CVE-2026-55053 Microsoft
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +12 more
Updated September 15, 2026
CVE-2026-61363 Microsoft
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVSS 7.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 15, 2026
CVE-2026-61923 Microsoft
Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +20 more
Updated September 15, 2026
CVE-2026-62717 Microsoft
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 15, 2026
CVE-2026-62753 Microsoft
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 15, 2026
CVE-2026-62772 Microsoft
Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 11 Version 26H1 for ARM64-based Systems · Windows 11 version 26H1 for x64-based Systems
Updated September 15, 2026
CVE-2026-65775 Microsoft
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 15, 2026
CVE-2026-65776 Microsoft
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 11 Version 24H2 for ARM64-based Systems · Windows 11 Version 24H2 for x64-based Systems · +6 more
Updated September 15, 2026
CVE-2026-65812 Microsoft
Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
CVSS 6.8
Update availability Patch status unknown Affected: Microsoft Teams for Android
Updated September 15, 2026
CVE-2026-68812 Microsoft
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +12 more
Updated September 15, 2026
CVE-2026-68841 Microsoft
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 15, 2026
CVE-2026-68847 Microsoft
Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 21H2 for 32-bit Systems · Windows 10 Version 21H2 for ARM64-based Systems · +15 more
Updated September 15, 2026
CVE-2026-69286 Microsoft
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally.
CVSS 5.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 15, 2026
CVE-2026-69314 Microsoft
Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network.
CVSS 7.1
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 15, 2026
CVE-2026-69321 Microsoft
Missing authentication for critical function in Windows Power Dependency Coordinator allows an authorized attacker to perform tampering locally.
CVSS 5.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 15, 2026
CVE-2026-69406 Microsoft
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally.
CVSS 5.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 15, 2026
CVE-2026-69416 Microsoft
Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.
CVSS 5.7
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 15, 2026
CVE-2026-69486 Microsoft
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Patch status unknown Affected: Microsoft Edge (Chromium-based)
Updated September 15, 2026
CVE-2026-69559 Microsoft
Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
CVSS 5.8
Update availability Patch status unknown Affected: Microsoft Teams for Android
Updated September 15, 2026
CVE-2026-69608 Microsoft
Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 15, 2026
CVE-2026-69619 Microsoft
Out-of-bounds read in Windows exFAT File System allows an authorized attacker to elevate privileges over a network.
CVSS 8.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 15, 2026
CVE-2026-69714 Microsoft
Stack-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.
CVSS 8.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 15, 2026
CVE-2026-80075 Microsoft
Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +26 more
Updated September 15, 2026
CVE-2026-80097 Microsoft
Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally.
CVSS 8.6
Update availability Patch status unknown Affected: Microsoft Authenticator for Android
Updated September 15, 2026