Patch Tuesday - September 2026
Microsoft's September 2026 Patch Tuesday fixes 999 CVEs, a record, with two zero-day privilege escalation flaws already exploited in the wild.
Microsoft published 974 own-product vulnerabilities plus 25 non-Microsoft CVEs, totaling 999 — the most CVEs Microsoft has ever released in a single day. Two flaws are exploited in the wild: CVE-2026-85880, an out-of-bounds write in Windows ALPC granting SYSTEM privileges, and CVE-2026-81963, an improper link resolution flaw in the Windows Update Stack also leading to SYSTEM. Chrome's V8 zero-day CVE-2026-85046 was patched in Edge on September 2, but Microsoft had not published a corresponding advisory, leaving uncertainty about other Chromium fixes in Edge. October 14 lifecycle changes end servicing for Windows 11 24H2 Home/Pro, Office 2021, and Exchange Server 2016/2019.
- Record 999 CVEs fixed on September 2026 Patch Tuesday
- CVE-2026-85880: Windows ALPC zero-day EoP exploited in the wild, grants SYSTEM
- CVE-2026-81963: Windows Update Stack EoP zero-day exploited in the wild
- Edge patched Chrome V8 zero-day CVE-2026-85046 without publishing an advisory
- Major Windows, Office, and Exchange end-of-support milestones arrive October 14, 2026
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-58611 | Local Privilege Escalation in Microsoft Xbox Gaming Services (CVE-2026-58611) CVE-2026-58611 is an improper authorization flaw (CWE-285) in Microsoft's Xbox Gaming Services on Windows in which the service fails to properly validate authorization for privileged operations. It is triggered locally: an attacker who already has a low-privileged foothold on a machine where the service is installed abuses the service without any user interaction. Successful exploitation elevates the attacker's privileges on the local machine, with high impact on confidentiality, integrity, and availability (CVSS 7.8 High). Potentially affected are Windows 10/11 PCs with the Gaming Service installed, which is typically bundled with the Xbox app, PC Game Pass, and many Microsoft Store games. As of the September 2026 Patch Tuesday there is no known exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only a 0.2% probability of exploitation within 30 days. Do: Apply the September 2026 Patch Tuesday and ensure the Microsoft Gaming Services package is current — it normally updates through the Microsoft Store, so also refresh the Store library on endpoints. Prioritize multi-user Windows machines, kiosks, and shared/VDI environments where local low-privileged access is more likely. No workaround is published, so patching is the primary mitigation. | 7.8 | <1% |
| masstens of millions of Windows 10/11 PCs with the Gaming Service installed | ||
| CVE-2026-62895 | Permissive Cross-Domain Policy Privilege Elevation in Microsoft Azure Arc Microsoft Azure Arc (CVE-2026-62895) contains a privilege elevation flaw caused by a permissive cross-domain policy that trusts untrusted domains, mapped by Microsoft to CWE-942 (permissive cross-domain policy with untrusted domains), CWE-1390 (weak authentication) and CWE-89 (SQL injection). An unauthenticated attacker can exploit it over a network, with CVSS scoring indicating some user interaction is required (AV:N/AC:L/PR:N/UI:R), by abusing the overly permissive cross-domain trust to elevate privileges, with high impact on confidentiality, integrity and availability (CVSS 3.1: 8.8 High). Any organization using Azure Arc to manage hybrid or multi-cloud resources is potentially affected. There is no evidence of exploitation in the wild, no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.7% probability of exploitation in the next 30 days (52nd percentile). Microsoft addressed the flaw as part of its September 2026 Patch Tuesday release, which fixed 966 flaws including 2 zero-days. Do: Apply Microsoft's September 2026 Patch Tuesday updates for Azure Arc across all Arc-enabled infrastructure, prioritizing environments where unauthenticated network users can reach Arc-connected resources. The available data does not include fixed version or KB details, so consult the Microsoft advisory for CVE-2026-62895 to identify the patched build for your components. In the interim, review and tighten the domains Azure Arc trusts in cross-domain policies and treat any unauthenticated network access to Arc-managed resources as a privilege-elevation risk. | 8.8 | <1% |
| masslikely hundreds of thousands to millions of managed servers across Azure Arc estates (adoption-based estimate; no counts in source data) | ||
| CVE-2026-69857 | Authorization Bypass Through User-Controlled Key in Microsoft Azure Cosmos DB CVE-2026-69857 is an authorization bypass through a user-controlled key (CWE-639, an IDOR-style flaw) in Microsoft Azure Cosmos DB, Microsoft's managed NoSQL database service: an authenticated principal can supply or alter a resource identifier (key) that the service fails to validate against the caller's permissions. Triggered over a network by a low-privileged, authorized user who manipulates such a key (CVSS 3.1 vector AV:N/AC:L/PR:L/UI:N), the flaw lets the attacker bypass access checks and perform spoofing, i.e., impersonate another identity or act outside their authorized scope. Per the CVSS vector, successful exploitation carries high impact on the confidentiality, integrity, and availability of data in the affected database account, since the attacker can read or modify data as a different authorized identity. Any organization using Azure Cosmos DB is potentially affected; because it is a fully managed Azure service there are no customer-managed installations, and no affected version ranges are specified in the advisory data. The flaw was addressed in Microsoft's September 2026 Patch Tuesday cycle (966 flaws fixed, including 2 zero-days); no public proof-of-concept is known, it is not in CISA's KEV, and EPSS estimates only a ~0.4% chance of exploitation within 30 days. Do: Review Microsoft's September 2026 security update guidance for CVE-2026-69857 and complete any required updates or customer-side actions for Azure Cosmos DB, confirming whether key rotation, RBAC/permission changes, or SDK updates are needed on your accounts. Because exploitation requires an authorized (authenticated) principal, audit who and what has access to Cosmos DB accounts, enforce least privilege on account keys and RBAC roles, and rotate account keys if exposure is suspected. No public PoC or in-the-wild exploitation is known and EPSS is low (~0.4% over 30 days), so treat this as high-priority routine patching within the normal Patch Tuesday cycle rather than an emergency. | 8.8 | <1% |
| large≈100,000+ Azure tenants/accounts with Cosmos DB resources (estimate) | ||
| CVE-2026-70352 | Unauthenticated Privilege Elevation in Microsoft Azure AI Language CVE-2026-70352 is a missing-authentication flaw (CWE-306) in Microsoft Azure AI Language, where a critical function can be reached without any credential check. An attacker triggers it by sending unauthenticated network requests to the affected Azure AI Language service, and per the CVSS score (AV:N/AC:L/PR:N/UI:N/S:C) the weakness is trivially exploitable remotely with no privileges or user interaction required. Because the impact is scoped-changed (S:C) with high confidentiality, integrity, and availability impact, a successful attacker gains elevated privileges within the service context, potentially reaching resources beyond the intended trust boundary. Any organization using the Azure AI Language cloud service is affected; as a Microsoft-managed service it was addressed through Microsoft's September 2026 security updates. There is currently no evidence of in-the-wild exploitation, no known public proof-of-concept, it is not on the CISA KEV list, and EPSS estimates only a 0.6% chance of exploitation in the next 30 days. Do: Because Azure AI Language is a Microsoft-managed service, confirm via the Azure Service Health portal or Microsoft's September 2026 advisory that your tenant has received the patched service update — no customer-side patching should be required for the cloud service. Review Azure AI Language access logs for anomalous or unexpected unauthenticated requests, and as defense-in-depth restrict endpoints with network controls such as private endpoints, firewalls, or restricted network access rules. | 10.0 | <1% |
| largeroughly 100,000–1,000,000 users/tenant applications (managed multi-tenant Azure service; exact counts not published) | ||
| CVE-2026-77909 | Insufficiently Protected Credentials in Microsoft Azure CycleCloud CVE-2026-77909 is a credential-protection flaw (CWE-522) in Microsoft Azure CycleCloud, Microsoft's tool for creating and managing HPC clusters in Azure, in which credentials are stored or transmitted with insufficient protection. A remote attacker who already holds a low-privileged authorized account can trigger the flaw over the network, with no user interaction required. Because the CVSS scope is changed with high confidentiality impact, the exposed credentials can likely be used in another security scope — for example, to retrieve or reuse secrets that grant access to additional resources beyond the immediate component — resulting in information disclosure, though integrity and availability are unaffected. Organizations running Azure CycleCloud to orchestrate HPC workloads in their Azure subscriptions are affected. There is no known public proof-of-concept, it is not in the CISA KEV catalog, EPSS is a modest 0.6% over 30 days, and no in-the-wild exploitation has been reported; a fix was distributed as part of Microsoft's September 2026 Patch Tuesday, which addressed 966 flaws. Do: Apply the Azure CycleCloud update from Microsoft's September 2026 Patch Tuesday to all CycleCloud application deployments in your Azure subscriptions, including standalone and cluster-attached instances. Since CycleCloud is customer-deployed, verify your installed build via the CycleCloud portal or CLI and update from the Azure Marketplace if outdated. As a precaution, audit and rotate credentials/API keys configured in CycleCloud, restrict network access to the application to trusted users, and review access logs for unusual credential retrieval by low-privileged accounts. | 7.7 | <1% |
| nicheunknown; plausibly in the low thousands of enterprise HPC deployments at most | ||
| CVE-2026-80097 | Improper Authentication in Microsoft Authenticator Enables Local Privilege Escalation CVE-2026-80097 is an improper authentication flaw (CWE-287) in Microsoft Authenticator that allows an unauthorized attacker to elevate privileges locally, rated 8.6 (high) with no privileges required, required user interaction, and a changed scope. Exploitation requires local access to a device running the app plus user interaction, and because the scope is changed, a successful attack crosses a security boundary beyond the Authenticator component itself. A successful exploit yields local privilege elevation with high impact to confidentiality, integrity, and availability. Anyone running affected versions of Microsoft Authenticator is affected; the app is Microsoft's standard multi-factor authentication app for Entra ID/Microsoft 365 and is widely deployed across enterprise and personal mobile devices. As of the September 2026 disclosure it is not known to be exploited - no public PoC, not in CISA KEV, EPSS 0.4% (33rd percentile) - and it was patched amid the record 974-flaw Patch Tuesday, though the two actively exploited zero-days in that release are Windows flaws, not this one. Do: Update Microsoft Authenticator through its usual app-store distribution channels (iOS App Store/Google Play) to the build released with September 2026 Patch Tuesday, and verify updated versions across the fleet via MDM or app inventory; specific patched build numbers were not provided in the source data. Prioritize shared workstations, kiosks, and hot-desked or BYOD endpoints where unprivileged local users interact with the app. No public PoC or in-the-wild exploitation is known, so routine prompt patching is appropriate. | 8.6 | <1% |
| mass≈100M+ users/devices (Microsoft's standard MFA app, with app-store install counts on the order of hundreds of millions) | ||
| CVE-2026-81349 | OS Command Injection Privilege Elevation in Microsoft Azure HDInsights CVE-2026-81349 is an operating-system command injection flaw (CWE-78) in Microsoft's Azure HDInsights managed big-data service. It is triggered when the service improperly neutralizes special elements passed into an OS command, and per the CVSS vector an attacker must already hold high-level authorized access, exploiting it over the network with no user interaction required. Successful exploitation allows the attacker to elevate privileges, with high impact on the confidentiality, integrity, and availability of the affected HDInsight environment. Only organizations running Azure HDInsight clusters are affected; the flaw was fixed as part of Microsoft's September 2026 Patch Tuesday, which addressed 966 flaws. No public proof-of-concept is known, it is not listed in CISA's KEV catalog, and EPSS estimates roughly a 0.7% chance of exploitation within 30 days. Do: Review Microsoft's September 2026 Patch Tuesday advisory for CVE-2026-81349 and apply any required service updates or customer actions to HDInsight clusters as directed. Because exploitation requires an already highly privileged authorized attacker, audit and restrict highly privileged roles, service principals, and identities with access to HDInsight resources. Monitor Azure Service Health and the MSRC advisory page for service-side remediation details. | 7.2 | <1% |
| moderatelikely on the order of low tens of thousands of Azure HDInsight clusters worldwide (exact counts unpublished) | ||
| CVE-2026-81963 +1 in the same advisory: …85880 | Local Privilege Escalation via Link Following in Windows Update Stack CVE-2026-81963 is a link-following flaw (CWE-59, improper link resolution before file access) in the Microsoft Windows Update Stack, in which the component fails to correctly resolve file links before opening them. A local attacker with low privileges can plant or manipulate a link (symlink/junction) that the privileged update stack follows during operation, redirecting its file access to an attacker-controlled target. The result is local privilege escalation — CVSS 3.1 rates this 7.8 (high) with high confidentiality, integrity, and availability impact — allowing an authorized local user or malware already on the machine to gain elevated rights. Affected products are Windows 11 23H2, 24H2, 25H2, and 26H1 and Windows Server 2025; any unpatched system on those versions is exposed to any local account holder. The flaw was fixed in Microsoft's record September 2026 Patch Tuesday (974 CVEs), was added to CISA's KEV on 2026-09-08 as one of two Windows zero-days reported as exploited in the wild, and has no known public PoC or confirmed ransomware use. Do: Immediately deploy the September 2026 Patch Tuesday cumulative updates to every Windows 11 23H2/24H2/25H2/26H1 and Windows Server 2025 host; as a KEV entry under BOD 26-04, prioritize internet-exposed and high-value assets, apply vendor mitigations (or discontinue use) where patching is delayed, and follow CISA's forensics triage requirements if compromise is suspected. Verify deployment via patch telemetry and review which local accounts can trigger update-stack activity on shared or multi-user systems. | 7.8 | <1% | KEV |
| masswell over 1,000,000 | |
| CVE-2026-83941 | Missing Authorization in Microsoft Entra ID Enables Privilege Escalation CVE-2026-83941 is a missing-authorization flaw (CWE-862) in Microsoft Entra ID, the cloud identity service behind Microsoft 365 and Azure. An already-authenticated, low-privileged user can send a network request to an Entra ID endpoint that fails to enforce proper authorization checks, requiring no user interaction. Exploitation lets the attacker elevate their privileges within the directory, with high confidentiality and integrity impact (CVSS 9.9, scope changed). Any organization that uses Microsoft Entra ID is in the affected population. The flaw was patched in Microsoft's September 2026 Patch Tuesday release; it is not in CISA KEV, has no known public proof-of-concept, and carries a low EPSS of roughly 0.7%. Do: Review Microsoft's September 2026 Patch Tuesday advisory for this CVE and apply any required tenant-side updates or configuration changes, noting that fixes for the cloud-hosted directory service are applied largely by Microsoft. Audit privileged role assignments and sign-in activity in your tenant for signs of unexpected elevation, and tighten who holds elevated roles. Monitor for additions to CISA KEV or public proof-of-concept code, which would raise urgency. | 9.9 | <1% |
| masshundreds of millions of user identities across hundreds of thousands of organizations (Entra ID underpins essentially all Microsoft 365/Azure tenants) | ||
| CVE-2026-84003 | Capture-replay authentication bypass in Microsoft MSAL for Node.js CVE-2026-84003 is an authentication bypass by capture-replay (CWE-294) in the Microsoft Authentication Library (MSAL) for Node.js, the library Node.js applications use to authenticate users and services against Microsoft's identity platform. An attacker positioned on the network who can capture authentication material in transit can replay it to authenticate as a legitimate user or client, with no privileges or user interaction required; the high attack complexity reflects the difficulty of intercepting and replaying the exchange while it remains valid. Successful exploitation enables spoofing with high impact on confidentiality and integrity (the attacker can act as the victim), though there is no availability impact. Any organization running Node.js server applications, APIs, daemons, or CLIs that depend on MSAL for Node.js is affected, with end users of those applications exposed through them. As of this writing there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts the 30-day exploitation probability at 0.4% (37th percentile); the fix shipped in Microsoft's September 2026 Patch Tuesday. Do: Upgrade the @azure/msal-node package to the patched release issued with September 2026 Patch Tuesday (check Microsoft's advisory for the exact fixed version numbers) and redeploy every Node.js service that depends on it. Review Microsoft Entra ID sign-in and authentication logs for the same captured credentials or tokens being replayed from unexpected sources, and prioritize internet-facing or network-exposed services where traffic interception is feasible. Note the high attack complexity: exploitation requires an attacker to capture in-flight authentication material, so exposure depends heavily on network paths and TLS posture. | 7.4 | <1% |
| mass~1M+ downstream Node.js deployments (npm downloads for @azure/msal-node run on the order of 1M/week) | ||
| CVE-2026-85045 | Race condition in Google Chrome V8 allows sandboxed code execution via crafted web page CVE-2026-85045 is a race condition (CWE-367, a time-of-check-to-time-of-use flaw) in the V8 JavaScript engine used by Google Chrome. An attacker triggers it by persuading a user to open a specially crafted HTML page, in which a timing window during V8's handling of an object leaves stale state that the attacker can leverage. Successful exploitation lets a remote attacker execute arbitrary code inside Chrome's renderer sandbox (but not escape it), yielding code execution at the browser's sandboxed privilege level; CVSS 3.1 rates this 7.5 High with a network vector, high attack complexity, and required user interaction. All Google Chrome installations running versions prior to 152.0.7977.82 are affected, which given Chrome's ubiquity means effectively every unpatched desktop and mobile Chrome deployment worldwide. No public proof-of-concept is known, the flaw is not on the CISA KEV catalog, and EPSS estimates a ~0.2% chance of exploitation within 30 days, though related reporting describes a sibling Chrome zero-day (CVE-2026-85046) exploited in the wild, signaling active attacker interest in this V8 code. Do: Update Google Chrome to 152.0.7977.82 or later on all endpoints and enforce the minimum version centrally (MDM/GPO/Intune/EDR), prioritizing internet-facing and high-risk users. Because the related Chrome zero-day CVE-2026-85046 was reportedly exploited in the wild and was addressed in the same release, treat this patch cycle as urgent. Also verify browser versions in any Chromium-based derivatives in your fleet, which typically pick up the V8 fix on their own release schedules. | 7.5 | <1% |
| massbillions of Chrome users/installations worldwide (Chrome holds roughly two-thirds desktop browser market share and 3+ billion users) | ||
| CVE-2026-85046 | Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046) Google Chrome versions prior to 152.0.7977.82 contain a type confusion flaw (CWE-843) in the V8 JavaScript engine, which mishandles object types during engine operations (public proof-of-concept writeups indicate it is reachable through array sorting and WebAssembly-related code paths). A remote attacker triggers the flaw simply by getting a user to open a crafted HTML page, with no privileges or authentication required. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, and public reporting shows it being chained with Windows zero-days (the 'BlueMoon' exploit kit) by Chinese espionage groups for broader compromise. Any user of an unpatched Chrome or another build embedding the affected V8 engine is exposed. The vulnerability is a zero-day that was actively exploited in the wild before patching, was added to CISA's KEV on 2026-09-04, and has five public proof-of-concept references. Do: Update Google Chrome to 152.0.7977.82 or later immediately, and apply the corresponding V8 fix in any Chromium-based browser in use. Federal agencies must apply mitigations in line with CISA BOD 26-04 and its cloud-services requirements, evaluating each asset's internet exposure. Because public reporting shows this flaw chained with Windows zero-days in 'BlueMoon' attacks, patch the related Windows vulnerabilities as well and hunt for signs of exploit-chain activity on high-exposure endpoints. | 8.8 | 1% | KEV PoC ×5 |
| massmultiple billions of users/installs (Chrome is the dominant desktop browser at roughly 65% market share, with an estimated 3+ billion active users, plus… |
Full article2,568 words · extracted from rapid7.com · click to collapse
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday, including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today.
Windows ALPC: zero-day EoP
The eternal game of elevation of privilege whack-a-mole between Microsoft and attackers continues. This month, the battle is centered on the Windows Advanced Local Procedure Call (ALPC) mechanism, a kernel capability that facilitates inter-process communication. Microsoft is aware of exploitation in the wild already. Successful abuse of the flaw underlying CVE-2026-85880 grants an attacker SYSTEM via a buffer overflow that enables an out-of-bounds write, and as we all know by now, this is exactly what would happen during the first five minutes of a technically accurate horror movie about ransomware. We can infer one silver lining here: since neither Server 2025 nor Windows 11 receives patches for CVE-2026-85880, it is likely that Microsoft’s ongoing efforts to level up memory safety by rewriting critical kernel components in Rust are paying off.
Windows Update Stack: zero-day EoP
Attackers disappointed by Microsoft’s move towards memory safety improvements for various critical kernel components need not leave empty-handed today. Microsoft is aware of existing exploitation in the wild for CVE-2026-81963, an elevation of privilege vulnerability in the Windows Update Stack that leads to SYSTEM privileges via improper link resolution. All supported versions of Windows receive a patch, which presumably tightens up controls to prevent the Windows Update Stack from following a malicious link and overwriting a system component with an attacker-controlled imposter. The relatively pedestrian CVSS v3 base score of 7.8 is no reason for less concern, since no serious attacker will bother developing an intricate one-shot RCE when a two-stage attack chain consisting of low-privileged local access coupled with elevation of privilege will achieve the same ultimate goal much more easily.
Living on the Edge: browser advisory uncertainty
For the second month in a row, Microsoft does not appear to have published any desktop browser security advisories between the start of the month and Patch Tuesday. Microsoft Edge is built on top of Google’s open-source Chromium project, and on September 3, 2026, Google Chrome patched CVE-2026-85046, an exploited-in-the-wild zero-day vulnerability in the V8 JavaScript engine relied upon by both Edge and Chrome. So, is Microsoft Edge falling dangerously behind Google Chrome? Well, maybe. In this specific case, the Edge stable channel did receive a patch a day earlier than Chrome on September 2, 2026, and we know this because the Edge release notes mention it. However, almost a week later, Microsoft still hasn’t published a security advisory for CVE-2026-85046, and until that URL returns something better than a 404, that will remain true. In short: if you’re patched, you are protected, but if you rely on advisories to know which vulns exist, you could miss this zero-day vulnerability altogether. Only Microsoft knows why this advisory is missing, but there is no reason to suppose that Microsoft is somehow immune to the pressures that come along with the vast increase in vulnerability volume. A patch without an advisory is perhaps marginally better than an advisory without a patch, but keeping track of exposures without reliable advisory materials is not straightforward. Chrome patched 11 other vulnerabilities at the same time as CVE-2026-85046, but it’s not yet clear if those are patched in Edge. Until Microsoft sets the record straight, the only safe assumption is that these vulnerabilities (e.g. CVE-2026-85045) remain unpatched in Edge.
Microsoft lifecycle update
The next Microsoft product lifecycle changes with broad impact occur on October 14, 2026, when Windows 11 24H2 Home & Pro reach end of servicing, and Windows Server 2022 moves to extended support, with free critical security updates continuing, but no further feature development. At the same time, the final curtain falls for Windows Server 2012 and 2012 R2 with the expiry of the third and final year of cash-for-updates Extended Security Update (ESU) program for these aging workhorses. Office 2021 also moves beyond support, including the Long-Term Servicing Channel, with no ESU available in that case. Also in October, Exchange Server 2016 and 2019 will join the “no ESU” club, after two previous six-month reprieves. Presumably, Microsoft really means it this time.
Summary tables
Apps vulnerabilities
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-80097 | Microsoft Authenticator Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.6 |
| CVE-2026-58611 | Xbox Gaming Services Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
Azure vulnerabilities
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-70352 | Azure AI Language Elevation of Privilege Vulnerability | N/A | No | 10.0 |
| CVE-2026-62895 | Azure Arc SQL Server Extension Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69857 | Azure Cosmos DB Spoofing Vulnerability | Exploitation More Likely | No | 8.5 |
| CVE-2026-77909 | Azure CycleCloud Information Disclosure Vulnerability | Exploitation Less Likely | No | 7.7 |
| CVE-2026-81349 | Azure HDInsight Ambari Elevation of Privilege Vulnerability | N/A | No | 7.2 |
| CVE-2026-83941 | Entra ID Elevation of Privilege Vulnerability | N/A | No | 9.9 |
| CVE-2026-84003 | Microsoft Authentication Library (MSAL) for Node.js Spoofing Vulnerability | Exploitation Less Likely | No | 7.4 |
| CVE-2026-83711 | Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability | N/A | No | 10.0 |
| CVE-2026-83948 | Microsoft Azure CLI Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.0 |
| CVE-2026-62906 | Microsoft Discovery Studio Information Disclosure Vulnerability | N/A | No | 7.4 |
| CVE-2026-62916 | Microsoft Entra ID Elevation of Privilege Vulnerability | N/A | No | 9.1 |
| CVE-2026-69854 | Spring Cloud Azure Elevation of Privilege Vulnerability | Exploitation More Likely | No | 9.0 |
Browser vulnerabilities
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-84323 | Chromium: CVE-2026-84323 Missing authorization in FileSystem | n/a | No | |
| CVE-2026-84324 | Chromium: CVE-2026-84324 Use after free in Proxy | n/a | No | |
| CVE-2026-84325 | Chromium: CVE-2026-84325 Improper input validation in DataTransfer | n/a | No | |
| CVE-2026-84326 | Chromium: CVE-2026-84326 Uninitialized resource in V8 | n/a | No | |
| CVE-2026-84327 | Chromium: CVE-2026-84327 Incorrect authorization in Autofill | n/a | No | |
| CVE-2026-84328 | Chromium: CVE-2026-84328 Missing authorization in FileSystem | n/a | No | |
| CVE-2026-84329 | Chromium: CVE-2026-84329 Confused deputy in CredentialProvider | n/a | No | |
| CVE-2026-84331 | Chromium: CVE-2026-84331 Incorrect authorization in Actor | n/a | No | |
| CVE-2026-84332 | Chromium: CVE-2026-84332 Incorrect authorization in SiteSettings | n/a | No | |
| CVE-2026-84334 | Chromium: CVE-2026-84334 Incorrect authorization in Chromoting | n/a | No | |
| CVE-2026-84335 | Chromium: CVE-2026-84335 Incorrect authorization in TabStrip | n/a | No | |
| CVE-2026-84347 | Chromium: CVE-2026-84347 Use after free in WebRTC | n/a | No | |
| CVE-2026-84348 | Chromium: CVE-2026-84348 Information leak in MediaCapture | n/a | No | |
| CVE-2026-84349 | Chromium: CVE-2026-84349 Use after free in Browser | n/a | No | |
| CVE-2026-84350 | Chromium: CVE-2026-84350 Use after free in TabStrip | n/a | No | |
| CVE-2026-84351 | Chromium: CVE-2026-84351 Buffer overflow in GPU | n/a | No | |
| CVE-2026-84353 | Chromium: CVE-2026-84353 Use after free in Shared Tab Groups | n/a | No | |
| CVE-2026-84354 | Chromium: CVE-2026-84354 Incorrect authorization in FileSystem | n/a | No | |
| CVE-2026-84355 | Chromium: CVE-2026-84355 Incorrect authorization in Navigation | n/a | No | |
| CVE-2026-84356 | Chromium: CVE-2026-84356 UI misrepresentation in FullScreen | n/a | No | |
| CVE-2026-84357 | Chromium: CVE-2026-84357 Improper input validation in Omnibox | n/a | No | |
| CVE-2026-84358 | Chromium: CVE-2026-84358 Improper privilege management in Downloads | n/a | No | |
| CVE-2026-84359 | Chromium: CVE-2026-84359 Information leak in Skia | n/a | No |
Developer Tools vulnerabilities
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-69439 | .NET and Visual Studio Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-69522 | .NET and Visual Studio Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-71328 | .NET and Visual Studio Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-69805 | .NET Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-69806 | .NET Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-58649 | .NET Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2025-70873 | An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file. | n/a | No | 7.5 |
| CVE-2026-57099 | ASP.NET Core Denial of Service Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-69304 | ASP.NET Core Denial of Service Vulnerability | Exploitation Less Likely | No | 5.9 |
| CVE-2026-34182 | CMS AuthEnvelopedData Processing May Accept Forged Messages | n/a | No | 9.1 |
| CVE-2026-81380 | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability | N/A | No | 5.3 |
| CVE-2026-81381 | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-81383 | Visual Studio Code Information Disclosure Vulnerability | Exploitation Less Likely | No | 7.4 |
| CVE-2026-70334 | Visual Studio Code Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-78461 | Visual Studio Code Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 7.4 |
| CVE-2026-78462 | Visual Studio Code Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-81356 | Visual Studio Code Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 8.2 |
| CVE-2026-81357 | Visual Studio Code Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 8.2 |
| CVE-2026-81376 | Visual Studio Code Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 9.6 |
| CVE-2026-81378 | Visual Studio Code Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 8.2 |
| CVE-2026-81379 | Visual Studio Code Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 8.2 |
| CVE-2026-81377 | Visual Studio Code Tampering Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-77906 | Visual Studio Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-77907 | Visual Studio Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
Mariner vulnerabilities
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2025-70873 | An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file. | n/a | No | 7.5 |
Microsoft Dynamics vulnerabilities
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-65772 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-77908 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | N/A | No | 8.8 |
| CVE-2026-77897 | Microsoft Power Automate Desktop Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-65818 | Power Automate Elevation of Privilege Vulnerability | N/A | No | 8.5 |
Microsoft Office vulnerabilities
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-80098 | Copilot Studio Elevation of Privilege Vulnerability | N/A | No | 9.3 |
| CVE-2026-81387 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-81390 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-81391 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-81392 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-81393 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-81394 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-81395 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Unlikely | No | 5.5 |
| CVE-2026-81399 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-81400 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Unlikely | No | 5.5 |
| CVE-2026-81401 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-81958 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Unlikely | No | 5.5 |
| CVE-2026-81386 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81388 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-81389 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-81396 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-81397 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81398 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81947 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81948 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81949 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-81950 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81951 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81953 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81954 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81956 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81957 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81959 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81960 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-70178 | Microsoft Fabric Elevation of Privilege Vulnerability | N/A | No | 8.5 |
| CVE-2026-69477 | Microsoft Office Access Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.3 |
| CVE-2026-69529 | Microsoft Office Access Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69614 | Microsoft Office Access Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69778 | Microsoft Office Access Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-72974 | Microsoft Office Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-78515 | Microsoft Office Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-85875 | Microsoft Office Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-78518 | Microsoft Office Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-78439 | Microsoft Office Graphics Component Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69626 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-69739 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-80076 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-80078 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-80082 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-80087 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-80089 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-80091 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-78520 | Microsoft Office Outlook Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-80073 | Microsoft Office Outlook Information Disclosure Vulnerability | Exploitation Less Likely | No | |
| CVE-2026-80084 | Microsoft Office Outlook Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-69629 | Microsoft Office Outlook Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-78509 | Microsoft Office Outlook Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-78519 | Microsoft Office Outlook Remote Code Execution Vulnerability | Exploitation Less Likely | No | |
| CVE-2026-78525 | Microsoft Office Outlook Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-72938 | Microsoft Office PowerPoint Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-72956 | Microsoft Office PowerPoint Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-72975 | Microsoft Office PowerPoint Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-72977 | Microsoft Office PowerPoint Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-78513 | Microsoft Office PowerPoint Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-80086 | Microsoft Office PowerPoint Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-69678 | Microsoft Office PowerPoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69767 | Microsoft Office PowerPoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69797 | Microsoft Office PowerPoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-80081 | Microsoft Office PowerPoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | |
| CVE-2026-69742 | Microsoft Office Publisher Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-81385 | Microsoft Office Publisher Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69285 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69442 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69632 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-77898 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-78505 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-78524 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69464 | Microsoft Office SharePoint Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69716 | Microsoft Office SharePoint Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69409 | Microsoft Office SharePoint Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-69636 | Microsoft Office SharePoint Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-69683 | Microsoft Office SharePoint Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-69904 | Microsoft Office SharePoint Information Disclosure Vulnerability | Exploitation Less Likely | No | 3.5 |
| CVE-2026-69268 | Microsoft Office SharePoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69273 | Microsoft Office SharePoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69282 | Microsoft Office SharePoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69465 | Microsoft Office SharePoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69724 | Microsoft Office SharePoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69804 | Microsoft Office SharePoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-69402 | Microsoft Office SharePoint Spoofing Vulnerability | Exploitation Less Likely | No | 7.3 |
| CVE-2026-69417 | Microsoft Office SharePoint Spoofing Vulnerability | Exploitation Less Likely | No | 7.3 |
| CVE-2026-69615 | Microsoft Office SharePoint Spoofing Vulnerability | Exploitation Unlikely | No | 3.5 |
| CVE-2026-69690 | Microsoft Office SharePoint Spoofing Vulnerability | Exploitation Unlikely | No | 4.6 |
| CVE-2026-64918 | Microsoft Office Spoofing Vulnerability | Exploitation Less Likely | No | 6.5 |
Open Source Software vulnerabilities
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-69805 | .NET Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2025-70873 | An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file. | n/a | No | 7.5 |
| CVE-2026-34182 | CMS AuthEnvelopedData Processing May Accept Forged Messages | n/a | No | 9.1 |
Server Software vulnerabilities
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-69378 | Microsoft Exchange Server Denial of Service Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-69380 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.1 |
| CVE-2026-69641 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 9.1 |
| CVE-2026-69382 | Microsoft Exchange Server Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.9 |
| CVE-2026-55007 | Microsoft Exchange Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.1 |
| CVE-2026-69355 | Microsoft Exchange Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69356 | Microsoft Exchange Server Spoofing Vulnerability | Exploitation Less Likely | No | 9.3 |
| CVE-2026-69361 | Microsoft Exchange Server Spoofing Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-69375 | Microsoft Exchange Server Tampering Vulnerability | Exploitation Less Likely | No | 6.5 |
SQL Server vulnerabilities
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-67376 | Microsoft SQL Server Denial of Service Vulnerability | Exploitation Unlikely | No | 7.5 |
| CVE-2026-67633 | Microsoft SQL Server Denial of Service Vulnerability | Exploitation Unlikely | No | 6.5 |
| CVE-2026-67641 | Microsoft SQL Server Denial of Service Vulnerability | Exploitation Unlikely | No | 6.5 |
| CVE-2026-66814 | Microsoft SQL Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-66818 | Microsoft SQL Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-66819 | Microsoft SQL Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-67368 | Microsoft SQL Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-67370 | Microsoft SQL Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-67381 | Microsoft SQL Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-67369 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-67383 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Unlikely | No | 6.5 |
| CVE-2026-67386 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Unlikely | No | 6.5 |
| CVE-2026-67389 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-67390 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-67393 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-67624 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-67629 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Unlikely | No | 6.5 |
| CVE-2026-67630 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-67645 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Unlikely | No | 6.5 |
| CVE-2026-67648 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-68776 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Unlikely | No | 6.5 |
| CVE-2026-68777 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-68778 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-68779 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-68780 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-68781 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-68784 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-69562 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-73029 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-77488 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Unlikely | No | 5.5 |
| CVE-2026-47297 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.1 |
| CVE-2026-67373 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-67378 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.5 |
| CVE-2026-67379 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.5 |
| CVE-2026-67380 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-67384 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-67385 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-67388 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-67631 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-67636 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.5 |
| CVE-2026-67638 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-67639 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-67642 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-67643 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-68775 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-68785 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 4.9 |
| CVE-2026-68786 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-68787 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-77481 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-77482 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-77484 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-77486 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-66816 | Microsoft SQL Server Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-66820 | SQL Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-73028 | SQL Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-77480 | SQL Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-77483 | SQL Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-77485 | SQL Server Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.0 |
| CVE-2026-77487 | SQL Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-78456 | SQL Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-78441 | Windows OLE DB Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-78442 | Windows OLE DB Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
CVE-2026-69839 | Windows iSCSI Target Service Denial of Service Vulnerability | Exploitation Unlikely | No | 6.5 |
| CVE-2026-69744 | Windows Kerberos Denial of Service Vulnerability | Exploitation Unlikely | No | 7.5 |
| CVE-2026-69760 | Windows Kerberos Denial of Service Vulnerability | Exploitation Unlikely | No | 7.5 |
| CVE-2026-69685 | Windows Kerberos Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-69822 | Windows Kerberos Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-69676 | Windows Kerberos Remote Code Execution Vulnerability | Exploitation More Likely | No | 8.8 |
| CVE-2026-68846 | Windows Kernel Elevation of Privilege Vulnerability | Exploitation More Likely | No | 7.1 |
| CVE-2026-68884 | Windows Kernel Elevation of Privilege Vulnerability | Exploitation More Likely | No | 7.0 |
| CVE-2026-69366 | Windows Kernel Elevation of Privilege Vulnerability | Exploitation More Likely | No | 7.1 |
| CVE-2026-69466 | Windows Kernel Elevation of Privilege Vulnerability | Exploitation More Likely | No | 7.0 |
| CVE-2026-69473 | Windows Kernel Elevation of Privilege Vulnerability | Exploitation More Likely | No | 7.0 |
| CVE-2026-69578 | Windows Kernel Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-83942 | Windows Kernel Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-85360 | Windows Kernel Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-69406 | Windows Kernel Information Disclosure Vulnerability | Exploitation More Likely | No | 5.5 |
| CVE-2026-69723 | Windows Kernel Information Disclosure Vulnerability | Exploitation More Likely | No | 5.7 |
| CVE-2026-69669 | Windows Kernel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-69421 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-84001 | Windows Key Distribution Center Denial of Service Vulnerability | Exploitation Unlikely | No | 7.5 |
| CVE-2026-69712 | Windows Key Distribution Center Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69428 | Windows LDAP - Lightweight Directory Access Protocol Denial of Service Vulnerability | Exploitation Unlikely | No | 7.5 |
| CVE-2026-69281 | Windows License Manager Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.0 |
| CVE-2026-69315 | Windows License Manager Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-69732 | Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.1 |
| CVE-2026-69451 | Windows Management Instrumentation Elevation of Privilege Vulnerability | Exploitation More Likely | No | 7.1 |
| CVE-2026-70582 | Windows Management Instrumentation Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 6.4 |
| CVE-2026-77905 | Windows Management Instrumentation Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-69349 | Windows Management Instrumentation Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.7 |
| CVE-2026-73012 | Windows Management Services Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69891 | Windows Media Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.0 |
| CVE-2026-70203 | Windows Media Player Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-72960 | Windows Media Player Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-69645 | Windows Message Queuing Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-68887 | Windows Message Queuing Queue Manager Denial of Service Vulnerability | Exploitation Unlikely | No | 7.5 |
| CVE-2026-72932 | Windows Message Queuing Queue Manager Information Disclosure Vulnerability | Exploitation Unlikely | No | 7.5 |
| CVE-2026-69579 | Windows Message Queuing Remote Code Execution Vulnerability | Exploitation Unlikely | No | 9.8 |
| CVE-2026-83997 | Windows Message Queuing Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.1 |
| CVE-2026-69440 | Windows MIDI Service Module Elevation of Privileges Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-69508 | Windows MIDI Service Module Elevation of Privileges Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-69720 | Windows MIDI Service Module Elevation of Privileges Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-78464 | Windows MIDI Service Module Elevation of Privileges Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-68842 | Windows MIDI Service Module Information Disclosure Vulnerability | Exploitation Unlikely | No | 5.5 |
| CVE-2026-69339 | Windows MIDI Service Module Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-70579 | Windows Mobile Broadband Information Disclosure Vulnerability | Exploitation Unlikely | No | 7.5 |
| CVE-2026-69377 | Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-69460 | Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability | Exploitation More Likely | No | 7.1 |
| CVE-2026-70577 | Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-73003 | Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.0 |
| CVE-2026-73022 | Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.0 |
| CVE-2026-69674 | Windows Modern Device Management (MDM) Security Feature Bypass Vulnerability | Exploitation Unlikely | No | 5.5 |
| CVE-2026-72963 | Windows Modern Execution Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-69357 | Windows NDIS Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.1 |
| CVE-2026-69396 | Windows NDIS Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.1 |
| CVE-2026-72982 | Windows Netlogon Remote Code Execution Vulnerability | Exploitation Unlikely | No | 9.8 |
| CVE-2026-62759 | Windows Netlogon Spoofing Vulnerability | Exploitation Unlikely | No | 7.5 |
| CVE-2026-72967 | Windows Network Connection Broker Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-68886 | Windows Network Connection Broker Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-69372 | Windows Network File System Denial of Service Vulnerability | Exploitation Less Likely | No | 5.7 |
| CVE-2026-69772 | Windows Network File System Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-71334 | Windows NFS Portmapper Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-69648 | Windows Notification Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.0 |
| CVE-2026-68832 | Windows NTFS Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-68834 | Windows NTFS Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 8.0 |
| CVE-2026-68838 | Windows NTFS Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.0 |
| CVE-2026-68841 | Windows NTFS Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-69265 | Windows NTFS Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-69312 | Windows NTFS Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-69332 | Windows NTFS Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 8.0 |
| CVE-2026-69340 | Windows NTFS Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.1 |
| CVE-2026-69379 | Windows NTFS Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.0 |
| CVE-2026-69505 | Windows NTFS Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 8.0 |
| CVE-2026-69532 | Windows NTFS Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-69567 | Windows NTFS Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.0 |
| CVE-2026-69875 | Windows NTFS Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 8.0 |
| CVE-2026-72935 | Windows NTFS Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 6.7 |
| CVE-2026-77503 | Windows NTFS Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.4 |
| CVE-2026-83995 | Windows NTFS Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-68851 | Windows NTFS Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-69504 | Windows NTFS Information Disclosure Vulnerability | Exploitation Unlikely | No | 5.5 |
| CVE-2026-69591 | Windows NTFS Information Disclosure Vulnerability | Exploitation Unlikely | No | 5.7 |
| CVE-2026-68833 | Windows NTFS Remote Code Execution Vulnerability | Exploitation Less Likely | No | 6.8 |
| CVE-2026-68875 | Windows NTFS Remote Code Execution Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-69461 | Windows NTFS Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69463 | Windows NTFS Remote Code Execution Vulnerability | Exploitation Unlikely | No | 9.8 |
| CVE-2026-69479 | Windows NTFS Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.4 |
| CVE-2026-69566 | Windows NTFS Remote Code Execution Vulnerability | Exploitation Unlikely | No | 6.8 |
| CVE-2026-69638 | Windows NTFS Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.4 |
| CVE-2026-69709 | Windows NTFS Remote Code Execution Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-71329 | Windows NTFS Remote Code Execution Vulnerability | Exploitation Less Likely | No | 6.8 |
| CVE-2026-69425 | Windows NTFS Tampering Vulnerability | Exploitation Unlikely | No | 4.7 |
| CVE-2026-69564 | Windows Online Certificate Status Protocol (OCSP) Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.0 |
| CVE-2026-69350 | Windows Overlay Filter Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 6.7 |
| CVE-2026-69368 | Windows Overlay Filter Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-69371 | Windows Overlay Filter Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 8.0 |
| CVE-2026-69373 | Windows Overlay Filter Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 6.7 |
| CVE-2026-69316 | Windows Overlay Filter Information Disclosure Vulnerability | Exploitation Unlikely | No | 4.7 |
| CVE-2026-69343 | Windows Overlay Filter Information Disclosure Vulnerability | Exploitation Unlikely | No | 5.5 |
| CVE-2026-69474 | Windows Overlay Filter Information Disclosure Vulnerability | Exploitation Unlikely | No | 4.8 |
| CVE-2026-70586 | Windows Paint Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-69480 | Windows Partition Management Driver Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-69492 | Windows Partition Management Driver Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-71341 | Windows Partition Management Driver Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-69324 | Windows Performance Monitor Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-69459 | Windows Power Dependency Coordinator Elevation of Privilege Vulnerability | Exploitation More Likely | No | 7.8 |
| CVE-2026-69321 | Windows Power Dependency Coordinator Tampering Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-69569 | Windows Print Spooler Components Denial of Service Vulnerability | Exploitation Less Likely | No | 5.7 |
| CVE-2026-68835 | Windows Print Spooler Components Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.1 |
| CVE-2026-68848 | Windows Print Spooler Components Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-69309 | Windows Print Spooler Components Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-69346 | Windows Print Spooler Components Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.0 |
| CVE-2026-69364 | Windows Print Spooler Components Elevation of Privilege Vulnerability | Exploitation More Likely | No | 7.1 |
| CVE-2026-69838 | Windows Print Spooler Components Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.0 |
| CVE-2026-69921 | Windows Print Spooler Components Elevation of Privilege Vulnerability | Exploitation More Likely | No | 7.8 |
| CVE-2026-70564 | Windows Print Spooler Components Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-69344 | Windows Print Spooler Components Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-69552 | Windows Print Spooler Components Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.7 |
| CVE-2026-85877 | Windows Print Spooler Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69602 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.1 |
| CVE-2026-68845 | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-68876 | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability | Exploitation More Likely | No | 8.0 |
| CVE-2026-69534 | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-69563 | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-68873 | Windows Program Compatibility Assistant Service Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-68874 | Windows Program Compatibility Assistant Service Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.7 |
| CVE-2026-62697 | Windows Push Notifications Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-69280 | Windows Push Notifications Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-69300 | Windows Push Notifications Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-69337 | Windows Registry Elevation of Privilege Vulnerability | Exploitation More Likely | No | 7.1 |
| CVE-2026-69530 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.1 |
| CVE-2026-78449 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.1 |
| CVE-2026-78450 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.1 |
| CVE-2026-69331 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-69455 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-71333 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-71342 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.0 |
| CVE-2026-71343 | Windows Remote Access Connection Manager Remote Code Execution Vulnerability | Exploitation More Likely | No | 7.8 |
| CVE-2026-71352 | Windows Remote Access Connection Manager Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-72966 | Windows Remote Access Connection Manager Tampering Vulnerability | Exploitation Unlikely | No | 5.5 |
| CVE-2026-77896 | Windows Remote Desktop Client Denial of Service Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-69317 | Windows Remote Desktop Client Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.7 |
| CVE-2026-69627 | Windows Remote Desktop Licensing Service Information Disclosure Vulnerability | Exploitation Unlikely | No | 5.5 |
| CVE-2026-70587 | Windows Remote Desktop Protocol Information Disclosure Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-69518 | Windows Remote Desktop Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69287 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-69475 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-80096 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69616 | Windows Remote Desktop Services Information Disclosure Vulnerability | Exploitation Unlikely | No | 5.5 |
| CVE-2026-83999 | Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-69617 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.0 |
| CVE-2026-83952 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-69548 | Windows RNDIS Information Disclosure Vulnerability | Exploitation Less Likely | No | 4.6 |
| CVE-2026-69768 | Windows RNDIS Remote Code Execution Vulnerability | Exploitation Unlikely | No | 9.8 |
| CVE-2026-72939 | Windows Routing and Remote Access Service (RRAS) Denial of Service Vulnerability | Exploitation Unlikely | No | 6.5 |
| CVE-2026-71351 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-71353 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-69590 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-69852 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Exploitation More Likely | No | 7.5 |
| CVE-2026-70570 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Exploitation Unlikely | No | 7.5 |
| CVE-2026-72950 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-72959 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-70575 | Windows Schannel Denial of Service Vulnerability | Exploitation Unlikely | No | 5.3 |
| CVE-2026-72940 | Windows Schannel Remote Code Execution Vulnerability | Exploitation More Likely | No | 8.8 |
| CVE-2026-69713 | Windows Secure Boot Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 4.4 |
| CVE-2026-69501 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-69846 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.2 |
| CVE-2026-69906 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.2 |
| CVE-2026-83939 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.2 |
| CVE-2026-72931 | Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability | Exploitation Unlikely | No | 4.7 |
| CVE-2026-71332 | Windows Secure Socket Tunneling Protocol (SSTP) Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-72930 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-73009 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
CVE-2026-69410 | Windows Win32k Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-69498 | Windows Win32k Elevation of Privilege Vulnerability | Exploitation More Likely | No | 7.0 |
| CVE-2026-69610 | Windows Win32k Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.0 |
| CVE-2026-69630 | Windows Win32k Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.0 |
| CVE-2026-69652 | Windows Win32k Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.0 |
| CVE-2026-69689 | Windows Win32k Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.0 |
| CVE-2026-69706 | Windows Win32k Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.1 |
| CVE-2026-69762 | Windows Win32k Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 8.0 |
| CVE-2026-69779 | Windows Win32k Elevation of Privilege Vulnerability | Exploitation More Likely | No | 7.0 |
| CVE-2026-69818 | Windows Win32k Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.0 |
| CVE-2026-69844 | Windows Win32k Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-70283 | Windows Win32k Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-70289 | Windows Win32k Elevation of Privilege Vulnerability | Exploitation More Likely | No | 7.8 |
| CVE-2026-69792 | Windows Win32K Security Feature Bypass Vulnerability | Exploitation Unlikely | No | 4.7 |
| CVE-2026-69517 | Windows Wireless Networking Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-69862 | Windows Wireless Wide Area Network Service Information Disclosure Vulnerability | Exploitation Unlikely | No | 5.5 |
| CVE-2026-69560 | Windows Work Folder Service Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-71336 | Windows Work Folder Service Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-80075 | Windows Work Folders Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-72927 | Winsock Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 6.7 |
| CVE-2026-78455 | Xbox Information Disclosure Vulnerability | Exploitation Less Likely | No | 4.3 |
Uncategorized Vulnerabilities
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-19931 | Negotiate ambient user conn reuse | n/a | No | 6.5 |
| CVE-2026-82208 | wolfSSL CA-cache hit overrides callback | n/a | No | 7.4 |
| CVE-2026-13608 | OpenLDAP SASL authentication bypass | n/a | No | 3.7 |
| CVE-2026-18924 | HTTP/2 server push UAF | n/a | No | 5.9 |
Zero-Day Vulnerabilities: Known Exploited
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-85880 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | Exploitation Detected | No | 7.8 |
| CVE-2026-81963 | Windows Update Stack Elevation of Privilege Vulnerability | Exploitation Detected | No | 7.8 |
Critical RCEs and EoPs
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-70352 | Azure AI Language Elevation of Privilege Vulnerability | N/A | No | 10.0 |
| CVE-2026-80098 | Copilot Studio Elevation of Privilege Vulnerability | N/A | No | 9.3 |
| CVE-2026-83941 | Entra ID Elevation of Privilege Vulnerability | N/A | No | 9.9 |
| CVE-2026-72983 | Internet Connection Sharing (ICS) Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-83711 | Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability | N/A | No | 10.0 |
| CVE-2026-69491 | Microsoft DirectMusic Remote Code Execution Vulnerability | Exploitation Unlikely | No | 9.8 |
| CVE-2026-62916 | Microsoft Entra ID Elevation of Privilege Vulnerability | N/A | No | 9.1 |
| CVE-2026-69641 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 9.1 |
| CVE-2026-73010 | Microsoft Failover Cluster Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-78509 | Microsoft Office Outlook Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-65669 | Microsoft SQL Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 9.6 |
| CVE-2026-69824 | Microsoft Standard XPS Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-69276 | Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability | Exploitation Unlikely | No | 9.8 |
| CVE-2026-69408 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | Exploitation Unlikely | No | 9.8 |
| CVE-2026-69586 | Microsoft Windows PDF Remote Code Execution Vulnerability | Exploitation Unlikely | No | 9.8 |
| CVE-2026-78510 | Microsoft Word Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-69525 | Remote Desktop Services Remote Code Execution Vulnerability | Exploitation More Likely | No | 9.8 |
| CVE-2026-69819 | RPC Runtime Library Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-66302 | Skype for Business Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-69854 | Spring Cloud Azure Elevation of Privilege Vulnerability | Exploitation More Likely | No | 9.0 |
| CVE-2026-69431 | Telnet Client Remote Code Execution Vulnerability | Exploitation Unlikely | No | 9.8 |
| CVE-2026-69496 | Windows Compressed Folder Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-69845 | Windows DHCP Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-72979 | Windows DHCP Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-69715 | Windows Direct Show Remote Code Execution Vulnerability | Exploitation Unlikely | No | 9.8 |
| CVE-2026-69730 | Windows DNS Server Remote Code Execution Vulnerability | Exploitation More Likely | No | 9.8 |
| CVE-2026-69493 | Windows Event Logging Service Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-77493 | Windows Graphics Component Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-69769 | Windows HTTP Print Provider Remote Code Execution Vulnerability | Exploitation Unlikely | No | 9.8 |
| CVE-2026-69910 | Windows Hyper-V Remote Code Execution Vulnerability | Exploitation Unlikely | No | 9.8 |
| CVE-2026-70296 | Windows Imaging Component Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-69669 | Windows Kernel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-69579 | Windows Message Queuing Remote Code Execution Vulnerability | Exploitation Unlikely | No | 9.8 |
| CVE-2026-72982 | Windows Netlogon Remote Code Execution Vulnerability | Exploitation Unlikely | No | 9.8 |
| CVE-2026-69463 | Windows NTFS Remote Code Execution Vulnerability | Exploitation Unlikely | No | 9.8 |
| CVE-2026-69768 | Windows RNDIS Remote Code Execution Vulnerability | Exploitation Unlikely | No | 9.8 |
| CVE-2026-69590 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-73009 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-69595 | Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-78445 | Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-69829 | Windows Shell Remote Code Execution Vulnerability | Exploitation Unlikely | No | 9.8 |
| CVE-2026-68839 | Windows USB Mass Storage Class Driver Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.rapid7.com/blog/post/em-patch-tuesday-september-2026