CVE-2026-69605 Microsoft
Use after free in Microsoft Install Service allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 21H2 for 32-bit Systems · Windows 10 Version 21H2 for ARM64-based Systems · +16 more
Updated September 30, 2026
CVE-2026-70125 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.8
Update availability Patch status unknown Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +4 more
Updated September 30, 2026
CVE-2026-70562 Microsoft
Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 30, 2026
CVE-2026-55556 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 rsyslog 8.2308.0-7 on Azure Linux 3.0
Updated September 30, 2026
CVE-2026-102267 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.4
Update availability Patch status unknown Affected: azl3 python-jwt 2.13.0-1 on Azure Linux 3.0
Updated September 30, 2026
CVE-2026-50332 Microsoft
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +25 more
Updated September 29, 2026
CVE-2026-50357 Microsoft
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +21 more
Updated September 29, 2026
CVE-2026-50375 Microsoft
Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally.
CVSS 6.3
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +17 more
Updated September 29, 2026
CVE-2026-50400 Microsoft
Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +25 more
Updated September 29, 2026
CVE-2026-50414 Microsoft
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.
CVSS 7.5
Update availability Security update available Affected: Windows 11 Version 24H2 for ARM64-based Systems · Windows 11 Version 24H2 for x64-based Systems · +6 more
Updated September 29, 2026
CVE-2026-56172 Microsoft
Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +20 more
Updated September 29, 2026
CVE-2026-57095 Microsoft
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.
CVSS 6.2
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +25 more
Updated September 29, 2026
CVE-2026-61930 Microsoft
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 29, 2026
CVE-2026-62688 Microsoft
Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 11 Version 24H2 for ARM64-based Systems · Windows 11 Version 24H2 for x64-based Systems · +4 more
Updated September 29, 2026
CVE-2026-62694 Microsoft
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 29, 2026
CVE-2026-62755 Microsoft
Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 29, 2026
CVE-2026-68880 Microsoft
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.
CVSS 8.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 29, 2026
CVE-2026-69307 Microsoft
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 29, 2026
CVE-2026-69522 Microsoft
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: .NET 10.0 installed on Windows · .NET 11.0 installed on Windows · +45 more
Updated September 29, 2026
CVE-2026-93599 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Patch status unknown Affected: azl3 kata-containers-cc 3.15.0.aks0-21 on Azure Linux 3.0 · azl3 rust 1.96.1-2 on Azure Linux 3.0
Updated September 29, 2026
CVE-2026-82412 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.8
Update availability Security update available Affected: azl3 ntopng 5.2.1-7 on Azure Linux 3.0
Updated September 29, 2026
CVE-2026-91728 Microsoft
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases ]( https://chromereleases.googleblog.com/2026 )) for more information.
CVSS 9.6
Update availability Patch status unknown Affected: Microsoft Edge (Chromium-based)
Updated September 29, 2026
CVE-2026-91745 Microsoft
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases ]( https://chromereleases.googleblog.com/2026 )) for more information.
CVSS 8.8
Update availability Patch status unknown Affected: Microsoft Edge (Chromium-based)
Updated September 29, 2026
CVE-2026-94286 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.1
Update availability Patch status unknown Affected: azl3 python-jwt 2.13.0-1 on Azure Linux 3.0
Updated September 29, 2026