CVE-2026-72926 Microsoft
Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-72927 Microsoft
Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally.
CVSS 6.7
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-72928 Microsoft
Use after free in Windows DNS allows an authorized attacker to execute code over a network.
CVSS 7.5
Update availability Security update available Affected: Windows Server 2025 · Windows Server 2025 (Server Core installation)
Updated September 8, 2026
CVE-2026-72929 Microsoft
Improper validation of integrity check value in Windows Installer allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 11 Version 23H2 for ARM64-based Systems · Windows 11 Version 23H2 for x64-based Systems · +8 more
Updated September 8, 2026
CVE-2026-72930 Microsoft
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-72931 Microsoft
Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally.
CVSS 4.7
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-72932 Microsoft
Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.
CVSS 7.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-72933 Microsoft
Heap-based buffer overflow in Microsoft WDAC OLE DB provider for SQL allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-72935 Microsoft
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVSS 6.7
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-72937 Microsoft
Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.
CVSS 5.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-72939 Microsoft
Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network.
CVSS 6.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-72940 Microsoft
Heap-based buffer overflow in Windows Schannel allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 11 Version 23H2 for ARM64-based Systems · Windows 11 Version 23H2 for x64-based Systems · +10 more
Updated September 8, 2026
CVE-2026-72941 Microsoft
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-72942 Microsoft
Out-of-bounds read in Windows Spaceport.sys allows an unauthorized attacker to disclose information over a network.
CVSS 6.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +26 more
Updated September 8, 2026
CVE-2026-72943 Microsoft
Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.
CVSS 7.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-72944 Microsoft
Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-72945 Microsoft
Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally.
CVSS 5.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +16 more
Updated September 8, 2026
CVE-2026-72946 Microsoft
Heap-based buffer overflow in Storage Port Driver allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 11 Version 24H2 for ARM64-based Systems · Windows 11 Version 24H2 for x64-based Systems · +6 more
Updated September 8, 2026
CVE-2026-72947 Microsoft
Integer underflow (wrap or wraparound) in Windows File History Service allows an authorized attacker to elevate privileges locally.
CVSS 6.4
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +20 more
Updated September 8, 2026
CVE-2026-72948 Microsoft
Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.
CVSS 6.7
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-72949 Microsoft
Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network.
CVSS 7.5
Update availability Security update available Affected: Windows 11 Version 23H2 for ARM64-based Systems · Windows 11 Version 23H2 for x64-based Systems · +10 more
Updated September 8, 2026
CVE-2026-72952 Microsoft
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +20 more
Updated September 8, 2026
CVE-2026-72953 Microsoft
Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 21H2 for 32-bit Systems · Windows 10 Version 21H2 for ARM64-based Systems · +16 more
Updated September 8, 2026
CVE-2026-72956 Microsoft
Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
CVSS 6.5
Update availability Patch status unknown Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +6 more
Updated September 8, 2026