CVE-2026-77492 Microsoft
Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.
CVSS 5.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-77494 Microsoft
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVSS 7.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-77498 Microsoft
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVSS 7.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-77500 Microsoft
Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +20 more
Updated September 8, 2026
CVE-2026-77501 Microsoft
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVSS 7.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-77502 Microsoft
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVSS 7.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-77503 Microsoft
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
CVSS 8.4
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-77887 Microsoft
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.
CVSS 6.4
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-77888 Microsoft
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVSS 7.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-77889 Microsoft
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVSS 7.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-77890 Microsoft
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVSS 7.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-77891 Microsoft
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.
CVSS 6.4
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-77892 Microsoft
No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack.
CVSS 6.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-77893 Microsoft
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVSS 7.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-77894 Microsoft
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-77895 Microsoft
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVSS 7.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-77896 Microsoft
Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network.
CVSS 6.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-77897 Microsoft
Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Power Automate agent for virtual desktops · Power Automate for Desktop
Updated September 8, 2026
CVE-2026-77899 Microsoft
Use after free in Windows Security Center allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 11 Version 24H2 for ARM64-based Systems · Windows 11 Version 24H2 for x64-based Systems · +6 more
Updated September 8, 2026
CVE-2026-77905 Microsoft
Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-77906 Microsoft
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft Visual Studio 2026 version 18.9
Updated September 8, 2026
CVE-2026-77907 Microsoft
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft Visual Studio 2026 version 18.9
Updated September 8, 2026
CVE-2026-77908 Microsoft
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft Dynamics 365 Customer Engagement V9.1
Updated September 8, 2026
CVE-2026-77909 Microsoft
Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network.
CVSS 7.7
Update availability Security update available Affected: Azure CycleCloud 8.9.2
Updated September 8, 2026