Vulnerabilities
1,639 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81385 | Untrusted deserialization RCE in Microsoft Office Publisher CVE-2026-81385 is a high-severity (CVSS 8.8) deserialization of untrusted data flaw (CWE-502) in Microsoft Office Publisher that allows an unauthorized attacker to execute code over a network. The network attack vector combined with the required user interaction indicates a client-side attack pattern: an attacker would most plausibly deliver a maliciously crafted Publisher document (e.g., via email or download), and code execution is triggered when the victim opens or processes it, with no authentication or privileges needed on the target beforehand. Successful exploitation yields arbitrary code execution on the victim's machine in the context of the user, with high impact on confidentiality, integrity, and availability. Anyone running Microsoft Office Publisher, which is typically installed as part of Microsoft 365/Office desktop suites on Windows endpoints, is affected. There is no known public proof-of-concept and the issue is not in CISA's KEV; EPSS currently puts 30-day exploitation probability at about 1% (62nd percentile), indicating a moderate-to-low likelihood of imminent in-the-wild exploitation. Do: Apply Microsoft's security update for Publisher as soon as it is available through Windows Update/the Office update channel and verify your Publisher build against the MSRC advisory for CVE-2026-81385. Until patched, treat unsolicited .pub files from untrusted sources with suspicion and consider filtering .pub attachments at the mail gateway. Note that Publisher is scheduled for retirement by Microsoft in October 2026, so fold migration planning into remediation. | 8.8 group max | 1% |
| masslikely millions to tens of millions of users (Publisher ships with many Office/Microsoft 365 desktop suites) | ||
| CVE-2026-83948 | Command Injection in Microsoft Azure CLI Allows Authenticated Remote Code Execution CVE-2026-83948 is a command injection flaw (CWE-77) in Microsoft Azure CLI in which special shell elements are not properly neutralized before the CLI executes commands. To trigger it, an attacker who already holds some authorized (low-privilege) access must get crafted input with special characters processed by Azure CLI in a user's session, over the network, with user interaction required and high attack complexity, per the CVSS vector. A successful attack yields remote code execution in the context of the user running the CLI, and because the CVSS scope is 'changed', code may execute beyond the vulnerable component, with high impact to confidentiality, integrity and availability. Any organization running Azure CLI on admin workstations, servers, or CI/CD pipelines is potentially affected, though specific affected and fixed versions are not stated in the available data; Microsoft shipped the fix in its September 2026 Patch Tuesday release. There is no evidence of exploitation so far: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns only a 0.4% probability of exploitation in the next 30 days. Do: Update Azure CLI to the patched version delivered in Microsoft's September 2026 security updates (check Microsoft's advisory for the exact fixed version number). Until patched, limit Azure CLI use to trusted sessions and avoid running it with crafted or untrusted input in interactive sessions, and inventory admin workstations, jump hosts, and CI/CD runners where the tool is installed. Because exploitation requires existing authorized access, prioritize remediation on environments where lower-privileged Azure identities or external users can reach CLI sessions. | 8.0 | <1% |
| massest. 1M+ installations (Azure CLI commonly installed across admin workstations, developer machines, and CI/CD runners) | ||
| CVE-2026-81354 | Heap-Based Buffer Overflow in Microsoft Windows Hello Allows Local Privilege Escalation Windows Hello, the biometric and PIN sign-in component built into Windows, contains a heap-based buffer overflow (CWE-122) that Microsoft rates high severity (CVSS 3.1: 8.2). The flaw is triggered locally by an attacker who already holds authorized high-privilege access to the system, when Windows Hello processes crafted input; the source data does not specify the exact code path. Successful exploitation allows the attacker to elevate privileges locally, and the CVSS scope-change (S:C) flag indicates the impact extends beyond the vulnerable component, with high confidentiality, integrity, and availability impact. Any Windows deployment containing the Windows Hello component is potentially affected, though exploitation requires prior local access with high privileges; specific affected build numbers were not provided in the source data. There is currently no known in-the-wild exploitation, no public proof-of-concept, no CISA KEV listing, and EPSS estimates only a 0.2% probability of exploitation within 30 days. Do: Apply Microsoft's security update for CVE-2026-81354 via Windows Update/WSUS as soon as it is released, prioritizing shared workstations, kiosks, and multi-user systems where several accounts hold local privileges. Until patched, restrict local administrative access to trusted users and monitor Microsoft's advisory for the exact affected build numbers. Given the 0.2% EPSS score, absence of KEV listing, and lack of public PoC, this can be handled in the regular patch cycle rather than as an emergency. | 8.2 group max | <1% |
| massRoughly 1 billion+ Windows devices include the Windows Hello component, with likely hundreds of millions actively using Hello sign-in | ||
| CVE-2026-83941 | Missing Authorization in Microsoft Entra ID Enables Privilege Escalation CVE-2026-83941 is a missing-authorization flaw (CWE-862) in Microsoft Entra ID, the cloud identity service behind Microsoft 365 and Azure. An already-authenticated, low-privileged user can send a network request to an Entra ID endpoint that fails to enforce proper authorization checks, requiring no user interaction. Exploitation lets the attacker elevate their privileges within the directory, with high confidentiality and integrity impact (CVSS 9.9, scope changed). Any organization that uses Microsoft Entra ID is in the affected population. The flaw was patched in Microsoft's September 2026 Patch Tuesday release; it is not in CISA KEV, has no known public proof-of-concept, and carries a low EPSS of roughly 0.7%. Do: Review Microsoft's September 2026 Patch Tuesday advisory for this CVE and apply any required tenant-side updates or configuration changes, noting that fixes for the cloud-hosted directory service are applied largely by Microsoft. Audit privileged role assignments and sign-in activity in your tenant for signs of unexpected elevation, and tighten who holds elevated roles. Monitor for additions to CISA KEV or public proof-of-concept code, which would raise urgency. | 8.8 | <1% |
| masshundreds of millions of user identities across hundreds of thousands of organizations (Entra ID underpins essentially all Microsoft 365/Azure tenants) | ||
| CVE-2026-80096 +1 in the same advisory: …83940 | Out-of-bounds Read Elevation-of-Privilege Flaw in Windows Remote Desktop Services CVE-2026-80096 is an out-of-bounds read (CWE-125) in Microsoft Windows Remote Desktop Services (RDS), the component that provides remote graphical sessions on Windows hosts. An attacker who already holds low-privileged, authorized access can trigger the flaw by sending crafted input to the RDS service over the network, causing the service to read beyond the bounds of an allocated memory buffer. Successful exploitation allows the attacker to elevate privileges on the target host, and the CVSS vector (AV:N/AC:L/PR:L/UI:N with high confidentiality, integrity, and availability impact) rates the issue 8.8 (High). Any Windows system with Remote Desktop Services enabled is potentially affected, though Microsoft has not published affected version details in the data available here. There is currently no evidence of exploitation, no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts the 30-day exploitation probability at 0.7% (52nd percentile). Do: Apply Microsoft's security update for CVE-2026-80096 via Windows Update/WSUS or the Microsoft advisory as soon as practical, prioritizing hosts running the Remote Desktop Services role or with RDP enabled. Inventory RDP exposure by checking for RDS-enabled systems and TCP/3389 listeners, and restrict internet-facing RDP (VPN, firewall rules, Network Level Authentication) as an interim mitigation. Monitor Microsoft's advisory for affected-version specifics and any updated guidance. | 8.8 group max | <1% |
| massmillions of Windows hosts with RDS/RDP enabled, including on the order of hundreds of thousands of internet-exposed RDP endpoints | ||
| CVE-2026-83939 | Untrusted Pointer Dereference LPE in Windows Secure Kernel Mode CVE-2026-83939 is an untrusted pointer dereference (CWE-822) in the Windows Secure Kernel Mode, the high-privilege virtualization-based security component of Windows. A local attacker who is already authorized and holds high privileges on the system can trigger the flaw by causing the Secure Kernel to dereference an attacker-influenced pointer, gaining local elevation of privileges. Because the CVSS scope is 'changed' (S:C), the flaw lets an attacker cross a security boundary beyond the process they started in, with high impact on confidentiality, integrity and availability. Any Windows installation whose Secure Kernel component is affected is at risk, per Microsoft's September 2026 Patch Tuesday advisory; exact version ranges are listed in Microsoft's bulletin. There is no known in-the-wild exploitation, no public proof-of-concept, and a low 0.3% EPSS probability of exploitation in the next 30 days, but a fix shipped as part of the 974-vulnerability September 2026 release. Do: Install the September 2026 Windows security (cumulative) updates from Microsoft's Patch Tuesday release for every affected Windows version in your environment; do not skip workloads where virtualization-based security features (e.g., HVCI/Credential Guard) are enabled, as they rely on the affected Secure Kernel. Because the flaw requires an attacker to already hold high local privileges, treat it as a chaining/enabler risk for adversary-in-the-middle post-exploitation and prioritize patching hosts with many privileged users or admins. No workaround or mitigation is listed in the source data; check Microsoft's advisory for per-version applicability and any released mitigation guidance. | 8.2 | <1% |
| mass≈1 billion+ Windows installations (Windows runs on over a billion active devices) | ||
| CVE-2026-83498 +1 in the same advisory: …83501 | Untrusted Pointer Dereference in Windows VBS Enclave Allows Local Privilege Escalation CVE-2026-83498 is an untrusted pointer dereference (CWE-822) in the Virtualization-Based Security (VBS) Enclave component of Microsoft Windows. An authorized local attacker, meaning someone who already holds low-privileged code execution on the machine, can cause the enclave to dereference attacker-controlled pointers with no user interaction required. Successful exploitation breaks the VBS enclave trust boundary and elevates the attacker's privileges locally, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). All Windows editions that ship the VBS Enclave feature are in scope, but the source data does not enumerate specific vulnerable builds, so defenders should consult Microsoft's advisory for the exact affected-product matrix. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, EPSS assigns only a 0.3% probability of exploitation within 30 days, and fixes shipped in Microsoft's September 2026 Patch Tuesday release, which addressed 974 vulnerabilities including 2 zero-days (this CVE is not confirmed to be one of the actively exploited ones). Do: Apply Microsoft's September 2026 Patch Tuesday cumulative updates to affected Windows systems, prioritizing multi-user hosts, jump servers, and endpoints where untrusted or low-privileged users can execute code. Verify VBS status via System Information (msinfo32) and confirm the September 2026 update is installed using the fixed-build details in Microsoft's advisory. No workaround is documented, and with no public PoC or in-the-wild exploitation known, routine patch cadence is reasonable for isolated single-user systems. | 7.8 group max | <1% |
| mass≈ hundreds of millions of Windows 10/11 devices ship the vulnerable VBS Enclave component | ||
| CVE-2026-81963 | Local Privilege Escalation via Link Following in Windows Update Stack CVE-2026-81963 is a link-following flaw (CWE-59, improper link resolution before file access) in the Microsoft Windows Update Stack, in which the component fails to correctly resolve file links before opening them. A local attacker with low privileges can plant or manipulate a link (symlink/junction) that the privileged update stack follows during operation, redirecting its file access to an attacker-controlled target. The result is local privilege escalation — CVSS 3.1 rates this 7.8 (high) with high confidentiality, integrity, and availability impact — allowing an authorized local user or malware already on the machine to gain elevated rights. Affected products are Windows 11 23H2, 24H2, 25H2, and 26H1 and Windows Server 2025; any unpatched system on those versions is exposed to any local account holder. The flaw was fixed in Microsoft's record September 2026 Patch Tuesday (974 CVEs), was added to CISA's KEV on 2026-09-08 as one of two Windows zero-days reported as exploited in the wild, and has no known public PoC or confirmed ransomware use. Do: Immediately deploy the September 2026 Patch Tuesday cumulative updates to every Windows 11 23H2/24H2/25H2/26H1 and Windows Server 2025 host; as a KEV entry under BOD 26-04, prioritize internet-exposed and high-value assets, apply vendor mitigations (or discontinue use) where patching is delayed, and follow CISA's forensics triage requirements if compromise is suspected. Verify deployment via patch telemetry and review which local accounts can trigger update-stack activity on shared or multi-user systems. | 7.8 | <1% | KEV |
| masswell over 1,000,000 | |
| CVE-2026-81376 | Security Feature Bypass in Microsoft Visual Studio Code CVE-2026-81376 is a critical security feature bypass in Microsoft Visual Studio Code caused by an incomplete comparison with missing factors (CWE-1023), resulting in a protection mechanism failure (CWE-693). The flaw is reachable over a network and exploitation requires user interaction (per the CVSS vector), such as inducing a user to act on attacker-controlled content, after which an unprivileged attacker can bypass the affected security check. The changed-scope metric indicates the bypass can cross a component boundary, and the high confidentiality, integrity and availability ratings mean a successful bypass can have serious consequences beyond weakening a single control. Everyone running Visual Studio Code is potentially affected; the available data does not specify the vulnerable version ranges or the fixing release. Exploitation has not been observed: no public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS estimates only about a 0.7% chance of exploitation in the next 30 days. Do: Monitor Microsoft's advisory for the fixed release and update Visual Studio Code as soon as a patched version is published, since no version numbers are available yet. Until then, exercise caution with untrusted files, repositories and prompts (user interaction is part of the attack vector), and prioritize scheduling the update given the 9.6 critical CVSS despite no known exploitation. | 9.6 group max | <1% |
| massTens of millions of users (VS Code is the most widely used code editor, with roughly 70%+ usage share among professional developers) |