CVE-2026-73009 Microsoft
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
CVSS 9.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-73010 Microsoft
Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.
CVSS 9.8
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +6 more
Updated September 8, 2026
CVE-2026-73013 Microsoft
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-73017 Microsoft
Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally.
CVSS 7.5
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +20 more
Updated September 8, 2026
CVE-2026-73018 Microsoft
Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-73023 Microsoft
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-77493 Microsoft
Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
CVSS 9.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-77495 Microsoft
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-77504 Microsoft
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-77505 Microsoft
Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
CVSS 8.1
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-78444 Microsoft
Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.
CVSS 8.1
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +6 more
Updated September 8, 2026
CVE-2026-78445 Microsoft
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
CVSS 9.8
Update availability Security update available Affected: Windows Server 2012 · Windows Server 2012 (Server Core installation) · +10 more
Updated September 8, 2026
CVE-2026-78449 Microsoft
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
CVSS 8.1
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-78450 Microsoft
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
CVSS 8.1
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +6 more
Updated September 8, 2026
CVE-2026-78519 Microsoft
Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +8 more
Updated September 8, 2026
CVE-2026-80083 Microsoft
Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code locally.
CVSS 8.8
Update availability Security update available Affected: Windows 11 Version 23H2 for ARM64-based Systems · Windows 11 Version 23H2 for x64-based Systems · +10 more
Updated September 8, 2026
CVE-2026-80098 Microsoft
Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.
CVSS 9.3
Update availability Patch status unknown Affected: Microsoft Copilot Studio
Updated September 8, 2026
CVE-2026-81352 Microsoft
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Web Media Extensions on Windows 10 Version 21H2 for 32-bit Systems · Web Media Extensions on Windows 10 Version 21H2 for ARM64-based Systems · +12 more
Updated September 8, 2026
CVE-2026-81354 Microsoft
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
CVSS 8.2
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +16 more
Updated September 8, 2026
CVE-2026-83501 Microsoft
Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.
CVSS 5.5
Update availability Security update available Affected: Windows 11 Version 23H2 for ARM64-based Systems · Windows 11 Version 23H2 for x64-based Systems · +8 more
Updated September 8, 2026
CVE-2026-83711 Microsoft
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
Update availability Patch status unknown Affected: Microsoft Azure Active Directory B2C
Updated September 8, 2026
CVE-2026-83939 Microsoft
Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVSS 8.2
Update availability Security update available Affected: Windows 11 Version 26H1 for ARM64-based Systems · Windows 11 version 26H1 for x64-based Systems
Updated September 8, 2026
CVE-2026-83941 Microsoft
Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.
CVSS 9.9
Update availability Patch status unknown Affected: Microsoft Entra ID
Updated September 8, 2026
CVE-2026-62815 Microsoft
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
CVSS 9.8
Update availability Security update available Affected: Windows 11 Version 23H2 for ARM64-based Systems · Windows 11 Version 23H2 for x64-based Systems · +10 more
Updated September 3, 2026