Report Name: Microsoft Patch Tuesday, September 2026Generated: 2026-09-08 23:21:21
| Product Name | Prevalence | U | C | H | M | L | A | Comment |
|---|---|---|---|---|---|---|---|---|
| Windows Container Manager Service | 0.9 | 1 | 1 | Windows component | ||||
| Windows DNS Server | 0.9 | 9 | 1 | 10 | Windows component | |||
| Windows Kernel | 0.9 | 1 | 10 | 11 | Windows Kernel | |||
| Windows SMB Client | 0.9 | 1 | 3 | 4 | Windows component | |||
| Windows TCP/IP | 0.9 | 1 | 5 | 6 | Windows component | |||
| Windows Win32k | 0.9 | 24 | 24 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | ||||
| ASP.NET Core | 0.8 | 2 | 2 | An open-source, server-side web-application framework designed for web development | ||||
| Connected User Experiences and Telemetry | 0.8 | 4 | 4 | Windows component | ||||
| DirectWrite | 0.8 | 2 | 2 | Windows сomponent | ||||
| Kernel Streaming WOW Thunk Service Driver | 0.8 | 2 | 2 | Windows component | ||||
| Microsoft COM | 0.8 | 2 | 2 | COM is a platform-independent, distributed, object-oriented system for creating binary software components that can interact | ||||
| Microsoft Exchange | 0.8 | 2 | 7 | 9 | Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft | |||
| Microsoft Office | 0.8 | 6 | 9 | 15 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |||
| Microsoft OpenSSH for Windows | 0.8 | 1 | 1 | Windows component | ||||
| Microsoft PowerShell | 0.8 | 2 | 2 | PowerShell or Microsoft PowerShell (formerly Windows PowerShell) is a task automation and configuration management program from Microsoft, consisting of a command-line shell and the associated scripting language | ||||
| Microsoft Remote Desktop App for Windows | 0.8 | 1 | 1 | Windows component | ||||
| Microsoft Windows Media Foundation | 0.8 | 6 | 6 | Windows component | ||||
| Microsoft Windows PDF | 0.8 | 1 | 1 | Windows component | ||||
| Microsoft Windows SCSI Class System File | 0.8 | 3 | 3 | Windows component | ||||
| Microsoft Windows Search Component | 0.8 | 11 | 11 | Windows component | ||||
| Microsoft Windows Speech | 0.8 | 3 | 3 | Windows component | ||||
| Role: Windows Fax Service | 0.8 | 3 | 3 | Windows component | ||||
| Storage Spaces Controller | 0.8 | 1 | 1 | Storage Spaces Controller | ||||
| Windows AF_UNIX Socket Provider | 0.8 | 1 | 1 | Windows component | ||||
| Windows ALPC | 0.8 | 2 | 2 | Windows component | ||||
| Windows Accounts Control | 0.8 | 2 | 2 | Windows component | ||||
| Windows Active Directory Domain Services | 0.8 | 3 | 2 | 5 | Windows component | |||
| Windows Advanced Local Procedure Call (ALPC) | 0.8 | 1 | 1 | Windows component | ||||
| Windows Ancillary Function Driver for WinSock | 0.8 | 2 | 2 | Windows component | ||||
| Windows Audio Service | 0.8 | 8 | 8 | Windows component | ||||
| Windows Authentication Methods | 0.8 | 1 | 1 | Windows component | ||||
| Windows Autopilot | 0.8 | 1 | 1 | Windows component | ||||
| Windows Bind Filter Driver | 0.8 | 1 | 1 | Windows component | ||||
| Windows Biometric Service | 0.8 | 64 | 64 | Windows component | ||||
| Windows BitLocker | 0.8 | 2 | 2 | Windows component | ||||
| Windows Bluetooth Port Driver | 0.8 | 2 | 2 | Windows component | ||||
| Windows Bluetooth Service | 0.8 | 4 | 4 | Windows component | ||||
| Windows Boot Manager | 0.8 | 1 | 1 | Windows component | ||||
| Windows Broadcast DVR User Service | 0.8 | 1 | 1 | Windows component | ||||
| Windows Broker Infrastructure Service | 0.8 | 1 | 1 | Windows component | ||||
| Windows CD-ROM Driver | 0.8 | 4 | 4 | Windows component | ||||
| Windows Camera Frame Server Monitor | 0.8 | 1 | 1 | Windows component | ||||
| Windows Cloud Files Mini Filter Driver | 0.8 | 3 | 3 | Windows component | ||||
| Windows Compressed Folder | 0.8 | 1 | 2 | 3 | Windows component | |||
| Windows Connected User Experiences and Telemetry | 0.8 | 1 | 1 | Windows component | ||||
| Windows Core Messaging | 0.8 | 2 | 2 | Windows component | ||||
| Windows Credential Guard | 0.8 | 2 | 2 | Windows component | ||||
| Windows Credential Providers | 0.8 | 1 | 2 | 3 | Windows component | |||
| Windows DCOM Server | 0.8 | 1 | 1 | Windows component | ||||
| Windows DHCP Client | 0.8 | 2 | 2 | Windows component | ||||
| Windows DHCP Server | 0.8 | 9 | 27 | 36 | Windows component | |||
| Windows DNS | 0.8 | 1 | 7 | 8 | Windows component | |||
| Windows DWM Core Library | 0.8 | 1 | 1 | Windows component | ||||
| Windows Defender Firewall Service | 0.8 | 2 | 2 | Windows component | ||||
| Windows Deployment Services | 0.8 | 4 | 4 | Windows component | ||||
| Windows Device Association Broker Service | 0.8 | 2 | 2 | Windows component | ||||
| Windows Device Association Service | 0.8 | 11 | 11 | Windows component | ||||
| Windows Device Health Attestation (DHA) | 0.8 | 1 | 1 | Windows component | ||||
| Windows Devices Human Interface | 0.8 | 1 | 1 | Windows component | ||||
| Windows Direct Show | 0.8 | 1 | 1 | Windows component | ||||
| Windows Display Enhancement Service | 0.8 | 1 | 1 | Windows component | ||||
| Windows Distributed File System (DFS) | 0.8 | 2 | 2 | Windows component | ||||
| Windows Embedded Mode Service | 0.8 | 1 | 1 | Windows component | ||||
| Windows Encrypting File System (EFS) | 0.8 | 3 | 3 | Windows component | ||||
| Windows Enterprise App Management | 0.8 | 2 | 2 | Windows component | ||||
| Windows Error Reporting | 0.8 | 12 | 12 | Windows component | ||||
| Windows Event Logging Service | 0.8 | 3 | 3 | Windows component | ||||
| Windows Failover Cluster | 0.8 | 2 | 2 | Windows component | ||||
| Windows Fast FAT Driver | 0.8 | 2 | 2 | Windows component | ||||
| Windows File History Service | 0.8 | 3 | 3 | Windows component | ||||
| Windows GDI | 0.8 | 1 | 1 | Windows component | ||||
| Windows GDI+ | 0.8 | 2 | 2 | Windows component | ||||
| Windows Graphics Component | 0.8 | 2 | 2 | Windows component | ||||
| Windows Group Policy | 0.8 | 1 | 1 | Windows component | ||||
| Windows HTTP Print Provider | 0.8 | 2 | 2 | Windows component | ||||
| Windows HTTP.sys | 0.8 | 1 | 1 | Windows component | ||||
| Windows Hello | 0.8 | 9 | 9 | Windows component | ||||
| Windows Host Guardian Service | 0.8 | 1 | 1 | Windows component | ||||
| Windows IP Address Management (IPAM) Service | 0.8 | 1 | 1 | Windows component | ||||
| Windows Image Acquisition | 0.8 | 4 | 4 | Windows component | ||||
| Windows Imaging Component | 0.8 | 7 | 1 | 8 | Windows component | |||
| Windows Installer | 0.8 | 5 | 5 | Windows component | ||||
| Windows Internet Connection Sharing (ICS) | 0.8 | 2 | 2 | Windows component | ||||
| Windows Internet Key Exchange (IKE) Extension | 0.8 | 2 | 2 | Windows component | ||||
| Windows Internet Key Exchange (IKE) Protocol Extensions | 0.8 | 1 | 1 | Windows component | ||||
| Windows Kerberos | 0.8 | 1 | 4 | 5 | Windows component | |||
| Windows Kernel-Mode Driver | 0.8 | 1 | 1 | Windows component | ||||
| Windows Key Distribution Center | 0.8 | 1 | 1 | 2 | Windows component | |||
| Windows LDAP - Lightweight Directory Access Protocol | 0.8 | 1 | 1 | Windows component | ||||
| Windows License Manager | 0.8 | 2 | 2 | Windows component | ||||
| Windows Link Layer Topology Discovery Protocol | 0.8 | 1 | 1 | Windows component | ||||
| Windows MIDI Service Module | 0.8 | 2 | 2 | Windows component | ||||
| Windows MIDI Service Module | 0.8 | 4 | 4 | Windows component | ||||
| Windows Management Instrumentation | 0.8 | 4 | 4 | Windows component | ||||
| Windows Management Services | 0.8 | 1 | 1 | Windows component | ||||
| Windows Media | 0.8 | 1 | 1 | Windows component | ||||
| Windows Media Player | 0.8 | 2 | 2 | Windows component | ||||
| Windows Message Queuing | 0.8 | 2 | 1 | 3 | Windows component | |||
| Windows Message Queuing Queue Manager | 0.8 | 2 | 2 | Windows component | ||||
| Windows Mobile Broadband | 0.8 | 1 | 1 | Windows component | ||||
| Windows Modern Device Management (MDM) | 0.8 | 6 | 6 | Windows component | ||||
| Windows Modern Execution Server | 0.8 | 1 | 1 | Windows component | ||||
| Windows NDIS | 0.8 | 2 | 2 | Windows component | ||||
| Windows NFS Portmapper | 0.8 | 1 | 1 | Windows component | ||||
| Windows NTFS | 0.8 | 6 | 23 | 29 | The default file system of the Windows NT family | |||
| Windows Netlogon | 0.8 | 1 | 1 | 2 | Windows component | |||
| Windows Network Connection Broker | 0.8 | 2 | 2 | Windows component | ||||
| Windows Network File System | 0.8 | 1 | 1 | 2 | Windows component | |||
| Windows Notification | 0.8 | 1 | 1 | Windows component | ||||
| Windows OLE DB | 0.8 | 1 | 1 | 2 | Windows component | |||
| Windows Online Certificate Status Protocol (OCSP) | 0.8 | 1 | 1 | Windows component | ||||
| Windows Overlay Filter | 0.8 | 7 | 7 | Windows component | ||||
| Windows Paint | 0.8 | 1 | 1 | Windows component | ||||
| Windows Partition Management Driver | 0.8 | 3 | 3 | Windows component | ||||
| Windows Performance Monitor | 0.8 | 1 | 1 | Windows component | ||||
| Windows Power Dependency Coordinator | 0.8 | 2 | 2 | Windows component | ||||
| Windows Print Spooler | 0.8 | 1 | 1 | Windows component | ||||
| Windows Print Spooler Components | 0.8 | 11 | 11 | Windows component | ||||
| Windows PrintWorkflowUserSvc | 0.8 | 1 | 1 | Windows component | ||||
| Windows Program Compatibility Assistant Service | 0.8 | 6 | 6 | Windows component | ||||
| Windows Push Notifications | 0.8 | 3 | 3 | Windows component | ||||
| Windows RNDIS | 0.8 | 1 | 1 | 2 | Windows component | |||
| Windows Registry | 0.8 | 1 | 1 | Windows component | ||||
| Windows Reliable Multicast Transport Driver (RMCAST) | 0.8 | 3 | 3 | Windows component | ||||
| Windows Remote Access Connection Manager | 0.8 | 2 | 5 | 7 | Windows component | |||
| Windows Remote Desktop | 0.8 | 1 | 1 | Windows component | ||||
| Windows Remote Desktop Client | 0.8 | 6 | 3 | 9 | Remote Desktop Protocol Client | |||
| Windows Remote Desktop Licensing Service | 0.8 | 1 | 1 | Windows component | ||||
| Windows Remote Desktop Protocol | 0.8 | 1 | 1 | Windows component | ||||
| Windows Remote Desktop Services | 0.8 | 4 | 4 | Remote Desktop Services, known as Terminal Services in Windows Server 2008 and earlier, is one of the components of Microsoft Windows that allow a user to initiate and control an interactive session on a remote computer or virtual machine over a network connection | ||||
| Windows Resilient File System (ReFS) | 0.8 | 2 | 2 | Windows component | ||||
| Windows Resilient File System (ReFS) Deduplication Service | 0.8 | 1 | 1 | Windows component | ||||
| Windows Routing and Remote Access Service (RRAS) | 0.8 | 5 | 3 | 8 | Windows component | |||
| Windows SMB Server | 0.8 | 2 | 2 | Windows component | ||||
| Windows SMB Server Network Transport Driver (srvnet.sys) | 0.8 | 1 | 1 | Windows component | ||||
| Windows Schannel | 0.8 | 1 | 1 | 2 | Windows component | |||
| Windows Secure Boot | 0.8 | 1 | 1 | Windows component | ||||
| Windows Secure Kernel Mode | 0.8 | 4 | 4 | Windows component | ||||
| Windows Secure Socket Tunneling Protocol (SSTP) | 0.8 | 1 | 3 | 4 | Windows component | |||
| Windows Security Health Service | 0.8 | 1 | 1 | Windows component | ||||
| Windows Server | 0.8 | 1 | 1 | Windows component | ||||
| Windows Services for NFS ONCRPC XDR Driver | 0.8 | 2 | 4 | 6 | Windows component | |||
| Windows Setup Files Cleanup | 0.8 | 1 | 1 | Windows component | ||||
| Windows Shell | 0.8 | 1 | 5 | 6 | Windows component | |||
| Windows Smart Card | 0.8 | 1 | 1 | Windows component | ||||
| Windows Spaceport.sys | 0.8 | 2 | 15 | 17 | Windows component | |||
| Windows Storage | 0.8 | 2 | 2 | Windows component | ||||
| Windows Storage Management Provider | 0.8 | 2 | 2 | Windows component | ||||
| Windows Storage Port Driver | 0.8 | 3 | 3 | Windows component | ||||
| Windows Storage Spaces Controller | 0.8 | 2 | 2 | 4 | Windows component | |||
| Windows Task Scheduler | 0.8 | 1 | 1 | Windows component | ||||
| Windows Text Shaping | 0.8 | 1 | 1 | 2 | Windows component | |||
| Windows URL Moniker | 0.8 | 1 | 1 | 2 | Windows component | |||
| Windows USB Audio Class Driver | 0.8 | 1 | 1 | Windows component | ||||
| Windows USB Audio Class driver (usbaudio.sys) | 0.8 | 8 | 8 | Windows component | ||||
| Windows USB Driver | 0.8 | 5 | 5 | Windows component | ||||
| Windows USB Hub Driver | 0.8 | 1 | 1 | Windows component | ||||
| Windows USB Mass Storage Class Driver | 0.8 | 1 | 2 | 3 | Windows component | |||
| Windows USB Video Driver | 0.8 | 5 | 5 | Windows component | ||||
| Windows Universal Disk Format File System Driver (UDFS) | 0.8 | 3 | 3 | Windows component | ||||
| Windows Universal Plug and Play (UPnP) Device Host | 0.8 | 2 | 2 | Windows component | ||||
| Windows Update Stack | 0.8 | 1 | 1 | Windows component | ||||
| Windows VHD miniport driver | 0.8 | 1 | 1 | Windows component | ||||
| Windows VOLSNAP.SYS | 0.8 | 1 | 1 | Windows component | ||||
| Windows Virtual Trusted Platform Module | 0.8 | 1 | 1 | Windows component | ||||
| Windows Virtualization-Based Security (VBS) | 0.8 | 1 | 1 | Windows component | ||||
| Windows Virtualization-Based Security (VBS) Enclave | 0.8 | 1 | 1 | Windows component | ||||
| Windows Volume Manager Extension Driver | 0.8 | 2 | 3 | 5 | Windows component | |||
| Windows Web Platform Storage | 0.8 | 1 | 1 | Windows component | ||||
| Windows WebClient Service | 0.8 | 1 | 1 | Windows component | ||||
| Windows Win32K | 0.8 | 1 | 1 | Windows component | ||||
| Windows Wireless Networking | 0.8 | 1 | 1 | Windows component | ||||
| Windows Wireless Wide Area Network Service | 0.8 | 1 | 1 | Windows component | ||||
| Windows Work Folder Service | 0.8 | 1 | 1 | 2 | Windows component | |||
| Windows Work Folders | 0.8 | 1 | 1 | Windows component | ||||
| Windows exFAT File System | 0.8 | 1 | 1 | Windows component | ||||
| Windows iSCSI | 0.8 | 3 | 1 | 4 | Windows component | |||
| Windows iSCSI Target Service | 0.8 | 1 | 1 | Windows component | ||||
| .NET | 0.7 | 3 | 3 | .NET | ||||
| .NET and Visual Studio | 0.7 | 2 | 1 | 3 | .NET and Visual Studio | |||
| HEVC Video Extensions | 0.7 | 2 | 2 | HEVC Video Extensions | ||||
| Raw Image Extension | 0.7 | 1 | 1 | Raw Image Extension | ||||
| VHD Miniport Driver | 0.7 | 7 | 7 | The Virtual Hard Disk (VHD) Miniport Driver is a Microsoft Windows kernel-mode storage driver that enables the operating system to mount, access, and manage Virtual Hard Disk (VHD and VHDX) files as block storage devices. It is used by Windows virtualization, backup, and virtual disk management features. | ||||
| Web Media Extensions | 0.7 | 1 | 1 | Web Media Extensions | ||||
| Windows Security Center | 0.7 | 1 | 1 | Windows Security Center (WSC) is a comprehensive reporting tool that helps users establish and maintain a protective security layer around their computer systems | ||||
| HEIF Image Extensions | 0.6 | 1 | 1 | The HEIF Image Extension enables Windows 10 devices to read and write files that use the High Efficiency Image File (HEIF) format. | ||||
| Microsoft Entra ID | 0.6 | 1 | 1 | Microsoft Entra ID is a cloud-based identity and access management solution | ||||
| Microsoft Excel | 0.6 | 28 | 28 | MS Office product | ||||
| Microsoft Office Graphics Component | 0.6 | 1 | 1 | Microsoft Office | ||||
| Microsoft Word | 0.6 | 3 | 3 | Microsoft Word is a widely used commercial word processor developed by Microsoft. It is a component of the Microsoft Office suite of productivity software but can also be purchased as a standalone product. | ||||
| Skype for Business | 0.6 | 7 | 7 | Skype for Business | ||||
| Windows Hyper-V | 0.6 | 5 | 5 | Hardware virtualization component of the client editions of Windows NT | ||||
| Active Directory Certificate Services (AD CS) | 0.5 | 4 | 4 | Active Directory Certificate Services (AD CS) | ||||
| Active Directory Domain Services | 0.5 | 1 | 1 | Active Directory Domain Services | ||||
| Active Directory Federation Services (AD FS) | 0.5 | 1 | 1 | Active Directory Federation Services (AD FS) | ||||
| Audio Video Control Transport Protocol | 0.5 | 1 | 1 | Audio Video Control Transport Protocol | ||||
| Azure AI Language | 0.5 | 1 | 1 | Azure AI Language | ||||
| Azure Arc SQL Server Extension | 0.5 | 1 | 1 | Azure Arc SQL Server Extension | ||||
| Azure Cosmos DB | 0.5 | 1 | 1 | Azure Cosmos DB | ||||
| Azure CycleCloud | 0.5 | 1 | 1 | Azure CycleCloud | ||||
| Azure HDInsight Ambari | 0.5 | 1 | 1 | Azure HDInsight Ambari | ||||
| BranchCache | 0.5 | 1 | 1 | BranchCache | ||||
| Connected Devices Platform Service (Cdpsvc) | 0.5 | 1 | 1 | Connected Devices Platform Service (Cdpsvc) | ||||
| Copilot Studio | 0.5 | 1 | 1 | Copilot Studio | ||||
| Data Sharing Service Client | 0.5 | 1 | 1 | Data Sharing Service Client | ||||
| Entra ID | 0.5 | 1 | 1 | Entra ID | ||||
| GitHub Copilot and Visual Studio Code | 0.5 | 2 | 2 | GitHub Copilot and Visual Studio Code | ||||
| Graphic Fonts | 0.5 | 3 | 3 | Graphic Fonts | ||||
| Graphics Kernel | 0.5 | 1 | 1 | Graphics Kernel | ||||
| HID Class Driver | 0.5 | 1 | 1 | HID Class Driver | ||||
| IP Helper | 0.5 | 1 | 1 | IP Helper | ||||
| Internet Connection Sharing (ICS) | 0.5 | 1 | 1 | Internet Connection Sharing (ICS) | ||||
| Internet Storage Name Service | 0.5 | 1 | 1 | Internet Storage Name Service | ||||
| Microsoft Account | 0.5 | 2 | 2 | Microsoft Account | ||||
| Microsoft Authentication Library (MSAL) for Node.js | 0.5 | 1 | 1 | Microsoft Authentication Library (MSAL) for Node.js | ||||
| Microsoft Authenticator | 0.5 | 1 | 1 | Microsoft Authenticator | ||||
| Microsoft Azure Active Directory B2C | 0.5 | 1 | 1 | Microsoft Azure Active Directory B2C | ||||
| Microsoft Azure CLI | 0.5 | 1 | 1 | Microsoft Azure CLI | ||||
| Microsoft DirectMusic | 0.5 | 1 | 1 | Microsoft DirectMusic | ||||
| Microsoft Discovery Studio | 0.5 | 1 | 1 | Microsoft Discovery Studio | ||||
| Microsoft Dynamics 365 On-Premises | 0.5 | 2 | 2 | Microsoft Dynamics 365 On-Premises | ||||
| Microsoft Fabric | 0.5 | 1 | 1 | Microsoft Fabric | ||||
| Microsoft Failover Cluster | 0.5 | 2 | 2 | Microsoft Failover Cluster | ||||
| Microsoft Graphics Component | 0.5 | 3 | 3 | Microsoft Graphics Component | ||||
| Microsoft Install Service | 0.5 | 1 | 1 | Microsoft Install Service | ||||
| Microsoft JScript | 0.5 | 2 | 2 | Microsoft JScript | ||||
| Microsoft Local Security Authority (LSA) Server | 0.5 | 3 | 3 | Microsoft Local Security Authority (LSA) Server | ||||
| Microsoft Office Access | 0.5 | 4 | 4 | Microsoft Office Access | ||||
| Microsoft Office Excel | 0.5 | 4 | 4 | Microsoft Office Excel | ||||
| Microsoft Office Outlook | 0.5 | 7 | 7 | Microsoft Office Outlook | ||||
| Microsoft Office PowerPoint | 0.5 | 10 | 10 | Microsoft Office PowerPoint | ||||
| Microsoft Office Publisher | 0.5 | 2 | 2 | Microsoft Office Publisher | ||||
| Microsoft Office SharePoint | 0.5 | 15 | 1 | 16 | Microsoft Office SharePoint | |||
| Microsoft Office Word | 0.5 | 35 | 35 | Microsoft Office Word | ||||
| Microsoft Power Automate Desktop | 0.5 | 1 | 1 | Microsoft Power Automate Desktop | ||||
| Microsoft SQL Server | 0.5 | 54 | 54 | Microsoft SQL Server | ||||
| Microsoft Standard XPS | 0.5 | 18 | 18 | Microsoft Standard XPS | ||||
| Microsoft Storage Port Driver | 0.5 | 1 | 1 | Microsoft Storage Port Driver | ||||
| Microsoft Teams for Android | 0.5 | 2 | 2 | Microsoft Teams for Android | ||||
| Microsoft Trace Data Helper | 0.5 | 1 | 1 | Microsoft Trace Data Helper | ||||
| Microsoft UxTheme Library (uxtheme.dll) | 0.5 | 1 | 1 | Microsoft UxTheme Library (uxtheme.dll) | ||||
| Microsoft VOLSNAP.SYS | 0.5 | 2 | 2 | Microsoft VOLSNAP.SYS | ||||
| Microsoft WDAC OLE DB provider for SQL | 0.5 | 1 | 1 | Microsoft WDAC OLE DB provider for SQL | ||||
| Microsoft WebP Image Extension | 0.5 | 1 | 1 | Microsoft WebP Image Extension | ||||
| Power Automate | 0.5 | 1 | 1 | Power Automate | ||||
| Push Message Routing Service | 0.5 | 1 | 1 | Push Message Routing Service | ||||
| RPC Runtime Library | 0.5 | 1 | 1 | RPC Runtime Library | ||||
| Remote Desktop Gateway Service | 0.5 | 2 | 2 | Remote Desktop Gateway Service | ||||
| Remote Desktop Licensing Service | 0.5 | 1 | 1 | Remote Desktop Licensing Service | ||||
| Remote Desktop Services Remote Code Execution Vulnerability | 0.5 | 5 | 5 | Remote Desktop Services Remote Code Execution Vulnerability | ||||
| SQL Server | 0.5 | 7 | 7 | SQL Server | ||||
| Skype for Business and Lync | 0.5 | 3 | 3 | Skype for Business and Lync | ||||
| Spring Cloud Azure | 0.5 | 1 | 1 | Spring Cloud Azure | ||||
| Telnet Client | 0.5 | 1 | 1 | Telnet Client | ||||
| Volume Manager Driver | 0.5 | 3 | 3 | Volume Manager Driver | ||||
| Volume Shadow Copy | 0.5 | 1 | 1 | Volume Shadow Copy | ||||
| Winsock | 0.5 | 1 | 1 | Winsock | ||||
| Xbox | 0.5 | 1 | 1 | Xbox | ||||
| Xbox Gaming Services | 0.5 | 1 | 1 | Xbox Gaming Services | ||||
| Visual Studio | 0.3 | 2 | 2 | Integrated development environment | ||||
| Visual Studio Code | 0.3 | 9 | 1 | 10 | Integrated development environment |
| Vulnerability Type | Criticality | U | C | H | M | L | A |
|---|---|---|---|---|---|---|---|
| Remote Code Execution | 1.0 | 122 | 135 | 257 | |||
| Security Feature Bypass | 0.9 | 2 | 16 | 18 | |||
| Elevation of Privilege | 0.85 | 1 | 4 | 433 | 438 | ||
| Information Disclosure | 0.83 | 175 | 175 | ||||
| Denial of Service | 0.7 | 56 | 56 | ||||
| Spoofing | 0.4 | 15 | 1 | 16 | |||
| Tampering | 0.3 | 12 | 1 | 13 |
| Source | U | C | H | M | L | A |
|---|---|---|---|---|---|---|
| Qualys | 1 | 50 | 64 | 115 | ||
| Tenable | 1 | 3 | 2 | 6 | ||
| Rapid7 | ||||||
| ZDI | 1 | 29 | 18 | 48 |
1.
Elevation of Privilege - Windows Update Stack (CVE-2026-81963) - Critical [716]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (cisa_kev object), Microsoft websites | |
| 0.6 | 17 | The existence of a private exploit is mentioned on Microsoft:PrivateExploit:Functional website | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-81963: Windows Update Stack Elevation of Privilege Vulnerability A link following flaw in the Windows Update Stack may allow an authenticated attacker to elevate privileges locally. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CISA added the CVE-2026-81963 to its Known Exploited Vulnerabilities Catalog, urging users to patch it before September 22, 2026.
Tenable: Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
Tenable: CVE-2026-81963 | Windows Update Stack elevation of privilege vulnerability
Tenable: CVE-2026-81963 is an EoP vulnerability affecting Windows Update Stack elevation of privilege vulnerability. It received a CVSSv3 score of 7.8 and was rated as important. According to Microsoft, this vulnerability was exploited in the wild as a zero-day.
Tenable: Since 2022, seven Windows Update Stack EoP vulnerabilities have been patched across Patch Tuesday releases, but CVE-2026-81963 is the first to have been exploited in the wild as a zero-day.
ZDI: - CVE-2026-81963 - Windows Update Stack Elevation of Privilege Vulnerability. This is the first bug being exploited in the wild, but we know little about how broadly that exploitation is. The bug itself is a privilege escalation in the Update Stack, which is worrisome, but I doubt the automatic update process itself is compromised. More likely is that this bug is being combined with a code execution bug to spread malware or ransomware. Patch this one quickly.
2.
Elevation of Privilege - Windows Advanced Local Procedure Call (ALPC) (CVE-2026-85880) - High [594]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (cisa_kev object), Microsoft websites | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-85880: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability The heap-based buffer overflow flaw in Windows ALPC may allow an authenticated attacker to elevate privileges locally. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CISA added the CVE-2026-85880 to its Known Exploited Vulnerabilities Catalog, urging users to patch it before September 22, 2026.
Tenable: Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
Tenable: CVE-2026-85880 | Windows Advanced Local Procedure Call (ALPC) elevation of privilege vulnerability
Tenable: CVE-2026-85880 is a EoP vulnerability affecting Windows Advanced Local Procedure Call (ALPC). It received a CVSSv3 score of 7.8 and is rated as important. According to Microsoft, this vulnerability was exploited in the wild, making it one of two zero-days addressed in the September Patch Tuesday release. Successful exploitation would allow an attacker to gain SYSTEM level privileges.
ZDI: - CVE-2026-85880 - Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability. This is the other bug currently being exploited, and it is also a privilege escalation bug. These types of bugs must be triggered by the user, but they can hide within documents, PDFs, and other attachments. As with the Update Stack EoP, we don’t know how widespread these exploits may be, so assume they are coming for you and patch quickly.
3.
Remote Code Execution - Windows DNS Server (CVE-2026-69730) - High [447]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69730, CVE-2026-69813, CVE-2026-69858, & CVE-2026-72987: Windows DNS Server Remote Code Execution Vulnerability The use-after-free flaw in Windows DNS may allow an unauthenticated attacker to execute code over a network.
Tenable: CVE-2026-69730 | Windows DNS Server remote code execution vulnerability
Tenable: CVE-2026-69730 is an RCE vulnerability affecting Windows DNS Server. It received a CVSSv3 score of 9.8 and is rated Critical. According to the advisory, an unauthenticated, remote attacker could send a crafted packet to exploit a use-after-free flaw in Windows DNS in order to achieve remote code execution. Microsoft assesses this flaw as “Exploitation More Likely.”
Tenable: Eight additional RCEs in Windows DNS Server were patched this month, however they did not achieve the same exploitability assessment as CVE-2026-69730. These eight are outlined in the table below:
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
4.
Remote Code Execution - Windows Kernel (CVE-2026-69669) - High [447]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows Kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
5.
Remote Code Execution - Windows DNS Server (CVE-2026-69551) - High [435]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
6.
Remote Code Execution - Microsoft Windows Media Foundation (CVE-2026-69408) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
7.
Remote Code Execution - Microsoft Windows PDF (CVE-2026-69586) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
8.
Remote Code Execution - Windows Compressed Folder (CVE-2026-69496) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
9.
Remote Code Execution - Windows DHCP Server (CVE-2026-69845) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69845: Windows DHCP Server Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows DHCP Server may allow an unauthenticated attacker to execute code over a network.
ZDI: Windows DHCP Server: Windows DHCP Server chimes in with 36 bugs: 12 RCE, 18 DoS, five info leaks, and one EoP. Nothing exploited or disclosed, but 22 of the 36 require no authentication. It's the third-largest single-component pile of the month, and it's all one story: someone pointed a (likely AI-assisted) fuzzer at DHCP packet parsing. In addition to the two wormable bugs already mentioned, there are three more that didn’t carry the exact wormable verbiage but look like close cousins: CVE-2026-69845 (9.8, heap overflow), CVE-2026-69266 (8.8, integer overflow), and CVE-2026-69620 (8.1, stack overflow). If you're being generous, that's five wormable-shaped bugs in DHCP Server alone. The remaining seven RCEs need an authorized attacker. CWE spread is pure memory corruption: heap, stack, UAF, integer overflow. There are 18 DoS bugs, and 13 are unauthenticated at a CVSS score of 7.5. Malformed packet in, service crash out. Individually boring, but collectively, an unauthenticated attacker on the network has 13 different ways to take out DHCP, and when DHCP dies, clients stop getting leases and the helpdesk phone starts ringing. Finally, there are a couple of oddballs here: CVE-2026-69297 is an info leak that could expose passwords stored in a recoverable format, which is a configuration-secrets problem rather than a memory bug. The lone EoP is missing authentication on a critical function.
10.
Remote Code Execution - Windows DHCP Server (CVE-2026-72979) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-72979: Windows DHCP Server Remote Code Execution Vulnerability The use-after-free flaw in Windows DHCP Server may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
11.
Remote Code Execution - Windows Direct Show (CVE-2026-69715) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
12.
Remote Code Execution - Windows Event Logging Service (CVE-2026-69493) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
13.
Remote Code Execution - Windows Graphics Component (CVE-2026-77493) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-77493: Microsoft Office Outlook Remote Code Execution Vulnerability A double-free flaw in Microsoft Office Outlook may allow an unauthenticated attacker to execute code over a network.
14.
Remote Code Execution - Windows HTTP Print Provider (CVE-2026-69769) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69769: Windows HTTP Print Provider Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows HTTP Print Provider may allow an unauthenticated attacker to execute code over a network.
15.
Remote Code Execution - Windows Imaging Component (CVE-2026-70296) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-70296: Windows Imaging Component Remote Code Execution Vulnerability An out-of-bounds write flaw in Windows Imaging Component may allow an unauthenticated attacker to execute code over a network.
16.
Remote Code Execution - Windows Message Queuing (CVE-2026-69579) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69579: Windows Message Queuing Remote Code Execution Vulnerability The use-after-free flaw in Windows Message Queuing may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
17.
Remote Code Execution - Windows NTFS (CVE-2026-69463) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ZDI: Windows NTFS: We have 30 bugs in this component: 16 EoP, 10 RCE, three info leaks, and one link-following oddball. All Important except the two 9.8 Critical RCEs. Like Biometric and DHCP, it's one bug class on repeat: 28 of 30 are memory-safety flaws (heap overflows lead at 12, then out-of-bounds reads). The headliner is CVE-2026-69463; simple heap-overflow RCE at 9.8, unauthenticated, network vector. The FAQ only offers the vague “in-network attacker calling arbitrary endpoints” phrasing, which likely means the remote path is something like SMB-reachable file operations rather than a raw packet, but a 9.8 in the file system driver everyone runs is still a top-tier patch either way. CVE-2026-69461 (8.8, stack overflow, unauth network) rides along just below them. Everything else can be somewhat dismissed as local-only noise, but remember the mount-a-drive trio that where “requires physical access” describes every USB port in the building.
18.
Remote Code Execution - Windows Netlogon (CVE-2026-72982) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-72982: Windows Netlogon Remote Code Execution Vulnerability The stack-based buffer overflow flaw in Windows Netlogon may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
19.
Remote Code Execution - Windows RNDIS (CVE-2026-69768) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
20.
Remote Code Execution - Windows Routing and Remote Access Service (RRAS) (CVE-2026-69590) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69590, CVE-2026-69852, CVE-2026-72950, & CVE-2026-72959: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Successful exploitation of the vulnerability may allow an attacker to gain unauthenticated access to the victim’s machine.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
21.
Remote Code Execution - Windows Secure Socket Tunneling Protocol (SSTP) (CVE-2026-73009) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-73009: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability The use-after-free flaw in Windows Secure Socket Tunneling Protocol (SSTP) may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
22.
Remote Code Execution - Windows Services for NFS ONCRPC XDR Driver (CVE-2026-69595) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69595 & CVE-2026-78445: Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability The use-after-free flaw in Windows Services for NFS ONCRPC XDR Driver may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
23.
Remote Code Execution - Windows Services for NFS ONCRPC XDR Driver (CVE-2026-78445) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69595 & CVE-2026-78445: Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability The use-after-free flaw in Windows Services for NFS ONCRPC XDR Driver may allow an unauthenticated attacker to execute code over a network.
24.
Remote Code Execution - Windows Shell (CVE-2026-69829) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69829: Windows Shell Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Shell may allow an unauthenticated attacker to execute code over a network.
25.
Remote Code Execution - Windows USB Mass Storage Class Driver (CVE-2026-68839) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ZDI: The USB Stack: There are 23 bugs impacting the USB stack, but I really only want to talk about one. CVE-2026-68839 (USB Mass Storage Class Driver) with a CVSS of 9.8 and a network vector. The FAQ offers only the generic “in-network attacker calling arbitrary endpoints” boilerplate, which doesn't explain how a USB class driver is network-reachable. Either the metric is scored to worst case or there's a remote path (RDP device redirection would be the plausible one). I'd treat the score skeptically in print but patch like it's real.
26.
Remote Code Execution - Windows DNS Server (CVE-2026-69782) - High [423]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
27.
Remote Code Execution - Windows DNS Server (CVE-2026-69813) - High [423]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69730, CVE-2026-69813, CVE-2026-69858, & CVE-2026-72987: Windows DNS Server Remote Code Execution Vulnerability The use-after-free flaw in Windows DNS may allow an unauthenticated attacker to execute code over a network.
28.
Remote Code Execution - Windows DNS Server (CVE-2026-69827) - High [423]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69827: Windows DNS Server Remote Code Execution Vulnerability A race condition flaw in the DNS Server may allow an unauthenticated attacker to execute code over a network.
29.
Remote Code Execution - Windows DNS Server (CVE-2026-69858) - High [423]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69730, CVE-2026-69813, CVE-2026-69858, & CVE-2026-72987: Windows DNS Server Remote Code Execution Vulnerability The use-after-free flaw in Windows DNS may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
30.
Remote Code Execution - Windows DNS Server (CVE-2026-69989) - High [423]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
31.
Remote Code Execution - Windows DNS Server (CVE-2026-72928) - High [423]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
32.
Remote Code Execution - Windows DNS Server (CVE-2026-77505) - High [423]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-77505: Windows DNS Server Remote Code Execution Vulnerability The use-after-free flaw in the DNS Server may allow an unauthenticated attacker to execute code over a network.
33.
Remote Code Execution - Windows SMB Client (CVE-2026-72936) - High [423]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
34.
Remote Code Execution - DirectWrite (CVE-2026-73006) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows сomponent | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-73006 & CVE-2026-78439: Microsoft Office Graphics Component Remote Code Execution Vulnerability The stack-based buffer overflow flaw in Microsoft Graphics Component may allow an unauthenticated attacker to execute code over a network.
35.
Remote Code Execution - DirectWrite (CVE-2026-73016) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows сomponent | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
36.
Remote Code Execution - Microsoft Exchange (CVE-2026-69355) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
37.
Remote Code Execution - Microsoft Office (CVE-2026-69285) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69285 & CVE-2026-78505: Microsoft Office Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Microsoft Office may allow an unauthenticated attacker to execute code over a network.
38.
Remote Code Execution - Microsoft Office (CVE-2026-69442) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
39.
Remote Code Execution - Microsoft Office (CVE-2026-69632) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69632, CVE-2026-69678, CVE-2026-69767, & CVE-2026-69797: Microsoft Office PowerPoint Remote Code Execution Vulnerability The use-after-free flaw in Microsoft Office PowerPoint may allow an unauthenticated attacker to execute code over a network.
40.
Remote Code Execution - Microsoft Office (CVE-2026-78505) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69285 & CVE-2026-78505: Microsoft Office Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Microsoft Office may allow an unauthenticated attacker to execute code over a network.
41.
Remote Code Execution - Microsoft Office (CVE-2026-78524) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
42.
Remote Code Execution - Microsoft Windows Media Foundation (CVE-2026-62706) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
43.
Remote Code Execution - Microsoft Windows Media Foundation (CVE-2026-62744) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
44.
Remote Code Execution - Microsoft Windows Media Foundation (CVE-2026-69386) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
45.
Remote Code Execution - Microsoft Windows Media Foundation (CVE-2026-69511) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
46.
Remote Code Execution - Microsoft Windows Media Foundation (CVE-2026-69601) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69601: Microsoft Windows Media Foundation Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Microsoft Windows Media Foundation may allow an unauthenticated attacker to execute code over a network.
47.
Remote Code Execution - Windows Credential Providers (CVE-2026-69729) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
48.
Remote Code Execution - Windows DHCP Server (CVE-2026-69266) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ZDI: Windows DHCP Server: Windows DHCP Server chimes in with 36 bugs: 12 RCE, 18 DoS, five info leaks, and one EoP. Nothing exploited or disclosed, but 22 of the 36 require no authentication. It's the third-largest single-component pile of the month, and it's all one story: someone pointed a (likely AI-assisted) fuzzer at DHCP packet parsing. In addition to the two wormable bugs already mentioned, there are three more that didn’t carry the exact wormable verbiage but look like close cousins: CVE-2026-69845 (9.8, heap overflow), CVE-2026-69266 (8.8, integer overflow), and CVE-2026-69620 (8.1, stack overflow). If you're being generous, that's five wormable-shaped bugs in DHCP Server alone. The remaining seven RCEs need an authorized attacker. CWE spread is pure memory corruption: heap, stack, UAF, integer overflow. There are 18 DoS bugs, and 13 are unauthenticated at a CVSS score of 7.5. Malformed packet in, service crash out. Individually boring, but collectively, an unauthenticated attacker on the network has 13 different ways to take out DHCP, and when DHCP dies, clients stop getting leases and the helpdesk phone starts ringing. Finally, there are a couple of oddballs here: CVE-2026-69297 is an info leak that could expose passwords stored in a recoverable format, which is a configuration-secrets problem rather than a memory bug. The lone EoP is missing authentication on a critical function.
49.
Remote Code Execution - Windows DHCP Server (CVE-2026-69547) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
50.
Remote Code Execution - Windows Event Logging Service (CVE-2026-69494) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
51.
Remote Code Execution - Windows Event Logging Service (CVE-2026-69495) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
52.
Remote Code Execution - Windows Graphics Component (CVE-2026-81955) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-81955: Windows Graphics Component Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Microsoft Graphics Component may allow an unauthenticated attacker to execute code over a network.
53.
Remote Code Execution - Windows Imaging Component (CVE-2026-69499) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69499: Windows Imaging Component Remote Code Execution Vulnerability An integer overflow flaw in Windows Imaging Component may allow an unauthenticated attacker to execute code over a network.
54.
Remote Code Execution - Windows Imaging Component (CVE-2026-69860) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69860, CVE-2026-73013, CVE-2026-73023, & CVE-2026-77495: Windows Imaging Component Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Imaging Component may allow an unauthenticated attacker to execute code over a network.
55.
Remote Code Execution - Windows Imaging Component (CVE-2026-73013) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69860, CVE-2026-73013, CVE-2026-73023, & CVE-2026-77495: Windows Imaging Component Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Imaging Component may allow an unauthenticated attacker to execute code over a network.
56.
Remote Code Execution - Windows Imaging Component (CVE-2026-73023) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69860, CVE-2026-73013, CVE-2026-73023, & CVE-2026-77495: Windows Imaging Component Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Imaging Component may allow an unauthenticated attacker to execute code over a network.
57.
Remote Code Execution - Windows Imaging Component (CVE-2026-77495) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69860, CVE-2026-73013, CVE-2026-73023, & CVE-2026-77495: Windows Imaging Component Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Imaging Component may allow an unauthenticated attacker to execute code over a network.
58.
Remote Code Execution - Windows Imaging Component (CVE-2026-83992) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
59.
Remote Code Execution - Windows Kerberos (CVE-2026-69676) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69676: Windows Kerberos Remote Code Execution Vulnerability An authentication-bypass flaw via capture-replay in Windows Kerberos may allow an authenticated attacker to execute code over a network.
Tenable: CVE-2026-69676 | Windows Kerberos remote code execution vulnerability
Tenable: CVE-2026-69676 is an RCE vulnerability affecting Windows Kerberos. It received a CVSSv3 score of 8.8 and is rated critical. An attacker with low-level access could exploit this authentication bypass flaw using capture-replay against Windows Kerberos in order to execute arbitrary code. Microsoft assesses this flaw as “Exploitation More Likely.”
ZDI: Kerberos and the KDC: Six different bugs affect these components, but it’s the two Critical rated ones that raised my eyebrows. Six bugs across Kerberos and the KDC — two Critical RCEs, two EoPs, and two DoS. Nothing exploited or disclosed, but one carries the rating that matters. CVE-2026-69676 is an RCE in Kerberos with a CVSS of 8.8 and classified as Exploitation More Likely. An authenticated attacker with low-level access sends a crafted request and executes code on the server, no user interaction. “The server” here means a domain controller, and any authenticated attacker means any domain user. So the realistic read is: one phished workstation account, one crafted request, code execution on the DC. That's a domain-compromise primitive, and Microsoft expects to see it exploited. CVE-2026-69712 is in KDC and reads almost identical to the previous: authenticated, low-level access, crafted request, code on the server, no interaction, but this one's a use-after-free in the KDC itself, the component that mints every ticket in the domain. Its practical impact is identical to 69676; only the exploitability rating separates them.
60.
Remote Code Execution - Windows Key Distribution Center (CVE-2026-69712) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69712: Windows Key Distribution Center Remote Code Execution Vulnerability The use-after-free flaw in the Windows Key Distribution Center may allow an authenticated attacker to execute code over a network.
ZDI: Kerberos and the KDC: Six different bugs affect these components, but it’s the two Critical rated ones that raised my eyebrows. Six bugs across Kerberos and the KDC — two Critical RCEs, two EoPs, and two DoS. Nothing exploited or disclosed, but one carries the rating that matters. CVE-2026-69676 is an RCE in Kerberos with a CVSS of 8.8 and classified as Exploitation More Likely. An authenticated attacker with low-level access sends a crafted request and executes code on the server, no user interaction. “The server” here means a domain controller, and any authenticated attacker means any domain user. So the realistic read is: one phished workstation account, one crafted request, code execution on the DC. That's a domain-compromise primitive, and Microsoft expects to see it exploited. CVE-2026-69712 is in KDC and reads almost identical to the previous: authenticated, low-level access, crafted request, code on the server, no interaction, but this one's a use-after-free in the KDC itself, the component that mints every ticket in the domain. Its practical impact is identical to 69676; only the exploitability rating separates them.
61.
Remote Code Execution - Windows Media Player (CVE-2026-70203) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-70203 & CVE-2026-72960: Windows Media Player Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Media Player may allow an unauthenticated attacker to execute code over a network.
62.
Remote Code Execution - Windows Media Player (CVE-2026-72960) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-70203 & CVE-2026-72960: Windows Media Player Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Media Player may allow an unauthenticated attacker to execute code over a network.
63.
Remote Code Execution - Windows NTFS (CVE-2026-69461) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ZDI: Windows NTFS: We have 30 bugs in this component: 16 EoP, 10 RCE, three info leaks, and one link-following oddball. All Important except the two 9.8 Critical RCEs. Like Biometric and DHCP, it's one bug class on repeat: 28 of 30 are memory-safety flaws (heap overflows lead at 12, then out-of-bounds reads). The headliner is CVE-2026-69463; simple heap-overflow RCE at 9.8, unauthenticated, network vector. The FAQ only offers the vague “in-network attacker calling arbitrary endpoints” phrasing, which likely means the remote path is something like SMB-reachable file operations rather than a raw packet, but a 9.8 in the file system driver everyone runs is still a top-tier patch either way. CVE-2026-69461 (8.8, stack overflow, unauth network) rides along just below them. Everything else can be somewhat dismissed as local-only noise, but remember the mount-a-drive trio that where “requires physical access” describes every USB port in the building.
64.
Remote Code Execution - Windows Network File System (CVE-2026-69772) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
65.
Remote Code Execution - Windows OLE DB (CVE-2026-78442) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
66.
Remote Code Execution - Windows Paint (CVE-2026-70586) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-70586: Windows Paint Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Paint may allow an unauthenticated attacker to execute code over a network.
67.
Remote Code Execution - Windows Print Spooler (CVE-2026-85877) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
68.
Remote Code Execution - Windows Remote Access Connection Manager (CVE-2026-71352) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
69.
Remote Code Execution - Windows Remote Desktop (CVE-2026-69518) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69518: Windows Remote Desktop Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Remote Desktop may allow an unauthenticated attacker to execute code over a network.
70.
Remote Code Execution - Windows Remote Desktop Client (CVE-2026-68828) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Remote Desktop Protocol Client | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
71.
Remote Code Execution - Windows Remote Desktop Client (CVE-2026-69485) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Remote Desktop Protocol Client | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
72.
Remote Code Execution - Windows Remote Desktop Client (CVE-2026-78463) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Remote Desktop Protocol Client | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
73.
Remote Code Execution - Windows Remote Desktop Client (CVE-2026-80074) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Remote Desktop Protocol Client | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
74.
Remote Code Execution - Windows Remote Desktop Client (CVE-2026-80077) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Remote Desktop Protocol Client | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
75.
Remote Code Execution - Windows Remote Desktop Client (CVE-2026-83998) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Remote Desktop Protocol Client | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
76.
Remote Code Execution - Windows Routing and Remote Access Service (RRAS) (CVE-2026-72950) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69590, CVE-2026-69852, CVE-2026-72950, & CVE-2026-72959: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Successful exploitation of the vulnerability may allow an attacker to gain unauthenticated access to the victim’s machine.
77.
Remote Code Execution - Windows Routing and Remote Access Service (RRAS) (CVE-2026-72959) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69590, CVE-2026-69852, CVE-2026-72950, & CVE-2026-72959: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Successful exploitation of the vulnerability may allow an attacker to gain unauthenticated access to the victim’s machine.
78.
Remote Code Execution - Windows Schannel (CVE-2026-72940) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ZDI: Exploitation More Likely: If you prioritize by Microsoft’s Exploit Index (XI), which I don’t recommend, there are a couple of bugs not mentioned yet: CVE-2026-72940 (Schannel RCE, CVSS 8.8, TLS stack), CVE-2026-72957 (Windows Deployment Services RCE, CVSS 7.8, PXE infrastructure), CVE-2026-71343 (Remote Access Connection Manager RCE, CVSS 7.8), and CVE-2026-70585 (a third NFS ONCRPC XDR RCE, CVSS 7.0). Again, I take all of these rating with a gigantic grain of salt, but you do you.
79.
Remote Code Execution - Windows URL Moniker (CVE-2026-69434) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
80.
Remote Code Execution - Windows Volume Manager Extension Driver (CVE-2026-69291) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
81.
Remote Code Execution - Windows Volume Manager Extension Driver (CVE-2026-69334) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
82.
Remote Code Execution - Windows Work Folder Service (CVE-2026-71336) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
83.
Remote Code Execution - Windows iSCSI (CVE-2026-69598) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
84.
Remote Code Execution - Windows iSCSI (CVE-2026-69628) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
85.
Elevation of Privilege - Microsoft Entra ID (CVE-2026-62916) - High [418]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.6 | 14 | Microsoft Entra ID is a cloud-based identity and access management solution | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Microsoft data source | |
| 0.5 | 10 | EPSS Probability is 0.00582, EPSS Percentile is 0.45704 |
Qualys: CVE-2026-62916: Microsoft Entra ID Elevation of Privilege Vulnerability An authentication bypass using an alternate path or channel in Microsoft Entra ID may allow an unauthenticated attacker to elevate privileges over a network.
86.
Elevation of Privilege - Azure AI Language (CVE-2026-70352) - High [413]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Azure AI Language | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Microsoft data source | |
| 0.5 | 10 | EPSS Probability is 0.00623, EPSS Percentile is 0.47667 |
Qualys: CVE-2026-70352: Azure AI Language Elevation of Privilege Vulnerability A missing authentication for a critical function in Azure AI Language may allow an unauthenticated attacker to elevate privileges over a network.
87.
Elevation of Privilege - Microsoft Azure Active Directory B2C (CVE-2026-83711) - High [413]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Azure Active Directory B2C | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Microsoft data source | |
| 0.5 | 10 | EPSS Probability is 0.00582, EPSS Percentile is 0.45704 |
Qualys: CVE-2026-83711: Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability An authorization bypass through a user-controlled key in Microsoft Azure Active Directory B2C may allow an unauthenticated attacker to elevate privileges over a network.
88.
Security Feature Bypass - Windows iSCSI (CVE-2026-73025) - High [413]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
89.
Remote Code Execution - Microsoft Exchange (CVE-2026-55007) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ZDI: - CVE-2026-55007 - Microsoft Exchange Server Remote Code Execution Vulnerability. There are several Exchange patches this month, but despite the CVSS rating, I find this one most important. A remote, unauthenticated attacker could get code execution on an affected Exchange server just by sending an email with a malicious Visio attachment. The code execution occurs when the server processes the mail – no need even for the Preview Pane. Microsoft states the exploit would be unreliable, but the attacker only needs to get it right once. Schedule your downtime and update your Exchange servers with haste.
90.
Remote Code Execution - Microsoft Office (CVE-2026-77898) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-77898: Microsoft Office PowerPoint Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Microsoft Office PowerPoint may allow an unauthenticated attacker to execute code over a network.
91.
Remote Code Execution - Microsoft OpenSSH for Windows (CVE-2026-69397) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
92.
Remote Code Execution - Windows Active Directory Domain Services (CVE-2026-62813) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
93.
Remote Code Execution - Windows Active Directory Domain Services (CVE-2026-69524) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
94.
Remote Code Execution - Windows Active Directory Domain Services (CVE-2026-69546) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
95.
Remote Code Execution - Windows DHCP Server (CVE-2026-69412) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
96.
Remote Code Execution - Windows DHCP Server (CVE-2026-69510) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
97.
Remote Code Execution - Windows DHCP Server (CVE-2026-69620) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ZDI: Windows DHCP Server: Windows DHCP Server chimes in with 36 bugs: 12 RCE, 18 DoS, five info leaks, and one EoP. Nothing exploited or disclosed, but 22 of the 36 require no authentication. It's the third-largest single-component pile of the month, and it's all one story: someone pointed a (likely AI-assisted) fuzzer at DHCP packet parsing. In addition to the two wormable bugs already mentioned, there are three more that didn’t carry the exact wormable verbiage but look like close cousins: CVE-2026-69845 (9.8, heap overflow), CVE-2026-69266 (8.8, integer overflow), and CVE-2026-69620 (8.1, stack overflow). If you're being generous, that's five wormable-shaped bugs in DHCP Server alone. The remaining seven RCEs need an authorized attacker. CWE spread is pure memory corruption: heap, stack, UAF, integer overflow. There are 18 DoS bugs, and 13 are unauthenticated at a CVSS score of 7.5. Malformed packet in, service crash out. Individually boring, but collectively, an unauthenticated attacker on the network has 13 different ways to take out DHCP, and when DHCP dies, clients stop getting leases and the helpdesk phone starts ringing. Finally, there are a couple of oddballs here: CVE-2026-69297 is an info leak that could expose passwords stored in a recoverable format, which is a configuration-secrets problem rather than a memory bug. The lone EoP is missing authentication on a critical function.
98.
Remote Code Execution - Windows DHCP Server (CVE-2026-69847) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
99.
Remote Code Execution - Windows DHCP Server (CVE-2026-69876) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
100.
Remote Code Execution - Windows DNS (CVE-2026-72987) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69730, CVE-2026-69813, CVE-2026-69858, & CVE-2026-72987: Windows DNS Server Remote Code Execution Vulnerability The use-after-free flaw in Windows DNS may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
101.
Remote Code Execution - Windows Deployment Services (CVE-2026-69607) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
102.
Remote Code Execution - Windows Deployment Services (CVE-2026-72943) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
103.
Remote Code Execution - Windows Deployment Services (CVE-2026-72954) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-72954: Windows Deployment Services Remote Code Execution Vulnerability The use-after-free flaw in Windows Deployment Services may allow an authenticated attacker to execute code over a network.
104.
Remote Code Execution - Windows Deployment Services (CVE-2026-72957) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-72957: Windows Deployment Services Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Deployment Services may allow an authenticated attacker to execute code locally.
ZDI: Exploitation More Likely: If you prioritize by Microsoft’s Exploit Index (XI), which I don’t recommend, there are a couple of bugs not mentioned yet: CVE-2026-72940 (Schannel RCE, CVSS 8.8, TLS stack), CVE-2026-72957 (Windows Deployment Services RCE, CVSS 7.8, PXE infrastructure), CVE-2026-71343 (Remote Access Connection Manager RCE, CVSS 7.8), and CVE-2026-70585 (a third NFS ONCRPC XDR RCE, CVSS 7.0). Again, I take all of these rating with a gigantic grain of salt, but you do you.
105.
Remote Code Execution - Windows HTTP Print Provider (CVE-2026-69623) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
106.
Remote Code Execution - Windows Internet Key Exchange (IKE) Protocol Extensions (CVE-2026-69429) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
107.
Remote Code Execution - Windows Link Layer Topology Discovery Protocol (CVE-2026-69732) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
108.
Remote Code Execution - Windows Message Queuing (CVE-2026-83997) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
109.
Remote Code Execution - Windows NTFS (CVE-2026-68875) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
110.
Remote Code Execution - Windows NTFS (CVE-2026-69479) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
111.
Remote Code Execution - Windows NTFS (CVE-2026-69638) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
112.
Remote Code Execution - Windows NTFS (CVE-2026-69709) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
113.
Remote Code Execution - Windows Reliable Multicast Transport Driver (RMCAST) (CVE-2026-69530) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69530, CVE-2026-78449, & CVE-2026-78450: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability The use-after-free flaw in the Reliable Multicast Transport Driver (RMCAST) may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
114.
Remote Code Execution - Windows Reliable Multicast Transport Driver (RMCAST) (CVE-2026-78449) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69530, CVE-2026-78449, & CVE-2026-78450: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability The use-after-free flaw in the Reliable Multicast Transport Driver (RMCAST) may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
115.
Remote Code Execution - Windows Reliable Multicast Transport Driver (RMCAST) (CVE-2026-78450) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69530, CVE-2026-78449, & CVE-2026-78450: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability The use-after-free flaw in the Reliable Multicast Transport Driver (RMCAST) may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
116.
Remote Code Execution - Windows Remote Access Connection Manager (CVE-2026-71343) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ZDI: Exploitation More Likely: If you prioritize by Microsoft’s Exploit Index (XI), which I don’t recommend, there are a couple of bugs not mentioned yet: CVE-2026-72940 (Schannel RCE, CVSS 8.8, TLS stack), CVE-2026-72957 (Windows Deployment Services RCE, CVSS 7.8, PXE infrastructure), CVE-2026-71343 (Remote Access Connection Manager RCE, CVSS 7.8), and CVE-2026-70585 (a third NFS ONCRPC XDR RCE, CVSS 7.0). Again, I take all of these rating with a gigantic grain of salt, but you do you.
117.
Remote Code Execution - Windows Routing and Remote Access Service (RRAS) (CVE-2026-69852) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69590, CVE-2026-69852, CVE-2026-72950, & CVE-2026-72959: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Successful exploitation of the vulnerability may allow an attacker to gain unauthenticated access to the victim’s machine.
118.
Remote Code Execution - Windows Routing and Remote Access Service (RRAS) (CVE-2026-70570) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
119.
Remote Code Execution - Windows Spaceport.sys (CVE-2026-69538) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
120.
Remote Code Execution - Windows Spaceport.sys (CVE-2026-71345) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
121.
Remote Code Execution - Windows Storage Spaces Controller (CVE-2026-68844) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
122.
Remote Code Execution - Windows Storage Spaces Controller (CVE-2026-68877) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
123.
Remote Code Execution - Windows Text Shaping (CVE-2026-69786) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
124.
Remote Code Execution - Windows VOLSNAP.SYS (CVE-2026-69426) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
125.
Security Feature Bypass - Windows TCP/IP (CVE-2026-69793) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
126.
Remote Code Execution - .NET and Visual Studio (CVE-2026-69522) - High [402]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | .NET and Visual Studio | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
127.
Remote Code Execution - .NET and Visual Studio (CVE-2026-71328) - High [402]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | .NET and Visual Studio | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
128.
Remote Code Execution - Raw Image Extension (CVE-2026-69649) - High [402]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Raw Image Extension | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69649: Raw Image Extension Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Raw Image Extension may allow an unauthenticated attacker to execute code over a network.
129.
Remote Code Execution - Web Media Extensions (CVE-2026-81352) - High [402]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Web Media Extensions | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-81352: Web Media Extensions Remote Code Execution Vulnerability The heap-based buffer overflow in the Microsoft Windows Codecs Library may allow an unauthenticated attacker to execute code over a network.
130.
Elevation of Privilege - Azure HDInsight Ambari (CVE-2026-81349) - Medium [399]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0.4 | 17 | The existence of a private exploit is mentioned on Microsoft:PrivateExploit:PoC website | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Azure HDInsight Ambari | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
131.
Elevation of Privilege - Windows Kernel (CVE-2026-83942) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | Windows Kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
132.
Elevation of Privilege - Windows SMB Client (CVE-2026-69544) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
133.
Elevation of Privilege - Windows Win32k (CVE-2026-68880) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
134.
Elevation of Privilege - Windows Win32k (CVE-2026-69301) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
135.
Elevation of Privilege - Windows Win32k (CVE-2026-69348) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
136.
Elevation of Privilege - Windows Win32k (CVE-2026-69689) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
137.
Elevation of Privilege - Windows Win32k (CVE-2026-69762) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
138.
Elevation of Privilege - Windows Win32k (CVE-2026-69844) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
139.
Elevation of Privilege - Windows Win32k (CVE-2026-70289) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
140.
Remote Code Execution - Microsoft Word (CVE-2026-78510) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Microsoft Word is a widely used commercial word processor developed by Microsoft. It is a component of the Microsoft Office suite of productivity software but can also be purchased as a standalone product. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-78509 & CVE-2026-78510: Microsoft Office Outlook Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Microsoft Office Outlook may allow an unauthenticated attacker to execute code over a network.
141.
Remote Code Execution - Skype for Business (CVE-2026-66302) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Skype for Business | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-66302: Skype for Business Remote Code Execution Vulnerability Successful exploitation of the vulnerability may allow an unauthenticated attacker to execute code over a network.
142.
Remote Code Execution - Windows Hyper-V (CVE-2026-69910) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Hardware virtualization component of the client editions of Windows NT | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
143.
Remote Code Execution - Windows BitLocker (CVE-2026-69449) - Medium [395]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
144.
Remote Code Execution - Windows Fast FAT Driver (CVE-2026-69347) - Medium [395]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
145.
Remote Code Execution - Windows NTFS (CVE-2026-68833) - Medium [395]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
146.
Remote Code Execution - Windows NTFS (CVE-2026-69566) - Medium [395]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
147.
Remote Code Execution - Windows NTFS (CVE-2026-71329) - Medium [395]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
148.
Remote Code Execution - Windows Remote Desktop Client (CVE-2026-69358) - Medium [395]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Remote Desktop Protocol Client | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
149.
Remote Code Execution - Windows Secure Socket Tunneling Protocol (SSTP) (CVE-2026-72930) - Medium [395]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
150.
Remote Code Execution - Windows Services for NFS ONCRPC XDR Driver (CVE-2026-70585) - Medium [395]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-70585: Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability The use-after-free flaw in Windows Services for NFS ONCRPC XDR Driver may allow an authenticated attacker to execute code locally.
ZDI: Exploitation More Likely: If you prioritize by Microsoft’s Exploit Index (XI), which I don’t recommend, there are a couple of bugs not mentioned yet: CVE-2026-72940 (Schannel RCE, CVSS 8.8, TLS stack), CVE-2026-72957 (Windows Deployment Services RCE, CVSS 7.8, PXE infrastructure), CVE-2026-71343 (Remote Access Connection Manager RCE, CVSS 7.8), and CVE-2026-70585 (a third NFS ONCRPC XDR RCE, CVSS 7.0). Again, I take all of these rating with a gigantic grain of salt, but you do you.
151.
Remote Code Execution - Windows Spaceport.sys (CVE-2026-71348) - Medium [395]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
152.
Remote Code Execution - Windows Spaceport.sys (CVE-2026-71349) - Medium [395]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
153.
Remote Code Execution - Windows Spaceport.sys (CVE-2026-71350) - Medium [395]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
154.
Remote Code Execution - Windows Spaceport.sys (CVE-2026-72952) - Medium [395]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
155.
Elevation of Privilege - Microsoft Exchange (CVE-2026-69641) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
156.
Elevation of Privilege - Windows Error Reporting (CVE-2026-83996) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
157.
Elevation of Privilege - Windows Hello (CVE-2026-69740) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69740, CVE-2026-69784, & CVE-2026-69864: Windows Hello Elevation of Privilege Vulnerability The use-after-free in Windows Hello may allow an authenticated attacker to elevate privileges locally.
158.
Elevation of Privilege - Windows Hello (CVE-2026-69784) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69740, CVE-2026-69784, & CVE-2026-69864: Windows Hello Elevation of Privilege Vulnerability The use-after-free in Windows Hello may allow an authenticated attacker to elevate privileges locally.
159.
Elevation of Privilege - Windows Management Services (CVE-2026-73012) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
160.
Elevation of Privilege - Windows Remote Desktop Services (CVE-2026-80096) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Remote Desktop Services, known as Terminal Services in Windows Server 2008 and earlier, is one of the components of Microsoft Windows that allow a user to initiate and control an interactive session on a remote computer or virtual machine over a network connection | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
161.
Remote Code Execution - HEVC Video Extensions (CVE-2026-58599) - Medium [390]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | HEVC Video Extensions | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-58599: HEVC Video Extensions Remote Code Execution Vulnerability The heap-based buffer overflow flaw in the Microsoft Windows Codecs Library may allow an unauthenticated attacker to execute code locally.
162.
Remote Code Execution - VHD Miniport Driver (CVE-2026-81355) - Medium [390]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | The Virtual Hard Disk (VHD) Miniport Driver is a Microsoft Windows kernel-mode storage driver that enables the operating system to mount, access, and manage Virtual Hard Disk (VHD and VHDX) files as block storage devices. It is used by Windows virtualization, backup, and virtual disk management features. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-81355: Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability The heap-based buffer overflow in the Virtual Hard Disk (VHD) Miniport Driver may allow an authenticated attacker to execute code locally.
163.
Elevation of Privilege - Windows Kernel (CVE-2026-68846) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | Windows Kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
164.
Elevation of Privilege - Windows Kernel (CVE-2026-68884) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | Windows Kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
165.
Elevation of Privilege - Windows Kernel (CVE-2026-69366) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | Windows Kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
166.
Elevation of Privilege - Windows Kernel (CVE-2026-69466) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | Windows Kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
167.
Elevation of Privilege - Windows Kernel (CVE-2026-69473) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | Windows Kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
168.
Elevation of Privilege - Windows Kernel (CVE-2026-69578) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | Windows Kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
169.
Elevation of Privilege - Windows Kernel (CVE-2026-85360) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | Windows Kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
170.
Elevation of Privilege - Windows TCP/IP (CVE-2026-69385) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
171.
Elevation of Privilege - Windows TCP/IP (CVE-2026-69404) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
172.
Elevation of Privilege - Windows TCP/IP (CVE-2026-69757) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
173.
Elevation of Privilege - Windows TCP/IP (CVE-2026-69761) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
174.
Elevation of Privilege - Windows Win32k (CVE-2026-69274) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
175.
Elevation of Privilege - Windows Win32k (CVE-2026-69333) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
176.
Elevation of Privilege - Windows Win32k (CVE-2026-69335) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
177.
Elevation of Privilege - Windows Win32k (CVE-2026-69410) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
178.
Elevation of Privilege - Windows Win32k (CVE-2026-69498) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
179.
Elevation of Privilege - Windows Win32k (CVE-2026-69610) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
180.
Elevation of Privilege - Windows Win32k (CVE-2026-69630) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
181.
Elevation of Privilege - Windows Win32k (CVE-2026-69652) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
182.
Elevation of Privilege - Windows Win32k (CVE-2026-69706) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
183.
Elevation of Privilege - Windows Win32k (CVE-2026-69779) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
184.
Elevation of Privilege - Windows Win32k (CVE-2026-69818) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
185.
Elevation of Privilege - Windows Win32k (CVE-2026-70283) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
186.
Remote Code Execution - Microsoft Office Graphics Component (CVE-2026-78439) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Microsoft Office | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-73006 & CVE-2026-78439: Microsoft Office Graphics Component Remote Code Execution Vulnerability The stack-based buffer overflow flaw in Microsoft Graphics Component may allow an unauthenticated attacker to execute code over a network.
187.
Remote Code Execution - Microsoft Word (CVE-2026-81952) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Microsoft Word is a widely used commercial word processor developed by Microsoft. It is a component of the Microsoft Office suite of productivity software but can also be purchased as a standalone product. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-81952: Microsoft Word Remote Code Execution Vulnerability The heap-based buffer overflow in Microsoft Office Word may allow an unauthenticated attacker to execute code over a network.
188.
Remote Code Execution - Windows Hyper-V (CVE-2026-69603) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Hardware virtualization component of the client editions of Windows NT | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69603: Windows Hyper-V Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Hyper-V may allow an authenticated attacker to execute code locally.
189.
Remote Code Execution - Windows Hyper-V (CVE-2026-80083) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Hardware virtualization component of the client editions of Windows NT | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-80083: Windows Hyper-V Remote Code Execution Vulnerability An untrusted pointer dereference flaw in Windows Hyper-V may allow an authenticated attacker to execute code locally.
190.
Remote Code Execution - Windows DHCP Server (CVE-2026-69878) - Medium [383]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 6.4. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
191.
Remote Code Execution - Windows DHCP Server (CVE-2026-77887) - Medium [383]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 6.4. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
192.
Remote Code Execution - Windows DHCP Server (CVE-2026-77891) - Medium [383]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 6.4. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
193.
Elevation of Privilege - Connected User Experiences and Telemetry (CVE-2026-69625) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
194.
Elevation of Privilege - Kernel Streaming WOW Thunk Service Driver (CVE-2026-69900) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
195.
Elevation of Privilege - Microsoft Exchange (CVE-2026-69380) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Tenable: CVE-2026-69380 | Microsoft Exchange Server elevation of privilege vulnerability
Tenable: CVE-2026-69380 is an EoP in Microsoft Exchange Server. It received a CVSSv3 score of 8.1 and is rated as important. This is a missing authorization vulnerability. An authenticated attacker with access to a mailbox through a low-user privilege user account could exploit this vulnerability to gain access to other mailboxes. Successful exploitation would allow the attacker to send and receive emails as other Exchange users as well as access attachments. Despite the high CVSS score, this vulnerability is rated as “Exploitation Less Likely” according to the Microsoft Exploitability Index.
ZDI: Exchange Server: Only nine bugs here, but there are some whoppers. Three different bugs rate CVSS 9.1 or higher. CVE-2026-69380 is an interesting exploit. A low-privileged user with a mailbox abuses request/token validation to impersonate any user and take over every mailbox: read, send, download attachments. Post-phish, this turns one compromised account into the whole org's mail. An unauthenticated mail-processing RCE plus a mailbox-takeover EoP in the same release is a chainable pair on paper. Initial access and lateral movement in one Cumulative Update. The other unauthenticated bug to mention is CVE-2026-69356, an specially crafted calendar invite; victim clicks the Join link, and script runs in their context. XSS wearing a spoofing label. Neat.
196.
Elevation of Privilege - Microsoft PowerShell (CVE-2026-69807) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | PowerShell or Microsoft PowerShell (formerly Windows PowerShell) is a task automation and configuration management program from Microsoft, consisting of a command-line shell and the associated scripting language | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
197.
Elevation of Privilege - Microsoft Windows Search Component (CVE-2026-68896) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
198.
Elevation of Privilege - Microsoft Windows Search Component (CVE-2026-69322) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
199.
Elevation of Privilege - Microsoft Windows Search Component (CVE-2026-69585) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
200.
Elevation of Privilege - Microsoft Windows Search Component (CVE-2026-69608) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
201.
Elevation of Privilege - Microsoft Windows Speech (CVE-2026-69444) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
202.
Elevation of Privilege - Microsoft Windows Speech (CVE-2026-69456) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
203.
Elevation of Privilege - Role: Windows Fax Service (CVE-2026-69509) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
204.
Elevation of Privilege - Role: Windows Fax Service (CVE-2026-72944) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
205.
Elevation of Privilege - Windows ALPC (CVE-2026-69874) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69874: Windows ALPC Elevation of Privilege Vulnerability Successful exploitation of the vulnerability may allow an authenticated attacker to elevate privileges locally.
206.
Elevation of Privilege - Windows Ancillary Function Driver for WinSock (CVE-2026-70342) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
207.
Elevation of Privilege - Windows Audio Service (CVE-2026-69447) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
208.
Elevation of Privilege - Windows Audio Service (CVE-2026-69604) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
209.
Elevation of Privilege - Windows Audio Service (CVE-2026-69801) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
210.
Elevation of Privilege - Windows Biometric Service (CVE-2026-69293) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
211.
Elevation of Privilege - Windows Biometric Service (CVE-2026-69298) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
212.
Elevation of Privilege - Windows Biometric Service (CVE-2026-69323) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
213.
Elevation of Privilege - Windows Biometric Service (CVE-2026-69352) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
214.
Elevation of Privilege - Windows Biometric Service (CVE-2026-69476) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
215.
Elevation of Privilege - Windows Biometric Service (CVE-2026-69489) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
216.
Elevation of Privilege - Windows Biometric Service (CVE-2026-69580) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
217.
Elevation of Privilege - Windows Biometric Service (CVE-2026-69583) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
218.
Elevation of Privilege - Windows Biometric Service (CVE-2026-69589) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
219.
Elevation of Privilege - Windows Biometric Service (CVE-2026-69593) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
220.
Elevation of Privilege - Windows Biometric Service (CVE-2026-69727) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ZDI: Windows Biometric Service: 64 bugs here, and 63 of them look almost identical. It's one bug class, stamped 56 times. CWE-122 heap-based buffer overflow accounts for 56 of them, with 5 integer overflows, 2 use-after-frees, and a NULL dereference rounding out the memory-corruption set. There are two worth noting: CVE-2026-69727. It has an outlier exploit vector: it reads “elevate privileges over a network” rather than locally, which is not what you want to see in a biometric service. The other is CVE-2026-73008. The lone info disclosure and it's CWE-359: exposure of private personal information. A biometric service leaking PII with high confidentiality impact is a worse look than the score implies. It also makes it a natural companion to the Hello cleartext tampering bug.
221.
Elevation of Privilege - Windows Biometric Service (CVE-2026-69738) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
222.
Elevation of Privilege - Windows Biometric Service (CVE-2026-69773) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
223.
Elevation of Privilege - Windows Biometric Service (CVE-2026-69787) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
224.
Elevation of Privilege - Windows Biometric Service (CVE-2026-69826) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
225.
Elevation of Privilege - Windows Biometric Service (CVE-2026-70572) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
226.
Elevation of Privilege - Windows Biometric Service (CVE-2026-70581) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
227.
Elevation of Privilege - Windows Biometric Service (CVE-2026-72941) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
228.
Elevation of Privilege - Windows Biometric Service (CVE-2026-72988) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
229.
Elevation of Privilege - Windows Biometric Service (CVE-2026-72990) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
230.
Elevation of Privilege - Windows Biometric Service (CVE-2026-72991) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
231.
Elevation of Privilege - Windows Biometric Service (CVE-2026-72992) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
232.
Elevation of Privilege - Windows Biometric Service (CVE-2026-72993) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
233.
Elevation of Privilege - Windows Biometric Service (CVE-2026-72994) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
234.
Elevation of Privilege - Windows Biometric Service (CVE-2026-72995) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
235.
Elevation of Privilege - Windows Biometric Service (CVE-2026-72996) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
236.
Elevation of Privilege - Windows Biometric Service (CVE-2026-72997) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
237.
Elevation of Privilege - Windows Biometric Service (CVE-2026-73000) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
238.
Elevation of Privilege - Windows Biometric Service (CVE-2026-73001) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
239.
Elevation of Privilege - Windows Biometric Service (CVE-2026-73002) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
240.
Elevation of Privilege - Windows Biometric Service (CVE-2026-73007) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
241.
Elevation of Privilege - Windows Biometric Service (CVE-2026-73011) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
242.
Elevation of Privilege - Windows Biometric Service (CVE-2026-73015) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
243.
Elevation of Privilege - Windows Biometric Service (CVE-2026-73020) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
244.
Elevation of Privilege - Windows Biometric Service (CVE-2026-73021) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
245.
Elevation of Privilege - Windows Biometric Service (CVE-2026-73026) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
246.
Elevation of Privilege - Windows Biometric Service (CVE-2026-77489) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
247.
Elevation of Privilege - Windows Biometric Service (CVE-2026-78447) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
248.
Elevation of Privilege - Windows Biometric Service (CVE-2026-78448) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
249.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83954) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
250.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83955) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
251.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83967) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
252.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83968) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
253.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83969) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
254.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83970) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
255.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83971) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
256.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83972) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
257.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83973) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
258.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83974) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
259.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83975) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
260.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83976) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
261.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83977) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
262.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83978) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
263.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83979) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
264.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83980) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
265.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83981) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
266.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83982) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
267.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83983) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
268.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83985) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
269.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83986) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
270.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83987) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
271.
Elevation of Privilege - Windows Biometric Service (CVE-2026-83988) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
272.
Elevation of Privilege - Windows BitLocker (CVE-2026-69458) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
273.
Elevation of Privilege - Windows Broker Infrastructure Service (CVE-2026-69391) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
274.
Elevation of Privilege - Windows CD-ROM Driver (CVE-2026-69283) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
275.
Elevation of Privilege - Windows CD-ROM Driver (CVE-2026-69561) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
276.
Elevation of Privilege - Windows Camera Frame Server Monitor (CVE-2026-69542) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
277.
Elevation of Privilege - Windows Compressed Folder (CVE-2026-69445) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
278.
Elevation of Privilege - Windows Core Messaging (CVE-2026-70583) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
279.
Elevation of Privilege - Windows Core Messaging (CVE-2026-70584) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
280.
Elevation of Privilege - Windows Credential Guard (CVE-2026-72958) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-72958: Windows Credential Guard Elevation of Privilege Vulnerability A double-free flaw in Windows Credential Guard may allow an authenticated attacker to elevate privileges locally.
281.
Elevation of Privilege - Windows Credential Providers (CVE-2026-69790) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
282.
Elevation of Privilege - Windows DCOM Server (CVE-2026-69284) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
283.
Elevation of Privilege - Windows DHCP Client (CVE-2026-69777) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
284.
Elevation of Privilege - Windows Device Association Service (CVE-2026-69478) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
285.
Elevation of Privilege - Windows Device Association Service (CVE-2026-69714) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
286.
Elevation of Privilege - Windows Device Association Service (CVE-2026-77500) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
287.
Elevation of Privilege - Windows Distributed File System (DFS) (CVE-2026-69424) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
288.
Elevation of Privilege - Windows Encrypting File System (EFS) (CVE-2026-69841) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
289.
Elevation of Privilege - Windows Enterprise App Management (CVE-2026-69481) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
290.
Elevation of Privilege - Windows Enterprise App Management (CVE-2026-69907) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
291.
Elevation of Privilege - Windows Error Reporting (CVE-2026-68894) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
292.
Elevation of Privilege - Windows Error Reporting (CVE-2026-69433) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
293.
Elevation of Privilege - Windows Error Reporting (CVE-2026-69436) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
294.
Elevation of Privilege - Windows Error Reporting (CVE-2026-69450) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
295.
Elevation of Privilege - Windows Error Reporting (CVE-2026-69462) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
296.
Elevation of Privilege - Windows Error Reporting (CVE-2026-69513) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
297.
Elevation of Privilege - Windows Error Reporting (CVE-2026-69612) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
298.
Elevation of Privilege - Windows Fast FAT Driver (CVE-2026-68878) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
299.
Elevation of Privilege - Windows GDI+ (CVE-2026-68827) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
300.
Elevation of Privilege - Windows Group Policy (CVE-2026-69717) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
301.
Elevation of Privilege - Windows Hello (CVE-2026-69710) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69710 & CVE-2026-69799: Windows Hello Elevation of Privilege Vulnerability A race condition in Windows Hello may allow an authenticated attacker to elevate privileges locally.
302.
Elevation of Privilege - Windows Hello (CVE-2026-69725) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69725: Windows Hello Elevation of Privilege Vulnerability A double-free flaw in Windows Hello may allow an authenticated attacker to elevate privileges locally.
303.
Elevation of Privilege - Windows Hello (CVE-2026-69799) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69710 & CVE-2026-69799: Windows Hello Elevation of Privilege Vulnerability A race condition in Windows Hello may allow an authenticated attacker to elevate privileges locally.
304.
Elevation of Privilege - Windows Hello (CVE-2026-69820) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69820 & CVE-2026-81354: Windows Hello Elevation of Privilege Vulnerability The heap-based buffer overflow flaw in Windows Hello may allow an authenticated attacker to elevate privileges locally.
305.
Elevation of Privilege - Windows Hello (CVE-2026-69864) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69740, CVE-2026-69784, & CVE-2026-69864: Windows Hello Elevation of Privilege Vulnerability The use-after-free in Windows Hello may allow an authenticated attacker to elevate privileges locally.
306.
Elevation of Privilege - Windows Hello (CVE-2026-81354) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69820 & CVE-2026-81354: Windows Hello Elevation of Privilege Vulnerability The heap-based buffer overflow flaw in Windows Hello may allow an authenticated attacker to elevate privileges locally.
307.
Elevation of Privilege - Windows Installer (CVE-2026-72929) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
308.
Elevation of Privilege - Windows Kerberos (CVE-2026-69685) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
309.
Elevation of Privilege - Windows Kerberos (CVE-2026-69822) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
310.
Elevation of Privilege - Windows Kernel-Mode Driver (CVE-2026-69421) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
311.
Elevation of Privilege - Windows MIDI Service Module (CVE-2026-69508) - Medium [380]
Description: Windows MIDI Service Module Elevation of Privileges Vulnerability
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
312.
Elevation of Privilege - Windows MIDI Service Module (CVE-2026-69720) - Medium [380]
Description: Windows MIDI Service Module Elevation of Privileges Vulnerability
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
313.
Elevation of Privilege - Windows Modern Device Management (MDM) (CVE-2026-69377) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
314.
Elevation of Privilege - Windows NFS Portmapper (CVE-2026-71334) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
315.
Elevation of Privilege - Windows NTFS (CVE-2026-68832) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
316.
Elevation of Privilege - Windows NTFS (CVE-2026-68834) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
317.
Elevation of Privilege - Windows NTFS (CVE-2026-68838) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
318.
Elevation of Privilege - Windows NTFS (CVE-2026-68841) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
319.
Elevation of Privilege - Windows NTFS (CVE-2026-69265) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
320.
Elevation of Privilege - Windows NTFS (CVE-2026-69312) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
321.
Elevation of Privilege - Windows NTFS (CVE-2026-69332) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
322.
Elevation of Privilege - Windows NTFS (CVE-2026-69505) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
323.
Elevation of Privilege - Windows NTFS (CVE-2026-69532) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
324.
Elevation of Privilege - Windows NTFS (CVE-2026-69875) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
325.
Elevation of Privilege - Windows NTFS (CVE-2026-77503) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
326.
Elevation of Privilege - Windows NTFS (CVE-2026-83995) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
327.
Elevation of Privilege - Windows Network Connection Broker (CVE-2026-72967) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
328.
Elevation of Privilege - Windows Overlay Filter (CVE-2026-69368) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
329.
Elevation of Privilege - Windows Overlay Filter (CVE-2026-69371) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
330.
Elevation of Privilege - Windows Partition Management Driver (CVE-2026-69480) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
331.
Elevation of Privilege - Windows Performance Monitor (CVE-2026-69324) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
332.
Elevation of Privilege - Windows Power Dependency Coordinator (CVE-2026-69459) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
333.
Elevation of Privilege - Windows Print Spooler Components (CVE-2026-68848) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
334.
Elevation of Privilege - Windows Print Spooler Components (CVE-2026-69346) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
335.
Elevation of Privilege - Windows Print Spooler Components (CVE-2026-69921) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
336.
Elevation of Privilege - Windows Print Spooler Components (CVE-2026-70564) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
337.
Elevation of Privilege - Windows Program Compatibility Assistant Service (CVE-2026-68845) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
338.
Elevation of Privilege - Windows Program Compatibility Assistant Service (CVE-2026-68876) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
339.
Elevation of Privilege - Windows Program Compatibility Assistant Service (CVE-2026-69534) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
340.
Elevation of Privilege - Windows Push Notifications (CVE-2026-62697) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
341.
Elevation of Privilege - Windows Remote Access Connection Manager (CVE-2026-69455) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
342.
Elevation of Privilege - Windows Remote Desktop Services (CVE-2026-69475) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Remote Desktop Services, known as Terminal Services in Windows Server 2008 and earlier, is one of the components of Microsoft Windows that allow a user to initiate and control an interactive session on a remote computer or virtual machine over a network connection | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
343.
Elevation of Privilege - Windows Resilient File System (ReFS) (CVE-2026-83952) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
344.
Elevation of Privilege - Windows Secure Kernel Mode (CVE-2026-69846) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69846: Windows Secure Kernel Mode Elevation of Privilege Vulnerability An integer overflow flaw in Windows Secure Kernel Mode may allow an authenticated attacker to elevate privileges locally.
345.
Elevation of Privilege - Windows Secure Kernel Mode (CVE-2026-69906) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69906: Windows Secure Kernel Mode Elevation of Privilege Vulnerability The heap-based buffer overflow flaw in Windows Secure Kernel Mode may allow an authenticated attacker to elevate privileges locally.
346.
Elevation of Privilege - Windows Secure Kernel Mode (CVE-2026-83939) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69501 & CVE-2026-83939: Windows Secure Kernel Mode Elevation of Privilege Vulnerability Untrusted pointer dereference in Windows Secure Kernel Mode may allow an authenticated attacker to elevate privileges locally.
347.
Elevation of Privilege - Windows Server (CVE-2026-56177) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
348.
Elevation of Privilege - Windows Services for NFS ONCRPC XDR Driver (CVE-2026-73024) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
349.
Elevation of Privilege - Windows Setup Files Cleanup (CVE-2026-69289) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
350.
Elevation of Privilege - Windows Shell (CVE-2026-69392) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
351.
Elevation of Privilege - Windows Shell (CVE-2026-69528) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
352.
Elevation of Privilege - Windows Smart Card (CVE-2026-69785) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
353.
Elevation of Privilege - Windows Spaceport.sys (CVE-2026-69512) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
354.
Elevation of Privilege - Windows Spaceport.sys (CVE-2026-69535) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
355.
Elevation of Privilege - Windows Spaceport.sys (CVE-2026-69643) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
356.
Elevation of Privilege - Windows Spaceport.sys (CVE-2026-69691) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
357.
Elevation of Privilege - Windows Spaceport.sys (CVE-2026-70569) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
358.
Elevation of Privilege - Windows Storage (CVE-2026-69328) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
359.
Elevation of Privilege - Windows Storage Management Provider (CVE-2026-69389) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
360.
Elevation of Privilege - Windows Storage Management Provider (CVE-2026-71337) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
361.
Elevation of Privilege - Windows Storage Spaces Controller (CVE-2026-69290) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
362.
Elevation of Privilege - Windows USB Audio Class driver (usbaudio.sys) (CVE-2026-69270) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
363.
Elevation of Privilege - Windows USB Audio Class driver (usbaudio.sys) (CVE-2026-69307) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
364.
Elevation of Privilege - Windows USB Audio Class driver (usbaudio.sys) (CVE-2026-69571) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
365.
Elevation of Privilege - Windows USB Audio Class driver (usbaudio.sys) (CVE-2026-69687) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
366.
Elevation of Privilege - Windows USB Audio Class driver (usbaudio.sys) (CVE-2026-69707) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
367.
Elevation of Privilege - Windows USB Driver (CVE-2026-69295) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
368.
Elevation of Privilege - Windows USB Driver (CVE-2026-69503) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
369.
Elevation of Privilege - Windows USB Driver (CVE-2026-72953) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
370.
Elevation of Privilege - Windows USB Video Driver (CVE-2026-69423) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
371.
Elevation of Privilege - Windows USB Video Driver (CVE-2026-69584) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
372.
Elevation of Privilege - Windows USB Video Driver (CVE-2026-72962) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-72962: Windows USB Video Driver Elevation of Privilege Vulnerability The heap-based buffer overflow flaw in the Windows USB Video Driver may allow an authenticated attacker to elevate local privileges.
373.
Elevation of Privilege - Windows Universal Disk Format File System Driver (UDFS) (CVE-2026-69592) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
374.
Elevation of Privilege - Windows Universal Disk Format File System Driver (UDFS) (CVE-2026-69758) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
375.
Elevation of Privilege - Windows VHD miniport driver (CVE-2026-56172) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
376.
Elevation of Privilege - Windows Virtual Trusted Platform Module (CVE-2026-69890) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69890: Windows Virtual Trusted Platform Module Elevation of Privilege Vulnerability The use-after-free flaw in the Windows Virtual Trusted Platform Module may allow an authenticated attacker to elevate local privileges.
377.
Elevation of Privilege - Windows Virtualization-Based Security (VBS) Enclave (CVE-2026-83498) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-83498: Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability An untrusted pointer dereference flaw in Windows Virtualization-Based Security (VBS) Enclave may allow an authenticated attacker to elevate privileges locally.
378.
Elevation of Privilege - Windows Volume Manager Extension Driver (CVE-2026-69582) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
379.
Elevation of Privilege - Windows Volume Manager Extension Driver (CVE-2026-77904) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
380.
Elevation of Privilege - Windows WebClient Service (CVE-2026-72965) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
381.
Elevation of Privilege - Windows Work Folders (CVE-2026-80075) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
382.
Elevation of Privilege - Windows exFAT File System (CVE-2026-69619) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
383.
Remote Code Execution - Internet Connection Sharing (ICS) (CVE-2026-72983) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Internet Connection Sharing (ICS) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-72983: Internet Connection Sharing (ICS) Remote Code Execution Vulnerability The use-after-free flaw in Windows Internet Connection Sharing (ICS) may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
384.
Remote Code Execution - Microsoft DirectMusic (CVE-2026-69491) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft DirectMusic | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
385.
Remote Code Execution - Microsoft Failover Cluster (CVE-2026-73010) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Failover Cluster | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-73010: Microsoft Failover Cluster Remote Code Execution Vulnerability The use-after-free flaw in Windows Failover Cluster may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
386.
Remote Code Execution - Microsoft Office Outlook (CVE-2026-78509) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Outlook | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-78509 & CVE-2026-78510: Microsoft Office Outlook Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Microsoft Office Outlook may allow an unauthenticated attacker to execute code over a network.
ZDI: Microsoft Office Components: There are 110 Office-family bugs this month (excluding SharePoint's 17): 64 RCE, 45 info disclosure, and 1 spoofing. Most are of the open-and-own variety, but a few stick out, namely a CVSS 98 bug in Outlook’s CVSS 9.8 duo. CVE-2026-78509 is a Critical RCE. It has a network vector, no user interaction per the metrics, and explicitly lists the Preview Pane as an attack vector. That's the worst combination Office offers: code execution from a message you merely preview. There are a few other Preview Pane bugs in Office and Word.
387.
Remote Code Execution - Microsoft Standard XPS (CVE-2026-69824) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Standard XPS | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ZDI: The Remnants: Another ~100 bugs land in six familiar components: Win32k (25), Standard XPS (18), WER (13), Device Association (13), Search (11), Print Spooler (11). Almost all are local EoPs to SYSTEM, but don't skim past them: 19 are rated More Likely, and XPS smuggles in an unauthenticated 9.8 RCE (CVE-2026-69824).
388.
Remote Code Execution - Microsoft UxTheme Library (uxtheme.dll) (CVE-2026-69276) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft UxTheme Library (uxtheme.dll) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
389.
Remote Code Execution - RPC Runtime Library (CVE-2026-69819) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | RPC Runtime Library | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
390.
Remote Code Execution - Remote Desktop Services Remote Code Execution Vulnerability (CVE-2026-69525) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Remote Desktop Services Remote Code Execution Vulnerability | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Tenable: CVE-2026-69525 | Remote Desktop Services remote code execution vulnerability
Tenable: CVE-2026-69525 is an RCE vulnerability affecting Remote Desktop Services. It received a CVSSv3 score of 9.8 and is rated as important. Successful exploitation of this flaw would allow an attacker to execute arbitrary code by exploiting a use-after-free flaw. Microsoft assesses this vulnerability as “Exploitation More Likely.”
Tenable: In addition to CVE-2026-69525, three RCEs in Remote Desktop Services were also patched this month. While each were rated as important, they differed in their CVSS scoring and exploitability rating as noted in the table below:
ZDI: - CVE-2026-69525 - Remote Desktop Services Remote Code Execution Vulnerability. This CVSS 9.8 bug allows remote, unauthenticated attackers to run arbitrary code on affected systems via a Use-After-Free bug. Microsoft notes it needs to be an “in-network attacker”, but the CVSS still says Network. Since many enterprises rely on RDP, I would treat this one seriously and test and deploy the patch soonest.
391.
Remote Code Execution - Telnet Client (CVE-2026-69431) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Telnet Client | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
392.
Security Feature Bypass - Microsoft PowerShell (CVE-2026-62801) - Medium [377]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | PowerShell or Microsoft PowerShell (formerly Windows PowerShell) is a task automation and configuration management program from Microsoft, consisting of a command-line shell and the associated scripting language | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
393.
Information Disclosure - Microsoft Remote Desktop App for Windows (CVE-2026-57098) - Medium [376]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
394.
Information Disclosure - Windows Device Health Attestation (DHA) (CVE-2026-69443) - Medium [376]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
395.
Information Disclosure - Windows Failover Cluster (CVE-2026-72989) - Medium [376]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
396.
Information Disclosure - Windows Message Queuing Queue Manager (CVE-2026-72932) - Medium [376]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
397.
Information Disclosure - Windows Mobile Broadband (CVE-2026-70579) - Medium [376]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
398.
Information Disclosure - Windows Remote Desktop Protocol (CVE-2026-70587) - Medium [376]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
399.
Information Disclosure - Windows Services for NFS ONCRPC XDR Driver (CVE-2026-71330) - Medium [376]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
400.
Elevation of Privilege - .NET and Visual Studio (CVE-2026-69439) - Medium [375]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.7 | 14 | .NET and Visual Studio | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
401.
Information Disclosure - Microsoft Discovery Studio (CVE-2026-62906) - Medium [374]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Discovery Studio | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to Microsoft data source | |
| 0.5 | 10 | EPSS Probability is 0.00666, EPSS Percentile is 0.49541 |
Qualys: CVE-2026-62906: Microsoft Discovery Studio Information Disclosure Vulnerability Improper neutralization of special elements in data query logic within Microsoft Discovery Studio may allow an unauthenticated attacker to disclose information over a network.
402.
Remote Code Execution - HEIF Image Extensions (CVE-2026-81353) - Medium [373]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | The HEIF Image Extension enables Windows 10 devices to read and write files that use the High Efficiency Image File (HEIF) format. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
403.
Remote Code Execution - Microsoft Excel (CVE-2026-81386) - Medium [373]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
404.
Remote Code Execution - Microsoft Excel (CVE-2026-81388) - Medium [373]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
405.
Remote Code Execution - Microsoft Excel (CVE-2026-81396) - Medium [373]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
406.
Remote Code Execution - Microsoft Excel (CVE-2026-81397) - Medium [373]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
407.
Remote Code Execution - Microsoft Excel (CVE-2026-81398) - Medium [373]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
408.
Remote Code Execution - Microsoft Excel (CVE-2026-81947) - Medium [373]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
409.
Remote Code Execution - Microsoft Excel (CVE-2026-81948) - Medium [373]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-81948, CVE-2026-81951, & CVE-2026-81959: Microsoft Excel Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Microsoft Office Excel may allow an unauthenticated attacker to execute code locally.
410.
Remote Code Execution - Microsoft Excel (CVE-2026-81949) - Medium [373]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-81949: Microsoft Excel Remote Code Execution Vulnerability An integer overflow flaw in Microsoft Office Excel may allow an unauthenticated attacker to execute code locally.
411.
Remote Code Execution - Microsoft Excel (CVE-2026-81950) - Medium [373]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-81950: Microsoft Excel Remote Code Execution Vulnerability A double-free flaw in Microsoft Office Excel may allow an unauthenticated attacker to execute code locally.
412.
Remote Code Execution - Microsoft Excel (CVE-2026-81951) - Medium [373]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-81948, CVE-2026-81951, & CVE-2026-81959: Microsoft Excel Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Microsoft Office Excel may allow an unauthenticated attacker to execute code locally.
413.
Remote Code Execution - Microsoft Excel (CVE-2026-81953) - Medium [373]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-81953: Microsoft Excel Remote Code Execution Vulnerability The stack-based buffer overflow flaw in Microsoft Office Excel may allow an unauthenticated attacker to execute code locally.
414.
Remote Code Execution - Microsoft Excel (CVE-2026-81954) - Medium [373]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
415.
Remote Code Execution - Microsoft Excel (CVE-2026-81956) - Medium [373]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
416.
Remote Code Execution - Microsoft Excel (CVE-2026-81957) - Medium [373]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
417.
Remote Code Execution - Microsoft Excel (CVE-2026-81959) - Medium [373]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-81948, CVE-2026-81951, & CVE-2026-81959: Microsoft Excel Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Microsoft Office Excel may allow an unauthenticated attacker to execute code locally.
418.
Remote Code Execution - Microsoft Excel (CVE-2026-81960) - Medium [373]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
419.
Remote Code Execution - Microsoft Word (CVE-2026-62804) - Medium [373]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Microsoft Word is a widely used commercial word processor developed by Microsoft. It is a component of the Microsoft Office suite of productivity software but can also be purchased as a standalone product. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
420.
Denial of Service - Windows TCP/IP (CVE-2026-69588) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
421.
Security Feature Bypass - Windows Container Manager Service (CVE-2026-69771) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | Windows component | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
422.
Information Disclosure - Windows Kernel (CVE-2026-69406) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | Windows Kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
423.
Information Disclosure - Windows Kernel (CVE-2026-69723) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | Windows Kernel | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
424.
Information Disclosure - Windows SMB Client (CVE-2026-69572) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
425.
Information Disclosure - Windows SMB Client (CVE-2026-69618) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
426.
Information Disclosure - Windows Win32k (CVE-2026-69609) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
427.
Information Disclosure - Windows Win32k (CVE-2026-69808) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
428.
Information Disclosure - Windows Win32k (CVE-2026-69832) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.6 | 10 | CVSS Base Score is 5.6. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
429.
Information Disclosure - Windows Win32k (CVE-2026-70290) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
430.
Remote Code Execution - Graphic Fonts (CVE-2026-72986) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Graphic Fonts | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-72986 & CVE-2026-73018: Graphic Fonts Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Graphic Fonts may allow an unauthenticated attacker to execute code over a network.
431.
Remote Code Execution - Graphic Fonts (CVE-2026-73018) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Graphic Fonts | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-72986 & CVE-2026-73018: Graphic Fonts Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Graphic Fonts may allow an unauthenticated attacker to execute code over a network.
432.
Remote Code Execution - Microsoft Dynamics 365 On-Premises (CVE-2026-65772) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Dynamics 365 On-Premises | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-65772: Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability The deserialization of untrusted data in Microsoft Dynamics 365 may allow an authenticated attacker to execute code over a network.
433.
Remote Code Execution - Microsoft Dynamics 365 On-Premises (CVE-2026-77908) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Dynamics 365 On-Premises | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
434.
Remote Code Execution - Microsoft Office Access (CVE-2026-69529) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Access | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
435.
Remote Code Execution - Microsoft Office Access (CVE-2026-69614) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Access | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
436.
Remote Code Execution - Microsoft Office Access (CVE-2026-69778) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Access | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
437.
Remote Code Execution - Microsoft Office Excel (CVE-2026-78518) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Excel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
438.
Remote Code Execution - Microsoft Office Outlook (CVE-2026-69629) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Outlook | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
439.
Remote Code Execution - Microsoft Office Outlook (CVE-2026-78519) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Outlook | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-78519: Microsoft Office Outlook Remote Code Execution Vulnerability Use of an uninitialized resource in Microsoft Office Outlook may allow an unauthenticated attacker to execute code over a network.
440.
Remote Code Execution - Microsoft Office Outlook (CVE-2026-78525) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Outlook | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-78525: Microsoft Office Outlook Remote Code Execution Vulnerability A use-after-free flaw in Microsoft Office Outlook may allow an unauthenticated attacker to execute code over a network.
441.
Remote Code Execution - Microsoft Office PowerPoint (CVE-2026-69678) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office PowerPoint | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69632, CVE-2026-69678, CVE-2026-69767, & CVE-2026-69797: Microsoft Office PowerPoint Remote Code Execution Vulnerability The use-after-free flaw in Microsoft Office PowerPoint may allow an unauthenticated attacker to execute code over a network.
442.
Remote Code Execution - Microsoft Office PowerPoint (CVE-2026-69767) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office PowerPoint | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69632, CVE-2026-69678, CVE-2026-69767, & CVE-2026-69797: Microsoft Office PowerPoint Remote Code Execution Vulnerability The use-after-free flaw in Microsoft Office PowerPoint may allow an unauthenticated attacker to execute code over a network.
443.
Remote Code Execution - Microsoft Office PowerPoint (CVE-2026-69797) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office PowerPoint | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69632, CVE-2026-69678, CVE-2026-69767, & CVE-2026-69797: Microsoft Office PowerPoint Remote Code Execution Vulnerability The use-after-free flaw in Microsoft Office PowerPoint may allow an unauthenticated attacker to execute code over a network.
444.
Remote Code Execution - Microsoft Office PowerPoint (CVE-2026-80081) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office PowerPoint | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
445.
Remote Code Execution - Microsoft Office Publisher (CVE-2026-69742) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Publisher | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
446.
Remote Code Execution - Microsoft Office Publisher (CVE-2026-81385) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Publisher | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
447.
Remote Code Execution - Microsoft Office SharePoint (CVE-2026-69268) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office SharePoint | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
448.
Remote Code Execution - Microsoft Office SharePoint (CVE-2026-69273) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office SharePoint | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
449.
Remote Code Execution - Microsoft Office SharePoint (CVE-2026-69282) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office SharePoint | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
450.
Remote Code Execution - Microsoft Office SharePoint (CVE-2026-69465) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office SharePoint | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ZDI: - CVE-2026-69465 - Microsoft Office SharePoint Remote Code Execution Vulnerability. I count 17 different SharePoint bugs in this release, with four leading to code execution. On its own, this bug doesn’t look like the worst, but SharePoint has been a popular target recently, and these are the types of bugs being used. An authenticated user can submit a page that bypasses a control-safety check, causing the affected server to load code from a filesystem under the attacker’s control. If you have SharePoint servers accessible from the internet, test and deploy these updates quickly.
451.
Remote Code Execution - Microsoft Office SharePoint (CVE-2026-69724) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office SharePoint | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
452.
Remote Code Execution - Microsoft Office Word (CVE-2026-69360) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
453.
Remote Code Execution - Microsoft Office Word (CVE-2026-69556) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
454.
Remote Code Execution - Microsoft Office Word (CVE-2026-69671) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
455.
Remote Code Execution - Microsoft Office Word (CVE-2026-69686) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
456.
Remote Code Execution - Microsoft Office Word (CVE-2026-69722) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
457.
Remote Code Execution - Microsoft Office Word (CVE-2026-69759) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
458.
Remote Code Execution - Microsoft Office Word (CVE-2026-69764) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
459.
Remote Code Execution - Microsoft Office Word (CVE-2026-72972) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
460.
Remote Code Execution - Microsoft Office Word (CVE-2026-72973) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
461.
Remote Code Execution - Microsoft Office Word (CVE-2026-77504) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-77504: Microsoft Office Word Remote Code Execution Vulnerability A double-free flaw in Microsoft Office Word may allow an unauthenticated attacker to execute code over a network.
462.
Remote Code Execution - Microsoft Office Word (CVE-2026-77901) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
463.
Remote Code Execution - Microsoft Office Word (CVE-2026-78504) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
464.
Remote Code Execution - Microsoft Office Word (CVE-2026-78507) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
465.
Remote Code Execution - Microsoft Office Word (CVE-2026-78511) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
466.
Remote Code Execution - Microsoft Office Word (CVE-2026-78512) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
467.
Remote Code Execution - Microsoft Office Word (CVE-2026-78514) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
468.
Remote Code Execution - Microsoft Office Word (CVE-2026-78517) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
469.
Remote Code Execution - Microsoft Office Word (CVE-2026-78521) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
470.
Remote Code Execution - Microsoft Office Word (CVE-2026-78526) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
471.
Remote Code Execution - Microsoft Office Word (CVE-2026-80080) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
472.
Remote Code Execution - Microsoft Office Word (CVE-2026-80085) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
473.
Remote Code Execution - Microsoft SQL Server (CVE-2026-67373) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
474.
Remote Code Execution - Microsoft SQL Server (CVE-2026-67380) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
475.
Remote Code Execution - Microsoft SQL Server (CVE-2026-67384) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
476.
Remote Code Execution - Microsoft SQL Server (CVE-2026-67385) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
477.
Remote Code Execution - Microsoft SQL Server (CVE-2026-67388) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
478.
Remote Code Execution - Microsoft SQL Server (CVE-2026-67631) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-67631 & CVE-2026-67643: Microsoft SQL Server Remote Code Execution Vulnerability The heap-based buffer overflow flaw in SQL Server may allow an authenticated attacker to execute code over a network.
479.
Remote Code Execution - Microsoft SQL Server (CVE-2026-67638) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
480.
Remote Code Execution - Microsoft SQL Server (CVE-2026-67639) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
481.
Remote Code Execution - Microsoft SQL Server (CVE-2026-67642) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
482.
Remote Code Execution - Microsoft SQL Server (CVE-2026-67643) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-67631 & CVE-2026-67643: Microsoft SQL Server Remote Code Execution Vulnerability The heap-based buffer overflow flaw in SQL Server may allow an authenticated attacker to execute code over a network.
483.
Remote Code Execution - Microsoft SQL Server (CVE-2026-68775) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
484.
Remote Code Execution - Microsoft SQL Server (CVE-2026-68786) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
485.
Remote Code Execution - Microsoft SQL Server (CVE-2026-77481) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
486.
Remote Code Execution - Microsoft SQL Server (CVE-2026-77482) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
487.
Remote Code Execution - Microsoft SQL Server (CVE-2026-77484) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
488.
Remote Code Execution - Microsoft SQL Server (CVE-2026-77486) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
489.
Remote Code Execution - Microsoft WDAC OLE DB provider for SQL (CVE-2026-72933) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft WDAC OLE DB provider for SQL | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
490.
Remote Code Execution - Microsoft WebP Image Extension (CVE-2026-70351) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft WebP Image Extension | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-70351: Microsoft WebP Image Extension Remote Code Execution Vulnerability An integer overflow flaw in Microsoft WebP Image Extension may allow an unauthenticated attacker to execute code over a network.
491.
Remote Code Execution - SQL Server (CVE-2026-78456) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
492.
Elevation of Privilege - Connected User Experiences and Telemetry (CVE-2026-68824) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
493.
Elevation of Privilege - Connected User Experiences and Telemetry (CVE-2026-68847) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
494.
Elevation of Privilege - Connected User Experiences and Telemetry (CVE-2026-69470) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
495.
Elevation of Privilege - Kernel Streaming WOW Thunk Service Driver (CVE-2026-69275) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
496.
Elevation of Privilege - Microsoft COM (CVE-2026-69299) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | COM is a platform-independent, distributed, object-oriented system for creating binary software components that can interact | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
497.
Elevation of Privilege - Microsoft Windows SCSI Class System File (CVE-2026-78451) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
498.
Elevation of Privilege - Microsoft Windows Search Component (CVE-2026-69305) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
499.
Elevation of Privilege - Microsoft Windows Search Component (CVE-2026-69600) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
500.
Elevation of Privilege - Microsoft Windows Search Component (CVE-2026-69911) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
501.
Elevation of Privilege - Role: Windows Fax Service (CVE-2026-69621) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
502.
Elevation of Privilege - Windows AF_UNIX Socket Provider (CVE-2026-70565) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
503.
Elevation of Privilege - Windows ALPC (CVE-2026-69834) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
504.
Elevation of Privilege - Windows Accounts Control (CVE-2026-69654) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
505.
Elevation of Privilege - Windows Accounts Control (CVE-2026-69816) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
506.
Elevation of Privilege - Windows Ancillary Function Driver for WinSock (CVE-2026-50349) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
507.
Elevation of Privilege - Windows Audio Service (CVE-2026-69311) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
508.
Elevation of Privilege - Windows Audio Service (CVE-2026-69394) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
509.
Elevation of Privilege - Windows Audio Service (CVE-2026-69540) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
510.
Elevation of Privilege - Windows Audio Service (CVE-2026-69692) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
511.
Elevation of Privilege - Windows Audio Service (CVE-2026-70562) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
512.
Elevation of Privilege - Windows Authentication Methods (CVE-2026-73005) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
513.
Elevation of Privilege - Windows Bind Filter Driver (CVE-2026-68825) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
514.
Elevation of Privilege - Windows Biometric Service (CVE-2026-70573) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
515.
Elevation of Privilege - Windows Bluetooth Port Driver (CVE-2026-69817) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
516.
Elevation of Privilege - Windows Bluetooth Service (CVE-2026-69388) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
517.
Elevation of Privilege - Windows Bluetooth Service (CVE-2026-69398) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
518.
Elevation of Privilege - Windows Bluetooth Service (CVE-2026-69448) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
519.
Elevation of Privilege - Windows Bluetooth Service (CVE-2026-69889) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
520.
Elevation of Privilege - Windows Boot Manager (CVE-2026-77892) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
521.
Elevation of Privilege - Windows Broadcast DVR User Service (CVE-2026-69735) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
522.
Elevation of Privilege - Windows Cloud Files Mini Filter Driver (CVE-2026-69279) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
523.
Elevation of Privilege - Windows Cloud Files Mini Filter Driver (CVE-2026-80093) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
524.
Elevation of Privilege - Windows Credential Guard (CVE-2026-70578) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
525.
Elevation of Privilege - Windows Credential Providers (CVE-2026-69814) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
526.
Elevation of Privilege - Windows DHCP Server (CVE-2026-69415) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
527.
Elevation of Privilege - Windows DNS (CVE-2026-69310) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
528.
Elevation of Privilege - Windows DNS (CVE-2026-72948) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
529.
Elevation of Privilege - Windows DWM Core Library (CVE-2026-69775) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
530.
Elevation of Privilege - Windows Defender Firewall Service (CVE-2026-70568) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
531.
Elevation of Privilege - Windows Device Association Broker Service (CVE-2026-69314) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
532.
Elevation of Privilege - Windows Device Association Broker Service (CVE-2026-69693) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
533.
Elevation of Privilege - Windows Device Association Service (CVE-2026-69296) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
534.
Elevation of Privilege - Windows Device Association Service (CVE-2026-69488) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
535.
Elevation of Privilege - Windows Device Association Service (CVE-2026-69574) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
536.
Elevation of Privilege - Windows Device Association Service (CVE-2026-69581) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
537.
Elevation of Privilege - Windows Device Association Service (CVE-2026-69711) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
538.
Elevation of Privilege - Windows Device Association Service (CVE-2026-69791) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
539.
Elevation of Privilege - Windows Device Association Service (CVE-2026-69866) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
540.
Elevation of Privilege - Windows Device Association Service (CVE-2026-83940) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
541.
Elevation of Privilege - Windows Devices Human Interface (CVE-2026-69472) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
542.
Elevation of Privilege - Windows Display Enhancement Service (CVE-2026-70567) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
543.
Elevation of Privilege - Windows Embedded Mode Service (CVE-2026-69430) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
544.
Elevation of Privilege - Windows Encrypting File System (EFS) (CVE-2026-69688) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
545.
Elevation of Privilege - Windows Error Reporting (CVE-2026-69362) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
546.
Elevation of Privilege - Windows Error Reporting (CVE-2026-69896) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
547.
Elevation of Privilege - Windows File History Service (CVE-2026-68837) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
548.
Elevation of Privilege - Windows File History Service (CVE-2026-71340) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
549.
Elevation of Privilege - Windows HTTP.sys (CVE-2026-69597) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
550.
Elevation of Privilege - Windows Host Guardian Service (CVE-2026-69682) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
551.
Elevation of Privilege - Windows IP Address Management (IPAM) Service (CVE-2026-69694) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
552.
Elevation of Privilege - Windows Image Acquisition (CVE-2026-69341) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
553.
Elevation of Privilege - Windows Image Acquisition (CVE-2026-69500) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
554.
Elevation of Privilege - Windows Image Acquisition (CVE-2026-69613) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
555.
Elevation of Privilege - Windows Installer (CVE-2026-62694) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
556.
Elevation of Privilege - Windows Installer (CVE-2026-69441) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
557.
Elevation of Privilege - Windows Installer (CVE-2026-71339) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
558.
Elevation of Privilege - Windows Installer (CVE-2026-77894) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
559.
Elevation of Privilege - Windows Internet Connection Sharing (ICS) (CVE-2026-72926) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
560.
Elevation of Privilege - Windows License Manager (CVE-2026-69281) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
561.
Elevation of Privilege - Windows MIDI Service Module (CVE-2026-69440) - Medium [368]
Description: Windows MIDI Service Module Elevation of Privileges Vulnerability
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
562.
Elevation of Privilege - Windows MIDI Service Module (CVE-2026-78464) - Medium [368]
Description: Windows MIDI Service Module Elevation of Privileges Vulnerability
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
563.
Elevation of Privilege - Windows Management Instrumentation (CVE-2026-69451) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
564.
Elevation of Privilege - Windows Management Instrumentation (CVE-2026-77905) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
565.
Elevation of Privilege - Windows Media (CVE-2026-69891) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
566.
Elevation of Privilege - Windows Message Queuing (CVE-2026-69645) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
567.
Elevation of Privilege - Windows Modern Device Management (MDM) (CVE-2026-69460) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
568.
Elevation of Privilege - Windows Modern Device Management (MDM) (CVE-2026-70577) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
569.
Elevation of Privilege - Windows Modern Device Management (MDM) (CVE-2026-73003) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
570.
Elevation of Privilege - Windows Modern Device Management (MDM) (CVE-2026-73022) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
571.
Elevation of Privilege - Windows Modern Execution Server (CVE-2026-72963) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
572.
Elevation of Privilege - Windows NDIS (CVE-2026-69357) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
573.
Elevation of Privilege - Windows NDIS (CVE-2026-69396) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
574.
Elevation of Privilege - Windows NTFS (CVE-2026-69340) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
575.
Elevation of Privilege - Windows NTFS (CVE-2026-69379) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
576.
Elevation of Privilege - Windows NTFS (CVE-2026-69567) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
577.
Elevation of Privilege - Windows NTFS (CVE-2026-72935) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.7 | 10 | CVSS Base Score is 6.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
578.
Elevation of Privilege - Windows Notification (CVE-2026-69648) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
579.
Elevation of Privilege - Windows Online Certificate Status Protocol (OCSP) (CVE-2026-69564) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
580.
Elevation of Privilege - Windows Overlay Filter (CVE-2026-69350) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
581.
Elevation of Privilege - Windows Overlay Filter (CVE-2026-69373) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
582.
Elevation of Privilege - Windows Partition Management Driver (CVE-2026-69492) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
583.
Elevation of Privilege - Windows Print Spooler Components (CVE-2026-68835) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
584.
Elevation of Privilege - Windows Print Spooler Components (CVE-2026-69309) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
585.
Elevation of Privilege - Windows Print Spooler Components (CVE-2026-69364) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
586.
Elevation of Privilege - Windows Print Spooler Components (CVE-2026-69838) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
587.
Elevation of Privilege - Windows PrintWorkflowUserSvc (CVE-2026-69602) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
588.
Elevation of Privilege - Windows Program Compatibility Assistant Service (CVE-2026-69563) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
589.
Elevation of Privilege - Windows Push Notifications (CVE-2026-69280) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
590.
Elevation of Privilege - Windows Push Notifications (CVE-2026-69300) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
591.
Elevation of Privilege - Windows Registry (CVE-2026-69337) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
592.
Elevation of Privilege - Windows Remote Access Connection Manager (CVE-2026-69331) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
593.
Elevation of Privilege - Windows Remote Access Connection Manager (CVE-2026-71333) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
594.
Elevation of Privilege - Windows Remote Access Connection Manager (CVE-2026-71342) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
595.
Elevation of Privilege - Windows Remote Desktop Services (CVE-2026-69287) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Remote Desktop Services, known as Terminal Services in Windows Server 2008 and earlier, is one of the components of Microsoft Windows that allow a user to initiate and control an interactive session on a remote computer or virtual machine over a network connection | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
596.
Elevation of Privilege - Windows Resilient File System (ReFS) (CVE-2026-69617) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
597.
Elevation of Privilege - Windows Resilient File System (ReFS) Deduplication Service (CVE-2026-83999) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
598.
Elevation of Privilege - Windows Routing and Remote Access Service (RRAS) (CVE-2026-71351) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
599.
Elevation of Privilege - Windows Routing and Remote Access Service (RRAS) (CVE-2026-71353) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
600.
Elevation of Privilege - Windows Secure Kernel Mode (CVE-2026-69501) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69501 & CVE-2026-83939: Windows Secure Kernel Mode Elevation of Privilege Vulnerability Untrusted pointer dereference in Windows Secure Kernel Mode may allow an authenticated attacker to elevate privileges locally.
601.
Elevation of Privilege - Windows Secure Socket Tunneling Protocol (SSTP) (CVE-2026-71332) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
602.
Elevation of Privilege - Windows Security Health Service (CVE-2026-78457) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
603.
Elevation of Privilege - Windows Shell (CVE-2026-69383) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
604.
Elevation of Privilege - Windows Shell (CVE-2026-69606) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
605.
Elevation of Privilege - Windows Storage Spaces Controller (CVE-2026-69575) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
606.
Elevation of Privilege - Windows USB Audio Class driver (usbaudio.sys) (CVE-2026-69413) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
607.
Elevation of Privilege - Windows USB Audio Class driver (usbaudio.sys) (CVE-2026-69469) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.6. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
608.
Elevation of Privilege - Windows USB Audio Class driver (usbaudio.sys) (CVE-2026-69859) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
609.
Elevation of Privilege - Windows USB Driver (CVE-2026-68840) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
610.
Elevation of Privilege - Windows USB Hub Driver (CVE-2026-72999) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
611.
Elevation of Privilege - Windows USB Mass Storage Class Driver (CVE-2026-69490) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
612.
Elevation of Privilege - Windows USB Video Driver (CVE-2026-69319) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
613.
Elevation of Privilege - Windows USB Video Driver (CVE-2026-69422) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
614.
Elevation of Privilege - Windows Universal Disk Format File System Driver (UDFS) (CVE-2026-69573) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
615.
Elevation of Privilege - Windows Volume Manager Extension Driver (CVE-2026-69468) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
616.
Elevation of Privilege - Windows Web Platform Storage (CVE-2026-69708) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
617.
Elevation of Privilege - Windows Wireless Networking (CVE-2026-69517) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
618.
Elevation of Privilege - Windows Work Folder Service (CVE-2026-69560) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
619.
Elevation of Privilege - Copilot Studio (CVE-2026-80098) - Medium [366]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Copilot Studio | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00293, EPSS Percentile is 0.21577 |
Qualys: CVE-2026-80098: Copilot Studio Elevation of Privilege Vulnerability An improper verification of a cryptographic signature in Copilot Studio may allow an unauthenticated attacker to elevate privileges over a network.
620.
Elevation of Privilege - Microsoft Fabric (CVE-2026-70178) - Medium [366]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Fabric | |
| 0.8 | 10 | CVSS Base Score is 8.5. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00414, EPSS Percentile is 0.34685 |
Qualys: CVE-2026-70178: Microsoft Fabric Elevation of Privilege Vulnerability A missing authorization flaw in Microsoft Fabric may allow an authenticated attacker to elevate privileges over a network.
621.
Elevation of Privilege - Power Automate (CVE-2026-65818) - Medium [366]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Power Automate | |
| 0.8 | 10 | CVSS Base Score is 8.5. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00329, EPSS Percentile is 0.2558 |
Qualys: CVE-2026-65818: Power Automate Elevation of Privilege Vulnerability The server-side request forgery (SSRF) flaw in Power Automate may allow an authenticated attacker to elevate privileges over a network.
622.
Security Feature Bypass - Windows Modern Device Management (MDM) (CVE-2026-69674) - Medium [365]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
623.
Information Disclosure - Microsoft Office (CVE-2026-69626) - Medium [364]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
624.
Information Disclosure - Microsoft Office (CVE-2026-69739) - Medium [364]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
625.
Information Disclosure - Microsoft Office (CVE-2026-80076) - Medium [364]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
626.
Information Disclosure - Microsoft Office (CVE-2026-80078) - Medium [364]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
627.
Information Disclosure - Microsoft Office (CVE-2026-80082) - Medium [364]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
628.
Information Disclosure - Microsoft Office (CVE-2026-80087) - Medium [364]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
629.
Information Disclosure - Microsoft Office (CVE-2026-80089) - Medium [364]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
630.
Information Disclosure - Microsoft Office (CVE-2026-80091) - Medium [364]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
631.
Information Disclosure - Microsoft Windows SCSI Class System File (CVE-2026-78453) - Medium [364]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
632.
Information Disclosure - Windows Compressed Folder (CVE-2026-70019) - Medium [364]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
633.
Information Disclosure - Windows Connected User Experiences and Telemetry (CVE-2026-69267) - Medium [364]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
634.
Information Disclosure - Windows DHCP Server (CVE-2026-69297) - Medium [364]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ZDI: Windows DHCP Server: Windows DHCP Server chimes in with 36 bugs: 12 RCE, 18 DoS, five info leaks, and one EoP. Nothing exploited or disclosed, but 22 of the 36 require no authentication. It's the third-largest single-component pile of the month, and it's all one story: someone pointed a (likely AI-assisted) fuzzer at DHCP packet parsing. In addition to the two wormable bugs already mentioned, there are three more that didn’t carry the exact wormable verbiage but look like close cousins: CVE-2026-69845 (9.8, heap overflow), CVE-2026-69266 (8.8, integer overflow), and CVE-2026-69620 (8.1, stack overflow). If you're being generous, that's five wormable-shaped bugs in DHCP Server alone. The remaining seven RCEs need an authorized attacker. CWE spread is pure memory corruption: heap, stack, UAF, integer overflow. There are 18 DoS bugs, and 13 are unauthenticated at a CVSS score of 7.5. Malformed packet in, service crash out. Individually boring, but collectively, an unauthenticated attacker on the network has 13 different ways to take out DHCP, and when DHCP dies, clients stop getting leases and the helpdesk phone starts ringing. Finally, there are a couple of oddballs here: CVE-2026-69297 is an info leak that could expose passwords stored in a recoverable format, which is a configuration-secrets problem rather than a memory bug. The lone EoP is missing authentication on a critical function.
635.
Information Disclosure - Windows OLE DB (CVE-2026-78441) - Medium [364]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
636.
Information Disclosure - Windows Spaceport.sys (CVE-2026-72942) - Medium [364]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
637.
Elevation of Privilege - .NET (CVE-2026-69805) - Medium [363]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.7 | 14 | .NET | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
638.
Elevation of Privilege - HEVC Video Extensions (CVE-2026-58600) - Medium [363]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.7 | 14 | HEVC Video Extensions | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
639.
Elevation of Privilege - VHD Miniport Driver (CVE-2026-69541) - Medium [363]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.7 | 14 | The Virtual Hard Disk (VHD) Miniport Driver is a Microsoft Windows kernel-mode storage driver that enables the operating system to mount, access, and manage Virtual Hard Disk (VHD and VHDX) files as block storage devices. It is used by Windows virtualization, backup, and virtual disk management features. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
640.
Elevation of Privilege - VHD Miniport Driver (CVE-2026-69681) - Medium [363]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.7 | 14 | The Virtual Hard Disk (VHD) Miniport Driver is a Microsoft Windows kernel-mode storage driver that enables the operating system to mount, access, and manage Virtual Hard Disk (VHD and VHDX) files as block storage devices. It is used by Windows virtualization, backup, and virtual disk management features. | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
641.
Elevation of Privilege - VHD Miniport Driver (CVE-2026-70574) - Medium [363]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.7 | 14 | The Virtual Hard Disk (VHD) Miniport Driver is a Microsoft Windows kernel-mode storage driver that enables the operating system to mount, access, and manage Virtual Hard Disk (VHD and VHDX) files as block storage devices. It is used by Windows virtualization, backup, and virtual disk management features. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
642.
Remote Code Execution - Microsoft Excel (CVE-2026-81389) - Medium [361]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
643.
Information Disclosure - Windows Win32k (CVE-2026-69853) - Medium [357]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Win32k.sys driver is the kernel side of some core parts of the Windows subsystem. Its main functionality is the GUI of Windows; it's responsible for window management. | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
644.
Remote Code Execution - Graphics Kernel (CVE-2026-73017) - Medium [357]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Graphics Kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-73017: Graphics Kernel Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Graphics Kernel may allow an authenticated attacker to execute code locally.
645.
Remote Code Execution - IP Helper (CVE-2026-72981) - Medium [357]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | IP Helper | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-72981: IP Helper Remote Code Execution Vulnerability The use-after-free flaw in IP Helper may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
646.
Remote Code Execution - Microsoft Azure CLI (CVE-2026-83948) - Medium [357]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Azure CLI | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
647.
Remote Code Execution - Microsoft Failover Cluster (CVE-2026-78444) - Medium [357]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Failover Cluster | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-78444: Microsoft Failover Cluster Remote Code Execution Vulnerability An untrusted pointer dereference flaw in Windows Failover Cluster may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
648.
Remote Code Execution - Microsoft Graphics Component (CVE-2026-84000) - Medium [357]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Graphics Component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
649.
Remote Code Execution - Microsoft JScript (CVE-2026-69325) - Medium [357]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft JScript | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
650.
Remote Code Execution - Microsoft JScript (CVE-2026-69438) - Medium [357]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft JScript | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
651.
Remote Code Execution - Microsoft Office SharePoint (CVE-2026-69804) - Medium [357]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office SharePoint | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
652.
Remote Code Execution - Microsoft SQL Server (CVE-2026-47297) - Medium [357]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
653.
Remote Code Execution - Microsoft SQL Server (CVE-2026-67378) - Medium [357]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.8 | 10 | CVSS Base Score is 8.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-67378: Microsoft SQL Server Remote Code Execution Vulnerability Successful exploitation of the vulnerability may allow an authenticated attacker to execute code over a network.
ZDI: Microsoft SQL Server: As previously mentioned, there are over 62 SQL Server bugs in this release: 61 in SQL Server proper plus the Azure Arc SQL Server Extension. Here’s the breakdown: 23 RCE, 14 EoP, 21 info disclosure, three DoS, and one SFB. Five are Critical. The overwhelming pattern is authenticated memory corruption. 55 of 62 require an authorized attacker, and the CWE spread is dominated by heap overflows (15 of the RCEs are CWE-122 alone) and out-of-bounds reads (13 of the info leaks). The template is CVE-2026-67378’s: log in, submit a crafted query, corrupt memory, run code on the server. That's why the 8.8s here are less scary than they score; an attacker already needs database credentials, but it's also textbook post-compromise lateral movement.
654.
Remote Code Execution - Microsoft SQL Server (CVE-2026-67379) - Medium [357]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.8 | 10 | CVSS Base Score is 8.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
655.
Remote Code Execution - Microsoft SQL Server (CVE-2026-67636) - Medium [357]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.8 | 10 | CVSS Base Score is 8.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-67636: Microsoft SQL Server Remote Code Execution Vulnerability An out-of-bounds read flaw in SQL Server may allow an authenticated attacker to execute code over a network.
656.
Remote Code Execution - Microsoft SQL Server (CVE-2026-68787) - Medium [357]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
657.
Remote Code Execution - Remote Desktop Services Remote Code Execution Vulnerability (CVE-2026-69514) - Medium [357]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Remote Desktop Services Remote Code Execution Vulnerability | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
658.
Remote Code Execution - Remote Desktop Services Remote Code Execution Vulnerability (CVE-2026-69539) - Medium [357]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Remote Desktop Services Remote Code Execution Vulnerability | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
659.
Remote Code Execution - Remote Desktop Services Remote Code Execution Vulnerability (CVE-2026-69599) - Medium [357]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Remote Desktop Services Remote Code Execution Vulnerability | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
660.
Elevation of Privilege - Windows Failover Cluster (CVE-2026-71338) - Medium [356]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 6.4. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
661.
Elevation of Privilege - Windows File History Service (CVE-2026-72947) - Medium [356]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 6.4. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
662.
Elevation of Privilege - Windows Management Instrumentation (CVE-2026-70582) - Medium [356]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 6.4. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
663.
Elevation of Privilege - Entra ID (CVE-2026-83941) - Medium [354]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Entra ID | |
| 1.0 | 10 | CVSS Base Score is 9.9. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-83941: Entra ID Elevation of Privilege Vulnerability A missing authorization flaw in Entra ID may allow an authenticated attacker to elevate privileges over a network.
664.
Elevation of Privilege - Microsoft SQL Server (CVE-2026-65669) - Medium [354]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft SQL Server | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-65669: Microsoft SQL Server Elevation of Privilege Vulnerability The code injection flaw in SQL Server may allow an unauthenticated attacker to elevate privileges over a network.
ZDI: - CVE-2026-65669 - Microsoft SQL Server Elevation of Privilege Vulnerability. Speaking of AI-assisted code audits, there are over 60 patches for SQL Server in the September release. This bug even has an AI component, as the attacker would need to convince a user to submit specially crafted instructions to SQL Copilot in SQL Server Management Studio. So there’s the user interaction component, but if they succeed, the attacker could gain access to the database at the user’s permission level. Patching SQL Server will not be trivial this month, so take your time with your testing and really guard those SQL Servers that may be connected to the Internet.
665.
Denial of Service - ASP.NET Core (CVE-2026-57099) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | An open-source, server-side web-application framework designed for web development | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
666.
Denial of Service - Microsoft Exchange (CVE-2026-69378) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
667.
Denial of Service - Windows Active Directory Domain Services (CVE-2026-69809) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
668.
Denial of Service - Windows DHCP Server (CVE-2026-69342) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
669.
Denial of Service - Windows DHCP Server (CVE-2026-70065) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
670.
Denial of Service - Windows DHCP Server (CVE-2026-77494) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
671.
Denial of Service - Windows DHCP Server (CVE-2026-77498) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
672.
Denial of Service - Windows DHCP Server (CVE-2026-77499) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
673.
Denial of Service - Windows DHCP Server (CVE-2026-77501) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
674.
Denial of Service - Windows DHCP Server (CVE-2026-77502) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
675.
Denial of Service - Windows DHCP Server (CVE-2026-77886) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
676.
Denial of Service - Windows DHCP Server (CVE-2026-77888) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
677.
Denial of Service - Windows DHCP Server (CVE-2026-77889) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
678.
Denial of Service - Windows DHCP Server (CVE-2026-77890) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
679.
Denial of Service - Windows DHCP Server (CVE-2026-77893) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
680.
Denial of Service - Windows DHCP Server (CVE-2026-77895) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
681.
Denial of Service - Windows DNS (CVE-2026-69631) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
682.
Denial of Service - Windows Internet Key Exchange (IKE) Extension (CVE-2026-69587) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
683.
Denial of Service - Windows Internet Key Exchange (IKE) Extension (CVE-2026-69881) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
684.
Denial of Service - Windows Kerberos (CVE-2026-69744) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
685.
Denial of Service - Windows Kerberos (CVE-2026-69760) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
686.
Denial of Service - Windows Key Distribution Center (CVE-2026-84001) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
687.
Denial of Service - Windows LDAP - Lightweight Directory Access Protocol (CVE-2026-69428) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
688.
Denial of Service - Windows Message Queuing Queue Manager (CVE-2026-68887) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
689.
Denial of Service - Windows SMB Server Network Transport Driver (srvnet.sys) (CVE-2026-72949) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
690.
Denial of Service - Windows Services for NFS ONCRPC XDR Driver (CVE-2026-83989) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
691.
Security Feature Bypass - Windows Win32K (CVE-2026-69792) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Windows component | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
692.
Information Disclosure - Microsoft COM (CVE-2026-69294) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | COM is a platform-independent, distributed, object-oriented system for creating binary software components that can interact | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
693.
Information Disclosure - Microsoft Exchange (CVE-2026-69382) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
694.
Information Disclosure - Microsoft Windows Search Component (CVE-2026-69507) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
695.
Information Disclosure - Microsoft Windows Search Component (CVE-2026-70145) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
696.
Information Disclosure - Storage Spaces Controller (CVE-2026-69568) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Storage Spaces Controller | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
697.
Information Disclosure - Windows Biometric Service (CVE-2026-73008) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ZDI: Windows Biometric Service: 64 bugs here, and 63 of them look almost identical. It's one bug class, stamped 56 times. CWE-122 heap-based buffer overflow accounts for 56 of them, with 5 integer overflows, 2 use-after-frees, and a NULL dereference rounding out the memory-corruption set. There are two worth noting: CVE-2026-69727. It has an outlier exploit vector: it reads “elevate privileges over a network” rather than locally, which is not what you want to see in a biometric service. The other is CVE-2026-73008. The lone info disclosure and it's CWE-359: exposure of private personal information. A biometric service leaking PII with high confidentiality impact is a worse look than the score implies. It also makes it a natural companion to the Hello cleartext tampering bug.
698.
Information Disclosure - Windows CD-ROM Driver (CVE-2026-78454) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
699.
Information Disclosure - Windows DHCP Server (CVE-2026-69803) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
700.
Information Disclosure - Windows DHCP Server (CVE-2026-69929) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
701.
Information Disclosure - Windows DHCP Server (CVE-2026-69930) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
702.
Information Disclosure - Windows DHCP Server (CVE-2026-70124) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
703.
Information Disclosure - Windows DNS (CVE-2026-69369) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
704.
Information Disclosure - Windows DNS (CVE-2026-69672) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
705.
Information Disclosure - Windows Defender Firewall Service (CVE-2026-68831) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
706.
Information Disclosure - Windows Encrypting File System (EFS) (CVE-2026-69794) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
707.
Information Disclosure - Windows Error Reporting (CVE-2026-69684) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
708.
Information Disclosure - Windows GDI (CVE-2026-77491) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
709.
Information Disclosure - Windows GDI+ (CVE-2026-69288) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
710.
Information Disclosure - Windows Imaging Component (CVE-2026-69318) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
711.
Information Disclosure - Windows License Manager (CVE-2026-69315) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
712.
Information Disclosure - Windows MIDI Service Module (CVE-2026-68842) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
713.
Information Disclosure - Windows MIDI Service Module (CVE-2026-69339) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
714.
Information Disclosure - Windows Management Instrumentation (CVE-2026-69349) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
715.
Information Disclosure - Windows NTFS (CVE-2026-68851) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
716.
Information Disclosure - Windows NTFS (CVE-2026-69504) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
717.
Information Disclosure - Windows NTFS (CVE-2026-69591) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
718.
Information Disclosure - Windows Network Connection Broker (CVE-2026-68886) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
719.
Information Disclosure - Windows Overlay Filter (CVE-2026-69343) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
720.
Information Disclosure - Windows Partition Management Driver (CVE-2026-71341) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
721.
Information Disclosure - Windows Print Spooler Components (CVE-2026-69344) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
722.
Information Disclosure - Windows Print Spooler Components (CVE-2026-69552) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
723.
Information Disclosure - Windows Program Compatibility Assistant Service (CVE-2026-68873) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
724.
Information Disclosure - Windows Program Compatibility Assistant Service (CVE-2026-68874) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
725.
Information Disclosure - Windows Remote Desktop Client (CVE-2026-69317) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Remote Desktop Protocol Client | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
726.
Information Disclosure - Windows Remote Desktop Licensing Service (CVE-2026-69627) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
727.
Information Disclosure - Windows Remote Desktop Services (CVE-2026-69616) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Remote Desktop Services, known as Terminal Services in Windows Server 2008 and earlier, is one of the components of Microsoft Windows that allow a user to initiate and control an interactive session on a remote computer or virtual machine over a network connection | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
728.
Information Disclosure - Windows SMB Server (CVE-2026-69403) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
729.
Information Disclosure - Windows Spaceport.sys (CVE-2026-69390) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
730.
Information Disclosure - Windows Spaceport.sys (CVE-2026-69393) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
731.
Information Disclosure - Windows Spaceport.sys (CVE-2026-69741) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
732.
Information Disclosure - Windows Spaceport.sys (CVE-2026-69770) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
733.
Information Disclosure - Windows Storage Port Driver (CVE-2026-72937) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
734.
Information Disclosure - Windows Storage Port Driver (CVE-2026-77492) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
735.
Information Disclosure - Windows Task Scheduler (CVE-2026-72945) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
736.
Information Disclosure - Windows Text Shaping (CVE-2026-69353) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
737.
Information Disclosure - Windows USB Audio Class Driver (CVE-2026-69286) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
738.
Information Disclosure - Windows USB Driver (CVE-2026-69457) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
739.
Information Disclosure - Windows USB Mass Storage Class Driver (CVE-2026-69527) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
740.
Information Disclosure - Windows Universal Plug and Play (UPnP) Device Host (CVE-2026-68830) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
741.
Information Disclosure - Windows Universal Plug and Play (UPnP) Device Host (CVE-2026-69351) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
742.
Information Disclosure - Windows Virtualization-Based Security (VBS) (CVE-2026-83501) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-83501: Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability An out-of-bounds read flaw in Windows Virtualization-Based Security (VBS) Enclave may allow an authenticated attacker to disclose information locally.
743.
Information Disclosure - Windows Wireless Wide Area Network Service (CVE-2026-69862) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
744.
Elevation of Privilege - .NET (CVE-2026-69806) - Medium [351]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.7 | 14 | .NET | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
745.
Elevation of Privilege - VHD Miniport Driver (CVE-2026-69549) - Medium [351]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.7 | 14 | The Virtual Hard Disk (VHD) Miniport Driver is a Microsoft Windows kernel-mode storage driver that enables the operating system to mount, access, and manage Virtual Hard Disk (VHD and VHDX) files as block storage devices. It is used by Windows virtualization, backup, and virtual disk management features. | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
746.
Elevation of Privilege - VHD Miniport Driver (CVE-2026-69611) - Medium [351]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.7 | 14 | The Virtual Hard Disk (VHD) Miniport Driver is a Microsoft Windows kernel-mode storage driver that enables the operating system to mount, access, and manage Virtual Hard Disk (VHD and VHDX) files as block storage devices. It is used by Windows virtualization, backup, and virtual disk management features. | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
747.
Elevation of Privilege - Windows Security Center (CVE-2026-77899) - Medium [351]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.7 | 14 | Windows Security Center (WSC) is a comprehensive reporting tool that helps users establish and maintain a protective security layer around their computer systems | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
748.
Information Disclosure - .NET (CVE-2026-58649) - Medium [348]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.7 | 14 | .NET | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
749.
Elevation of Privilege - Windows Hyper-V (CVE-2026-72961) - Medium [347]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.6 | 14 | Hardware virtualization component of the client editions of Windows NT | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-72961: Windows Hyper-V Elevation of Privilege Vulnerability An out-of-bounds read flaw in Windows Hyper-V may allow an authenticated attacker to elevate privileges locally.
750.
Denial of Service - Windows DNS Server (CVE-2026-78523) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
751.
Remote Code Execution - Microsoft Office Access (CVE-2026-69477) - Medium [345]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Office Access | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
752.
Remote Code Execution - Remote Desktop Services Remote Code Execution Vulnerability (CVE-2026-69536) - Medium [345]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Remote Desktop Services Remote Code Execution Vulnerability | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
753.
Information Disclosure - Skype for Business (CVE-2026-66304) - Medium [343]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | Skype for Business | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
754.
Elevation of Privilege - Azure Arc SQL Server Extension (CVE-2026-62895) - Medium [342]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Azure Arc SQL Server Extension | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
755.
Elevation of Privilege - Microsoft Authenticator (CVE-2026-80097) - Medium [342]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Authenticator | |
| 0.9 | 10 | CVSS Base Score is 8.6. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ZDI: - CVE-2026-80097 - Microsoft Authenticator Elevation of Privilege Vulnerability. This is the worst type of privilege escalation as it uses a bug in the authentication system itself. An attacker would need to install a malicious app on an Android device, then convince a user to complete the authentication sequence. Once done, the attacker gets the auth tokens and can access resources as the affected user. If you have a large Android user base, best not to ignore this one.
756.
Elevation of Privilege - Microsoft Office SharePoint (CVE-2026-69464) - Medium [342]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Office SharePoint | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
757.
Elevation of Privilege - Microsoft Office SharePoint (CVE-2026-69716) - Medium [342]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Office SharePoint | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ZDI: SharePoint Server: This month’s release includes 16 SharePoint bugs: six RCE, two EoP, four spoofing, and four info disclosure. All Important, none exploited or publicly disclosed, nothing rated above “Exploitation Less Likely”, but given SharePoint's recent history of “Less Likely” becoming “in the KEV catalog,” the RCE set deserves respect. The RCE bugs do all require authentication, but the level is pretty basic, although the bug classes (deserialization, SQLi, SSRF, XSS, auth bypass) read like a web-app pentest report rather than memory corruption. The EoPs continue the theme of web-app sins in a server product: CVE-2026-69716 is a SQL injection letting a low-privileged user run database commands with elevated privileges; CVE-2026-83950 is an SSRF-based EoP; 69464 is an unnecessary-privileges flaw at CVSS 8.8.
758.
Elevation of Privilege - Microsoft SQL Server (CVE-2026-66814) - Medium [342]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
759.
Elevation of Privilege - Microsoft SQL Server (CVE-2026-66818) - Medium [342]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
760.
Elevation of Privilege - Microsoft SQL Server (CVE-2026-66819) - Medium [342]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
761.
Elevation of Privilege - Microsoft SQL Server (CVE-2026-67368) - Medium [342]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
762.
Elevation of Privilege - Microsoft SQL Server (CVE-2026-67370) - Medium [342]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
763.
Elevation of Privilege - Microsoft SQL Server (CVE-2026-67381) - Medium [342]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
764.
Elevation of Privilege - SQL Server (CVE-2026-66820) - Medium [342]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
765.
Elevation of Privilege - SQL Server (CVE-2026-73028) - Medium [342]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
766.
Elevation of Privilege - SQL Server (CVE-2026-77480) - Medium [342]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
767.
Elevation of Privilege - SQL Server (CVE-2026-77483) - Medium [342]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
768.
Elevation of Privilege - SQL Server (CVE-2026-77487) - Medium [342]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | SQL Server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
769.
Elevation of Privilege - Spring Cloud Azure (CVE-2026-69854) - Medium [342]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Spring Cloud Azure | |
| 0.9 | 10 | CVSS Base Score is 9.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-69854: Spring Cloud Azure Elevation of Privilege Vulnerability An improper authentication flaw in Spring Cloud Azure may allow an unauthenticated attacker to elevate privileges over a network.
770.
Denial of Service - Windows Active Directory Domain Services (CVE-2026-62762) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
771.
Denial of Service - Windows DHCP Client (CVE-2026-69781) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
772.
Denial of Service - Windows DHCP Server (CVE-2026-69497) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
773.
Denial of Service - Windows Remote Desktop Client (CVE-2026-77896) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Remote Desktop Protocol Client | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
774.
Denial of Service - Windows Routing and Remote Access Service (RRAS) (CVE-2026-72939) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
775.
Denial of Service - Windows SMB Server (CVE-2026-69374) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
776.
Denial of Service - Windows iSCSI (CVE-2026-68898) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
777.
Denial of Service - Windows iSCSI Target Service (CVE-2026-69839) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
778.
Information Disclosure - Microsoft Windows SCSI Class System File (CVE-2026-78452) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
779.
Information Disclosure - Windows Bluetooth Port Driver (CVE-2026-68849) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
780.
Information Disclosure - Windows CD-ROM Driver (CVE-2026-78508) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
781.
Information Disclosure - Windows Image Acquisition (CVE-2026-69483) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
782.
Information Disclosure - Windows Overlay Filter (CVE-2026-69316) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
783.
Information Disclosure - Windows Overlay Filter (CVE-2026-69474) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
784.
Information Disclosure - Windows RNDIS (CVE-2026-69548) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
785.
Information Disclosure - Windows Spaceport.sys (CVE-2026-69895) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
786.
Information Disclosure - Windows Storage Port Driver (CVE-2026-69381) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
787.
Security Feature Bypass - Windows Hello (CVE-2026-72980) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Windows component | |
| 0.4 | 10 | CVSS Base Score is 4.4. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-72980: Windows Hello Security Feature Bypass Vulnerability An uncontrolled search path element in Windows Hello may allow an authenticated attacker to bypass a security feature locally.
788.
Security Feature Bypass - Windows Secure Boot (CVE-2026-69713) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Windows component | |
| 0.4 | 10 | CVSS Base Score is 4.4. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
789.
Security Feature Bypass - Windows URL Moniker (CVE-2026-73019) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Windows component | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
790.
Elevation of Privilege - Windows Hyper-V (CVE-2026-69553) - Medium [335]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.6 | 14 | Hardware virtualization component of the client editions of Windows NT | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
791.
Remote Code Execution - Visual Studio (CVE-2026-77906) - Medium [335]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.3 | 14 | Integrated development environment | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
792.
Remote Code Execution - Visual Studio (CVE-2026-77907) - Medium [335]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.3 | 14 | Integrated development environment | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
793.
Information Disclosure - Skype for Business (CVE-2026-66306) - Medium [331]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | Skype for Business | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
794.
Elevation of Privilege - Active Directory Certificate Services (AD CS) (CVE-2026-62810) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Active Directory Certificate Services (AD CS) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
795.
Elevation of Privilege - Active Directory Certificate Services (AD CS) (CVE-2026-69821) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Active Directory Certificate Services (AD CS) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
796.
Elevation of Privilege - Active Directory Domain Services (CVE-2026-69359) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Active Directory Domain Services | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
797.
Elevation of Privilege - Data Sharing Service Client (CVE-2026-73014) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Data Sharing Service Client | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
798.
Elevation of Privilege - Graphic Fonts (CVE-2026-69576) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Graphic Fonts | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
799.
Elevation of Privilege - HID Class Driver (CVE-2026-69731) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | HID Class Driver | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
800.
Elevation of Privilege - Microsoft Account (CVE-2026-68850) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Account | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
801.
Elevation of Privilege - Microsoft Graphics Component (CVE-2026-69467) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Graphics Component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
802.
Elevation of Privilege - Microsoft Graphics Component (CVE-2026-83990) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Graphics Component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
803.
Elevation of Privilege - Microsoft Local Security Authority (LSA) Server (CVE-2026-69277) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Local Security Authority (LSA) Server | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
804.
Elevation of Privilege - Microsoft Local Security Authority (LSA) Server (CVE-2026-69365) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Local Security Authority (LSA) Server | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
805.
Elevation of Privilege - Microsoft Local Security Authority (LSA) Server (CVE-2026-69594) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Local Security Authority (LSA) Server | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
806.
Elevation of Privilege - Microsoft Standard XPS (CVE-2026-68885) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Standard XPS | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
807.
Elevation of Privilege - Microsoft Standard XPS (CVE-2026-68888) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Standard XPS | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
808.
Elevation of Privilege - Microsoft Standard XPS (CVE-2026-68890) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Standard XPS | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
809.
Elevation of Privilege - Microsoft Standard XPS (CVE-2026-68892) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Standard XPS | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
810.
Elevation of Privilege - Microsoft Standard XPS (CVE-2026-69269) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Standard XPS | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
811.
Elevation of Privilege - Microsoft Standard XPS (CVE-2026-69271) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Standard XPS | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
812.
Elevation of Privilege - Microsoft Storage Port Driver (CVE-2026-72946) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Storage Port Driver | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
813.
Elevation of Privilege - Microsoft Trace Data Helper (CVE-2026-56198) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Trace Data Helper | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
814.
Elevation of Privilege - Microsoft VOLSNAP.SYS (CVE-2026-69420) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft VOLSNAP.SYS | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
815.
Elevation of Privilege - Microsoft VOLSNAP.SYS (CVE-2026-69427) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft VOLSNAP.SYS | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
816.
Elevation of Privilege - Volume Manager Driver (CVE-2026-69407) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Volume Manager Driver | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
817.
Elevation of Privilege - Volume Manager Driver (CVE-2026-69418) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Volume Manager Driver | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
818.
Elevation of Privilege - Volume Manager Driver (CVE-2026-69432) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Volume Manager Driver | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
819.
Elevation of Privilege - Xbox Gaming Services (CVE-2026-58611) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Xbox Gaming Services | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
820.
Denial of Service - ASP.NET Core (CVE-2026-69304) - Medium [329]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | An open-source, server-side web-application framework designed for web development | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
821.
Denial of Service - Windows DHCP Server (CVE-2026-69405) - Medium [329]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
822.
Denial of Service - Windows DHCP Server (CVE-2026-69416) - Medium [329]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
823.
Denial of Service - Windows DHCP Server (CVE-2026-69637) - Medium [329]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
824.
Denial of Service - Windows DHCP Server (CVE-2026-69679) - Medium [329]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
825.
Denial of Service - Windows DNS (CVE-2026-70091) - Medium [329]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
826.
Denial of Service - Windows Network File System (CVE-2026-69372) - Medium [329]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
827.
Denial of Service - Windows Print Spooler Components (CVE-2026-69569) - Medium [329]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
828.
Information Disclosure - Windows Storage (CVE-2026-78516) - Medium [329]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
829.
Security Feature Bypass - Visual Studio Code (CVE-2026-81376) - Medium [329]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.3 | 14 | Integrated development environment | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
830.
Security Feature Bypass - Microsoft SQL Server (CVE-2026-66816) - Medium [327]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
831.
Information Disclosure - Azure CycleCloud (CVE-2026-77909) - Medium [326]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Azure CycleCloud | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
832.
Denial of Service - VHD Miniport Driver (CVE-2026-69384) - Medium [324]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | The Virtual Hard Disk (VHD) Miniport Driver is a Microsoft Windows kernel-mode storage driver that enables the operating system to mount, access, and manage Virtual Hard Disk (VHD and VHDX) files as block storage devices. It is used by Windows virtualization, backup, and virtual disk management features. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
833.
Remote Code Execution - Microsoft SQL Server (CVE-2026-68785) - Medium [321]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.5 | 10 | CVSS Base Score is 4.9. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
834.
Information Disclosure - Microsoft Excel (CVE-2026-81387) - Medium [319]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | MS Office product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
835.
Information Disclosure - Microsoft Excel (CVE-2026-81390) - Medium [319]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | MS Office product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
836.
Information Disclosure - Microsoft Excel (CVE-2026-81391) - Medium [319]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | MS Office product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
837.
Information Disclosure - Microsoft Excel (CVE-2026-81392) - Medium [319]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | MS Office product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
838.
Information Disclosure - Microsoft Excel (CVE-2026-81393) - Medium [319]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | MS Office product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
839.
Information Disclosure - Microsoft Excel (CVE-2026-81394) - Medium [319]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | MS Office product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
840.
Information Disclosure - Microsoft Excel (CVE-2026-81395) - Medium [319]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | MS Office product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
841.
Information Disclosure - Microsoft Excel (CVE-2026-81399) - Medium [319]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | MS Office product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
842.
Information Disclosure - Microsoft Excel (CVE-2026-81400) - Medium [319]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | MS Office product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
843.
Information Disclosure - Microsoft Excel (CVE-2026-81401) - Medium [319]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | MS Office product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
844.
Information Disclosure - Microsoft Excel (CVE-2026-81958) - Medium [319]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | MS Office product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
845.
Elevation of Privilege - Audio Video Control Transport Protocol (CVE-2026-69401) - Medium [318]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Audio Video Control Transport Protocol | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
846.
Elevation of Privilege - Connected Devices Platform Service (Cdpsvc) (CVE-2026-69516) - Medium [318]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Connected Devices Platform Service (Cdpsvc) | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
847.
Elevation of Privilege - Microsoft Install Service (CVE-2026-69605) - Medium [318]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Install Service | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
848.
Elevation of Privilege - Microsoft Power Automate Desktop (CVE-2026-77897) - Medium [318]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Power Automate Desktop | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
849.
Elevation of Privilege - Microsoft Standard XPS (CVE-2026-68889) - Medium [318]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Standard XPS | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
850.
Elevation of Privilege - Microsoft Standard XPS (CVE-2026-68897) - Medium [318]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Standard XPS | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
851.
Elevation of Privilege - Microsoft Standard XPS (CVE-2026-69272) - Medium [318]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Standard XPS | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
852.
Elevation of Privilege - Microsoft Standard XPS (CVE-2026-69313) - Medium [318]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Standard XPS | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
853.
Elevation of Privilege - Microsoft Standard XPS (CVE-2026-69336) - Medium [318]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Standard XPS | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
854.
Elevation of Privilege - Remote Desktop Gateway Service (CVE-2026-69292) - Medium [318]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Remote Desktop Gateway Service | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
855.
Elevation of Privilege - Remote Desktop Gateway Service (CVE-2026-69338) - Medium [318]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Remote Desktop Gateway Service | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
856.
Elevation of Privilege - Remote Desktop Licensing Service (CVE-2026-68893) - Medium [318]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Remote Desktop Licensing Service | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
857.
Elevation of Privilege - SQL Server (CVE-2026-77485) - Medium [318]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | SQL Server | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
858.
Elevation of Privilege - Volume Shadow Copy (CVE-2026-72985) - Medium [318]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Volume Shadow Copy | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
859.
Elevation of Privilege - Winsock (CVE-2026-72927) - Medium [318]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Winsock | |
| 0.7 | 10 | CVSS Base Score is 6.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
860.
Denial of Service - Windows Distributed File System (DFS) (CVE-2026-78446) - Medium [317]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
861.
Denial of Service - Windows Schannel (CVE-2026-70575) - Medium [317]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
862.
Denial of Service - Windows Secure Socket Tunneling Protocol (SSTP) (CVE-2026-72931) - Medium [317]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
863.
Security Feature Bypass - Visual Studio Code (CVE-2026-78462) - Medium [317]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.3 | 14 | Integrated development environment | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
864.
Information Disclosure - Active Directory Certificate Services (AD CS) (CVE-2026-69395) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Active Directory Certificate Services (AD CS) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
865.
Information Disclosure - GitHub Copilot and Visual Studio Code (CVE-2026-81381) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | GitHub Copilot and Visual Studio Code | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
866.
Information Disclosure - Microsoft Office Excel (CVE-2026-72974) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office Excel | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
867.
Information Disclosure - Microsoft Office Excel (CVE-2026-78515) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office Excel | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
868.
Information Disclosure - Microsoft Office Outlook (CVE-2026-78520) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office Outlook | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-78520: Microsoft Office Outlook Information Disclosure Vulnerability An out-of-bounds read flaw in Microsoft Office Outlook may allow an unauthenticated attacker to execute code over a network.
869.
Information Disclosure - Microsoft Office Outlook (CVE-2026-80073) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office Outlook | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
870.
Information Disclosure - Microsoft Office Outlook (CVE-2026-80084) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office Outlook | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
871.
Information Disclosure - Microsoft Office PowerPoint (CVE-2026-72938) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office PowerPoint | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
872.
Information Disclosure - Microsoft Office PowerPoint (CVE-2026-72956) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office PowerPoint | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
873.
Information Disclosure - Microsoft Office PowerPoint (CVE-2026-72975) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office PowerPoint | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
874.
Information Disclosure - Microsoft Office PowerPoint (CVE-2026-72977) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office PowerPoint | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
875.
Information Disclosure - Microsoft Office PowerPoint (CVE-2026-80086) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office PowerPoint | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
876.
Information Disclosure - Microsoft Office SharePoint (CVE-2026-69409) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office SharePoint | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
877.
Information Disclosure - Microsoft Office SharePoint (CVE-2026-69636) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office SharePoint | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
878.
Information Disclosure - Microsoft Office SharePoint (CVE-2026-69683) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office SharePoint | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
879.
Information Disclosure - Microsoft Office Word (CVE-2026-69719) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
880.
Information Disclosure - Microsoft Office Word (CVE-2026-69734) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
881.
Information Disclosure - Microsoft Office Word (CVE-2026-77911) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
882.
Information Disclosure - Microsoft Office Word (CVE-2026-78502) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
883.
Information Disclosure - Microsoft Office Word (CVE-2026-78503) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
884.
Information Disclosure - Microsoft Office Word (CVE-2026-78522) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
885.
Information Disclosure - Microsoft Office Word (CVE-2026-80079) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
886.
Information Disclosure - Microsoft Office Word (CVE-2026-80088) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
887.
Information Disclosure - Microsoft Office Word (CVE-2026-80090) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
888.
Information Disclosure - Microsoft SQL Server (CVE-2026-67369) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
889.
Information Disclosure - Microsoft SQL Server (CVE-2026-67383) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
890.
Information Disclosure - Microsoft SQL Server (CVE-2026-67386) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
891.
Information Disclosure - Microsoft SQL Server (CVE-2026-67389) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
892.
Information Disclosure - Microsoft SQL Server (CVE-2026-67390) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
893.
Information Disclosure - Microsoft SQL Server (CVE-2026-67393) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
894.
Information Disclosure - Microsoft SQL Server (CVE-2026-67624) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
895.
Information Disclosure - Microsoft SQL Server (CVE-2026-67629) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
896.
Information Disclosure - Microsoft SQL Server (CVE-2026-67630) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
897.
Information Disclosure - Microsoft SQL Server (CVE-2026-67645) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
898.
Information Disclosure - Microsoft SQL Server (CVE-2026-67648) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
899.
Information Disclosure - Microsoft SQL Server (CVE-2026-68776) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
900.
Information Disclosure - Microsoft SQL Server (CVE-2026-68777) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
901.
Information Disclosure - Microsoft SQL Server (CVE-2026-68778) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
902.
Information Disclosure - Microsoft SQL Server (CVE-2026-68779) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
903.
Information Disclosure - Microsoft SQL Server (CVE-2026-68780) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
904.
Information Disclosure - Microsoft SQL Server (CVE-2026-68781) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
905.
Information Disclosure - Microsoft SQL Server (CVE-2026-68784) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
906.
Information Disclosure - Microsoft SQL Server (CVE-2026-69562) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
907.
Information Disclosure - Microsoft SQL Server (CVE-2026-73029) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
908.
Information Disclosure - Microsoft Teams for Android (CVE-2026-65812) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Teams for Android | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
909.
Spoofing - Microsoft Exchange (CVE-2026-69356) - Medium [311]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ZDI: Exchange Server: Only nine bugs here, but there are some whoppers. Three different bugs rate CVSS 9.1 or higher. CVE-2026-69380 is an interesting exploit. A low-privileged user with a mailbox abuses request/token validation to impersonate any user and take over every mailbox: read, send, download attachments. Post-phish, this turns one compromised account into the whole org's mail. An unauthenticated mail-processing RCE plus a mailbox-takeover EoP in the same release is a chainable pair on paper. Initial access and lateral movement in one Cumulative Update. The other unauthenticated bug to mention is CVE-2026-69356, an specially crafted calendar invite; victim clicks the Join link, and script runs in their context. XSS wearing a spoofing label. Neat.
910.
Security Feature Bypass - Visual Studio Code (CVE-2026-70334) - Medium [305]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.3 | 14 | Integrated development environment | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
911.
Security Feature Bypass - Visual Studio Code (CVE-2026-81356) - Medium [305]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.3 | 14 | Integrated development environment | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
912.
Security Feature Bypass - Visual Studio Code (CVE-2026-81357) - Medium [305]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.3 | 14 | Integrated development environment | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
913.
Security Feature Bypass - Visual Studio Code (CVE-2026-81378) - Medium [305]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.3 | 14 | Integrated development environment | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
914.
Security Feature Bypass - Visual Studio Code (CVE-2026-81379) - Medium [305]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.3 | 14 | Integrated development environment | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
915.
Denial of Service - BranchCache (CVE-2026-69329) - Medium [303]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | BranchCache | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
916.
Denial of Service - Microsoft SQL Server (CVE-2026-67376) - Medium [303]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
917.
Denial of Service - Skype for Business and Lync (CVE-2026-66307) - Medium [303]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Skype for Business and Lync | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
918.
Information Disclosure - Internet Storage Name Service (CVE-2026-68895) - Medium [302]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Internet Storage Name Service | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
919.
Information Disclosure - Microsoft Account (CVE-2026-68852) - Medium [302]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Account | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
920.
Information Disclosure - Microsoft Office Excel (CVE-2026-85875) - Medium [302]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office Excel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
921.
Information Disclosure - Microsoft Office PowerPoint (CVE-2026-78513) - Medium [302]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office PowerPoint | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
922.
Information Disclosure - Microsoft Office Word (CVE-2026-68843) - Medium [302]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
923.
Information Disclosure - Microsoft Office Word (CVE-2026-78506) - Medium [302]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
924.
Information Disclosure - Microsoft Office Word (CVE-2026-83949) - Medium [302]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
925.
Information Disclosure - Microsoft Office Word (CVE-2026-83951) - Medium [302]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
926.
Information Disclosure - Microsoft SQL Server (CVE-2026-77488) - Medium [302]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
927.
Information Disclosure - Microsoft Standard XPS (CVE-2026-68881) - Medium [302]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Standard XPS | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
928.
Information Disclosure - Microsoft Standard XPS (CVE-2026-69308) - Medium [302]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Standard XPS | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
929.
Information Disclosure - Microsoft Standard XPS (CVE-2026-69345) - Medium [302]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Standard XPS | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
930.
Information Disclosure - Microsoft Standard XPS (CVE-2026-69367) - Medium [302]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Standard XPS | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
931.
Information Disclosure - Microsoft Standard XPS (CVE-2026-69376) - Medium [302]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Standard XPS | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
932.
Information Disclosure - Microsoft Teams for Android (CVE-2026-69559) - Medium [302]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Teams for Android | |
| 0.6 | 10 | CVSS Base Score is 5.8. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
933.
Information Disclosure - Push Message Routing Service (CVE-2026-69303) - Medium [302]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Push Message Routing Service | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
934.
Spoofing - Windows DNS (CVE-2026-69680) - Medium [300]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
935.
Spoofing - Windows Netlogon (CVE-2026-62759) - Medium [300]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
936.
Spoofing - Windows Shell (CVE-2026-70563) - Medium [300]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
937.
Spoofing - Azure Cosmos DB (CVE-2026-69857) - Medium [297]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Azure Cosmos DB | |
| 0.8 | 10 | CVSS Base Score is 8.5. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.00423, EPSS Percentile is 0.35504 |
Qualys: CVE-2026-69857: Azure Cosmos DB Spoofing Vulnerability An authorization bypass via a user-controlled key in Azure Cosmos DB may allow an authenticated attacker to perform network spoofing.
938.
Security Feature Bypass - Visual Studio Code (CVE-2026-78461) - Medium [294]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.3 | 14 | Integrated development environment | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
939.
Denial of Service - Microsoft SQL Server (CVE-2026-67633) - Medium [291]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
940.
Denial of Service - Microsoft SQL Server (CVE-2026-67641) - Medium [291]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Microsoft SQL Server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
941.
Denial of Service - Skype for Business and Lync (CVE-2026-66303) - Medium [291]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Skype for Business and Lync | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
942.
Denial of Service - Skype for Business and Lync (CVE-2026-66308) - Medium [291]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Skype for Business and Lync | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
943.
Information Disclosure - GitHub Copilot and Visual Studio Code (CVE-2026-81380) - Medium [291]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | GitHub Copilot and Visual Studio Code | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
944.
Information Disclosure - Microsoft Office Word (CVE-2026-72976) - Medium [291]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office Word | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
945.
Information Disclosure - Microsoft Standard XPS (CVE-2026-68891) - Medium [291]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Standard XPS | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
946.
Spoofing - Microsoft Exchange (CVE-2026-69361) - Medium [288]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
947.
Spoofing - Microsoft Office (CVE-2026-64918) - Medium [288]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
948.
Information Disclosure - Visual Studio Code (CVE-2026-81383) - Medium [281]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.3 | 14 | Integrated development environment | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
949.
Denial of Service - Active Directory Federation Services (AD FS) (CVE-2026-72978) - Medium [279]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Active Directory Federation Services (AD FS) | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
950.
Information Disclosure - Xbox (CVE-2026-78455) - Medium [279]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Xbox | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
951.
Tampering - Microsoft Exchange (CVE-2026-69375) - Medium [270]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.3 | 15 | Tampering | |
| 0.8 | 14 | Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
952.
Tampering - Windows Error Reporting (CVE-2026-69482) - Medium [270]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.3 | 15 | Tampering | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
953.
Information Disclosure - Microsoft Office SharePoint (CVE-2026-69904) - Medium [267]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Office SharePoint | |
| 0.3 | 10 | CVSS Base Score is 3.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
954.
Spoofing - Skype for Business (CVE-2026-69646) - Medium [266]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.6 | 14 | Skype for Business | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
955.
Tampering - Microsoft Windows Search Component (CVE-2026-69453) - Medium [258]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.3 | 15 | Tampering | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
956.
Tampering - Microsoft Windows Search Component (CVE-2026-69554) - Medium [258]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.3 | 15 | Tampering | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
957.
Tampering - Microsoft Windows Speech (CVE-2026-69531) - Medium [258]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.3 | 15 | Tampering | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
958.
Tampering - Windows Autopilot (CVE-2026-73004) - Medium [258]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.3 | 15 | Tampering | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
959.
Tampering - Windows Cloud Files Mini Filter Driver (CVE-2026-83991) - Medium [258]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.3 | 15 | Tampering | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
960.
Tampering - Windows Internet Connection Sharing (ICS) (CVE-2026-72964) - Medium [258]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.3 | 15 | Tampering | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
961.
Tampering - Windows Power Dependency Coordinator (CVE-2026-69321) - Medium [258]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.3 | 15 | Tampering | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
962.
Tampering - Windows Remote Access Connection Manager (CVE-2026-72966) - Medium [258]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.3 | 15 | Tampering | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
963.
Spoofing - Skype for Business (CVE-2026-63523) - Medium [254]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.6 | 14 | Skype for Business | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
964.
Spoofing - Skype for Business (CVE-2026-66305) - Medium [254]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.6 | 14 | Skype for Business | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
965.
Spoofing - Skype for Business (CVE-2026-69642) - Medium [254]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.6 | 14 | Skype for Business | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
966.
Tampering - Windows NTFS (CVE-2026-69425) - Medium [246]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.3 | 15 | Tampering | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
967.
Spoofing - Microsoft Authentication Library (MSAL) for Node.js (CVE-2026-84003) - Medium [238]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft Authentication Library (MSAL) for Node.js | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
968.
Spoofing - Microsoft Office SharePoint (CVE-2026-69402) - Medium [238]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft Office SharePoint | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
969.
Spoofing - Microsoft Office SharePoint (CVE-2026-69417) - Medium [238]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft Office SharePoint | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
970.
Tampering - Active Directory Certificate Services (AD CS) (CVE-2026-69624) - Medium [220]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.3 | 15 | Tampering | |
| 0.5 | 14 | Active Directory Certificate Services (AD CS) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
971.
Spoofing - Microsoft Office SharePoint (CVE-2026-69690) - Medium [214]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft Office SharePoint | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
972.
Spoofing - Microsoft Office SharePoint (CVE-2026-69615) - Low [190]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft Office SharePoint | |
| 0.3 | 10 | CVSS Base Score is 3.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
973.
Tampering - Visual Studio Code (CVE-2026-81377) - Low [186]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.3 | 15 | Tampering | |
| 0.3 | 14 | Integrated development environment | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
Qualys: CVE-2026-81963: Windows Update Stack Elevation of Privilege Vulnerability A link following flaw in the Windows Update Stack may allow an authenticated attacker to elevate privileges locally. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CISA added the CVE-2026-81963 to its Known Exploited Vulnerabilities Catalog, urging users to patch it before September 22, 2026.
Tenable: Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
Tenable: CVE-2026-81963 | Windows Update Stack elevation of privilege vulnerability
Tenable: CVE-2026-81963 is an EoP vulnerability affecting Windows Update Stack elevation of privilege vulnerability. It received a CVSSv3 score of 7.8 and was rated as important. According to Microsoft, this vulnerability was exploited in the wild as a zero-day.
Tenable: Since 2022, seven Windows Update Stack EoP vulnerabilities have been patched across Patch Tuesday releases, but CVE-2026-81963 is the first to have been exploited in the wild as a zero-day.
ZDI: - CVE-2026-81963 - Windows Update Stack Elevation of Privilege Vulnerability. This is the first bug being exploited in the wild, but we know little about how broadly that exploitation is. The bug itself is a privilege escalation in the Update Stack, which is worrisome, but I doubt the automatic update process itself is compromised. More likely is that this bug is being combined with a code execution bug to spread malware or ransomware. Patch this one quickly.
Qualys: CVE-2026-85880: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability The heap-based buffer overflow flaw in Windows ALPC may allow an authenticated attacker to elevate privileges locally. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CISA added the CVE-2026-85880 to its Known Exploited Vulnerabilities Catalog, urging users to patch it before September 22, 2026.
Tenable: Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
Tenable: CVE-2026-85880 | Windows Advanced Local Procedure Call (ALPC) elevation of privilege vulnerability
Tenable: CVE-2026-85880 is a EoP vulnerability affecting Windows Advanced Local Procedure Call (ALPC). It received a CVSSv3 score of 7.8 and is rated as important. According to Microsoft, this vulnerability was exploited in the wild, making it one of two zero-days addressed in the September Patch Tuesday release. Successful exploitation would allow an attacker to gain SYSTEM level privileges.
ZDI: - CVE-2026-85880 - Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability. This is the other bug currently being exploited, and it is also a privilege escalation bug. These types of bugs must be triggered by the user, but they can hide within documents, PDFs, and other attachments. As with the Update Stack EoP, we don’t know how widespread these exploits may be, so assume they are coming for you and patch quickly.
Qualys: CVE-2026-69730, CVE-2026-69813, CVE-2026-69858, & CVE-2026-72987: Windows DNS Server Remote Code Execution Vulnerability The use-after-free flaw in Windows DNS may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-77505: Windows DNS Server Remote Code Execution Vulnerability The use-after-free flaw in the DNS Server may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-69827: Windows DNS Server Remote Code Execution Vulnerability A race condition flaw in the DNS Server may allow an unauthenticated attacker to execute code over a network.
Tenable: CVE-2026-69730 | Windows DNS Server remote code execution vulnerability
Tenable: CVE-2026-69730 is an RCE vulnerability affecting Windows DNS Server. It received a CVSSv3 score of 9.8 and is rated Critical. According to the advisory, an unauthenticated, remote attacker could send a crafted packet to exploit a use-after-free flaw in Windows DNS in order to achieve remote code execution. Microsoft assesses this flaw as “Exploitation More Likely.”
Tenable: Eight additional RCEs in Windows DNS Server were patched this month, however they did not achieve the same exploitability assessment as CVE-2026-69730. These eight are outlined in the table below:
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
Qualys: CVE-2026-69601: Microsoft Windows Media Foundation Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Microsoft Windows Media Foundation may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-69845: Windows DHCP Server Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows DHCP Server may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-72979: Windows DHCP Server Remote Code Execution Vulnerability The use-after-free flaw in Windows DHCP Server may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
ZDI: Windows DHCP Server: Windows DHCP Server chimes in with 36 bugs: 12 RCE, 18 DoS, five info leaks, and one EoP. Nothing exploited or disclosed, but 22 of the 36 require no authentication. It's the third-largest single-component pile of the month, and it's all one story: someone pointed a (likely AI-assisted) fuzzer at DHCP packet parsing. In addition to the two wormable bugs already mentioned, there are three more that didn’t carry the exact wormable verbiage but look like close cousins: CVE-2026-69845 (9.8, heap overflow), CVE-2026-69266 (8.8, integer overflow), and CVE-2026-69620 (8.1, stack overflow). If you're being generous, that's five wormable-shaped bugs in DHCP Server alone. The remaining seven RCEs need an authorized attacker. CWE spread is pure memory corruption: heap, stack, UAF, integer overflow. There are 18 DoS bugs, and 13 are unauthenticated at a CVSS score of 7.5. Malformed packet in, service crash out. Individually boring, but collectively, an unauthenticated attacker on the network has 13 different ways to take out DHCP, and when DHCP dies, clients stop getting leases and the helpdesk phone starts ringing. Finally, there are a couple of oddballs here: CVE-2026-69297 is an info leak that could expose passwords stored in a recoverable format, which is a configuration-secrets problem rather than a memory bug. The lone EoP is missing authentication on a critical function.
Qualys: CVE-2026-77493: Microsoft Office Outlook Remote Code Execution Vulnerability A double-free flaw in Microsoft Office Outlook may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-81955: Windows Graphics Component Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Microsoft Graphics Component may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-69769: Windows HTTP Print Provider Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows HTTP Print Provider may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-69860, CVE-2026-73013, CVE-2026-73023, & CVE-2026-77495: Windows Imaging Component Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Imaging Component may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-69499: Windows Imaging Component Remote Code Execution Vulnerability An integer overflow flaw in Windows Imaging Component may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-70296: Windows Imaging Component Remote Code Execution Vulnerability An out-of-bounds write flaw in Windows Imaging Component may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-69579: Windows Message Queuing Remote Code Execution Vulnerability The use-after-free flaw in Windows Message Queuing may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
ZDI: Windows NTFS: We have 30 bugs in this component: 16 EoP, 10 RCE, three info leaks, and one link-following oddball. All Important except the two 9.8 Critical RCEs. Like Biometric and DHCP, it's one bug class on repeat: 28 of 30 are memory-safety flaws (heap overflows lead at 12, then out-of-bounds reads). The headliner is CVE-2026-69463; simple heap-overflow RCE at 9.8, unauthenticated, network vector. The FAQ only offers the vague “in-network attacker calling arbitrary endpoints” phrasing, which likely means the remote path is something like SMB-reachable file operations rather than a raw packet, but a 9.8 in the file system driver everyone runs is still a top-tier patch either way. CVE-2026-69461 (8.8, stack overflow, unauth network) rides along just below them. Everything else can be somewhat dismissed as local-only noise, but remember the mount-a-drive trio that where “requires physical access” describes every USB port in the building.
Qualys: CVE-2026-72982: Windows Netlogon Remote Code Execution Vulnerability The stack-based buffer overflow flaw in Windows Netlogon may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
Qualys: CVE-2026-69590, CVE-2026-69852, CVE-2026-72950, & CVE-2026-72959: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Successful exploitation of the vulnerability may allow an attacker to gain unauthenticated access to the victim’s machine.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
Qualys: CVE-2026-73009: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability The use-after-free flaw in Windows Secure Socket Tunneling Protocol (SSTP) may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
Qualys: CVE-2026-69595 & CVE-2026-78445: Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability The use-after-free flaw in Windows Services for NFS ONCRPC XDR Driver may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-70585: Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability The use-after-free flaw in Windows Services for NFS ONCRPC XDR Driver may allow an authenticated attacker to execute code locally.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
ZDI: Exploitation More Likely: If you prioritize by Microsoft’s Exploit Index (XI), which I don’t recommend, there are a couple of bugs not mentioned yet: CVE-2026-72940 (Schannel RCE, CVSS 8.8, TLS stack), CVE-2026-72957 (Windows Deployment Services RCE, CVSS 7.8, PXE infrastructure), CVE-2026-71343 (Remote Access Connection Manager RCE, CVSS 7.8), and CVE-2026-70585 (a third NFS ONCRPC XDR RCE, CVSS 7.0). Again, I take all of these rating with a gigantic grain of salt, but you do you.
Qualys: CVE-2026-69829: Windows Shell Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Shell may allow an unauthenticated attacker to execute code over a network.
ZDI: The USB Stack: There are 23 bugs impacting the USB stack, but I really only want to talk about one. CVE-2026-68839 (USB Mass Storage Class Driver) with a CVSS of 9.8 and a network vector. The FAQ offers only the generic “in-network attacker calling arbitrary endpoints” boilerplate, which doesn't explain how a USB class driver is network-reachable. Either the metric is scored to worst case or there's a remote path (RDP device redirection would be the plausible one). I'd treat the score skeptically in print but patch like it's real.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
Qualys: CVE-2026-73006 & CVE-2026-78439: Microsoft Office Graphics Component Remote Code Execution Vulnerability The stack-based buffer overflow flaw in Microsoft Graphics Component may allow an unauthenticated attacker to execute code over a network.
ZDI: - CVE-2026-55007 - Microsoft Exchange Server Remote Code Execution Vulnerability. There are several Exchange patches this month, but despite the CVSS rating, I find this one most important. A remote, unauthenticated attacker could get code execution on an affected Exchange server just by sending an email with a malicious Visio attachment. The code execution occurs when the server processes the mail – no need even for the Preview Pane. Microsoft states the exploit would be unreliable, but the attacker only needs to get it right once. Schedule your downtime and update your Exchange servers with haste.
Qualys: CVE-2026-69632, CVE-2026-69678, CVE-2026-69767, & CVE-2026-69797: Microsoft Office PowerPoint Remote Code Execution Vulnerability The use-after-free flaw in Microsoft Office PowerPoint may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-69285 & CVE-2026-78505: Microsoft Office Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Microsoft Office may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-77898: Microsoft Office PowerPoint Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Microsoft Office PowerPoint may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-69676: Windows Kerberos Remote Code Execution Vulnerability An authentication-bypass flaw via capture-replay in Windows Kerberos may allow an authenticated attacker to execute code over a network.
Tenable: CVE-2026-69676 | Windows Kerberos remote code execution vulnerability
Tenable: CVE-2026-69676 is an RCE vulnerability affecting Windows Kerberos. It received a CVSSv3 score of 8.8 and is rated critical. An attacker with low-level access could exploit this authentication bypass flaw using capture-replay against Windows Kerberos in order to execute arbitrary code. Microsoft assesses this flaw as “Exploitation More Likely.”
ZDI: Kerberos and the KDC: Six different bugs affect these components, but it’s the two Critical rated ones that raised my eyebrows. Six bugs across Kerberos and the KDC — two Critical RCEs, two EoPs, and two DoS. Nothing exploited or disclosed, but one carries the rating that matters. CVE-2026-69676 is an RCE in Kerberos with a CVSS of 8.8 and classified as Exploitation More Likely. An authenticated attacker with low-level access sends a crafted request and executes code on the server, no user interaction. “The server” here means a domain controller, and any authenticated attacker means any domain user. So the realistic read is: one phished workstation account, one crafted request, code execution on the DC. That's a domain-compromise primitive, and Microsoft expects to see it exploited. CVE-2026-69712 is in KDC and reads almost identical to the previous: authenticated, low-level access, crafted request, code on the server, no interaction, but this one's a use-after-free in the KDC itself, the component that mints every ticket in the domain. Its practical impact is identical to 69676; only the exploitability rating separates them.
Qualys: CVE-2026-69712: Windows Key Distribution Center Remote Code Execution Vulnerability The use-after-free flaw in the Windows Key Distribution Center may allow an authenticated attacker to execute code over a network.
ZDI: Kerberos and the KDC: Six different bugs affect these components, but it’s the two Critical rated ones that raised my eyebrows. Six bugs across Kerberos and the KDC — two Critical RCEs, two EoPs, and two DoS. Nothing exploited or disclosed, but one carries the rating that matters. CVE-2026-69676 is an RCE in Kerberos with a CVSS of 8.8 and classified as Exploitation More Likely. An authenticated attacker with low-level access sends a crafted request and executes code on the server, no user interaction. “The server” here means a domain controller, and any authenticated attacker means any domain user. So the realistic read is: one phished workstation account, one crafted request, code execution on the DC. That's a domain-compromise primitive, and Microsoft expects to see it exploited. CVE-2026-69712 is in KDC and reads almost identical to the previous: authenticated, low-level access, crafted request, code on the server, no interaction, but this one's a use-after-free in the KDC itself, the component that mints every ticket in the domain. Its practical impact is identical to 69676; only the exploitability rating separates them.
Qualys: CVE-2026-70203 & CVE-2026-72960: Windows Media Player Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Media Player may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-70586: Windows Paint Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Paint may allow an unauthenticated attacker to execute code over a network.
ZDI: Exploitation More Likely: If you prioritize by Microsoft’s Exploit Index (XI), which I don’t recommend, there are a couple of bugs not mentioned yet: CVE-2026-72940 (Schannel RCE, CVSS 8.8, TLS stack), CVE-2026-72957 (Windows Deployment Services RCE, CVSS 7.8, PXE infrastructure), CVE-2026-71343 (Remote Access Connection Manager RCE, CVSS 7.8), and CVE-2026-70585 (a third NFS ONCRPC XDR RCE, CVSS 7.0). Again, I take all of these rating with a gigantic grain of salt, but you do you.
Qualys: CVE-2026-69518: Windows Remote Desktop Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Remote Desktop may allow an unauthenticated attacker to execute code over a network.
ZDI: Exploitation More Likely: If you prioritize by Microsoft’s Exploit Index (XI), which I don’t recommend, there are a couple of bugs not mentioned yet: CVE-2026-72940 (Schannel RCE, CVSS 8.8, TLS stack), CVE-2026-72957 (Windows Deployment Services RCE, CVSS 7.8, PXE infrastructure), CVE-2026-71343 (Remote Access Connection Manager RCE, CVSS 7.8), and CVE-2026-70585 (a third NFS ONCRPC XDR RCE, CVSS 7.0). Again, I take all of these rating with a gigantic grain of salt, but you do you.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
Qualys: CVE-2026-69730, CVE-2026-69813, CVE-2026-69858, & CVE-2026-72987: Windows DNS Server Remote Code Execution Vulnerability The use-after-free flaw in Windows DNS may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
Qualys: CVE-2026-72954: Windows Deployment Services Remote Code Execution Vulnerability The use-after-free flaw in Windows Deployment Services may allow an authenticated attacker to execute code over a network.
Qualys: CVE-2026-72957: Windows Deployment Services Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Deployment Services may allow an authenticated attacker to execute code locally.
ZDI: Exploitation More Likely: If you prioritize by Microsoft’s Exploit Index (XI), which I don’t recommend, there are a couple of bugs not mentioned yet: CVE-2026-72940 (Schannel RCE, CVSS 8.8, TLS stack), CVE-2026-72957 (Windows Deployment Services RCE, CVSS 7.8, PXE infrastructure), CVE-2026-71343 (Remote Access Connection Manager RCE, CVSS 7.8), and CVE-2026-70585 (a third NFS ONCRPC XDR RCE, CVSS 7.0). Again, I take all of these rating with a gigantic grain of salt, but you do you.
Qualys: CVE-2026-69530, CVE-2026-78449, & CVE-2026-78450: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability The use-after-free flaw in the Reliable Multicast Transport Driver (RMCAST) may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
Qualys: CVE-2026-69649: Raw Image Extension Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Raw Image Extension may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-81352: Web Media Extensions Remote Code Execution Vulnerability The heap-based buffer overflow in the Microsoft Windows Codecs Library may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-78509 & CVE-2026-78510: Microsoft Office Outlook Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Microsoft Office Outlook may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-81952: Microsoft Word Remote Code Execution Vulnerability The heap-based buffer overflow in Microsoft Office Word may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-66302: Skype for Business Remote Code Execution Vulnerability Successful exploitation of the vulnerability may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-69603: Windows Hyper-V Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Hyper-V may allow an authenticated attacker to execute code locally.
Qualys: CVE-2026-80083: Windows Hyper-V Remote Code Execution Vulnerability An untrusted pointer dereference flaw in Windows Hyper-V may allow an authenticated attacker to execute code locally.
Qualys: CVE-2026-58599: HEVC Video Extensions Remote Code Execution Vulnerability The heap-based buffer overflow flaw in the Microsoft Windows Codecs Library may allow an unauthenticated attacker to execute code locally.
Qualys: CVE-2026-81355: Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability The heap-based buffer overflow in the Virtual Hard Disk (VHD) Miniport Driver may allow an authenticated attacker to execute code locally.
Qualys: CVE-2026-73006 & CVE-2026-78439: Microsoft Office Graphics Component Remote Code Execution Vulnerability The stack-based buffer overflow flaw in Microsoft Graphics Component may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-72983: Internet Connection Sharing (ICS) Remote Code Execution Vulnerability The use-after-free flaw in Windows Internet Connection Sharing (ICS) may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
Qualys: CVE-2026-73010: Microsoft Failover Cluster Remote Code Execution Vulnerability The use-after-free flaw in Windows Failover Cluster may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-78444: Microsoft Failover Cluster Remote Code Execution Vulnerability An untrusted pointer dereference flaw in Windows Failover Cluster may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
Qualys: CVE-2026-78509 & CVE-2026-78510: Microsoft Office Outlook Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Microsoft Office Outlook may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-78519: Microsoft Office Outlook Remote Code Execution Vulnerability Use of an uninitialized resource in Microsoft Office Outlook may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-78525: Microsoft Office Outlook Remote Code Execution Vulnerability A use-after-free flaw in Microsoft Office Outlook may allow an unauthenticated attacker to execute code over a network.
ZDI: Microsoft Office Components: There are 110 Office-family bugs this month (excluding SharePoint's 17): 64 RCE, 45 info disclosure, and 1 spoofing. Most are of the open-and-own variety, but a few stick out, namely a CVSS 98 bug in Outlook’s CVSS 9.8 duo. CVE-2026-78509 is a Critical RCE. It has a network vector, no user interaction per the metrics, and explicitly lists the Preview Pane as an attack vector. That's the worst combination Office offers: code execution from a message you merely preview. There are a few other Preview Pane bugs in Office and Word.
ZDI: The Remnants: Another ~100 bugs land in six familiar components: Win32k (25), Standard XPS (18), WER (13), Device Association (13), Search (11), Print Spooler (11). Almost all are local EoPs to SYSTEM, but don't skim past them: 19 are rated More Likely, and XPS smuggles in an unauthenticated 9.8 RCE (CVE-2026-69824).
Tenable: CVE-2026-69525 | Remote Desktop Services remote code execution vulnerability
Tenable: CVE-2026-69525 is an RCE vulnerability affecting Remote Desktop Services. It received a CVSSv3 score of 9.8 and is rated as important. Successful exploitation of this flaw would allow an attacker to execute arbitrary code by exploiting a use-after-free flaw. Microsoft assesses this vulnerability as “Exploitation More Likely.”
Tenable: In addition to CVE-2026-69525, three RCEs in Remote Desktop Services were also patched this month. While each were rated as important, they differed in their CVSS scoring and exploitability rating as noted in the table below:
ZDI: - CVE-2026-69525 - Remote Desktop Services Remote Code Execution Vulnerability. This CVSS 9.8 bug allows remote, unauthenticated attackers to run arbitrary code on affected systems via a Use-After-Free bug. Microsoft notes it needs to be an “in-network attacker”, but the CVSS still says Network. Since many enterprises rely on RDP, I would treat this one seriously and test and deploy the patch soonest.
Qualys: CVE-2026-81948, CVE-2026-81951, & CVE-2026-81959: Microsoft Excel Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Microsoft Office Excel may allow an unauthenticated attacker to execute code locally.
Qualys: CVE-2026-81949: Microsoft Excel Remote Code Execution Vulnerability An integer overflow flaw in Microsoft Office Excel may allow an unauthenticated attacker to execute code locally.
Qualys: CVE-2026-81950: Microsoft Excel Remote Code Execution Vulnerability A double-free flaw in Microsoft Office Excel may allow an unauthenticated attacker to execute code locally.
Qualys: CVE-2026-81953: Microsoft Excel Remote Code Execution Vulnerability The stack-based buffer overflow flaw in Microsoft Office Excel may allow an unauthenticated attacker to execute code locally.
Qualys: CVE-2026-72986 & CVE-2026-73018: Graphic Fonts Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Graphic Fonts may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-65772: Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability The deserialization of untrusted data in Microsoft Dynamics 365 may allow an authenticated attacker to execute code over a network.
Qualys: CVE-2026-69632, CVE-2026-69678, CVE-2026-69767, & CVE-2026-69797: Microsoft Office PowerPoint Remote Code Execution Vulnerability The use-after-free flaw in Microsoft Office PowerPoint may allow an unauthenticated attacker to execute code over a network.
ZDI: - CVE-2026-69465 - Microsoft Office SharePoint Remote Code Execution Vulnerability. I count 17 different SharePoint bugs in this release, with four leading to code execution. On its own, this bug doesn’t look like the worst, but SharePoint has been a popular target recently, and these are the types of bugs being used. An authenticated user can submit a page that bypasses a control-safety check, causing the affected server to load code from a filesystem under the attacker’s control. If you have SharePoint servers accessible from the internet, test and deploy these updates quickly.
Qualys: CVE-2026-77504: Microsoft Office Word Remote Code Execution Vulnerability A double-free flaw in Microsoft Office Word may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-67631 & CVE-2026-67643: Microsoft SQL Server Remote Code Execution Vulnerability The heap-based buffer overflow flaw in SQL Server may allow an authenticated attacker to execute code over a network.
Qualys: CVE-2026-67378: Microsoft SQL Server Remote Code Execution Vulnerability Successful exploitation of the vulnerability may allow an authenticated attacker to execute code over a network.
Qualys: CVE-2026-67636: Microsoft SQL Server Remote Code Execution Vulnerability An out-of-bounds read flaw in SQL Server may allow an authenticated attacker to execute code over a network.
ZDI: Microsoft SQL Server: As previously mentioned, there are over 62 SQL Server bugs in this release: 61 in SQL Server proper plus the Azure Arc SQL Server Extension. Here’s the breakdown: 23 RCE, 14 EoP, 21 info disclosure, three DoS, and one SFB. Five are Critical. The overwhelming pattern is authenticated memory corruption. 55 of 62 require an authorized attacker, and the CWE spread is dominated by heap overflows (15 of the RCEs are CWE-122 alone) and out-of-bounds reads (13 of the info leaks). The template is CVE-2026-67378’s: log in, submit a crafted query, corrupt memory, run code on the server. That's why the 8.8s here are less scary than they score; an attacker already needs database credentials, but it's also textbook post-compromise lateral movement.
Qualys: CVE-2026-70351: Microsoft WebP Image Extension Remote Code Execution Vulnerability An integer overflow flaw in Microsoft WebP Image Extension may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-73017: Graphics Kernel Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Graphics Kernel may allow an authenticated attacker to execute code locally.
Qualys: CVE-2026-72981: IP Helper Remote Code Execution Vulnerability The use-after-free flaw in IP Helper may allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability . CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability . CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability . CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability . CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability (SigRed’s spiritual successor) . CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability . CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability . CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability . CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability . CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability . CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability . CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability . CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability . CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability . CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability . CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability . Here’s the full list of CVEs released by Microsoft for September 2026:
Qualys: CVE-2026-62916: Microsoft Entra ID Elevation of Privilege Vulnerability An authentication bypass using an alternate path or channel in Microsoft Entra ID may allow an unauthenticated attacker to elevate privileges over a network.
Qualys: CVE-2026-70352: Azure AI Language Elevation of Privilege Vulnerability A missing authentication for a critical function in Azure AI Language may allow an unauthenticated attacker to elevate privileges over a network.
Qualys: CVE-2026-83711: Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability An authorization bypass through a user-controlled key in Microsoft Azure Active Directory B2C may allow an unauthenticated attacker to elevate privileges over a network.
Tenable: CVE-2026-69380 | Microsoft Exchange Server elevation of privilege vulnerability
Tenable: CVE-2026-69380 is an EoP in Microsoft Exchange Server. It received a CVSSv3 score of 8.1 and is rated as important. This is a missing authorization vulnerability. An authenticated attacker with access to a mailbox through a low-user privilege user account could exploit this vulnerability to gain access to other mailboxes. Successful exploitation would allow the attacker to send and receive emails as other Exchange users as well as access attachments. Despite the high CVSS score, this vulnerability is rated as “Exploitation Less Likely” according to the Microsoft Exploitability Index.
ZDI: Exchange Server: Only nine bugs here, but there are some whoppers. Three different bugs rate CVSS 9.1 or higher. CVE-2026-69380 is an interesting exploit. A low-privileged user with a mailbox abuses request/token validation to impersonate any user and take over every mailbox: read, send, download attachments. Post-phish, this turns one compromised account into the whole org's mail. An unauthenticated mail-processing RCE plus a mailbox-takeover EoP in the same release is a chainable pair on paper. Initial access and lateral movement in one Cumulative Update. The other unauthenticated bug to mention is CVE-2026-69356, an specially crafted calendar invite; victim clicks the Join link, and script runs in their context. XSS wearing a spoofing label. Neat.
Qualys: CVE-2026-69740, CVE-2026-69784, & CVE-2026-69864: Windows Hello Elevation of Privilege Vulnerability The use-after-free in Windows Hello may allow an authenticated attacker to elevate privileges locally.
Qualys: CVE-2026-69710 & CVE-2026-69799: Windows Hello Elevation of Privilege Vulnerability A race condition in Windows Hello may allow an authenticated attacker to elevate privileges locally.
Qualys: CVE-2026-69820 & CVE-2026-81354: Windows Hello Elevation of Privilege Vulnerability The heap-based buffer overflow flaw in Windows Hello may allow an authenticated attacker to elevate privileges locally.
Qualys: CVE-2026-69725: Windows Hello Elevation of Privilege Vulnerability A double-free flaw in Windows Hello may allow an authenticated attacker to elevate privileges locally.
Qualys: CVE-2026-69874: Windows ALPC Elevation of Privilege Vulnerability Successful exploitation of the vulnerability may allow an authenticated attacker to elevate privileges locally.
ZDI: Windows Biometric Service: 64 bugs here, and 63 of them look almost identical. It's one bug class, stamped 56 times. CWE-122 heap-based buffer overflow accounts for 56 of them, with 5 integer overflows, 2 use-after-frees, and a NULL dereference rounding out the memory-corruption set. There are two worth noting: CVE-2026-69727. It has an outlier exploit vector: it reads “elevate privileges over a network” rather than locally, which is not what you want to see in a biometric service. The other is CVE-2026-73008. The lone info disclosure and it's CWE-359: exposure of private personal information. A biometric service leaking PII with high confidentiality impact is a worse look than the score implies. It also makes it a natural companion to the Hello cleartext tampering bug.
Qualys: CVE-2026-72958: Windows Credential Guard Elevation of Privilege Vulnerability A double-free flaw in Windows Credential Guard may allow an authenticated attacker to elevate privileges locally.
Qualys: CVE-2026-69501 & CVE-2026-83939: Windows Secure Kernel Mode Elevation of Privilege Vulnerability Untrusted pointer dereference in Windows Secure Kernel Mode may allow an authenticated attacker to elevate privileges locally.
Qualys: CVE-2026-69846: Windows Secure Kernel Mode Elevation of Privilege Vulnerability An integer overflow flaw in Windows Secure Kernel Mode may allow an authenticated attacker to elevate privileges locally.
Qualys: CVE-2026-69906: Windows Secure Kernel Mode Elevation of Privilege Vulnerability The heap-based buffer overflow flaw in Windows Secure Kernel Mode may allow an authenticated attacker to elevate privileges locally.
Qualys: CVE-2026-72962: Windows USB Video Driver Elevation of Privilege Vulnerability The heap-based buffer overflow flaw in the Windows USB Video Driver may allow an authenticated attacker to elevate local privileges.
Qualys: CVE-2026-69890: Windows Virtual Trusted Platform Module Elevation of Privilege Vulnerability The use-after-free flaw in the Windows Virtual Trusted Platform Module may allow an authenticated attacker to elevate local privileges.
Qualys: CVE-2026-83498: Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability An untrusted pointer dereference flaw in Windows Virtualization-Based Security (VBS) Enclave may allow an authenticated attacker to elevate privileges locally.
Qualys: CVE-2026-80098: Copilot Studio Elevation of Privilege Vulnerability An improper verification of a cryptographic signature in Copilot Studio may allow an unauthenticated attacker to elevate privileges over a network.
Qualys: CVE-2026-70178: Microsoft Fabric Elevation of Privilege Vulnerability A missing authorization flaw in Microsoft Fabric may allow an authenticated attacker to elevate privileges over a network.
Qualys: CVE-2026-65818: Power Automate Elevation of Privilege Vulnerability The server-side request forgery (SSRF) flaw in Power Automate may allow an authenticated attacker to elevate privileges over a network.
Qualys: CVE-2026-83941: Entra ID Elevation of Privilege Vulnerability A missing authorization flaw in Entra ID may allow an authenticated attacker to elevate privileges over a network.
Qualys: CVE-2026-65669: Microsoft SQL Server Elevation of Privilege Vulnerability The code injection flaw in SQL Server may allow an unauthenticated attacker to elevate privileges over a network.
ZDI: - CVE-2026-65669 - Microsoft SQL Server Elevation of Privilege Vulnerability. Speaking of AI-assisted code audits, there are over 60 patches for SQL Server in the September release. This bug even has an AI component, as the attacker would need to convince a user to submit specially crafted instructions to SQL Copilot in SQL Server Management Studio. So there’s the user interaction component, but if they succeed, the attacker could gain access to the database at the user’s permission level. Patching SQL Server will not be trivial this month, so take your time with your testing and really guard those SQL Servers that may be connected to the Internet.
Qualys: CVE-2026-72961: Windows Hyper-V Elevation of Privilege Vulnerability An out-of-bounds read flaw in Windows Hyper-V may allow an authenticated attacker to elevate privileges locally.
ZDI: - CVE-2026-80097 - Microsoft Authenticator Elevation of Privilege Vulnerability. This is the worst type of privilege escalation as it uses a bug in the authentication system itself. An attacker would need to install a malicious app on an Android device, then convince a user to complete the authentication sequence. Once done, the attacker gets the auth tokens and can access resources as the affected user. If you have a large Android user base, best not to ignore this one.
ZDI: SharePoint Server: This month’s release includes 16 SharePoint bugs: six RCE, two EoP, four spoofing, and four info disclosure. All Important, none exploited or publicly disclosed, nothing rated above “Exploitation Less Likely”, but given SharePoint's recent history of “Less Likely” becoming “in the KEV catalog,” the RCE set deserves respect. The RCE bugs do all require authentication, but the level is pretty basic, although the bug classes (deserialization, SQLi, SSRF, XSS, auth bypass) read like a web-app pentest report rather than memory corruption. The EoPs continue the theme of web-app sins in a server product: CVE-2026-69716 is a SQL injection letting a low-privileged user run database commands with elevated privileges; CVE-2026-83950 is an SSRF-based EoP; 69464 is an unnecessary-privileges flaw at CVSS 8.8.
Qualys: CVE-2026-69854: Spring Cloud Azure Elevation of Privilege Vulnerability An improper authentication flaw in Spring Cloud Azure may allow an unauthenticated attacker to elevate privileges over a network.
Qualys: CVE-2026-72980: Windows Hello Security Feature Bypass Vulnerability An uncontrolled search path element in Windows Hello may allow an authenticated attacker to bypass a security feature locally.
Qualys: CVE-2026-62906: Microsoft Discovery Studio Information Disclosure Vulnerability Improper neutralization of special elements in data query logic within Microsoft Discovery Studio may allow an unauthenticated attacker to disclose information over a network.
ZDI: Windows DHCP Server: Windows DHCP Server chimes in with 36 bugs: 12 RCE, 18 DoS, five info leaks, and one EoP. Nothing exploited or disclosed, but 22 of the 36 require no authentication. It's the third-largest single-component pile of the month, and it's all one story: someone pointed a (likely AI-assisted) fuzzer at DHCP packet parsing. In addition to the two wormable bugs already mentioned, there are three more that didn’t carry the exact wormable verbiage but look like close cousins: CVE-2026-69845 (9.8, heap overflow), CVE-2026-69266 (8.8, integer overflow), and CVE-2026-69620 (8.1, stack overflow). If you're being generous, that's five wormable-shaped bugs in DHCP Server alone. The remaining seven RCEs need an authorized attacker. CWE spread is pure memory corruption: heap, stack, UAF, integer overflow. There are 18 DoS bugs, and 13 are unauthenticated at a CVSS score of 7.5. Malformed packet in, service crash out. Individually boring, but collectively, an unauthenticated attacker on the network has 13 different ways to take out DHCP, and when DHCP dies, clients stop getting leases and the helpdesk phone starts ringing. Finally, there are a couple of oddballs here: CVE-2026-69297 is an info leak that could expose passwords stored in a recoverable format, which is a configuration-secrets problem rather than a memory bug. The lone EoP is missing authentication on a critical function.
ZDI: Windows Biometric Service: 64 bugs here, and 63 of them look almost identical. It's one bug class, stamped 56 times. CWE-122 heap-based buffer overflow accounts for 56 of them, with 5 integer overflows, 2 use-after-frees, and a NULL dereference rounding out the memory-corruption set. There are two worth noting: CVE-2026-69727. It has an outlier exploit vector: it reads “elevate privileges over a network” rather than locally, which is not what you want to see in a biometric service. The other is CVE-2026-73008. The lone info disclosure and it's CWE-359: exposure of private personal information. A biometric service leaking PII with high confidentiality impact is a worse look than the score implies. It also makes it a natural companion to the Hello cleartext tampering bug.
Qualys: CVE-2026-83501: Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability An out-of-bounds read flaw in Windows Virtualization-Based Security (VBS) Enclave may allow an authenticated attacker to disclose information locally.
Qualys: CVE-2026-78520: Microsoft Office Outlook Information Disclosure Vulnerability An out-of-bounds read flaw in Microsoft Office Outlook may allow an unauthenticated attacker to execute code over a network.
ZDI: Exchange Server: Only nine bugs here, but there are some whoppers. Three different bugs rate CVSS 9.1 or higher. CVE-2026-69380 is an interesting exploit. A low-privileged user with a mailbox abuses request/token validation to impersonate any user and take over every mailbox: read, send, download attachments. Post-phish, this turns one compromised account into the whole org's mail. An unauthenticated mail-processing RCE plus a mailbox-takeover EoP in the same release is a chainable pair on paper. Initial access and lateral movement in one Cumulative Update. The other unauthenticated bug to mention is CVE-2026-69356, an specially crafted calendar invite; victim clicks the Join link, and script runs in their context. XSS wearing a spoofing label. Neat.
Qualys: CVE-2026-69857: Azure Cosmos DB Spoofing Vulnerability An authorization bypass via a user-controlled key in Azure Cosmos DB may allow an authenticated attacker to perform network spoofing.