CVE-2026-77491
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77492
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78454
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78506
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-170
Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78513
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-125
T1005
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81387
MEDIUM
CVSS: 5.5
EPSS: 0.6%
CWE-497
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81390
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-125
T1005
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81391
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-908
T1005
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81392
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-20
CWE-125
T1005
T1190
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81393
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-125
T1005
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81394
MEDIUM
CVSS: 5.5
EPSS: 0.6%
CWE-497
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81395
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-125
T1005
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81399
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-126
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81400
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-125
T1005
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81401
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-843
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81958
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-908
T1005
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-83501
MEDIUM
CVSS: 5.5
EPSS: 0.4%
CWE-125
T1005
Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-83949
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-126
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-83951
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-126
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-83991
MEDIUM
CVSS: 5.5
EPSS: 0.3%
CWE-306
T1078
Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-85875
MEDIUM
CVSS: 5.5
EPSS: 0.5%
CWE-125
T1005
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70575
MEDIUM
CVSS: 5.3
EPSS: 1.0%
CWE-476
T1499
Null pointer dereference in Windows Schannel allows an authorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78446
MEDIUM
CVSS: 5.3
EPSS: 0.8%
CWE-416
T1203
Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81380
MEDIUM
CVSS: 5.3
EPSS: 0.6%
CWE-77
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72976
MEDIUM
CVSS: 5.0
EPSS: 0.5%
CWE-125
T1005
Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68785
MEDIUM
CVSS: 4.9
EPSS: 1.1%
CWE-122
T1203
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69474
MEDIUM
CVSS: 4.8
EPSS: 0.7%
CWE-126
CWE-416
T1203
Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68849
MEDIUM
CVSS: 4.7
EPSS: 0.3%
CWE-125
T1005
Out-of-bounds read in Windows Bluetooth Port Driver allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68891
MEDIUM
CVSS: 4.7
EPSS: 0.3%
CWE-125
T1005
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69316
MEDIUM
CVSS: 4.7
EPSS: 0.3%
CWE-126
Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69425
MEDIUM
CVSS: 4.7
EPSS: 0.3%
CWE-59
T1083
Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to perform tampering locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69483
MEDIUM
CVSS: 4.7
EPSS: 0.3%
CWE-125
T1005
Out-of-bounds read in Windows Image Acquisition allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69771
MEDIUM
CVSS: 4.7
EPSS: 0.3%
CWE-59
T1083
Improper link resolution before file access ('link following') in Windows Container Manager Service allows an authorized attacker to bypass a security feature locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69792
MEDIUM
CVSS: 4.7
EPSS: 0.2%
CWE-362
T1068
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to bypass a security feature locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69853
MEDIUM
CVSS: 4.7
EPSS: 0.3%
CWE-908
T1005
Use of uninitialized resource in Windows Win32K allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69895
MEDIUM
CVSS: 4.7
EPSS: 0.3%
CWE-125
T1005
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72931
MEDIUM
CVSS: 4.7
EPSS: 0.3%
CWE-772
T1499
Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69381
MEDIUM
CVSS: 4.6
EPSS: 0.5%
CWE-125
T1005
Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physical attack.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69548
MEDIUM
CVSS: 4.6
EPSS: 0.5%
CWE-122
T1203
Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical attack.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69690
MEDIUM
CVSS: 4.6
EPSS: 0.4%
CWE-79
T1189
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78452
MEDIUM
CVSS: 4.6
EPSS: 0.5%
CWE-125
T1005
Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78508
MEDIUM
CVSS: 4.6
EPSS: 0.5%
CWE-125
T1005
Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69713
MEDIUM
CVSS: 4.4
EPSS: 0.4%
Dependency on vulnerable third-party component in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72980
MEDIUM
CVSS: 4.4
EPSS: 0.6%
CWE-427
Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-73019
MEDIUM
CVSS: 4.3
EPSS: 0.8%
CWE-41
Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78455
MEDIUM
CVSS: 4.3
EPSS: 0.5%
CWE-125
T1005
Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78516
MEDIUM
CVSS: 4.3
EPSS: 0.5%
CWE-126
Insertion of sensitive information into externally-accessible file or directory in Windows Storage allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69615
LOW
CVSS: 3.5
EPSS: 0.4%
CWE-79
T1189
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69904
LOW
CVSS: 3.5
EPSS: 0.6%
CWE-918
T1190
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):