CVE-2026-67645 Microsoft
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVSS 6.5
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Updated September 8, 2026
CVE-2026-67648 Microsoft
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
CVSS 6.5
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Updated September 8, 2026
CVE-2026-68775 Microsoft
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Updated September 8, 2026
CVE-2026-68776 Microsoft
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
CVSS 6.5
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Updated September 8, 2026
CVE-2026-68777 Microsoft
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVSS 6.5
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Updated September 8, 2026
CVE-2026-68778 Microsoft
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVSS 6.5
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Updated September 8, 2026
CVE-2026-68779 Microsoft
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVSS 6.5
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Updated September 8, 2026
CVE-2026-68780 Microsoft
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVSS 6.5
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Updated September 8, 2026
CVE-2026-68781 Microsoft
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVSS 6.5
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Updated September 8, 2026
CVE-2026-68784 Microsoft
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVSS 6.5
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Updated September 8, 2026
CVE-2026-68785 Microsoft
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVSS 4.9
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Updated September 8, 2026
CVE-2026-68786 Microsoft
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Updated September 8, 2026
CVE-2026-68787 Microsoft
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Updated September 8, 2026
CVE-2026-68827 Microsoft
Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.
CVSS 8.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-68828 Microsoft
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-68830 Microsoft
Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.
CVSS 5.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-68831 Microsoft
Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.
CVSS 5.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-68832 Microsoft
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-68833 Microsoft
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
CVSS 6.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-68834 Microsoft
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
CVSS 8.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-68835 Microsoft
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.
CVSS 7.1
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-68837 Microsoft
Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +20 more
Updated September 8, 2026
CVE-2026-68838 Microsoft
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
CVSS 8.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-68839 Microsoft
Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.
CVSS 9.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026