CVE-2026-56859 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Security update available Affected: azl3 gcc 13.2.0-7 on Azure Linux 3.0 · azl3 golang 1.25.12-1 on Azure Linux 3.0 · +5 more
Updated September 17, 2026
CVE-2026-56862 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Security update available Affected: azl3 gcc 13.2.0-7 on Azure Linux 3.0 · azl3 golang 1.25.12-1 on Azure Linux 3.0 · +5 more
Updated September 17, 2026
CVE-2026-56853 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Security update available Affected: azl3 golang 1.25.12-1 on Azure Linux 3.0 · azl3 golang 1.26.5-2 on Azure Linux 3.0 · +4 more
Updated September 17, 2026
CVE-2026-27145 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Security update available Affected: azl3 golang 1.25.10-1 on Azure Linux 3.0 · azl3 golang 1.25.11-3 on Azure Linux 3.0 · +3 more
Updated September 17, 2026
CVE-2026-42504 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Security update available Affected: azl3 golang 1.25.10-1 on Azure Linux 3.0 · azl3 golang 1.25.11-3 on Azure Linux 3.0 · +3 more
Updated September 17, 2026
CVE-2026-87776 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Security update available Affected: azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0
Updated September 17, 2026
CVE-2026-89161 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.4
Update availability Security update available Affected: azl3 php 8.3.33-1 on Azure Linux 3.0 · azl3 qtbase 6.6.3-5 on Azure Linux 3.0 · +2 more
Updated September 17, 2026
CVE-2026-85880 Microsoft
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +18 more
Updated September 16, 2026
CVE-2026-49805 Microsoft
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +25 more
Updated September 15, 2026
CVE-2026-50351 Microsoft
Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +25 more
Updated September 15, 2026
CVE-2026-50683 Microsoft
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.
CVSS 8.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +13 more
Updated September 15, 2026
CVE-2026-50688 Microsoft
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +25 more
Updated September 15, 2026
CVE-2026-55053 Microsoft
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +12 more
Updated September 15, 2026
CVE-2026-61363 Microsoft
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVSS 7.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 15, 2026
CVE-2026-61923 Microsoft
Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +20 more
Updated September 15, 2026
CVE-2026-62717 Microsoft
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 15, 2026
CVE-2026-62753 Microsoft
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 15, 2026
CVE-2026-62772 Microsoft
Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 11 Version 26H1 for ARM64-based Systems · Windows 11 version 26H1 for x64-based Systems
Updated September 15, 2026
CVE-2026-65775 Microsoft
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 15, 2026
CVE-2026-65776 Microsoft
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 11 Version 24H2 for ARM64-based Systems · Windows 11 Version 24H2 for x64-based Systems · +6 more
Updated September 15, 2026
CVE-2026-65812 Microsoft
Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
CVSS 6.8
Update availability Patch status unknown Affected: Microsoft Teams for Android
Updated September 15, 2026
CVE-2026-68812 Microsoft
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +12 more
Updated September 15, 2026
CVE-2026-68841 Microsoft
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 15, 2026
CVE-2026-68847 Microsoft
Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 21H2 for 32-bit Systems · Windows 10 Version 21H2 for ARM64-based Systems · +15 more
Updated September 15, 2026