CVE-2026-81963 Microsoft
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 11 Version 23H2 for ARM64-based Systems · Windows 11 Version 23H2 for x64-based Systems · +8 more
Updated September 15, 2026
CVE-2026-85893 Microsoft
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
CVSS 8.8
Update availability Patch status unknown Affected: Microsoft Edge (Chromium-based)
Updated September 15, 2026
CVE-2026-0799 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.7
Update availability Security update available Affected: azl3 libpcap 1.10.6-1 on Azure Linux 3.0 · azl3 nmap 7.95-4 on Azure Linux 3.0
Updated September 15, 2026
CVE-2026-80229 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Security update available Affected: azl3 rust 1.75.0-30 on Azure Linux 3.0
Updated September 15, 2026
CVE-2026-58051 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 6.5
Update availability Patch status unknown Affected: azl3 libssh 0.10.6-8 on Azure Linux 3.0 · azl3 libssh2 1.11.1-3 on Azure Linux 3.0 · +2 more
Updated September 15, 2026
CVE-2026-66034 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Patch status unknown Affected: azl3 libssh2 1.11.1-4 on Azure Linux 3.0 · azl3 rust 1.75.0-30 on Azure Linux 3.0
Updated September 15, 2026
CVE-2026-14680 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.8
Update availability Security update available Affected: azl3 postgresql 16.14-1 on Azure Linux 3.0 · azl3 postgresql 16.15-1 on Azure Linux 3.0
Updated September 15, 2026
CVE-2026-62721 Microsoft
Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 14, 2026
CVE-2026-54874 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Security update available Affected: azl3 cloud-hypervisor 51.1.101-2 on Azure Linux 3.0 · azl3 edk2 20240524git3e722403cd16-18 on Azure Linux 3.0 · +6 more
Updated September 13, 2026
CVE-2026-63072 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Security update available Affected: azl3 cloud-hypervisor 51.1.101-2 on Azure Linux 3.0 · azl3 edk2 20240524git3e722403cd16-18 on Azure Linux 3.0 · +7 more
Updated September 13, 2026
CVE-2026-63076 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Security update available Affected: azl3 cloud-hypervisor 51.1.101-2 on Azure Linux 3.0 · azl3 edk2 20240524git3e722403cd16-18 on Azure Linux 3.0 · +7 more
Updated September 13, 2026
CVE-2026-63075 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Security update available Affected: azl3 cloud-hypervisor 51.1.101-2 on Azure Linux 3.0 · azl3 kata-containers 3.32.0.kata0-2 on Azure Linux 3.0 · +4 more
Updated September 13, 2026
CVE-2026-77176 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.1
Update availability Security update available Affected: azl3 kata-containers 3.32.0.kata0-2 on Azure Linux 3.0 · azl3 kata-containers 3.32.0.kata0-5 on Azure Linux 3.0
Updated September 13, 2026
CVE-2026-58050 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.0
Update availability Security update available Affected: azl3 rust 1.96.1-1 on Azure Linux 3.0
Updated September 12, 2026
CVE-2026-50676 Microsoft
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 11 Version 24H2 for ARM64-based Systems · Windows 11 Version 24H2 for x64-based Systems · +4 more
Updated September 11, 2026
CVE-2026-50679 Microsoft
Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 11 Version 24H2 for ARM64-based Systems · Windows 11 Version 24H2 for x64-based Systems · +6 more
Updated September 11, 2026
CVE-2026-54112 Microsoft
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +17 more
Updated September 11, 2026
CVE-2026-54124 Microsoft
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 21H2 for 32-bit Systems · Windows 10 Version 21H2 for ARM64-based Systems · +15 more
Updated September 11, 2026
CVE-2026-61349 Microsoft
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +26 more
Updated September 11, 2026
CVE-2026-62799 Microsoft
Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 11 Version 26H1 for ARM64-based Systems · Windows 11 version 26H1 for x64-based Systems
Updated September 11, 2026
CVE-2026-69405 Microsoft
Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.
CVSS 5.7
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 11, 2026
CVE-2026-69461 Microsoft
Stack-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 11, 2026
CVE-2026-69468 Microsoft
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 11, 2026
CVE-2026-70334 Microsoft
Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVSS 7.8
Update availability Patch status unknown Affected: Visual Studio Code
Updated September 11, 2026