in Microsoft Windows Speech allows an authorized attacker to perform tampering locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69554
MEDIUM
CVSS: 5.5
EPSS: 0.3%
CWE-306
T1078
Missing authentication for critical function in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69568
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69609
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
CWE-193
T1005
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69616
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69618
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69627
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69672
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-908
T1005
Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69674
MEDIUM
CVSS: 5.5
EPSS: 0.3%
CWE-306
T1078
Missing authentication for critical function in Windows Modern Device Management (MDM) allows an authorized attacker to bypass a security feature locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69684
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-209
Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69741
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69770
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-908
T1005
Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69794
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-126
Buffer over-read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69808
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69862
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-125
CWE-200
T1005
T1083
Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70145
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70290
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-908
T1005
Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-71341
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72937
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72945
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-908
T1005
Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72964
MEDIUM
CVSS: 5.5
EPSS: 0.3%
CWE-306
T1078
Missing authentication for critical function in Windows Internet Connection Sharing (ICS) allows an authorized attacker to perform tampering locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72966
MEDIUM
CVSS: 5.5
EPSS: 0.3%
CWE-862
T1078
Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-73004
MEDIUM
CVSS: 5.5
EPSS: 0.3%
CWE-306
T1078
Missing authentication for critical function in Windows Autopilot allows an authorized attacker to perform tampering locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-73008
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-359
Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77488
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-191
Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):