ZeroHour
Product

Spring Cloud Azure

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including 113 critical, with two Windows privilege-escalation bugs (CVE-2026-81963, CVE-2026-85880) exploited in the wild.

Microsoft's September 2026 security update addresses 973 vulnerabilities across its product lineup, 113 rated critical, of which 82 are remote code execution flaws. Two vulnerabilities are confirmed exploited in the wild: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack (CVSS 7.8), and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8). Microsoft flags several bugs as more likely to be exploited, including a 9.8 RCE in Windows DNS Server (CVE-2026-69730), an 8.8 RCE in Windows Kerberos (CVE-2026-69676), and a 9.0 EoP in Spring Cloud Azure (CVE-2026-69854). Cisco Talos published accompanying Snort rules to detect exploitation attempts against the prominent flaws.

Cisco Talos · 7d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69676+27 CVEs

Related CVEs

  • Unauthenticated Heap Overflow RCE in Microsoft Windows DHCP Server
    CVE-2026-69845 is a heap-based buffer overflow caused by improper input validation (CWE-20/CWE-122) in the Windows DHCP Server service, letting an unauthorized remote attacker execute arbitrary code with no privileges or user interaction required. An attacker triggers it by sending specially crafted DHCP network traffic to a machine running the DHCP Server role, and successful exploitation gives full compromise of the affected host (confidentiality, integrity, and availability all rated high per the 9.8 CVSS score). Affected products span Windows 10 1607 and 1807/1809-era releases through Windows Server 2012, 2016, 2019, 2022, and 2025, meaning both legacy out-of-support and current server builds are exposed. Microsoft addressed the flaw in the September 2026 Patch Tuesday release. No public proof-of-concept or in-the-wild exploitation is known, and EPSS currently puts 30-day exploitation probability at about 1%.
    · microsoft windows 10 1607 1607 (all editions/branches in this build line as listed by Microsoft) · microsoft windows 10 1809 1809 (LTSC/Server-equivalent branch as listed by Microsoft)mass
  • Critical unauthenticated file-path RCE in Microsoft Skype for Business
    CVE-2026-66302 is a critical (CVSS 9.8) vulnerability in Microsoft Skype for Business in which an external attacker controls the file name or path used by the software (CWE-73, external control of file name or path). The flaw is exploitable over a network with no authentication, no privileges, and no user interaction, so a remote unauthenticated attacker who can reach the affected Skype for Business service can trigger it. Successful exploitation yields remote code execution on the target, with high impact on confidentiality, integrity, and availability. Any organization running the affected Skype for Business deployment, presumably the on-premises Skype for Business server product, is affected; the available data does not specify the exact affected version ranges. No public proof-of-concept is known, the CVE is not in CISA's KEV catalog, and EPSS assigns roughly a 0.5% probability of exploitation in the next 30 days, so no exploitation is currently known.
    · Microsoft Skype for Businesslarge
  • Kerberos Capture-Replay Authentication Bypass in Microsoft Windows (RCE)
    CVE-2026-69676 is a capture-replay authentication bypass (CWE-294) in the Windows Kerberos implementation, disclosed by Microsoft as part of the September 2026 Patch Tuesday. An attacker who is already authorized (low-privilege credentials) can replay captured authentication material over the network to bypass authentication checks. Successful exploitation results in remote code execution, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score of 8.8). Any organization running Windows in an Active Directory environment is potentially affected, since Kerberos is the default authentication protocol for Windows domains. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a ~1.2% chance of exploitation within 30 days, though it shipped in a record-sized Patch Tuesday release alongside two actively exploited zero-days.
    · Microsoft Windows (Kerberos authentication implementation)mass
  • Untrusted Pointer Dereference RCE in Microsoft SQL Server (authorized attacker)
    Microsoft SQL Server contains an untrusted pointer dereference (CWE-822), a memory-safety flaw in which the database engine dereferences a pointer derived from untrusted input. It is triggered remotely by an authorized, low-privileged attacker whose input causes the engine to follow the invalid pointer; the high attack complexity (AC:H) in the CVSS vector means successful exploitation depends on specific runtime conditions. A successful attacker gains remote code execution, and the changed-scope (S:C) designation plus high confidentiality, integrity, and availability scores indicate code may execute beyond the SQL Server service's normal security context with severe impact. Any organization running affected Microsoft SQL Server builds is exposed, though the available data does not specify affected version ranges, so defenders should consult Microsoft's advisory for exact builds. No public proof-of-concept, CISA KEV listing, or in-the-wild exploitation is currently known, and EPSS estimates only a 0.5% probability of exploitation within the next 30 days.
    · Microsoft SQL Servermass
  • Untrusted Pointer Dereference LPE in Windows Secure Kernel Mode
    CVE-2026-83939 is an untrusted pointer dereference (CWE-822) in the Windows Secure Kernel Mode, the high-privilege virtualization-based security component of Windows. A local attacker who is already authorized and holds high privileges on the system can trigger the flaw by causing the Secure Kernel to dereference an attacker-influenced pointer, gaining local elevation of privileges. Because the CVSS scope is 'changed' (S:C), the flaw lets an attacker cross a security boundary beyond the process they started in, with high impact on confidentiality, integrity and availability. Any Windows installation whose Secure Kernel component is affected is at risk, per Microsoft's September 2026 Patch Tuesday advisory; exact version ranges are listed in Microsoft's bulletin. There is no known in-the-wild exploitation, no public proof-of-concept, and a low 0.3% EPSS probability of exploitation in the next 30 days, but a fix shipped as part of the 974-vulnerability September 2026 release.
    · Microsoft Windows (Secure Kernel Mode component)mass
  • Heap Overflow in Microsoft Windows Secure Kernel Mode Allows Local Privilege Escalation
    CVE-2026-69906 is a heap-based buffer overflow (CWE-122) in Windows Secure Kernel Mode, the isolated, higher-trust kernel component that underpins Microsoft's Virtualization-Based Security (VBS). It is triggered locally by an already-authorized attacker who holds high privileges on the machine (CVSS PR:H), with no user interaction required. Successful exploitation allows the attacker to elevate privileges into the secure kernel's trust scope (CVSS scope-changed, S:C), with high impact to confidentiality, integrity, and availability, and potential undermining of VBS-protected assets such as credential isolation. Affected systems are Microsoft Windows releases that ship the Secure Kernel Mode component; the source data does not enumerate specific affected version ranges, and fixes shipped in Microsoft's September 2026 Patch Tuesday, whose coverage also highlighted related Snort detection rules. As of publication there is no known public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation within 30 days (25th percentile).
    · Microsoft Windows (Secure Kernel Mode component / Virtualization-Based Security)mass
  • Integer Overflow in Windows Secure Kernel Mode Enables Local Privilege Escalation
    CVE-2026-69846 is an integer overflow or wraparound flaw (CWE-190) in the Windows Secure Kernel Mode, the isolated kernel component that underpins Virtualization-Based Security features such as Credential Guard. It is triggered locally by an authorized attacker who already holds high privileges on the machine (per the CVSS PR:H vector), by causing a size or count computation to wrap around and corrupt secure kernel memory. Successful exploitation lets the attacker elevate privileges across a security boundary (CVSS Scope: Changed), potentially gaining code execution at a higher trust level and undermining VBS-based protections. All Windows builds listed for this CVE in Microsoft's September 2026 Patch Tuesday advisory are affected; the available data does not enumerate specific versions, so administrators should consult the advisory for exact ranges. There is currently no public proof-of-concept, no entry in CISA's KEV catalog, and only a modest 0.3% EPSS probability of exploitation within 30 days, so no in-the-wild exploitation is known.
    · Microsoft Windows (Secure Kernel Mode)mass
  • Heap-Based Buffer Overflow in Windows Deployment Services Allows Local Code Execution
    CVE-2026-72957 is a heap-based buffer overflow (CWE-122) in Microsoft's Windows Deployment Services (WDS), the optional Windows Server role used for network-based operating system deployment such as PXE boot and imaging. The flaw is triggered locally: an authorized, low-privileged attacker sends crafted input to the WDS service, overflowing a heap buffer with no user interaction required. Successful exploitation allows the attacker to execute code locally on the affected server, and the high confidentiality, integrity, and availability ratings combined with the low privilege requirement are consistent with a local elevation-of-privilege outcome. Any organization running the WDS server role on Windows Server is affected; the provided data does not specify which Windows Server versions are impacted. As of the available data the flaw is not known to be exploited: it is absent from CISA KEV, has no public proof-of-concept, carries a low 0.3% EPSS score, and was addressed in Microsoft's September 2026 Patch Tuesday.
    · Microsoft Windows Deployment Services (Windows Server role)large
  • Use-after-free in Windows Services for NFS ONCRPC XDR Driver enables local code execution
    CVE-2026-70585 is a use-after-free (CWE-416) memory-safety flaw in the Windows Services for NFS ONCRPC XDR driver, the Windows component that handles ONCRPC/XDR protocol processing for NFS interoperability. An authorized attacker with low privileges on the host can trigger the flaw locally with no user interaction, though exploitation is rated high attack complexity, and successful exploitation yields local code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.0 High). Exposure is limited to Windows systems where the optional Services for NFS / Client for NFS feature is enabled, since the vulnerable driver is tied to that NFS interoperability functionality. As of the September 2026 Patch Tuesday release, there is no known in-the-wild exploitation, no public proof of concept, the flaw is not in CISA KEV, and EPSS assigns a low 0.3% 30-day exploitation probability.
    · Microsoft Windows Services for NFS ONCRPC XDR Driver (Services for NFS / Client for NFS component)large
  • Out-of-Bounds Read in Windows Virtualization-Based Security (VBS) Enclave
    An out-of-bounds read (CWE-125) in the Windows Virtualization-Based Security (VBS) Enclave allows a locally authenticated, low-privilege attacker to read memory beyond the enclave's intended boundary. It is triggered by code running locally under an authorized account that interacts with the enclave, with no user interaction required. The result is information disclosure only - potentially leaking data the enclave was meant to isolate, such as secrets or protected content - with no impact on integrity or availability. Any Windows system with VBS Enclave support is affected; Microsoft patched the issue in its September 2026 Patch Tuesday release, which fixed 974 vulnerabilities. No public proof-of-concept exists, the flaw is not in CISA's KEV catalog, and EPSS assigns roughly a 0.3 percent 30-day exploitation probability, so no exploitation is currently known.
    · Microsoft Windows Virtualization-Based Security (VBS) Enclavemass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.