CVE-2026-80093 Microsoft
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +20 more
Updated September 8, 2026
CVE-2026-80096 Microsoft
Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
CVSS 8.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Updated September 8, 2026
CVE-2026-81349 Microsoft
Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.
CVSS 7.2
Update availability Security update available Affected: Azure HDInsight
Updated September 8, 2026
CVE-2026-81353 Microsoft
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: HEIF Image Extension
Updated September 8, 2026
CVE-2026-81356 Microsoft
Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVSS 8.2
Update availability Patch status unknown Affected: Visual Studio Code
Updated September 8, 2026
CVE-2026-81376 Microsoft
Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVSS 9.6
Update availability Patch status unknown Affected: Visual Studio Code
Updated September 8, 2026
CVE-2026-81377 Microsoft
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
CVSS 6.5
Update availability Patch status unknown Affected: Visual Studio Code
Updated September 8, 2026
CVE-2026-81378 Microsoft
Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVSS 8.2
Update availability Patch status unknown Affected: Visual Studio Code
Updated September 8, 2026
CVE-2026-81380 Microsoft
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
CVSS 5.3
Update availability Patch status unknown Affected: Visual Studio Code
Updated September 8, 2026
CVE-2026-81381 Microsoft
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
CVSS 6.5
Update availability Patch status unknown Affected: Visual Studio Code
Updated September 8, 2026
CVE-2026-81383 Microsoft
Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
CVSS 7.4
Update availability Patch status unknown Affected: Visual Studio Code
Updated September 8, 2026
CVE-2026-81385 Microsoft
Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
CVSS 8.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +8 more
Updated September 8, 2026
CVE-2026-83940 Microsoft
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
CVSS 7.0
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-83942 Microsoft
Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +20 more
Updated September 8, 2026
CVE-2026-83948 Microsoft
Improper neutralization of special elements used in a command ('command injection') in Microsoft Azure CLI allows an authorized attacker to execute code over a network.
CVSS 8.0
Update availability Patch status unknown Affected: Microsoft Azure CLI
Updated September 8, 2026
CVE-2026-83949 Microsoft
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVSS 5.5
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +8 more
Updated September 8, 2026
CVE-2026-83951 Microsoft
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVSS 5.5
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +8 more
Updated September 8, 2026
CVE-2026-83952 Microsoft
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 11 Version 24H2 for ARM64-based Systems · Windows 11 Version 24H2 for x64-based Systems · +6 more
Updated September 8, 2026
CVE-2026-83954 Microsoft
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-83955 Microsoft
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-83967 Microsoft
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-83968 Microsoft
Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-83969 Microsoft
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026
CVE-2026-83970 Microsoft
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +24 more
Updated September 8, 2026