CVE-2026-73008 Microsoft
Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally.
CVSS 5.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-73011 Microsoft
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-73012 Microsoft
Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-73014 Microsoft
Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-73015 Microsoft
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-73019 Microsoft
Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network.
CVSS 4.3
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-73020 Microsoft
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-73021 Microsoft
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-73022 Microsoft
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +20 more
Updated September 8, 2026
CVE-2026-73025 Microsoft
Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
CVSS 9.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-73026 Microsoft
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-73028 Microsoft
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Updated September 8, 2026
CVE-2026-73029 Microsoft
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
CVSS 6.5
Update availability Security update available Affected: Microsoft SQL Server 2019 for x64-based Systems (CU 32) · Microsoft SQL Server 2019 for x64-based Systems (GDR) · +4 more
Updated September 8, 2026
CVE-2026-77480 Microsoft
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Updated September 8, 2026
CVE-2026-77481 Microsoft
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Updated September 8, 2026
CVE-2026-77482 Microsoft
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +2 more
Updated September 8, 2026
CVE-2026-77483 Microsoft
Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Updated September 8, 2026
CVE-2026-77484 Microsoft
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft SQL Server 2019 for x64-based Systems (CU 32) · Microsoft SQL Server 2019 for x64-based Systems (GDR) · +4 more
Updated September 8, 2026
CVE-2026-77485 Microsoft
Use after free in SQL Server allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Updated September 8, 2026
CVE-2026-77486 Microsoft
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +2 more
Updated September 8, 2026
CVE-2026-77487 Microsoft
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Updated September 8, 2026
CVE-2026-77488 Microsoft
Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.
CVSS 5.5
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Updated September 8, 2026
CVE-2026-77489 Microsoft
Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-77491 Microsoft
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
CVSS 5.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026