CVE-2026-69890 Microsoft
Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally.
CVSS 7.5
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +20 more
Updated September 8, 2026
CVE-2026-69906 Microsoft
Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVSS 8.2
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-70178 Microsoft
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
CVSS 8.5
Update availability Patch status unknown Affected: Microsoft Fabric
Updated September 8, 2026
CVE-2026-70203 Microsoft
Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-70296 Microsoft
Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
CVSS 9.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-70351 Microsoft
Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: WebP Image Extension
Updated September 8, 2026
CVE-2026-70352 Microsoft
Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
Update availability Patch status unknown Affected: Azure AI Language Authoring
Updated September 8, 2026
CVE-2026-70585 Microsoft
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally.
CVSS 7.0
Update availability Security update available Affected: Windows Server 2012 · Windows Server 2012 (Server Core installation) · +10 more
Updated September 8, 2026
CVE-2026-70586 Microsoft
Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-72950 Microsoft
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-72954 Microsoft
Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.
CVSS 7.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-72957 Microsoft
Heap-based buffer overflow in Windows Deployment Services allows an authorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-72958 Microsoft
Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.
CVSS 8.2
Update availability Security update available Affected: Windows 11 Version 24H2 for ARM64-based Systems · Windows 11 Version 24H2 for x64-based Systems · +6 more
Updated September 8, 2026
CVE-2026-72959 Microsoft
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-72960 Microsoft
Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-72961 Microsoft
Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
CVSS 8.2
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-72962 Microsoft
Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.
CVSS 8.2
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +20 more
Updated September 8, 2026
CVE-2026-72979 Microsoft
Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVSS 9.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-72980 Microsoft
Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.
CVSS 4.4
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-72981 Microsoft
Use after free in IP Helper allows an unauthorized attacker to execute code over a network.
CVSS 8.1
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-72982 Microsoft
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
CVSS 9.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-72983 Microsoft
Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.
CVSS 9.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-72986 Microsoft
Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-72987 Microsoft
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
CVSS 8.1
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026