ZeroHour

Vulnerabilities

12,090 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-66302
Critical unauthenticated file-path RCE in Microsoft Skype for Business

CVE-2026-66302 is a critical (CVSS 9.8) vulnerability in Microsoft Skype for Business in which an external attacker controls the file name or path used by the software (CWE-73, external control of file name or path). The flaw is exploitable over a network with no authentication, no privileges, and no user interaction, so a remote unauthenticated attacker who can reach the affected Skype for Business service can trigger it. Successful exploitation yields remote code execution on the target, with high impact on confidentiality, integrity, and availability. Any organization running the affected Skype for Business deployment, presumably the on-premises Skype for Business server product, is affected; the available data does not specify the exact affected version ranges. No public proof-of-concept is known, the CVE is not in CISA's KEV catalog, and EPSS assigns roughly a 0.5% probability of exploitation in the next 30 days, so no exploitation is currently known.

Do: Apply Microsoft's September 2026 Patch Tuesday updates for Skype for Business as soon as testing permits, since the fix is delivered through that release. Until patched, restrict network access to Skype for Business services (for example, firewall or VPN rules limiting who can reach the server), and identify any Skype for Business endpoints exposed to the internet for prioritized patching and monitoring. Check vendor advisory pages for the specific affected and fixed version numbers for your deployment.

9.8
group max
<1%
  • Microsoft Skype for Business
largelikely tens of thousands of on-premises Skype for Business servers across thousands of organizations (estimated; Microsoft publishes no current install counts)
CVE-2026-85880
Heap-Based Buffer Overflow in Windows ALPC Enables Local Privilege Escalation

CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), the Windows mechanism for local inter-process communication. An authorized local attacker can trigger the overflow by submitting crafted input over ALPC, corrupting heap memory in the component that handles the request. Successful exploitation allows the attacker to execute code with elevated privileges, typically gaining SYSTEM-level control of the local host, which is especially valuable as a post-exploitation or sandbox-escape step. Affected products include Windows 10 (1607, 1809, 21H2, 22H2) and Windows Server 2012, 2016, 2019, and 2022, meaning most on-premises Windows estates are in scope. The flaw was fixed in Microsoft's record 974-CVE September 2026 Patch Tuesday and was added to CISA's KEV on 2026-09-08, confirming exploitation in the wild; press reports describe Windows zero-days being chained with a Chrome zero-day in 'BlueMoon' kit attacks, though the data does not explicitly confirm this CVE is the Windows flaw in that chain.

Do: Apply Microsoft's September 2026 security (cumulative) updates for each affected Windows 10 and Windows Server build, as no public PoC or workaround is documented; CISA's KEV listing (added 2026-09-08) triggers BOD 26-04 patching requirements for federal agencies, so prioritize accordingly. Give priority to hosts where unprivileged users can log in — RDS/VDI servers, jump boxes, shared workstations — and to internet-exposed Windows servers, since an ALPC local privilege escalation is a common component in exploit chains combining remote code execution or browser flaws with elevation to SYSTEM. Organizations unable to patch promptly should follow BOD 26-04 guidance for cloud services or restrict local access to affected hosts until updates are applied.

7.8<1% KEV
  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows Server 2012, 2016, 2019, 2022
mass≈100M+ Windows installations (Windows 10 1607–22H2 on consumer/enterprise endpoints plus widely deployed Windows Server 2012–2022)
CVE-2026-85877
+2 in the same advisory: …83952 …83999
Heap-Based Buffer Overflow RCE in Windows Print Spooler Components (CVE-2026-85877)

CVE-2026-85877 is a heap-based buffer overflow (CWE-122) in the Windows Print Spooler components, fixed by Microsoft in its September 2026 Patch Tuesday release. A remote, unauthenticated attacker can trigger the flaw by sending crafted input to the Print Spooler service over the network, though the CVSS vector (UI:R) indicates some form of user interaction is required for successful exploitation. If exploited, the attacker gains arbitrary code execution on the target system, with the CVSS base metrics indicating high impact to confidentiality, integrity, and availability. Any Windows system with the Print Spooler service enabled is affected; the available data does not enumerate specific vulnerable Windows versions or builds. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.4% probability of exploitation within the next 30 days (37th percentile).

Do: Apply the September 2026 Microsoft Patch Tuesday security updates as soon as possible, prioritizing Windows servers and other systems where the Print Spooler is reachable from untrusted networks. As interim mitigation, disable the Print Spooler service on hosts that do not need printing and restrict inbound RPC/SMB access to spooler-enabled machines. Audit your estate for systems running the Print Spooler service and confirm patched status after deployment.

8.8
group max
<1%
  • Microsoft Windows Print Spooler Components (Windows systems with the Print Spooler service enabled)
masshundreds of millions of Windows devices (Print Spooler enabled by default on Windows workstations and most servers)
CVE-2026-83951
+1 in the same advisory: …85875
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

NVD description · AI analysis pending
5.5<1%
  • microsoft 365 apps
  • microsoft office 2019
  • microsoft office 2021
  • +1 more
CVE-2026-83992
Heap-Based Buffer Overflow RCE in Microsoft Windows Imaging Component

CVE-2026-83992 is a heap-based buffer overflow (CWE-122) in the Windows Imaging Component (WIC), the built-in Windows service that decodes image files. An unauthenticated remote attacker can trigger the overflow by convincing a user to open or preview a specially crafted image; the CVSS 8.8 vector (AV:N/AC:L/PR:N/UI:R) confirms no privileges are required but user interaction is needed. Successful exploitation yields remote code execution in the context of the affected process, with high impact on confidentiality, integrity, and availability. Effectively all Windows systems that parse images with WIC are plausibly affected, though the available data does not enumerate specific Windows version ranges. There is currently no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.6% probability of exploitation within 30 days (47th percentile), indicating no known in-the-wild exploitation; the flaw was addressed in Microsoft's September 2026 Patch Tuesday, which fixed 973 vulnerabilities including two unrelated exploited zero-days.

Do: Apply Microsoft's September 2026 Patch Tuesday Windows security updates across all endpoints and servers, prioritizing user-facing systems. Because exploitation requires user interaction, exercise caution with image files from untrusted sources (email attachments, downloads, preview panes) until patching is complete. Verify patch status by confirming the latest Windows cumulative update is installed on each system.

8.8
group max
<1%
  • Microsoft Windows Imaging Component (WIC), a component of Microsoft Windows
masshundreds of millions of Windows devices (WIC is a default component present on essentially all Windows installations)
CVE-2026-84003
Capture-replay authentication bypass in Microsoft MSAL for Node.js

CVE-2026-84003 is an authentication bypass by capture-replay (CWE-294) in the Microsoft Authentication Library (MSAL) for Node.js, the library Node.js applications use to authenticate users and services against Microsoft's identity platform. An attacker positioned on the network who can capture authentication material in transit can replay it to authenticate as a legitimate user or client, with no privileges or user interaction required; the high attack complexity reflects the difficulty of intercepting and replaying the exchange while it remains valid. Successful exploitation enables spoofing with high impact on confidentiality and integrity (the attacker can act as the victim), though there is no availability impact. Any organization running Node.js server applications, APIs, daemons, or CLIs that depend on MSAL for Node.js is affected, with end users of those applications exposed through them. As of this writing there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts the 30-day exploitation probability at 0.4% (37th percentile); the fix shipped in Microsoft's September 2026 Patch Tuesday.

Do: Upgrade the @azure/msal-node package to the patched release issued with September 2026 Patch Tuesday (check Microsoft's advisory for the exact fixed version numbers) and redeploy every Node.js service that depends on it. Review Microsoft Entra ID sign-in and authentication logs for the same captured credentials or tokens being replayed from unexpected sources, and prioritize internet-facing or network-exposed services where traffic interception is feasible. Note the high attack complexity: exploitation requires an attacker to capture in-flight authentication material, so exposure depends heavily on network paths and TLS posture.

7.4<1%
  • Microsoft Authentication Library (MSAL) for Node.js (@azure/msal-node)
mass~1M+ downstream Node.js deployments (npm downloads for @azure/msal-node run on the order of 1M/week)
CVE-2026-83997
Use-After-Free RCE in Windows Message Queuing (MSMQ)

CVE-2026-83997 is a use-after-free (CWE-416) vulnerability in Microsoft's Windows Message Queuing (MSMQ) service that permits an unauthenticated, remote attacker to execute arbitrary code over the network. It is triggered when the MSMQ service processes specially crafted network traffic that causes memory to be used after it has been freed, with the high attack-complexity rating (AC:H) indicating the attacker likely needs to win a timing or state race to land the free-then-use condition. Successful exploitation yields code execution in the context of the MSMQ service, with high confidentiality, integrity, and availability impact, meaning an attacker could take over the affected host. Only Windows systems that have the optional Message Queuing (MSMQ) feature installed and running are exposed, since MSMQ is not enabled by default on most Windows installations and is typically found on legacy application and queuing servers. There is no evidence of exploitation so far: the flaw is not in CISA's KEV, no public proof-of-concept is known, EPSS is 0.5% (42nd percentile), and the two actively exploited zero-days mentioned in September 2026 Patch Tuesday headlines are separate issues fixed in the same release.

Do: Apply Microsoft's September 2026 Patch Tuesday security updates for Windows, which include the fix for CVE-2026-83997, prioritizing servers where the Message Queuing (msmq/mqsvc) service is installed. Where MSMQ is not required, disable and remove the Message Queuing feature; where it is needed, restrict inbound access to MSMQ network ports from untrusted networks and verify the service is not exposed to the internet.

8.1<1%
  • Microsoft Windows Message Queuing (MSMQ) - Windows releases with the optional Message Queuing feature installed and running
largeplausibly on the order of hundreds of thousands of Windows hosts worldwide have MSMQ installed (estimate), with only a smaller subset internet-exposed
CVE-2026-83991
Missing Authentication in Windows Cloud Files Mini Filter Enables Local Tampering

CVE-2026-83991 is a missing-authentication flaw (CWE-306) in the Windows Cloud Files Mini Filter Driver, the kernel component that handles cloud placeholder files such as OneDrive Files On-Demand. A local attacker who already has low-privileged authorized access to a machine can invoke the driver's critical function without proper authentication checks and tamper with cloud-managed file data, with high integrity impact but no confidentiality or availability loss per the CVSS vector. Because the attack vector is local (AV:L) with required privileges of only a standard user, it does not by itself enable remote compromise; it matters most on shared or multi-user systems where untrusted users hold local accounts. All supported Windows 10 releases from 1809 onward, Windows 11 from 23H2 onward, and Windows Server 2019/2022/2025 are listed as affected. The flaw is not in CISA's KEV, its EPSS score is a low 0.3%, but a public proof-of-concept write-up exists on GitHub, and Microsoft shipped a fix as part of its September 2026 Patch Tuesday release.

Do: Apply Microsoft's September 2026 Patch Tuesday security updates to all affected Windows 10, Windows 11, and Windows Server builds. Prioritize shared workstations, VDI hosts, and servers where low-privileged or untrusted users have local sign-in rights, since exploitation requires local access and only tampers with cloud files data. No in-the-wild exploitation is reported (EPSS 0.3%, not in KEV), but a public PoC exists, so treat the patch as routine-high priority rather than emergency.

5.5<1% PoC
  • microsoft Windows 10 1809 Windows 10 version 1809 (all builds prior to the September 2026 security update)
  • microsoft Windows 10 21H2 Windows 10 version 21H2 (all builds prior to the September 2026 security update)
  • microsoft Windows 10 22H2 Windows 10 version 22H2 (all builds prior to the September 2026 security update)
  • +7 more
masshundreds of millions of Windows devices (Windows 10/11 installed base exceeds 1 billion machines)
CVE-2026-83990
Local Privilege Escalation via Stack Overflow in Microsoft Graphics Component

CVE-2026-83990 is a stack-based buffer overflow (CWE-121) in the Microsoft Graphics Component, the Windows component that processes graphics operations. Per the CVSS vector, a local, low-privileged authorized user can trigger the overflow without user interaction, corrupting a stack buffer in the component. A successful attacker elevates privileges locally, gaining higher (typically administrator/SYSTEM-level) rights with high impact on confidentiality, integrity, and availability on the host. Any system shipping the Graphics Component is affected; specific version ranges were not enumerated in the source data, and fixes ship in Microsoft's September 2026 security updates. There is no public PoC, the flaw is not in CISA KEV, and EPSS is low (0.3%), so exploitation is not confirmed; it was patched as part of September 2026 Patch Tuesday, which also addressed two separately exploited zero-days.

Do: Apply Microsoft's September 2026 security updates (Patch Tuesday) to all Windows clients and servers via Windows Update, WSUS, or Intune/ConfigMgr, since no public PoC or workaround is known. Prioritize systems that expose interactive logon to untrusted or standard users, such as RDP hosts, terminal servers, and shared workstations, because local access is required for exploitation. Confirm deployment of the September 2026 updates in your patch-management reporting before marking this CVE closed.

7.8<1%
  • Microsoft Graphics Component (shipped with Microsoft Windows)
mass≈1 billion+ Windows devices (Graphics Component present across the Windows install base)