CVE-2026-68824 Microsoft
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 21H2 for 32-bit Systems · Windows 10 Version 21H2 for ARM64-based Systems · +16 more
Updated September 22, 2026
CVE-2026-69498 Microsoft
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +20 more
Updated September 22, 2026
CVE-2026-69572 Microsoft
Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information over a network.
CVSS 5.7
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 22, 2026
CVE-2026-69620 Microsoft
Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVSS 8.1
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 22, 2026
CVE-2026-77886 Microsoft
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVSS 7.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 22, 2026
CVE-2026-61548 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.1
Update availability Security update available Affected: azl3 rsyslog 8.2308.0-6 on Azure Linux 3.0
Updated September 21, 2026
CVE-2026-40400 Microsoft
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
CVSS 8.0
Update availability Security update available Affected: PowerShell 7.5 · PowerShell 7.6 · +27 more
Updated September 21, 2026
CVE-2026-55039 Microsoft
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +12 more
Updated September 21, 2026
CVE-2026-62871 Microsoft
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: .NET 8.0 installed on Windows · .NET 9.0 installed on Windows · +2 more
Updated September 21, 2026
CVE-2026-63516 Microsoft
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVSS 6.5
Update availability Security update available Affected: Microsoft SharePoint Enterprise Server 2016 · Microsoft SharePoint Server 2019 · +1 more
Updated September 21, 2026
CVE-2026-68798 Microsoft
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +7 more
Updated September 21, 2026
CVE-2026-68825 Microsoft
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 11 Version 23H2 for ARM64-based Systems · Windows 11 Version 23H2 for x64-based Systems · +8 more
Updated September 21, 2026
CVE-2026-77901 Microsoft
Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated September 21, 2026
CVE-2026-78517 Microsoft
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated September 21, 2026
CVE-2026-78524 Microsoft
Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated September 21, 2026
CVE-2026-78526 Microsoft
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated September 21, 2026
CVE-2026-78689 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.1
Update availability Security update available Affected: azl3 nginx 1.28.3-8 on Azure Linux 3.0
Updated September 20, 2026
CVE-2026-54330 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.1
Update availability Security update available Affected: azl3 ceph 18.2.2-12 on Azure Linux 3.0
Updated September 20, 2026
CVE-2026-78254 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.4
Update availability Security update available Affected: azl3 ant 1.10.14-1 on Azure Linux 3.0
Updated September 19, 2026
CVE-2026-86145 Microsoft
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).
CVSS 8.2
Update availability Security update available Affected: azl3 pcre2 10.42-3 on Azure Linux 3.0
Updated September 19, 2026
CVE-2026-86140 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.0
Update availability Security update available Affected: azl3 libxml2 2.11.5-10 on Azure Linux 3.0
Updated September 19, 2026
CVE-2026-78408 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.9
Update availability Security update available Affected: azl3 util-linux 2.40.2-5 on Azure Linux 3.0
Updated September 19, 2026
CVE-2026-78410 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.8
Update availability Security update available Affected: azl3 util-linux 2.40.2-5 on Azure Linux 3.0
Updated September 19, 2026
CVE-2026-33630 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Security update available Affected: azl3 fluent-bit 3.1.10-6 on Azure Linux 3.0
Updated September 19, 2026