CVE-2026-77911 Microsoft
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVSS 6.5
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated September 8, 2026
CVE-2026-78441 Microsoft
Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network.
CVSS 6.5
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +2 more
Updated September 8, 2026
CVE-2026-78442 Microsoft
Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +2 more
Updated September 8, 2026
CVE-2026-78447 Microsoft
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-78448 Microsoft
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-78451 Microsoft
Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.
CVSS 6.8
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +20 more
Updated September 8, 2026
CVE-2026-78452 Microsoft
Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack.
CVSS 4.6
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +20 more
Updated September 8, 2026
CVE-2026-78454 Microsoft
Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.
CVSS 5.5
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +20 more
Updated September 8, 2026
CVE-2026-78455 Microsoft
Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack.
CVSS 4.3
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +20 more
Updated September 8, 2026
CVE-2026-78456 Microsoft
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft SQL Server 2022 for x64-based Systems (CU 26) · Microsoft SQL Server 2022 for x64-based Systems (GDR)
Updated September 8, 2026
CVE-2026-78457 Microsoft
Use after free in Windows Security App allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 11 Version 24H2 for ARM64-based Systems · Windows 11 Version 24H2 for x64-based Systems · +8 more
Updated September 8, 2026
CVE-2026-78461 Microsoft
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVSS 7.4
Update availability Patch status unknown Affected: Visual Studio Code
Updated September 8, 2026
CVE-2026-78462 Microsoft
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVSS 8.8
Update availability Patch status unknown Affected: Visual Studio Code
Updated September 8, 2026
CVE-2026-78463 Microsoft
Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Remote Desktop client for Windows Desktop
Updated September 8, 2026
CVE-2026-78464 Microsoft
Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 11 Version 24H2 for ARM64-based Systems · Windows 11 Version 24H2 for x64-based Systems · +4 more
Updated September 8, 2026
CVE-2026-78508 Microsoft
Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack.
CVSS 4.6
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-78516 Microsoft
Insertion of sensitive information into externally-accessible file or directory in Windows Storage allows an authorized attacker to disclose information locally.
CVSS 4.3
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-78522 Microsoft
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVSS 6.5
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +8 more
Updated September 8, 2026
CVE-2026-78523 Microsoft
Use after free in Windows DNS allows an unauthorized attacker to deny service over a network.
CVSS 5.9
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated September 8, 2026
CVE-2026-80074 Microsoft
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Remote Desktop client for Windows Desktop
Updated September 8, 2026
CVE-2026-80077 Microsoft
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Remote Desktop client for Windows Desktop
Updated September 8, 2026
CVE-2026-80079 Microsoft
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVSS 6.5
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +8 more
Updated September 8, 2026
CVE-2026-80081 Microsoft
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Patch status unknown Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems
Updated September 8, 2026
CVE-2026-80084 Microsoft
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.
CVSS 6.5
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +8 more
Updated September 8, 2026