CVE-2026-69607 Microsoft
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
CVSS 7.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-69609 Microsoft
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
CVSS 5.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-69610 Microsoft
Buffer over-read in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-69611 Microsoft
Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-69613 Microsoft
Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-69614 Microsoft
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +8 more
Updated September 8, 2026
CVE-2026-69615 Microsoft
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVSS 3.5
Update availability Security update available Affected: Microsoft SharePoint Server Subscription Edition
Updated September 8, 2026
CVE-2026-69616 Microsoft
Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to disclose information locally.
CVSS 5.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-69617 Microsoft
Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 11 Version 26H1 for ARM64-based Systems · Windows 11 version 26H1 for x64-based Systems · +2 more
Updated September 8, 2026
CVE-2026-69618 Microsoft
Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally.
CVSS 5.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-69621 Microsoft
Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-69623 Microsoft
Heap-based buffer overflow in Windows HTTP Print Provider allows an authorized attacker to execute code over a network.
CVSS 8.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-69624 Microsoft
Incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) allows an authorized attacker to perform tampering over a network.
CVSS 6.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-69625 Microsoft
Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges over a network.
CVSS 8.0
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +20 more
Updated September 8, 2026
CVE-2026-69627 Microsoft
Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disclose information locally.
CVSS 5.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-69628 Microsoft
Heap-based buffer overflow in Windows iSCSI allows an authorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-69629 Microsoft
Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +8 more
Updated September 8, 2026
CVE-2026-69630 Microsoft
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-69631 Microsoft
Integer overflow or wraparound in Windows DNS allows an unauthorized attacker to deny service over a network.
CVSS 7.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-69638 Microsoft
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVSS 8.4
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-69641 Microsoft
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVSS 9.1
Update availability Security update available Affected: Microsoft Exchange Server 2016 Cumulative Update 23 · Microsoft Exchange Server 2019 Cumulative Update 14 · +2 more
Updated September 8, 2026
CVE-2026-69642 Microsoft
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
CVSS 6.5
Update availability Security update available Affected: Skype for Business Server 2015 CU13 · Skype for Business Server 2019 CU8 · +1 more
Updated September 8, 2026
CVE-2026-69643 Microsoft
Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.
CVSS 8.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-69645 Microsoft
Use after free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026