CVE-2026-93687 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Patch status unknown Affected: azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0
Updated September 25, 2026
CVE-2026-93749 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Patch status unknown Affected: azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0
Updated September 25, 2026
CVE-2026-69184 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Patch status unknown Affected: azl3 c-ares 1.30.0-2 on Azure Linux 3.0 · azl3 fluent-bit 3.1.10-7 on Azure Linux 3.0
Updated September 25, 2026
CVE-2026-6668 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Patch status unknown Affected: azl3 pgbouncer 1.25.2-1 on Azure Linux 3.0
Updated September 25, 2026
CVE-2026-19888 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Patch status unknown Affected: azl3 pgbouncer 1.25.2-1 on Azure Linux 3.0
Updated September 25, 2026
CVE-2026-47292 Microsoft
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Patch status unknown Affected: Visual Studio Code - MSSQL Extension
Updated September 24, 2026
CVE-2026-54981 Microsoft
Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.
CVSS 7.8
Update availability Patch status unknown Affected: Python extension for Visual Studio Code
Updated September 24, 2026
CVE-2026-59113 Microsoft
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Patch status unknown Affected: Visual Studio Code
Updated September 24, 2026
CVE-2026-63521 Microsoft
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVSS 5.5
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +8 more
Updated September 24, 2026
CVE-2026-65675 Microsoft
No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.
CVSS 7.1
Update availability Patch status unknown Affected: Microsoft Visual Studio Code CoPilot Chat Extension
Updated September 24, 2026
CVE-2026-68894 Microsoft
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network.
CVSS 8.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 24, 2026
CVE-2026-69282 Microsoft
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft SharePoint Server Subscription Edition
Updated September 24, 2026
CVE-2026-69409 Microsoft
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
CVSS 6.5
Update availability Security update available Affected: Microsoft SharePoint Server Subscription Edition
Updated September 24, 2026
CVE-2026-69636 Microsoft
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
CVSS 6.5
Update availability Security update available Affected: Microsoft SharePoint Server Subscription Edition
Updated September 24, 2026
CVE-2026-69637 Microsoft
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.
CVSS 5.7
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 24, 2026
CVE-2026-69681 Microsoft
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges over a network.
CVSS 8.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 24, 2026
CVE-2026-69732 Microsoft
Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an unauthorized attacker to execute code over a network.
CVSS 8.1
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 24, 2026
CVE-2026-69803 Microsoft
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.
CVSS 5.9
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 24, 2026
CVE-2026-70324 Microsoft
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft SharePoint Enterprise Server 2016 · Microsoft SharePoint Server 2019 · +1 more
Updated September 24, 2026
CVE-2026-71337 Microsoft
Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 21H2 for 32-bit Systems · Windows 10 Version 21H2 for ARM64-based Systems · +16 more
Updated September 24, 2026
CVE-2026-80073 Microsoft
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.
CVSS 6.5
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +8 more
Updated September 24, 2026
CVE-2026-81357 Microsoft
Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVSS 8.2
Update availability Patch status unknown Affected: Visual Studio Code
Updated September 24, 2026
CVE-2026-74752 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.0
Update availability Patch status unknown Affected: azl3 kernel 6.6.150.1-1 on Azure Linux 3.0 · azl3 kernel 6.6.152.1-1 on Azure Linux 3.0 · +1 more
Updated September 24, 2026
CVE-2026-90030 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.8
Update availability Security update available Affected: azl3 kernel 6.6.150.1-1 on Azure Linux 3.0 · azl3 kernel 6.6.152.1-1 on Azure Linux 3.0 · +1 more
Updated September 24, 2026