CVE-2026-47297 Microsoft
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
CVSS 8.1
Update availability Security update available Affected: Microsoft SQL Server 2019 for x64-based Systems (CU 32) · Microsoft SQL Server 2019 for x64-based Systems (GDR) · +4 more
Updated September 8, 2026
CVE-2026-50349 Microsoft
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-50453 Microsoft
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
CVSS 6.1
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +25 more
Updated September 8, 2026
CVE-2026-54990 Microsoft
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVSS 9.8
Update availability Security update available Affected: Windows 11 Version 24H2 for ARM64-based Systems · Windows 11 Version 24H2 for x64-based Systems · +6 more
Updated September 8, 2026
CVE-2026-55007 Microsoft
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
CVSS 8.1
Update availability Security update available Affected: Microsoft Exchange Server 2019 Cumulative Update 14 · Microsoft Exchange Server 2019 Cumulative Update 15 · +1 more
Updated September 8, 2026
CVE-2026-56177 Microsoft
Use after free in Windows Server allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-56198 Microsoft
Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 11 Version 24H2 for ARM64-based Systems · Windows 11 Version 24H2 for x64-based Systems · +6 more
Updated September 8, 2026
CVE-2026-57085 Microsoft
Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
CVSS 5.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +25 more
Updated September 8, 2026
CVE-2026-57098 Microsoft
Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.
CVSS 7.5
Update availability Security update available Affected: Remote Desktop client for Windows Desktop
Updated September 8, 2026
CVE-2026-58600 Microsoft
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: HEVC Video Extensions · HEVC Video Extensions for Licensed Applications · +22 more
Updated September 8, 2026
CVE-2026-58611 Microsoft
Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Xbox Gaming Services
Updated September 8, 2026
CVE-2026-58649 Microsoft
Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.
CVSS 6.5
Update availability Security update available Affected: .NET 10.0 installed on Linux · .NET 10.0 installed on Mac OS · +12 more
Updated September 8, 2026
CVE-2026-61920 Microsoft
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.
CVSS 6.6
Update availability Security update available Affected: Windows Server 2012 R2 · Windows Server 2012 R2 (Server Core installation) · +8 more
Updated September 8, 2026
CVE-2026-62706 Microsoft
Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-62714 Microsoft
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVSS 6.5
Update availability Security update available Affected: Windows Server 2012 · Windows Server 2012 (Server Core installation) · +10 more
Updated September 8, 2026
CVE-2026-62715 Microsoft
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVSS 6.5
Update availability Security update available Affected: Windows Server 2012 R2 · Windows Server 2012 R2 (Server Core installation) · +8 more
Updated September 8, 2026
CVE-2026-62716 Microsoft
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVSS 6.5
Update availability Security update available Affected: Windows Server 2012 · Windows Server 2012 (Server Core installation) · +10 more
Updated September 8, 2026
CVE-2026-62718 Microsoft
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVSS 6.5
Update availability Security update available Affected: Windows Server 2012 · Windows Server 2012 (Server Core installation) · +10 more
Updated September 8, 2026
CVE-2026-62720 Microsoft
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVSS 6.5
Update availability Security update available Affected: Windows Server 2012 · Windows Server 2012 (Server Core installation) · +10 more
Updated September 8, 2026
CVE-2026-62742 Microsoft
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVSS 6.5
Update availability Security update available Affected: Windows Server 2012 · Windows Server 2012 (Server Core installation) · +10 more
Updated September 8, 2026
CVE-2026-62745 Microsoft
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVSS 6.5
Update availability Security update available Affected: Windows Server 2012 · Windows Server 2012 (Server Core installation) · +10 more
Updated September 8, 2026
CVE-2026-62759 Microsoft
Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.
CVSS 7.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-62761 Microsoft
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows Server 2012 · Windows Server 2012 (Server Core installation) · +10 more
Updated September 8, 2026
CVE-2026-62762 Microsoft
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
CVSS 6.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026