Skip to content
Threat Feed
high threat

Microsoft Security Updates — August 2026

Roundup of Microsoft security advisories published in August 2026.

CVE search metadata

CVE search record: CVE-2026-62873. Severity: critical. CVSS: 9.8. EPSS: 0.53%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-65667. Severity: critical. CVSS: 10.0. EPSS: 0.62%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-68419. Severity: high. CVSS: 7.8. EPSS: 0.13%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-50472. Severity: high. CVSS: 7.0. EPSS: 0.25%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-59133. Severity: high. CVSS: 8.8. EPSS: 0.94%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-62715. Severity: medium. CVSS: 6.5. EPSS: 0.48%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-62737. Severity: high. CVSS: 7.8. EPSS: 2.84%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-62785. Severity: high. CVSS: 8.8. EPSS: 0.84%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-62815. Severity: critical. CVSS: 9.8. EPSS: 0.98%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-63513. Severity: high. CVSS: 7.8. EPSS: 0.35%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-63515. Severity: high. CVSS: 7.8. EPSS: 0.35%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-63517. Severity: medium. CVSS: 5.5. EPSS: 0.36%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-63518. Severity: high. CVSS: 7.8. EPSS: 0.35%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-68820. Severity: high. CVSS: 7.0. EPSS: 6.18%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-65783. Severity: high. CVSS: 7.0. EPSS: 0.20%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-72971. Severity: medium. CVSS: 5.5. EPSS: 0.47%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-61355. Severity: high. CVSS: 7.8. EPSS: 0.31%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-62749. Severity: high. CVSS: 7.0. EPSS: 0.20%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-62781. Severity: high. CVSS: 8.1. EPSS: 0.52%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-62832. Severity: high. CVSS: 7.8. EPSS: 3.29%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-63528. Severity: medium. CVSS: 5.5. EPSS: 0.34%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-64901. Severity: high. CVSS: 8.8. EPSS: 1.91%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-65679. Severity: high. CVSS: 8.1. EPSS: 0.57%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-65779. Severity: high. CVSS: 7.0. EPSS: 0.21%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-65781. Severity: high. CVSS: 7.0. EPSS: 0.20%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-68805. Severity: high. CVSS: 7.8. EPSS: 0.33%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-56179. Severity: high. CVSS: 8.3. EPSS: 0.23%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-62834. Severity: critical. CVSS: 9.3. EPSS: 0.29%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

CVE search record: CVE-2026-66309. Severity: critical. CVSS: 9.1. EPSS: 0.47%. KEV: no. Brief: Microsoft Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/

What's new

  • 1. added CVE-2026-56179 +4 Aug 28, 21:32 via msrc
  • 2. added CVE-2026-63528 +1 Aug 28, 21:21 via msrc
  • 3. added CVE-2026-59133 +1 Aug 28, 21:20 via msrc
  • 4. added CVE-2026-64901 +1 Aug 28, 21:20 via msrc
  • 5. added CVE-2026-61355 +2 Aug 28, 21:20 via msrc

This roundup covers 494 Microsoft security vulnerabilities. CVSS base scores range from 5.5 to 10.0. None are reported as actively exploited at the time of release. The issues affect .NET, .NET Core, AMT, Access, Active Directory Certificate Services, Active Directory Domain Services, Application Information Services, Application Insights Profiler, Azure Active Directory, Azure Arc, Azure Attestation, Azure Confidential Ledger, Azure CycleCloud, Azure Data Factory, Azure Data Manager for Energy, Azure Kubernetes Service, Azure Logic Apps, Azure Managed Instance for Apache Cassandra, Azure Monitor Agent, Azure SQL Database, Azure SQL Managed Instance, Azure SRE Agent, Azure Service Bus, Azure Stack HCI, Azure Storage Explorer, Azure Virtual Machines, Bluetooth, COM, Capability Access Management Service, Copilot, Defender for Endpoint, Desktop Window Manager, Dynamics 365, Dynamics Business Central, Edge, Entra Connect, Excel, Exchange Online, Exchange Server, GitHub Copilot, HDF5, High Performance Computing, High Performance Computing Pack, Hyper-V, Local Security Authority Server, Microsoft .NET Framework, Microsoft 365 Admin Center, Microsoft Copilot in Azure, Microsoft Entra, Microsoft Entra Provisioning Service, Microsoft Fabric, Microsoft Malware Protection Engine, Microsoft Partner Center, Microsoft Planetary Computer Pro, Microsoft Purview eDiscovery, Microsoft QUIC, Microsoft Teams, Office, Office Access, Office Word, OneDrive, Outlook, Power Apps, Power BI, PowerPoint, PowerShell, PowerShell Core, Reliable Multicast Transport Driver, Remote Desktop Client, Remote Desktop Services, Remote Help, Remote Registry Service, Routing and Remote Access Service, Rpm, SMB Client, SQL Server, SharePoint, SharePoint Online, SharePoint Server, Teams, Virtual Hard Disk, Visual Studio Code, Visual Studio Code CoPilot Chat Extension, Windows, Windows Ancillary Function Driver for WinSock, Windows Autopilot, Windows Backup Engine, Windows Bind Filter Driver, Windows Cloud Files Mini Filter Driver, Windows Common Log File System Driver, Windows Container Isolation FS Filter Driver, Windows Cross Device Service, Windows DHCP Client, Windows DHCP Server, Windows DNS, Windows DNS Server, Windows DWM Core Library, Windows Deployment Services, Windows Device Association Service, Windows Display Enhancement Service, Windows Encrypting File System, Windows Event Logging Service, Windows GDI+, Windows Graphics Kernel, Windows HTTP Protocol Stack, Windows HTTP.sys, Windows Hello, Windows Imaging Component, Windows Installer, Windows Kerberos, Windows Kernel, Windows Key Guard, Windows LDAP, Windows License Manager, Windows MIDI Service, Windows MIDI Service Module, Windows Management Instrumentation, Windows Management Services, Windows Message Queuing, Windows Modern Device Management, Windows NTFS, Windows Narrator, Windows Network Connection Broker, Windows Network File System, Windows Package Manager, Windows Program Compatibility Assistant Service, Windows Projected File System, Windows Push Notifications, Windows Remote Access API, Windows Remote Access Connection Manager, Windows Remote Desktop Services, Windows SMB Client, Windows SMB Server, Windows Search Component, Windows Secure Socket Tunneling Protocol, Windows Sensor Data Service, Windows Storage, Windows Storage Port Driver, Windows Telephony Service, Windows Universal Disk Format File System Driver, Windows User Profile Service, Windows Work Folder Service, Windows iSCSI Target Service, Winlogon, Word, dma-buf/udmabuf, firmware, ims-pcu, iomap, ksmbd, mctp, net/handshake, pds_core, wanxl.

Summary

CVEProductSeverityCVSSEPSSKEVSource
CVE-2026-50481Azure Active DirectorynoNVD (authoritative)
CVE-2026-50515Azure Service BusnoNVD (authoritative)
CVE-2026-56161Azure Logic AppsnoNVD (authoritative)
CVE-2026-59115Microsoft Entra Provisioning ServicenoNVD (authoritative)
CVE-2026-59118Power AppsnoNVD (authoritative)
CVE-2026-62830Azure SRE AgentnoNVD (authoritative)
CVE-2026-62873Microsoft 365 Admin CenternoNVD (authoritative)
CVE-2026-62896Microsoft TeamsnoNVD (authoritative)
CVE-2026-63508Microsoft Planetary Computer Pro (GeoCatalog)noNVD (authoritative)
CVE-2026-65667Microsoft TeamsCritical10.00.62%noNVD (authoritative)
CVE-2026-68823Azure Confidential LedgernoNVD (authoritative)
CVE-2026-70332SharePoint OnlinenoNVD (authoritative)
CVE-2026-49163Application Insights ProfilernoNVD (authoritative)
CVE-2026-62836Azure SQL Managed InstancenoNVD (authoritative)
CVE-2026-62918Microsoft TeamsnoNVD (authoritative)
CVE-2026-65668Microsoft Purview eDiscoverynoNVD (authoritative)
CVE-2026-68480WindowsnoMSRC (authoritative)
CVE-2026-64564WindowsnoMSRC (authoritative)
CVE-2026-64590dma-buf/udmabufnoMSRC (authoritative)
CVE-2026-54876WindowsnoMSRC (authoritative)
CVE-2026-44605RpmnoMSRC (authoritative)
CVE-2026-64573BluetoothnoMSRC (authoritative)
CVE-2026-64565ims-pcunoMSRC (authoritative)
CVE-2026-64578ksmbdnoMSRC (authoritative)
CVE-2024-21380Dynamics Business CentralnoMSRC (authoritative)
CVE-2025-2308HDF5noMSRC (authoritative)
CVE-2025-2309HDF5noMSRC (authoritative)
CVE-2026-68097ksmbdnoMSRC (authoritative)
CVE-2026-68388WindowsnoMSRC (authoritative)
CVE-2026-68187n/anoMSRC (authoritative)
CVE-2026-68152AMTnoMSRC (authoritative)
CVE-2026-68189WindowsnoMSRC (authoritative)
CVE-2026-68312WindowsnoMSRC (authoritative)
CVE-2026-68130ksmbdnoMSRC (authoritative)
CVE-2026-68176WindowsnoMSRC (authoritative)
CVE-2026-68145iomapnoMSRC (authoritative)
CVE-2026-68318pds_corenoMSRC (authoritative)
CVE-2026-68118WindowsnoMSRC (authoritative)
CVE-2026-68175WindowsnoMSRC (authoritative)
CVE-2026-68328WindowsnoMSRC (authoritative)
CVE-2026-68406WindowsnoMSRC (authoritative)
CVE-2026-68317WindowsnoMSRC (authoritative)
CVE-2026-68099ksmbdnoMSRC (authoritative)
CVE-2026-68354WindowsnoMSRC (authoritative)
CVE-2026-68326WindowsnoMSRC (authoritative)
CVE-2026-68151WindowsnoMSRC (authoritative)
CVE-2026-68343WindowsnoMSRC (authoritative)
CVE-2026-68184WindowsnoMSRC (authoritative)
CVE-2026-68124mctpnoMSRC (authoritative)
CVE-2026-68401firmwarenoMSRC (authoritative)
CVE-2026-68322WindowsnoMSRC (authoritative)
CVE-2026-68214WindowsnoMSRC (authoritative)
CVE-2026-68327wanxlnoMSRC (authoritative)
CVE-2026-68188WindowsnoMSRC (authoritative)
CVE-2026-68132WindowsnoMSRC (authoritative)
CVE-2026-68304WindowsnoMSRC (authoritative)
CVE-2026-68098ksmbdnoMSRC (authoritative)
CVE-2026-68348WindowsnoMSRC (authoritative)
CVE-2026-68195WindowsnoMSRC (authoritative)
CVE-2026-68419WindowsHigh7.80.13%noMSRC (authoritative)
CVE-2026-68171WindowsnoMSRC (authoritative)
CVE-2026-64523net/handshakenoMSRC (authoritative)
CVE-2026-64388SMB ClientnoMSRC (authoritative)
CVE-2025-37938WindowsnoMSRC (authoritative)
CVE-2026-68207WindowsnoMSRC (authoritative)
CVE-2026-50472WindowsHigh7.00.25%noMSRC (authoritative)
CVE-2026-56174Windows NarratornoMSRC (authoritative)
CVE-2026-58650Visual Studio CodenoMSRC (authoritative)
CVE-2026-65768TeamsnoMSRC (authoritative)
CVE-2026-57105SharePointnoMSRC (authoritative)
CVE-2026-62829SharePoint ServernoMSRC (authoritative)
CVE-2026-62827SharePoint ServernoMSRC (authoritative)
CVE-2026-62837SharePoint ServernoMSRC (authoritative)
CVE-2026-63514SharePoint ServernoMSRC (authoritative)
CVE-2026-63512SharePoint ServernoMSRC (authoritative)
CVE-2026-63516SharePoint ServernoMSRC (authoritative)
CVE-2026-63520SharePoint ServernoMSRC (authoritative)
CVE-2026-40375Dynamics Business CentralnoMSRC (authoritative)
CVE-2026-54113Windows KernelnoMSRC (authoritative)
CVE-2026-54984Windows Imaging ComponentnoMSRC (authoritative)
CVE-2026-49179Active Directory Domain ServicesnoMSRC (authoritative)
CVE-2026-58612PowerShell CorenoMSRC (authoritative)
CVE-2026-59113Visual Studio CodenoMSRC (authoritative)
CVE-2026-47299Azure Monitor AgentnoMSRC (authoritative)
CVE-2026-47285Visual Studio CodenoMSRC (authoritative)
CVE-2026-59124High Performance Computing PacknoMSRC (authoritative)
CVE-2026-59127Windows InstallernoMSRC (authoritative)
CVE-2026-59128Windows Encrypting File SystemnoMSRC (authoritative)
CVE-2026-59133High Performance Computing (HPC) PackHigh8.80.94%noMSRC (authoritative)
CVE-2026-59132WindowsnoMSRC (authoritative)
CVE-2026-59135Windows Search ComponentnoMSRC (authoritative)
CVE-2026-59134Remote Desktop ClientnoMSRC (authoritative)
CVE-2026-59136COMnoMSRC (authoritative)
CVE-2026-59137Windows Event Logging ServicenoMSRC (authoritative)
CVE-2026-59138Remote Registry ServicenoMSRC (authoritative)
CVE-2026-61345Remote Registry ServicenoMSRC (authoritative)
CVE-2026-61346Windows Graphics KernelnoMSRC (authoritative)
CVE-2026-61353Windows Telephony ServicenoMSRC (authoritative)
CVE-2026-61347Windows Event Logging ServicenoMSRC (authoritative)
CVE-2026-61361Windows DHCP ClientnoMSRC (authoritative)
CVE-2026-61348Windows Ancillary Function Driver for WinSocknoMSRC (authoritative)
CVE-2026-61356Remote Desktop ServicesnoMSRC (authoritative)
CVE-2026-61367Remote Desktop ServicesnoMSRC (authoritative)
CVE-2026-61923Windows Display Enhancement ServicenoMSRC (authoritative)
CVE-2026-61366Windows Network Connection BrokernoMSRC (authoritative)
CVE-2026-61368Hyper-VnoMSRC (authoritative)
CVE-2026-61924Remote Desktop ClientnoMSRC (authoritative)
CVE-2026-61925Windows InstallernoMSRC (authoritative)
CVE-2026-61927WindowsnoMSRC (authoritative)
CVE-2026-61928Windows HellonoMSRC (authoritative)
CVE-2026-61930Windows KernelnoMSRC (authoritative)
CVE-2026-61937WindowsnoMSRC (authoritative)
CVE-2026-62692Remote Desktop ServicesnoMSRC (authoritative)
CVE-2026-61932Windows DWM Core LibrarynoMSRC (authoritative)
CVE-2026-61933WindowsnoMSRC (authoritative)
CVE-2026-61934WindowsnoMSRC (authoritative)
CVE-2026-61936WindowsnoMSRC (authoritative)
CVE-2026-61939WinlogonnoMSRC (authoritative)
CVE-2026-62695Windows StoragenoMSRC (authoritative)
CVE-2026-62688Windows MIDI ServicenoMSRC (authoritative)
CVE-2026-62690Windows Push NotificationsnoMSRC (authoritative)
CVE-2026-62693Windows MIDI Service ModulenoMSRC (authoritative)
CVE-2026-62696Windows Program Compatibility Assistant ServicenoMSRC (authoritative)
CVE-2026-62702WindowsnoMSRC (authoritative)
CVE-2026-62699Windows Universal Disk Format File System DrivernoMSRC (authoritative)
CVE-2026-62703Windows DWM Core LibrarynoMSRC (authoritative)
CVE-2026-62705Windows Bind Filter DrivernoMSRC (authoritative)
CVE-2026-62707Windows Modern Device ManagementnoMSRC (authoritative)
CVE-2026-62713Windows Cloud Files Mini Filter DrivernoMSRC (authoritative)
CVE-2026-62712WindowsnoMSRC (authoritative)
CVE-2026-62718Windows DHCP ServernoMSRC (authoritative)
CVE-2026-62715Windows DHCP ServernoMSRC (authoritative)
CVE-2026-62716Windows DHCP ServernoMSRC (authoritative)
CVE-2026-62719Windows Message QueuingnoMSRC (authoritative)
CVE-2026-62722Windows Bind Filter DrivernoMSRC (authoritative)
CVE-2026-62723Windows Telephony ServicenoMSRC (authoritative)
CVE-2026-62724Windows Telephony ServicenoMSRC (authoritative)
CVE-2026-62748Windows Telephony ServicenoMSRC (authoritative)
CVE-2026-62729Windows Telephony ServicenoMSRC (authoritative)
CVE-2026-62746WindowsnoMSRC (authoritative)
CVE-2026-62740Windows Imaging ComponentnoMSRC (authoritative)
CVE-2026-62753Windows HTTP.sysnoMSRC (authoritative)
CVE-2026-62735WindowsnoMSRC (authoritative)
CVE-2026-62737Windows KernelHigh7.82.84%noMSRC (authoritative)
CVE-2026-62739WindowsnoMSRC (authoritative)
CVE-2026-62742Windows DHCP ServernoMSRC (authoritative)
CVE-2026-62745Windows DHCP ServernoMSRC (authoritative)
CVE-2026-62747Windows Device Association ServicenoMSRC (authoritative)
CVE-2026-62750Windows HTTP Protocol StacknoMSRC (authoritative)
CVE-2026-62754WindowsnoMSRC (authoritative)
CVE-2026-62783Windows Remote Access Connection ManagernoMSRC (authoritative)
CVE-2026-62755Windows DHCP ClientnoMSRC (authoritative)
CVE-2026-62758Windows Remote Access Connection ManagernoMSRC (authoritative)
CVE-2026-62766WindowsnoMSRC (authoritative)
CVE-2026-62773WindowsnoMSRC (authoritative)
CVE-2026-62772Windows Container Isolation FS Filter DrivernoMSRC (authoritative)
CVE-2026-62774WindowsnoMSRC (authoritative)
CVE-2026-62785Windows LDAPHigh8.80.84%noMSRC (authoritative)
CVE-2026-62777Windows License ManagernoMSRC (authoritative)
CVE-2026-62779WindowsnoMSRC (authoritative)
CVE-2026-62792WindowsnoMSRC (authoritative)
CVE-2026-62784Local Security Authority ServernoMSRC (authoritative)
CVE-2026-62787Windows DNS ServernoMSRC (authoritative)
CVE-2026-62798WindowsnoMSRC (authoritative)
CVE-2026-62795WindowsnoMSRC (authoritative)
CVE-2026-62796WindowsnoMSRC (authoritative)
CVE-2026-62797Windows NTFSnoMSRC (authoritative)
CVE-2026-62812Windows DHCP ServernoMSRC (authoritative)
CVE-2026-62815Microsoft QUICCritical9.80.98%noMSRC (authoritative)
CVE-2026-62816Reliable Multicast Transport Driver (RMCAST)noMSRC (authoritative)
CVE-2026-62817Windows DNS ServernoMSRC (authoritative)
CVE-2026-62818Active Directory Certificate ServicesnoMSRC (authoritative)
CVE-2026-62819Routing and Remote Access ServicenoMSRC (authoritative)
CVE-2026-62820Windows DNS ServernoMSRC (authoritative)
CVE-2026-62876WindowsnoMSRC (authoritative)
CVE-2026-62877WindowsnoMSRC (authoritative)
CVE-2026-62878Windows DNS ServernoMSRC (authoritative)
CVE-2026-62889Windows Secure Socket Tunneling ProtocolnoMSRC (authoritative)
CVE-2026-62890Windows GDI+noMSRC (authoritative)
CVE-2026-62892Capability Access Management ServicenoMSRC (authoritative)
CVE-2026-62893Windows Deployment ServicesnoMSRC (authoritative)
CVE-2026-62894Windows DWM Core LibrarynoMSRC (authoritative)
CVE-2026-62899.NETnoMSRC (authoritative)
CVE-2026-62900.NETnoMSRC (authoritative)
CVE-2026-62901.NETnoMSRC (authoritative)
CVE-2026-62902.NETnoMSRC (authoritative)
CVE-2026-62908Windows Backup EnginenoMSRC (authoritative)
CVE-2026-62909.NETnoMSRC (authoritative)
CVE-2026-62910Exchange ServernoMSRC (authoritative)
CVE-2026-62912Exchange ServernoMSRC (authoritative)
CVE-2026-62913Exchange ServernoMSRC (authoritative)
CVE-2026-62914Exchange ServernoMSRC (authoritative)
CVE-2026-62915Exchange ServernoMSRC (authoritative)
CVE-2026-54123Defender for EndpointnoMSRC (authoritative)
CVE-2026-63513OfficeHigh7.80.35%noMSRC (authoritative)
CVE-2026-63515OfficeHigh7.80.35%noMSRC (authoritative)
CVE-2026-63517OfficeMedium5.50.36%noMSRC (authoritative)
CVE-2026-63518Office WordHigh7.80.35%noMSRC (authoritative)
CVE-2026-63521OfficenoMSRC (authoritative)
CVE-2026-63519OfficenoMSRC (authoritative)
CVE-2026-64922SharePoint ServernoMSRC (authoritative)
CVE-2026-65657OfficenoMSRC (authoritative)
CVE-2026-65656OfficenoMSRC (authoritative)
CVE-2026-65658SharePoint ServernoMSRC (authoritative)
CVE-2026-65661OfficenoMSRC (authoritative)
CVE-2026-65663SharePoint ServernoMSRC (authoritative)
CVE-2026-65660SharePoint ServernoMSRC (authoritative)
CVE-2026-65664OfficenoMSRC (authoritative)
CVE-2026-65665SharePoint ServernoMSRC (authoritative)
CVE-2026-65662WindowsnoMSRC (authoritative)
CVE-2026-65671Windows Remote Access APInoMSRC (authoritative)
CVE-2026-65672WindowsnoMSRC (authoritative)
CVE-2026-65675Visual Studio Code CoPilot Chat ExtensionnoMSRC (authoritative)
CVE-2026-65678WindowsnoMSRC (authoritative)
CVE-2026-65785Windows DHCP ClientnoMSRC (authoritative)
CVE-2026-65784WindowsnoMSRC (authoritative)
CVE-2026-65786Desktop Window ManagernoMSRC (authoritative)
CVE-2026-65789Windows DNS ServernoMSRC (authoritative)
CVE-2026-65787Desktop Window ManagernoMSRC (authoritative)
CVE-2026-65788Desktop Window ManagernoMSRC (authoritative)
CVE-2026-65807ExcelnoMSRC (authoritative)
CVE-2026-65811Power BInoMSRC (authoritative)
CVE-2026-65813Exchange ServernoMSRC (authoritative)
CVE-2026-65814Windows Storage Port DrivernoMSRC (authoritative)
CVE-2026-65815Dynamics 365noMSRC (authoritative)
CVE-2026-66799Windows Key GuardnoMSRC (authoritative)
CVE-2026-68792OfficenoMSRC (authoritative)
CVE-2026-68793ExcelnoMSRC (authoritative)
CVE-2026-68794ExcelnoMSRC (authoritative)
CVE-2026-68795ExcelnoMSRC (authoritative)
CVE-2026-68796ExcelnoMSRC (authoritative)
CVE-2026-68800ExcelnoMSRC (authoritative)
CVE-2026-68802ExcelnoMSRC (authoritative)
CVE-2026-68807ExcelnoMSRC (authoritative)
CVE-2026-68806ExcelnoMSRC (authoritative)
CVE-2026-68808ExcelnoMSRC (authoritative)
CVE-2026-68809PowerPointnoMSRC (authoritative)
CVE-2026-68810ExcelnoMSRC (authoritative)
CVE-2026-68811ExcelnoMSRC (authoritative)
CVE-2026-68813ExcelnoMSRC (authoritative)
CVE-2026-68815ExcelnoMSRC (authoritative)
CVE-2026-68816ExcelnoMSRC (authoritative)
CVE-2026-68819Windows Network File SystemnoMSRC (authoritative)
CVE-2026-68820Windows Ancillary Function Driver for WinSockHigh7.06.18%noMSRC (authoritative)
CVE-2026-68821Windows Package ManagernoMSRC (authoritative)
CVE-2026-69320Visual Studio CodenoMSRC (authoritative)
CVE-2026-69278Visual Studio CodenoMSRC (authoritative)
CVE-2026-69306Visual Studio CodenoMSRC (authoritative)
CVE-2026-70307WindowsnoMSRC (authoritative)
CVE-2026-66301Dynamics 365noMSRC (authoritative)
CVE-2026-70312PowerPointnoMSRC (authoritative)
CVE-2026-70311Office WordnoMSRC (authoritative)
CVE-2026-70313PowerPointnoMSRC (authoritative)
CVE-2026-70310OfficenoMSRC (authoritative)
CVE-2026-70316PowerPointnoMSRC (authoritative)
CVE-2026-70315OfficenoMSRC (authoritative)
CVE-2026-70321SharePointnoMSRC (authoritative)
CVE-2026-70318ExcelnoMSRC (authoritative)
CVE-2026-70314OfficenoMSRC (authoritative)
CVE-2026-70317OfficenoMSRC (authoritative)
CVE-2026-70325PowerPointnoMSRC (authoritative)
CVE-2026-70319Office WordnoMSRC (authoritative)
CVE-2026-70320PowerPointnoMSRC (authoritative)
CVE-2026-70323OfficenoMSRC (authoritative)
CVE-2026-70322PowerPointnoMSRC (authoritative)
CVE-2026-70324SharePointnoMSRC (authoritative)
CVE-2026-70327ExcelnoMSRC (authoritative)
CVE-2026-70328ExcelnoMSRC (authoritative)
CVE-2026-70329OutlooknoMSRC (authoritative)
CVE-2026-70304Windows DNSnoMSRC (authoritative)
CVE-2026-70330Windows DNSnoMSRC (authoritative)
CVE-2026-70335GitHub CopilotnoMSRC (authoritative)
CVE-2026-70336Visual Studio CodenoMSRC (authoritative)
CVE-2026-57104Azure Storage ExplorernoMSRC (authoritative)
CVE-2026-70340Azure CycleCloudnoMSRC (authoritative)
CVE-2026-65806Azure CycleCloudnoMSRC (authoritative)
CVE-2026-61352Remote Desktop ClientnoMSRC (authoritative)
CVE-2026-65783Windows AutopilotHigh7.00.20%noMSRC (authoritative)
CVE-2026-66804Windows Cross Device ServicenoMSRC (authoritative)
CVE-2026-70344Windows InstallernoMSRC (authoritative)
CVE-2026-70345Windows InstallernoMSRC (authoritative)
CVE-2026-70346Windows InstallernoMSRC (authoritative)
CVE-2026-70347Windows InstallernoMSRC (authoritative)
CVE-2026-70348Windows Management ServicesnoMSRC (authoritative)
CVE-2026-70355SharePoint ServernoMSRC (authoritative)
CVE-2026-72971Windows Container Isolation FS Filter DriverMedium5.50.47%noMSRC (authoritative)
CVE-2026-42976WindowsnoMSRC (authoritative)
CVE-2026-54981Visual Studio CodenoMSRC (authoritative)
CVE-2026-6726WindowsnoMSRC (authoritative)
CVE-2026-58641.NETnoMSRC (authoritative)
CVE-2026-58651WordnoMSRC (authoritative)
CVE-2026-59122Windows Telephony ServicenoMSRC (authoritative)
CVE-2026-59125Virtual Hard Disk (VHD) Miniport DrivernoMSRC (authoritative)
CVE-2026-59126Windows Event Logging ServicenoMSRC (authoritative)
CVE-2026-61349Windows Work Folder ServicenoMSRC (authoritative)
CVE-2026-61363Remote Desktop ClientnoMSRC (authoritative)
CVE-2026-61359Windows StoragenoMSRC (authoritative)
CVE-2026-61355Windows Sensor Data ServiceHigh7.80.31%noMSRC (authoritative)
CVE-2026-61364Windows Remote Desktop ServicesnoMSRC (authoritative)
CVE-2026-61365Remote Desktop ServicesnoMSRC (authoritative)
CVE-2026-61357Application Information ServicesnoMSRC (authoritative)
CVE-2026-61358WindowsnoMSRC (authoritative)
CVE-2026-61360WindowsnoMSRC (authoritative)
CVE-2026-61920Windows DNS ServernoMSRC (authoritative)
CVE-2026-61926WindowsnoMSRC (authoritative)
CVE-2026-61918Remote Desktop ClientnoMSRC (authoritative)
CVE-2026-61921Remote Desktop ClientnoMSRC (authoritative)
CVE-2026-61929WindowsnoMSRC (authoritative)
CVE-2026-61938Windows InstallernoMSRC (authoritative)
CVE-2026-62698WindowsnoMSRC (authoritative)
CVE-2026-62700WindowsnoMSRC (authoritative)
CVE-2026-62701Windows Telephony ServicenoMSRC (authoritative)
CVE-2026-62708Windows KernelnoMSRC (authoritative)
CVE-2026-62709Windows GDI+noMSRC (authoritative)
CVE-2026-62710Windows Device Association ServicenoMSRC (authoritative)
CVE-2026-62711WindowsnoMSRC (authoritative)
CVE-2026-62720Windows DHCP ServernoMSRC (authoritative)
CVE-2026-62714Windows DHCP ServernoMSRC (authoritative)
CVE-2026-62717Windows Message QueuingnoMSRC (authoritative)
CVE-2026-62721WindowsnoMSRC (authoritative)
CVE-2026-62725Windows Telephony ServicenoMSRC (authoritative)
CVE-2026-62726Windows Telephony ServicenoMSRC (authoritative)
CVE-2026-62728Windows Common Log File System DrivernoMSRC (authoritative)
CVE-2026-62733WindowsnoMSRC (authoritative)
CVE-2026-62743WindowsnoMSRC (authoritative)
CVE-2026-62730WindowsnoMSRC (authoritative)
CVE-2026-62732Windows Telephony ServicenoMSRC (authoritative)
CVE-2026-62734Windows Telephony ServicenoMSRC (authoritative)
CVE-2026-62736Windows DHCP ClientnoMSRC (authoritative)
CVE-2026-62757WindowsnoMSRC (authoritative)
CVE-2026-62741WindowsnoMSRC (authoritative)
CVE-2026-62749Windows KernelHigh7.00.20%noMSRC (authoritative)
CVE-2026-62751Windows Projected File SystemnoMSRC (authoritative)
CVE-2026-62752Windows KerberosnoMSRC (authoritative)
CVE-2026-62769Windows DNSnoMSRC (authoritative)
CVE-2026-62771Windows Cloud Files Mini Filter DrivernoMSRC (authoritative)
CVE-2026-62761Windows DHCP ServernoMSRC (authoritative)
CVE-2026-62768Windows InstallernoMSRC (authoritative)
CVE-2026-62770WindowsnoMSRC (authoritative)
CVE-2026-62775Windows Container Isolation FS Filter DrivernoMSRC (authoritative)
CVE-2026-62799Windows SMB ClientnoMSRC (authoritative)
CVE-2026-62776Windows DHCP ServernoMSRC (authoritative)
CVE-2026-62778Windows DNSnoMSRC (authoritative)
CVE-2026-62780WindowsnoMSRC (authoritative)
CVE-2026-62782Windows SMB ClientnoMSRC (authoritative)
CVE-2026-62781WindowsnoMSRC (authoritative)
CVE-2026-62800Windows SMB ServernoMSRC (authoritative)
CVE-2026-62786WindowsnoMSRC (authoritative)
CVE-2026-62788WindowsnoMSRC (authoritative)
CVE-2026-62790Windows SMB ServernoMSRC (authoritative)
CVE-2026-62793WindowsnoMSRC (authoritative)
CVE-2026-62803Windows DHCP ServernoMSRC (authoritative)
CVE-2026-62807Windows DHCP ServernoMSRC (authoritative)
CVE-2026-62811WindowsnoMSRC (authoritative)
CVE-2026-62814Windows DHCP ServernoMSRC (authoritative)
CVE-2026-62823Windows DHCP ServernoMSRC (authoritative)
CVE-2026-62824Remote Desktop ClientnoMSRC (authoritative)
CVE-2026-62822Windows GDI+noMSRC (authoritative)
CVE-2026-62832Windows User Profile ServiceHigh7.83.29%noMSRC (authoritative)
CVE-2026-62871.NETnoMSRC (authoritative)
CVE-2026-62880WindowsnoMSRC (authoritative)
CVE-2026-62881Windows DNSnoMSRC (authoritative)
CVE-2026-62883Windows DNSnoMSRC (authoritative)
CVE-2026-62885WindowsnoMSRC (authoritative)
CVE-2026-62886.NETnoMSRC (authoritative)
CVE-2026-62887WindowsnoMSRC (authoritative)
CVE-2026-62888WindowsnoMSRC (authoritative)
CVE-2026-62911Exchange ServernoMSRC (authoritative)
CVE-2026-62842OfficenoMSRC (authoritative)
CVE-2026-63524OfficenoMSRC (authoritative)
CVE-2026-63525OfficenoMSRC (authoritative)
CVE-2026-63526OfficenoMSRC (authoritative)
CVE-2026-63528Office WordMedium5.50.34%noMSRC (authoritative)
CVE-2026-63527Office WordnoMSRC (authoritative)
CVE-2026-63529OfficenoMSRC (authoritative)
CVE-2026-63530OfficenoMSRC (authoritative)
CVE-2026-63531Office WordnoMSRC (authoritative)
CVE-2026-63532OfficenoMSRC (authoritative)
CVE-2026-63533OfficenoMSRC (authoritative)
CVE-2026-64897SharePoint ServernoMSRC (authoritative)
CVE-2026-64898OfficenoMSRC (authoritative)
CVE-2026-64900SharePoint ServernoMSRC (authoritative)
CVE-2026-64902SharePoint ServernoMSRC (authoritative)
CVE-2026-64899OfficenoMSRC (authoritative)
CVE-2026-64903OfficenoMSRC (authoritative)
CVE-2026-64901SharePoint ServerHigh8.81.91%noMSRC (authoritative)
CVE-2026-64904OfficenoMSRC (authoritative)
CVE-2026-64905Office WordnoMSRC (authoritative)
CVE-2026-64907Office WordnoMSRC (authoritative)
CVE-2026-64906AccessnoMSRC (authoritative)
CVE-2026-64909OfficenoMSRC (authoritative)
CVE-2026-64910OfficenoMSRC (authoritative)
CVE-2026-64912AccessnoMSRC (authoritative)
CVE-2026-64911OfficenoMSRC (authoritative)
CVE-2026-64908Office AccessnoMSRC (authoritative)
CVE-2026-64914AccessnoMSRC (authoritative)
CVE-2026-64915Office WordnoMSRC (authoritative)
CVE-2026-64916SharePoint ServernoMSRC (authoritative)
CVE-2026-64920AccessnoMSRC (authoritative)
CVE-2026-64917Office WordnoMSRC (authoritative)
CVE-2026-64919AccessnoMSRC (authoritative)
CVE-2026-64921SharePoint ServernoMSRC (authoritative)
CVE-2026-62882OutlooknoMSRC (authoritative)
CVE-2026-65673Entra ConnectnoMSRC (authoritative)
CVE-2026-65681Windows iSCSI Target ServicenoMSRC (authoritative)
CVE-2026-65679Windows iSCSI Target ServicenoMSRC (authoritative)
CVE-2026-65773Windows KernelnoMSRC (authoritative)
CVE-2026-65774Windows InstallernoMSRC (authoritative)
CVE-2026-65775WindowsnoMSRC (authoritative)
CVE-2026-65776WindowsnoMSRC (authoritative)
CVE-2026-65779Windows AutopilotHigh7.00.21%noMSRC (authoritative)
CVE-2026-65780Windows AutopilotnoMSRC (authoritative)
CVE-2026-65778Windows AutopilotnoMSRC (authoritative)
CVE-2026-65782Windows AutopilotnoMSRC (authoritative)
CVE-2026-65781Windows AutopilotHigh7.00.20%noMSRC (authoritative)
CVE-2026-65790Windows Message QueuingnoMSRC (authoritative)
CVE-2026-65791Windows iSCSI Target ServicenoMSRC (authoritative)
CVE-2026-65795Windows DNSnoMSRC (authoritative)
CVE-2026-65794WindowsnoMSRC (authoritative)
CVE-2026-65797Windows DNSnoMSRC (authoritative)
CVE-2026-65799Windows DNSnoMSRC (authoritative)
CVE-2026-65798Windows DNSnoMSRC (authoritative)
CVE-2026-65796Windows iSCSI Target ServicenoMSRC (authoritative)
CVE-2026-66802Azure AttestationnoMSRC (authoritative)
CVE-2026-66805SharePoint ServernoMSRC (authoritative)
CVE-2026-66806Office WordnoMSRC (authoritative)
CVE-2026-66807OfficenoMSRC (authoritative)
CVE-2026-66808SharePoint ServernoMSRC (authoritative)
CVE-2026-66810Office WordnoMSRC (authoritative)
CVE-2026-66809OfficenoMSRC (authoritative)
CVE-2026-68797ExcelnoMSRC (authoritative)
CVE-2026-68798ExcelnoMSRC (authoritative)
CVE-2026-68799ExcelnoMSRC (authoritative)
CVE-2026-68801ExcelnoMSRC (authoritative)
CVE-2026-68803ExcelnoMSRC (authoritative)
CVE-2026-68804ExcelnoMSRC (authoritative)
CVE-2026-68805ExcelHigh7.80.33%noMSRC (authoritative)
CVE-2026-68812ExcelnoMSRC (authoritative)
CVE-2026-68814ExcelnoMSRC (authoritative)
CVE-2026-68817ExcelnoMSRC (authoritative)
CVE-2026-56179WindowsnoMSRC (authoritative)
CVE-2026-70130OfficenoMSRC (authoritative)
CVE-2026-70306SharePointnoMSRC (authoritative)
CVE-2026-70326SharePoint ServernoMSRC (authoritative)
CVE-2026-70337PowerShell CorenoMSRC (authoritative)
CVE-2026-70354.NET CorenoMSRC (authoritative)
CVE-2026-71331Azure AttestationnoMSRC (authoritative)
CVE-2026-62738Windows Management InstrumentationnoMSRC (authoritative)
CVE-2026-62898Microsoft QUICnoMSRC (authoritative)
CVE-2026-65767TeamsnoMSRC (authoritative)
CVE-2026-58639SharePoint ServernoMSRC (authoritative)
CVE-2026-62839SharePoint ServernoMSRC (authoritative)
CVE-2026-62917SharePoint ServernoMSRC (authoritative)
CVE-2026-65680OneDrivenoMSRC (authoritative)
CVE-2026-50516Azure Kubernetes ServicenoNVD (authoritative)
CVE-2026-62869Microsoft EntranoNVD (authoritative)
CVE-2026-62872Microsoft .NET FrameworknoNVD (authoritative)
CVE-2026-62897.NET (< 10.0.11)noNVD (authoritative)
CVE-2026-63522Azure SQL DatabasenoNVD (authoritative)
CVE-2026-70339EdgenoMSRC (authoritative)
CVE-2026-50523PowerShell (7.4.0 < 7.4.19.0)noNVD (authoritative)
CVE-2026-69414Microsoft Malware Protection EnginenoNVD (authoritative)
CVE-2026-24301CopilotnoMSRC (authoritative)
CVE-2026-62727n/anoNVD (authoritative)
CVE-2026-62834Azure Data FactoryCritical9.30.29%noNVD (authoritative)
CVE-2026-63509Microsoft FabricnoNVD (authoritative)
CVE-2026-65770Azure Managed Instance for Apache CassandranoNVD (authoritative)
CVE-2026-65816Azure ArcnoNVD (authoritative)
CVE-2026-69400Azure Logic AppsnoNVD (authoritative)
CVE-2026-69555Azure ArcnoNVD (authoritative)
CVE-2026-69836Microsoft EntranoNVD (authoritative)
CVE-2026-69851Microsoft EntranoNVD (authoritative)
CVE-2026-55013n/anoNVD (authoritative)
CVE-2026-66800Azure Data FactorynoNVD (authoritative)
CVE-2026-69419Azure Data Manager for EnergynoNVD (authoritative)
CVE-2026-69519Azure Stack HCInoNVD (authoritative)
CVE-2026-69543Azure Virtual MachinesnoNVD (authoritative)
CVE-2026-69558Microsoft Partner CenternoNVD (authoritative)
CVE-2026-69855Microsoft Copilot in AzurenoNVD (authoritative)
CVE-2026-65801Exchange OnlinenoMSRC (authoritative)
CVE-2026-68789Azure SQL DatabasenoMSRC (authoritative)
CVE-2026-55015Remote HelpnoMSRC (authoritative)
CVE-2026-66309Azure SQL DatabaseCritical9.10.47%noMSRC (authoritative)
CVE-2026-68782Azure SQL DatabasenoMSRC (authoritative)
CVE-2026-69502Azure SQL DatabasenoMSRC (authoritative)
CVE-2019-1068SQL Servernosource (authoritative)
CVE-2026-70331EdgenoMSRC (authoritative)
CVE-2026-58616EdgenoMSRC (authoritative)
CVE-2026-62904EdgenoMSRC (authoritative)
CVE-2026-66323EdgenoMSRC (authoritative)
CVE-2026-66324EdgenoMSRC (authoritative)
CVE-2026-66798EdgenoMSRC (authoritative)
CVE-2026-70341EdgenoMSRC (authoritative)
CVE-2026-72984EdgenoMSRC (authoritative)

CVE-2026-50481

CVE-2026-50481 is a critical vulnerability in Microsoft Azure Active Directory involving the modification of assumed-immutable data (MAID). An authorized attacker can exploit this flaw to escalate privileges within the environment over a network, potentially leading to unauthorized administrative access.

Affected products:

  • Azure Active Directory

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-50481

CVE-2026-50515

CVE-2026-50515 is a critical deserialization of untrusted data vulnerability in Azure Service Bus that permits an authenticated attacker with low privileges to achieve remote code execution. Detection efforts should focus on monitoring anomalous serialized data payloads sent to service bus endpoints and unexpected process execution spawned by the Azure Service Bus service account.

Affected products:

  • Azure Service Bus

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-50515

CVE-2026-56161

CVE-2026-56161 describes an improper access control vulnerability in Microsoft Azure Logic Apps. An authenticated attacker can exploit this vulnerability to disclose sensitive information over a network. The vulnerability carries a CVSS 3.1 base score of 9.6, indicating a critical risk.

Affected products:

  • Azure Logic Apps

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-56161

Related in this roundup: CVE-2026-69400.

CVE-2026-59115

CVE-2026-59115 is a critical path traversal vulnerability in the Microsoft Entra Provisioning Service (SyncFabric). An authorized attacker can leverage this vulnerability by using a specific input string ('.../...//') to elevate their privileges over a network. The vulnerability has a CVSS base score of 9.9, indicating a significant risk to the integrity, confidentiality, and availability of the affected cloud service.

Affected products:

  • Microsoft Entra Provisioning Service

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-59115

CVE-2026-59118

CVE-2026-59118 is an improper authorization vulnerability in Microsoft Power Apps that allows an unauthorized attacker to perform a privilege escalation over a network. The vulnerability carries a CVSS 3.1 base score of 9.3, indicating a critical severity impact on confidentiality and integrity, necessitating restricted access controls within the affected cloud service.

Affected products:

  • Power Apps

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-59118

CVE-2026-62830

A vulnerability in the Azure SRE Agent stemming from missing authorization (CWE-862) allows an already authorized network attacker to perform privilege escalation. The vulnerability is rated critical with a CVSS 3.1 score of 9.9, as it enables full scope impact across confidentiality, integrity, and availability within the cloud environment.

Affected products:

  • Azure SRE Agent

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62830

CVE-2026-62873

The Microsoft 365 Admin Center is vulnerable to an improper verification of cryptographic signature vulnerability (CWE-347). This flaw allows a remote, unauthorized attacker to elevate their privileges over a network, potentially leading to full compromise of confidentiality, integrity, and availability.

Affected products:

  • Microsoft 365 Admin Center

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62873

CVE-2026-62896

Microsoft Teams contains an improper authentication vulnerability that allows an authenticated attacker to perform privilege escalation over a network. This flaw represents a critical security risk due to the potential for unauthorized access elevation within the application environment.

Affected products:

  • Microsoft Teams

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62896

Related in this roundup: CVE-2026-65667, CVE-2026-62918.

CVE-2026-63508

Microsoft Planetary Computer Pro (GeoCatalog) contains a vulnerability due to missing authentication for a critical function. This allows an unauthorized attacker to perform privilege escalation over a network. The vulnerability is classified as critical and has a CVSS base score of 10.0.

Affected products:

  • Microsoft Planetary Computer Pro (GeoCatalog)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-63508

CVE-2026-65667

CVE-2026-65667 is a critical security vulnerability in Microsoft Teams involving missing authorization (CWE-862). This flaw allows a remote, unauthenticated attacker to elevate privileges over a network, potentially leading to unauthorized access to sensitive information and system integrity compromises.

Affected products:

  • Microsoft Teams

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-65667

Related in this roundup: CVE-2026-62896, CVE-2026-62918.

CVE-2026-68823

CVE-2026-68823 involves an exposed dangerous method or function in the Azure Confidential Ledger service, which allows an authorized attacker to achieve remote code execution over a network. The vulnerability is classified as CWE-749 and carries a critical CVSS base score of 9.1.

Affected products:

  • Azure Confidential Ledger

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-68823

CVE-2026-70332

CVE-2026-70332 is a Server-Side Request Forgery (SSRF) vulnerability in Microsoft SharePoint Online. An unauthenticated attacker can exploit this flaw to perform spoofing over a network, potentially leading to unauthorized information disclosure, interaction with internal services, or further lateral movement within the cloud environment.

Affected products:

  • SharePoint Online

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70332

CVE-2026-49163

Application Insights Profiler is vulnerable to a path traversal flaw (CWE-22) that allows an authorized attacker to elevate their privileges over a network. This vulnerability indicates improper limitation of a pathname to a restricted directory.

Affected products:

  • Application Insights Profiler

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-49163

CVE-2026-62836

CVE-2026-62836 identifies a vulnerability in Azure SQL Managed Instance due to improper restriction of communication channels to intended endpoints. This flaw allows an unauthenticated, remote attacker to escalate privileges over a network connection by exploiting the misconfigured communication path.

Affected products:

  • Azure SQL Managed Instance

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62836

CVE-2026-62918

CVE-2026-62918 is a vulnerability in Microsoft Teams involving improper verification of cryptographic signatures. This flaw allows an unauthorized remote attacker to perform spoofing attacks over a network, potentially leading to unauthorized data manipulation or masquerading within the platform.

Affected products:

  • Microsoft Teams

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62918

Related in this roundup: CVE-2026-62896, CVE-2026-65667.

CVE-2026-65668

Microsoft Purview eDiscovery contains an improper access control vulnerability that allows an authenticated attacker to perform a privilege escalation attack over the network. Detection should focus on monitoring unauthorized account role modifications or unexpected administrative actions within the Purview compliance console.

Affected products:

  • Microsoft Purview eDiscovery

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-65668

CVE-2026-68480

CVE-2026-68480 relates to a vulnerability in the x86 Safe-RET implementation regarding interrupt injection, which could allow a local attacker to potentially bypass security protections or escalate privileges. Security updates for affected versions of the Windows operating system address the robustness of the return mechanism against these specific interrupt vectors.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68480

Related in this roundup: CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-64564

CVE-2026-64564 involves a vulnerability in the SCTP (Stream Control Transmission Protocol) implementation within Microsoft Windows. The issue occurs during DEL-IP processing, where the ASCONF (Address Configuration Change Chunk) packet handling incorrectly attempts to free its own transport, potentially leading to a use-after-free or memory management error.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64564

Related in this roundup: CVE-2026-68480, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-64590

CVE-2026-64590 identifies an issue within the dma-buf/udmabuf component where a redundant CPU synchronization triggers a cacheline EEXIST warning. This update addresses the underlying logic to ensure proper synchronization handling.

Affected products:

  • dma-buf/udmabuf

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64590

CVE-2026-54876

CVE-2026-54876 describes a client-side memory leak vulnerability within the OCSP (Online Certificate Status Protocol) response checking mechanism in Microsoft Windows products.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54876

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-44605

CVE-2026-44605 describes a heap-based buffer overflow vulnerability located in the ndb slot table parsing logic within Rpm. This vulnerability could potentially allow for arbitrary code execution or memory corruption when processing malformed slot tables.

Affected products:

  • Rpm

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44605

CVE-2026-64573

A vulnerability identified in the Bluetooth NVM tag length TLV parser leads to an underflow condition. This security update from Microsoft addresses the flaw to prevent potential memory corruption or exploitation within the Bluetooth component.

Affected products:

  • Bluetooth

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64573

CVE-2026-64565

CVE-2026-64565 refers to a heap-based buffer overflow vulnerability located within the ims_pcu_process_data() function of the ims-pcu component, potentially allowing for memory corruption or arbitrary code execution.

Affected products:

  • ims-pcu

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64565

CVE-2026-64578

CVE-2026-64578 identifies a vulnerability in the ksmbd kernel-mode SMB server, where insufficient validation of compound request sizes before reading StructureSize2 can lead to memory safety issues. Detection engineering should focus on monitoring SMB traffic patterns for malformed or oversized requests that could trigger improper bounds handling.

Affected products:

  • ksmbd

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64578

Related in this roundup: CVE-2026-68097, CVE-2026-68130, CVE-2026-68099, CVE-2026-68098.

CVE-2024-21380

CVE-2024-21380 is an information disclosure vulnerability affecting Microsoft Dynamics Business Central and Dynamics NAV. The disclosure indicates an informational update to build numbers provided by Microsoft in the Security Update Guide, with no functional changes described in the provided content.

Affected products:

  • Dynamics Business Central
  • Dynamics NAV

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21380

Related in this roundup: CVE-2026-40375.

CVE-2025-2308

CVE-2025-2308 is a heap-based buffer overflow vulnerability residing in the H5Z__scaleoffset_decompress_one_byte function within the HDF5 scale-offset filter, potentially allowing for arbitrary code execution if a maliciously crafted HDF5 file is processed.

Affected products:

  • HDF5

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-2308

Related in this roundup: CVE-2025-2309.

CVE-2025-2309

CVE-2025-2309 refers to a heap-based buffer overflow vulnerability identified in the HDF5 library specifically within the H5T__bit_copy type conversion logic. The vulnerability could potentially lead to memory corruption or arbitrary code execution if an attacker provides a maliciously crafted HDF5 file to an application utilizing the affected library code for data processing.

Affected products:

  • HDF5

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-2309

Related in this roundup: CVE-2025-2308.

CVE-2026-68097

CVE-2026-68097 identifies a vulnerability in ksmbd where the software fails to properly validate the size of an Access Control Entry (ACE) against the number of Security Identifier (SID) sub-authorities. This vulnerability could potentially lead to memory corruption or other instability issues when processing malicious SMB traffic.

Affected products:

  • ksmbd

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68097

Related in this roundup: CVE-2026-64578, CVE-2026-68130, CVE-2026-68099, CVE-2026-68098.

CVE-2026-68388

CVE-2026-68388 addresses a vulnerability in the SMB client component of the Windows operating system related to the improper handling of overlapping allocated ranges during fallocate operations, which may lead to memory corruption or instability.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68388

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68187

CVE-2026-68187 describes an unsigned loop counter wrap vulnerability within the transfer_args_to_stack() function in Microsoft software, potentially allowing for memory corruption or unstable execution states.

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68187

CVE-2026-68152

CVE-2026-68152 addresses a use-after-free vulnerability within the AMT delayed works component in Microsoft products, which could potentially lead to system instability or arbitrary code execution.

Affected products:

  • AMT

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68152

CVE-2026-68189

CVE-2026-68189 refers to a vulnerability within the Bluetooth hci_sync component in Microsoft Windows. The issue involves a lack of protection during UUID list traversal, which may lead to memory safety issues or instability during Bluetooth stack operations.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68189

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68312

CVE-2026-68312 describes a memory leak vulnerability in the CIFS (Common Internet File System) implementation within the Windows kernel. The issue specifically occurs in the deferred close drain paths when a kmalloc memory allocation fails, leading to a cifsFileInfo object leak, which could potentially be leveraged for denial-of-service conditions.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68312

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68130

CVE-2026-68130 identifies a security vulnerability in the ksmbd component within Microsoft Windows Server. The flaw involves the premature destruction of the previous session before NTLM authentication is fully completed, which could lead to authentication bypass or session handling errors. Security teams should ensure that the provided update is applied to affected server environments to enforce proper session lifecycle management during the authentication handshake.

Affected products:

  • ksmbd

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68130

Related in this roundup: CVE-2026-64578, CVE-2026-68097, CVE-2026-68099, CVE-2026-68098.

CVE-2026-68176

CVE-2026-68176 describes a vulnerability in mmiotrace involving a potential NULL pointer dereferencing issue regarding the hiter->dev pointer. This flaw could lead to a system crash or unstable behavior when handled improperly during tracing operations.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68176

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68145

CVE-2026-68145 concerns an out-of-bounds vulnerability in the iomap component, specifically triggered during bitmap_set operations involving zero-length ranges. This flaw could potentially allow for memory corruption, impacting system stability or security.

Affected products:

  • iomap

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68145

CVE-2026-68318

CVE-2026-68318 is a vulnerability in pds_core involving a use-after-free condition triggered during the removal process of a workqueue. The issue arises due to improper memory management, which could potentially be exploited to cause a system crash or arbitrary code execution.

Affected products:

  • pds_core

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68318

CVE-2026-68118

CVE-2026-68118 describes a vulnerability in the TCP stack implementation where improper handling of challenge ACKs for non-exact RST packets in the SYN-RECEIVED state can be exploited to cause a denial-of-service condition or disrupt network connections.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68118

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68175

CVE-2026-68175 refers to a resource leak vulnerability identified within the mmiotrace trace_pipe close function in Microsoft Windows, which could potentially be leveraged for local denial-of-service conditions or resource exhaustion.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68175

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68328

CVE-2026-68328 identifies a vulnerability within the Windows nfp (Near-Field Proximity) driver related to resource mutex allocation, as reported by the Microsoft Security Response Center.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68328

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68406

CVE-2026-68406 identifies a vulnerability in the wifi cfg80211 subsystem where the PMSR FTM preamble range is improperly validated. This flaw can potentially lead to memory corruption or instability within the wireless driver stack, necessitating a security update to ensure proper bounds checking for wireless frame parameters.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68406

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68317

CVE-2026-68317 refers to a vulnerability in pds_core involving race conditions during auxiliary device addition or deletion. The issue requires patching to ensure stability and prevent potential exploitation via race conditions.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68317

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68099

CVE-2026-68099 is a vulnerability in the ksmbd component within Microsoft Windows, where an integer overflow check in check_add_overflow() fails to correctly restore DACL size, potentially leading to the processing of malformed ACLs. This flaw could be exploited to cause memory corruption or denial of service conditions by submitting specially crafted SMB packets.

Affected products:

  • ksmbd

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68099

Related in this roundup: CVE-2026-64578, CVE-2026-68097, CVE-2026-68130, CVE-2026-68098.

CVE-2026-68354

CVE-2026-68354 refers to a vulnerability within the Windows firewire network driver stack involving improper handling of fragmented datagram reassembly, which may allow for potential exploitation during network packet processing.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68354

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68326

CVE-2026-68326 is a vulnerability within the mwifiex Wi-Fi driver, specifically involving improper bounds checking of uAP association event Information Elements (IEs) against the event buffer. This flaw could potentially allow for memory corruption or other impacts depending on how the driver processes malformed association packets.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68326

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68151

CVE-2026-68151 identifies a vulnerability within the binfmt_elf_fdpic loader, which incorrectly handles multiple PT_INTERP segments in an ELF file. By only honoring the first PT_INTERP, the implementation may lead to inconsistencies in how executable files are parsed and executed, potentially impacting system security and loader integrity.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68151

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68343

CVE-2026-68343 describes a vulnerability in the Microsoft SMB client related to the validation of DFS referral PathConsumed. This flaw potentially allows an attacker to manipulate path validation logic within SMB communications.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68343

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68184

CVE-2026-68184 describes a stack-based out-of-bounds read vulnerability within the CDROMVOLCTRL functionality of the Windows CD-ROM driver. This flaw could potentially be leveraged by an attacker to read sensitive data from the stack, though specific exploitation vectors are not detailed beyond the vulnerability type.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68184

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68124

CVE-2026-68124 identifies a buffer overflow vulnerability within the MCTP serial driver components, triggered by the improper handling of zero-length frames. An attacker could potentially exploit this flaw to cause memory corruption or a system crash.

Affected products:

  • mctp

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68124

CVE-2026-68401

CVE-2026-68401 describes an out-of-bounds write vulnerability within the arm_ffa component of Microsoft firmware, specifically located in the ffa_setup_and_transmit() function, which requires a security update to remediate.

Affected products:

  • firmware

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68401

CVE-2026-68322

CVE-2026-68322 describes a NULL pointer dereference vulnerability within the rds (Reliable Datagram Sockets) component of Microsoft Windows, specifically occurring when IPv6 is disabled. This vulnerability can lead to a system crash, resulting in a denial of service condition.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68322

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68214

CVE-2026-68214 identifies a use-after-free vulnerability located in the rtl2832 driver's remove function (rtl2832_remove) within the Windows kernel. This flaw could potentially be leveraged to trigger system instability or lead to memory corruption, requiring a kernel-level security update to address the lifetime management of the driver object.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68214

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68327

CVE-2026-68327 is a vulnerability identified in the Microsoft wanxl WAN driver component. The vulnerability relates to the handling of hardware reset sequences in relation to Base Address Register (BAR) mapping. Successful exploitation of this issue could potentially lead to undefined system behavior or stability issues within the network driver stack.

Affected products:

  • wanxl

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68327

CVE-2026-68188

CVE-2026-68188 describes a use-after-free (UAF) vulnerability within the RFCOMM protocol implementation of the Bluetooth stack, specifically triggered during the set_termios operation.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68188

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68132

CVE-2026-68132 is a vulnerability addressed by Microsoft that involves a deadlock condition occurring during the emergency thaw process on frozen block devices within the Windows operating system.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68132

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68304

CVE-2026-68304 addresses a call trace warning in the brcmfmac wireless driver related to 802.1X-SHA256 authentication processing. While technical details are limited, the issue involves handling of authentication frames within the Broadcom wireless stack.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68304

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68098

CVE-2026-68098 is a vulnerability in the ksmbd kernel-mode SMB server component within Microsoft Windows. The issue involves improper handling of DACL (Discretionary Access Control List) deduplication during ACE (Access Control Entry) copying operations, which may lead to memory safety issues when processing malformed requests.

Affected products:

  • ksmbd

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68098

Related in this roundup: CVE-2026-64578, CVE-2026-68097, CVE-2026-68130, CVE-2026-68099.

CVE-2026-68348

CVE-2026-68348 involves an issue in the ASoC (ALSA System on Chip) subsystem specifically related to the tas2781 audio amplifier driver, where firmware description string parsing is not properly bounded, potentially leading to memory corruption or related stability issues.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68348

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68195

CVE-2026-68195 describes a vulnerability in the mt76 driver for MediaTek WiFi chipsets, specifically affecting the mt7615 module. The vulnerability involves improper handling of TXRX_NOTIFY events on non-MMIO buses, requiring a patch to drop these notifications to maintain stability and security.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68195

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68419

CVE-2026-68419 is a vulnerability in the Linux kernel's irdma (RDMA) subsystem. The flaw specifically pertains to the rereg_mr function, which fails to properly validate that the memory region being re-registered is a valid memory region, potentially leading to unauthorized memory access or system instability.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68419

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68171

CVE-2026-68171 refers to a vulnerability in the Linux kernel for the arm64 architecture, specifically related to syscall handling. The flaw involves a synchronization issue where the saved x0 register may not correctly reflect updates made by a tracer during a system call, potentially leading to security boundary bypasses or incorrect syscall execution context.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68171

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-64523

CVE-2026-64523 is a vulnerability in the Microsoft net/handshake component involving the handling of long-lived file references during submission processes, which has been identified and addressed by Microsoft via the Security Update Guide.

Affected products:

  • net/handshake

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64523

CVE-2026-64388

CVE-2026-64388 refers to a security update for the Microsoft SMB client component, specifically addressing improper handling of POSIX chown/chgrp operations when using SMB3 POSIX Extensions.

Affected products:

  • SMB Client

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64388

CVE-2025-37938

CVE-2025-37938 refers to a security vulnerability related to the tracing of event formats containing '%*p' sequences. The provided content is a placeholder index for a Microsoft Security Response Center advisory, and specific technical details regarding the vulnerability's impact, affected products, or exploitation vectors are not currently available within the source text.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-37938

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-68207

CVE-2026-68207 involves an error in the Video4Linux2 (v4l2) device registration process within the Linux kernel, specifically related to improper cleanup during probe errors. This flaw could potentially lead to inconsistent system states or kernel-level instability upon initialization failure.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68207

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-50472

A heap-based buffer overflow vulnerability in the Windows LUA File Virtualization (LUAFV) filter driver allows a locally authenticated attacker to escalate privileges to the level of the kernel or system.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50472

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-56174

CVE-2026-56174 describes an elevation of privilege vulnerability in Windows Narrator Braille caused by an untrusted search path. An attacker with local access can exploit this vulnerability to execute code or perform operations with higher privileges than their account typically permits.

Affected products:

  • Windows Narrator

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56174

CVE-2026-58650

CVE-2026-58650 describes an authorization bypass vulnerability in Visual Studio Code where a user-controlled key can be leveraged to bypass security features locally. An unauthorized attacker requires local access to exploit this flaw, which stems from improper handling of authorization keys.

Affected products:

  • Visual Studio Code

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58650

Related in this roundup: CVE-2026-59113, CVE-2026-47285, CVE-2026-69320, CVE-2026-69278, CVE-2026-69306, CVE-2026-70336, CVE-2026-54981.

CVE-2026-65768

Microsoft Teams for Android contains a path traversal vulnerability that allows a remote, unauthorized attacker to execute arbitrary code on the target device via network-based exploitation.

Affected products:

  • Teams

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65768

Related in this roundup: CVE-2026-65767.

CVE-2026-57105

CVE-2026-57105 is a spoofing vulnerability in Microsoft Office SharePoint caused by improper neutralization of input during web page generation. An authenticated attacker can exploit this cross-site scripting vulnerability to conduct spoofing attacks over the network.

Affected products:

  • SharePoint

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57105

Related in this roundup: CVE-2026-70321, CVE-2026-70324, CVE-2026-70306.

CVE-2026-62829

CVE-2026-62829 is a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server that allows an authenticated attacker to perform spoofing attacks over a network by injecting malicious input during web page generation.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62829

Related in this roundup: CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-62827

CVE-2026-62827 is an elevation of privilege vulnerability in Microsoft SharePoint Server caused by improper authentication, allowing an authenticated attacker to elevate their privileges over a network.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62827

Related in this roundup: CVE-2026-62829, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-62837

CVE-2026-62837 describes a relative path traversal vulnerability in Microsoft SharePoint Server that allows an authenticated attacker to perform unauthorized information disclosure over the network.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62837

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-63514

CVE-2026-63514 is a remote code execution vulnerability in Microsoft SharePoint Server caused by improper deserialization of untrusted data. An authorized attacker can exploit this flaw over the network to execute arbitrary code within the context of the application.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63514

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-63512

CVE-2026-63512 is a security vulnerability in Microsoft SharePoint Server that results from incorrect authorization handling. An attacker who has obtained authorized access to the system can exploit this flaw to perform unauthorized tampering with data or configuration over a network, potentially undermining system integrity.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63512

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-63516

Microsoft SharePoint Server contains a vulnerability due to deserialization of untrusted data. An authorized attacker can leverage this flaw to perform spoofing attacks over a network.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63516

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-63520

CVE-2026-63520 is a remote code execution vulnerability in Microsoft SharePoint Server caused by improper input validation. An unauthenticated attacker can exploit this flaw over a network to execute arbitrary code on the affected server.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63520

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-40375

CVE-2026-40375 is an information disclosure vulnerability in Microsoft Dynamics Business Central resulting from a missing authorization check. An authenticated attacker on the network can leverage this flaw to access sensitive information without proper authorization.

Affected products:

  • Dynamics Business Central

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40375

Related in this roundup: CVE-2024-21380.

CVE-2026-54113

CVE-2026-54113 is a denial of service vulnerability in the Windows Kernel due to improper resource allocation limits within the Remote Procedure Call (RPC) implementation. An unauthorized network-based attacker can exploit this flaw to exhaust system resources, leading to a crash or service disruption.

Affected products:

  • Windows Kernel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54113

Related in this roundup: CVE-2026-61930, CVE-2026-62737, CVE-2026-62708, CVE-2026-62749, CVE-2026-65773.

CVE-2026-54984

A heap-based buffer overflow vulnerability in the Windows Imaging Component allows an unauthorized local attacker to achieve remote code execution by processing specially crafted image files.

Affected products:

  • Windows Imaging Component

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54984

Related in this roundup: CVE-2026-62740.

CVE-2026-49179

CVE-2026-49179 describes a command injection vulnerability in Windows Active Directory Domain Services that enables unauthorized network-based remote code execution. Attackers can leverage this flaw to execute arbitrary commands by sending specially crafted inputs to the affected directory service.

Affected products:

  • Active Directory Domain Services

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49179

CVE-2026-58612

CVE-2026-58612 is a server-side request forgery (SSRF) vulnerability in Microsoft PowerShell Core that allows an unauthorized attacker to perform unauthorized network requests to disclose sensitive information.

Affected products:

  • PowerShell Core

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58612

Related in this roundup: CVE-2026-70337.

CVE-2026-59113

CVE-2026-59113 describes a missing authorization vulnerability in Visual Studio Code that allows a remote, unauthenticated attacker to execute arbitrary code via the network.

Affected products:

  • Visual Studio Code

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59113

Related in this roundup: CVE-2026-58650, CVE-2026-47285, CVE-2026-69320, CVE-2026-69278, CVE-2026-69306, CVE-2026-70336, CVE-2026-54981.

CVE-2026-47299

CVE-2026-47299 is an elevation of privilege vulnerability in the Azure Monitor Agent caused by improper neutralization of special elements used in a command (command injection). An authorized attacker can exploit this flaw over a network to elevate their privileges on the targeted system.

Affected products:

  • Azure Monitor Agent

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47299

CVE-2026-47285

CVE-2026-47285 is a command injection vulnerability in Visual Studio Code that permits an unauthorized attacker to disclose sensitive information over the network due to improper neutralization of special command elements.

Affected products:

  • Visual Studio Code

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47285

Related in this roundup: CVE-2026-58650, CVE-2026-59113, CVE-2026-69320, CVE-2026-69278, CVE-2026-69306, CVE-2026-70336, CVE-2026-54981.

CVE-2026-59124

Microsoft High Performance Computing (HPC) Pack is vulnerable to remote code execution due to improper deserialization of untrusted data, allowing an unauthorized attacker to execute arbitrary code over the network.

Affected products:

  • High Performance Computing Pack

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59124

CVE-2026-59127

CVE-2026-59127 describes an elevation of privilege vulnerability in the Windows Installer service caused by an integer overflow or wraparound condition. A local attacker with low-level authorization can exploit this flaw to gain elevated privileges on the affected system.

Affected products:

  • Windows Installer

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59127

Related in this roundup: CVE-2026-61925, CVE-2026-70344, CVE-2026-70345, CVE-2026-70346, CVE-2026-70347, CVE-2026-61938, CVE-2026-62768, CVE-2026-65774.

CVE-2026-59128

CVE-2026-59128 is an out-of-bounds read vulnerability in the Windows Encrypting File System (EFS). An authorized attacker with local access can exploit this flaw to disclose sensitive information, potentially bypassing security controls related to file encryption.

Affected products:

  • Windows Encrypting File System

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59128

CVE-2026-59133

CVE-2026-59133 describes a vulnerability in Microsoft High Performance Computing (HPC) Pack that allows an authenticated attacker to perform a privilege escalation over the network due to the application executing with unnecessary elevated privileges.

Affected products:

  • High Performance Computing (HPC) Pack

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59133

CVE-2026-59132

CVE-2026-59132 describes a denial of service vulnerability in the Windows TCP/IP stack. An unauthenticated attacker could trigger this vulnerability by sending specially crafted packets to a target system, resulting in a system crash or service disruption.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59132

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-59135

CVE-2026-59135 is an information disclosure vulnerability within the Microsoft Windows Search Component. The vulnerability stems from weak authentication mechanisms, which can be exploited by a locally authorized attacker to gain unauthorized access to sensitive information.

Affected products:

  • Windows Search Component

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59135

CVE-2026-59134

CVE-2026-59134 is a heap-based buffer overflow vulnerability within the Microsoft Remote Desktop Client, which permits an unauthorized remote attacker to achieve arbitrary code execution over a network connection.

Affected products:

  • Remote Desktop Client

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59134

Related in this roundup: CVE-2026-61924, CVE-2026-61352, CVE-2026-61363, CVE-2026-61918, CVE-2026-61921, CVE-2026-62824.

CVE-2026-59136

CVE-2026-59136 is an information disclosure vulnerability in Microsoft COM for Windows. It stems from the use of an uninitialized resource, which allows an authorized local attacker to access sensitive information by exploiting the way the component handles memory or resources during execution.

Affected products:

  • COM

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59136

CVE-2026-59137

The Windows Event Logging Service contains a vulnerability involving the use of an uninitialized resource. This flaw allows an authenticated local attacker to perform an information disclosure attack against the service.

Affected products:

  • Windows Event Logging Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59137

Related in this roundup: CVE-2026-61347, CVE-2026-59126.

CVE-2026-59138

CVE-2026-59138 refers to a Denial of Service (DoS) vulnerability within the Microsoft Remote Registry Service, potentially allowing an attacker to disrupt the service functionality.

Affected products:

  • Remote Registry Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59138

Related in this roundup: CVE-2026-61345.

CVE-2026-61345

CVE-2026-61345 is a denial-of-service vulnerability affecting the Microsoft Remote Registry Service. Successful exploitation allows an attacker to cause the service to become unresponsive, disrupting remote registry management capabilities on the affected Windows system.

Affected products:

  • Remote Registry Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61345

Related in this roundup: CVE-2026-59138.

CVE-2026-61346

A use-after-free vulnerability exists in the Windows Graphics Kernel that allows a locally authenticated attacker to escalate privileges. Successful exploitation requires an attacker to have local access and perform specific actions to trigger the use-after-free condition.

Affected products:

  • Windows Graphics Kernel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61346

CVE-2026-61353

A heap-based buffer overflow vulnerability exists in the Windows Telephony Service, allowing an authenticated attacker to perform local privilege escalation. Successful exploitation requires the attacker to have sufficient local access to interact with the service, resulting in elevated system privileges.

Affected products:

  • Windows Telephony Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61353

Related in this roundup: CVE-2026-62723, CVE-2026-62724, CVE-2026-62748, CVE-2026-62729, CVE-2026-59122, CVE-2026-62701, CVE-2026-62725, CVE-2026-62726, CVE-2026-62732, CVE-2026-62734.

CVE-2026-61347

The Windows Event Logging Service contains a buffer over-read vulnerability that can be exploited by an authorized attacker to disclose sensitive information from the system locally.

Affected products:

  • Windows Event Logging Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61347

Related in this roundup: CVE-2026-59137, CVE-2026-59126.

CVE-2026-61361

CVE-2026-61361 is a use-after-free vulnerability within the Windows DHCP Client that allows an authorized attacker to achieve remote code execution on the target system.

Affected products:

  • Windows DHCP Client

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61361

Related in this roundup: CVE-2026-62755, CVE-2026-65785, CVE-2026-62736.

CVE-2026-61348

CVE-2026-61348 is a use-after-free vulnerability within the Windows Ancillary Function Driver for WinSock (afdsys.sys). This vulnerability allows a locally authenticated attacker to gain escalated privileges on the host system, necessitating a patch to prevent exploitation of the driver's memory management.

Affected products:

  • Windows Ancillary Function Driver for WinSock

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61348

Related in this roundup: CVE-2026-68820.

CVE-2026-61356

CVE-2026-61356 describes an elevation of privilege vulnerability in Windows Remote Desktop Services caused by missing authentication for a critical function. An attacker who has already gained local access can exploit this flaw to escalate their privileges within the system.

Affected products:

  • Remote Desktop Services

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61356

Related in this roundup: CVE-2026-61367, CVE-2026-62692, CVE-2026-61365.

CVE-2026-61367

CVE-2026-61367 is a local privilege escalation vulnerability in Microsoft Windows Remote Desktop Services caused by improper authentication handling. An attacker who has already gained authorized access to the system can exploit this flaw to execute code or perform actions with elevated privileges.

Affected products:

  • Remote Desktop Services

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61367

Related in this roundup: CVE-2026-61356, CVE-2026-62692, CVE-2026-61365.

CVE-2026-61923

CVE-2026-61923 describes a heap-based buffer overflow vulnerability within the Windows Display Enhancement Service. This flaw allows a locally authenticated attacker to escalate their privileges to a higher level of authority on the target system.

Affected products:

  • Windows Display Enhancement Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61923

CVE-2026-61366

A double free vulnerability in the Windows Network Connection Broker component allows a locally authenticated attacker to elevate their privileges on the host system.

Affected products:

  • Windows Network Connection Broker

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61366

CVE-2026-61368

CVE-2026-61368 is a heap-based buffer overflow vulnerability in Windows Hyper-V that enables an authorized local attacker to perform an information disclosure attack.

Affected products:

  • Hyper-V

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61368

CVE-2026-61924

CVE-2026-61924 describes an out-of-bounds read vulnerability in the Microsoft Remote Desktop Client, which can be leveraged by a remote unauthorized attacker to disclose sensitive information over a network. Detection efforts should focus on anomalous traffic patterns involving the RDP protocol and monitoring for exploitation attempts targeting the Remote Desktop Client service.

Affected products:

  • Remote Desktop Client

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61924

Related in this roundup: CVE-2026-59134, CVE-2026-61352, CVE-2026-61363, CVE-2026-61918, CVE-2026-61921, CVE-2026-62824.

CVE-2026-61925

CVE-2026-61925 describes a local privilege escalation vulnerability in the Windows Installer service caused by incorrect authorization. An attacker who has already gained local access to a system can exploit this vulnerability to escalate their privileges.

Affected products:

  • Windows Installer

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61925

Related in this roundup: CVE-2026-59127, CVE-2026-70344, CVE-2026-70345, CVE-2026-70346, CVE-2026-70347, CVE-2026-61938, CVE-2026-62768, CVE-2026-65774.

CVE-2026-61927

A use-after-free vulnerability exists in the Windows Bind Filter Driver that allows a locally authenticated attacker to elevate their privileges to a higher level within the system.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61927

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-61928

A vulnerability exists in Windows Hello where sensitive information is stored in cleartext, allowing an attacker with local access to perform tampering operations against the authentication mechanism.

Affected products:

  • Windows Hello

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61928

CVE-2026-61930

CVE-2026-61930 is a heap-based buffer overflow vulnerability in the Windows Kernel that allows an authorized local attacker to elevate their privileges on an affected system.

Affected products:

  • Windows Kernel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61930

Related in this roundup: CVE-2026-54113, CVE-2026-62737, CVE-2026-62708, CVE-2026-62749, CVE-2026-65773.

CVE-2026-61937

An integer overflow or wraparound vulnerability in the Windows HTTP.sys kernel driver allows a locally authenticated attacker to elevate their privileges to a higher integrity level. The vulnerability involves improper handling of arithmetic operations within the HTTP protocol stack.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61937

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62692

CVE-2026-62692 is a heap-based buffer overflow vulnerability in Windows Remote Desktop Services. An authenticated attacker can exploit this flaw to execute code with elevated privileges on the target system.

Affected products:

  • Remote Desktop Services

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62692

Related in this roundup: CVE-2026-61356, CVE-2026-61367, CVE-2026-61365.

CVE-2026-61932

The Windows DWM Core Library is susceptible to a type confusion vulnerability, which can be exploited by an authorized local attacker to achieve privilege escalation.

Affected products:

  • Windows DWM Core Library

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61932

Related in this roundup: CVE-2026-62703, CVE-2026-62894.

CVE-2026-61933

CVE-2026-61933 is an out-of-bounds read vulnerability in the Windows Desktop Window Manager (DWM) Core Library that enables a locally authenticated attacker to perform unauthorized information disclosure.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61933

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-61934

The Windows Bind Filter Driver contains a use-after-free vulnerability that enables a locally authenticated attacker to escalate their privileges. This flaw resides within the kernel-mode driver, allowing for unauthorized privilege escalation on affected Windows systems.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61934

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-61936

A security feature bypass vulnerability exists in the Windows Defender Firewall Service due to missing authorization checks. An attacker with local access can exploit this vulnerability to bypass firewall restrictions, potentially allowing unauthorized network traffic or service interaction.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61936

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-61939

CVE-2026-61939 is a local privilege escalation vulnerability in the Windows Winlogon component caused by a use-after-free flaw. An authenticated attacker can exploit this vulnerability to gain elevated privileges on an affected Windows system.

Affected products:

  • Winlogon

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61939

CVE-2026-62695

CVE-2026-62695 is a local privilege escalation vulnerability resulting from a heap-based buffer overflow in the Windows Storage component. An authenticated attacker can exploit this flaw to gain elevated privileges on the target system.

Affected products:

  • Windows Storage

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62695

Related in this roundup: CVE-2026-61359.

CVE-2026-62688

A heap-based buffer overflow vulnerability in the Windows MIDI Service Module allows an authenticated local attacker to escalate their privileges to a higher level of authority on the host system.

Affected products:

  • Windows MIDI Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62688

CVE-2026-62690

A race condition vulnerability in the Windows Push Notifications service allows an authorized local attacker to achieve privilege escalation due to improper synchronization during concurrent resource access.

Affected products:

  • Windows Push Notifications

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62690

CVE-2026-62693

A race condition vulnerability exists within the Windows MIDI Service Module that allows a locally authenticated attacker to elevate privileges. The flaw arises from improper synchronization when using shared resources during concurrent execution.

Affected products:

  • Windows MIDI Service Module

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62693

CVE-2026-62696

CVE-2026-62696 describes an integer underflow vulnerability in the Windows Program Compatibility Assistant Service that allows an authorized local attacker to achieve privilege escalation by exploiting the arithmetic error during service processing.

Affected products:

  • Windows Program Compatibility Assistant Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62696

CVE-2026-62702

CVE-2026-62702 is a vulnerability within the Windows Graphics Kernel that allows a local attacker to cause a denial of service condition on affected Windows systems.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62702

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62699

The Windows Universal Disk Format File System Driver (UDFS) is vulnerable to a heap-based buffer overflow that can be exploited by an unauthorized attacker to achieve remote code execution via a physical attack vector.

Affected products:

  • Windows Universal Disk Format File System Driver

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62699

CVE-2026-62703

CVE-2026-62703 describes an out-of-bounds read vulnerability in the Windows DWM Core Library. An authorized local attacker can exploit this flaw to disclose sensitive information from the system, potentially aiding in further exploitation phases.

Affected products:

  • Windows DWM Core Library

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62703

Related in this roundup: CVE-2026-61932, CVE-2026-62894.

CVE-2026-62705

CVE-2026-62705 is a race condition vulnerability within the Windows Bind Filter Driver that allows an authorized local attacker to gain elevated system privileges. The flaw stems from improper synchronization when accessing shared resources, which could be exploited to compromise system integrity.

Affected products:

  • Windows Bind Filter Driver

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62705

Related in this roundup: CVE-2026-62722.

CVE-2026-62707

A use-after-free vulnerability exists in the Windows Modern Device Management (MDM) component that can be exploited by an authenticated attacker to perform a local privilege escalation. Successful exploitation requires the attacker to have existing access to the system.

Affected products:

  • Windows Modern Device Management

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62707

CVE-2026-62713

CVE-2026-62713 describes a heap-based buffer overflow vulnerability in the Windows Cloud Files Mini Filter Driver that allows a locally authenticated attacker to gain elevated privileges. Detection strategies should focus on monitoring for unusual process creation or memory manipulation involving the Cloud Files Mini Filter driver, which may indicate exploitation attempts.

Affected products:

  • Windows Cloud Files Mini Filter Driver

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62713

Related in this roundup: CVE-2026-62771.

CVE-2026-62712

CVE-2026-62712 is a heap-based buffer overflow vulnerability in the Win32k component of Windows. An attacker who has already gained local authorization can exploit this vulnerability to execute arbitrary code with elevated privileges on the affected system.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62712

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62718

An integer underflow vulnerability in the Windows DHCP Server allows an unauthorized attacker to disclose sensitive information from the server by sending specially crafted packets over an adjacent network segment.

Affected products:

  • Windows DHCP Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62718

Related in this roundup: CVE-2026-62715, CVE-2026-62716, CVE-2026-62742, CVE-2026-62745, CVE-2026-62812, CVE-2026-62720, CVE-2026-62714, CVE-2026-62761, CVE-2026-62776, CVE-2026-62803, CVE-2026-62807, CVE-2026-62814, CVE-2026-62823.

CVE-2026-62715

CVE-2026-62715 describes an integer underflow vulnerability in the Windows DHCP Server service. This flaw enables an unauthorized attacker on an adjacent network to potentially disclose sensitive information due to improper handling of integer arithmetic during network packet processing.

Affected products:

  • Windows DHCP Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62715

Related in this roundup: CVE-2026-62718, CVE-2026-62716, CVE-2026-62742, CVE-2026-62745, CVE-2026-62812, CVE-2026-62720, CVE-2026-62714, CVE-2026-62761, CVE-2026-62776, CVE-2026-62803, CVE-2026-62807, CVE-2026-62814, CVE-2026-62823.

CVE-2026-62716

CVE-2026-62716 is an information disclosure vulnerability in the Windows DHCP Server component caused by an integer underflow condition. An unauthorized attacker located on an adjacent network can exploit this flaw to read sensitive data.

Affected products:

  • Windows DHCP Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62716

Related in this roundup: CVE-2026-62718, CVE-2026-62715, CVE-2026-62742, CVE-2026-62745, CVE-2026-62812, CVE-2026-62720, CVE-2026-62714, CVE-2026-62761, CVE-2026-62776, CVE-2026-62803, CVE-2026-62807, CVE-2026-62814, CVE-2026-62823.

CVE-2026-62719

CVE-2026-62719 is a heap-based buffer overflow vulnerability in Windows Message Queuing that allows an attacker with authorized access to elevate privileges locally on the target system.

Affected products:

  • Windows Message Queuing

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62719

Related in this roundup: CVE-2026-62717, CVE-2026-65790.

CVE-2026-62722

A heap-based buffer overflow vulnerability in the Windows Bind Filter Driver allows an authenticated attacker to perform local privilege escalation. The vulnerability exists within the driver's handling of memory operations, which can be triggered by a local user to execute code with elevated permissions.

Affected products:

  • Windows Bind Filter Driver

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62722

Related in this roundup: CVE-2026-62705.

CVE-2026-62723

A vulnerability in the Windows Telephony Service allows a local, authenticated attacker to gain elevated privileges through a use-after-free flaw. Successful exploitation enables the attacker to execute code or perform operations with higher permissions than their initial account allows.

Affected products:

  • Windows Telephony Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62723

Related in this roundup: CVE-2026-61353, CVE-2026-62724, CVE-2026-62748, CVE-2026-62729, CVE-2026-59122, CVE-2026-62701, CVE-2026-62725, CVE-2026-62726, CVE-2026-62732, CVE-2026-62734.

CVE-2026-62724

A use-after-free vulnerability in the Windows Telephony Service allows a local, authorized attacker to escalate privileges on a compromised Windows system.

Affected products:

  • Windows Telephony Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62724

Related in this roundup: CVE-2026-61353, CVE-2026-62723, CVE-2026-62748, CVE-2026-62729, CVE-2026-59122, CVE-2026-62701, CVE-2026-62725, CVE-2026-62726, CVE-2026-62732, CVE-2026-62734.

CVE-2026-62748

The Windows Telephony Service contains a race condition vulnerability during concurrent execution involving shared resources. A locally authenticated attacker can exploit this improper synchronization to execute arbitrary code or gain elevated privileges on the target system.

Affected products:

  • Windows Telephony Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62748

Related in this roundup: CVE-2026-61353, CVE-2026-62723, CVE-2026-62724, CVE-2026-62729, CVE-2026-59122, CVE-2026-62701, CVE-2026-62725, CVE-2026-62726, CVE-2026-62732, CVE-2026-62734.

CVE-2026-62729

CVE-2026-62729 describes a local privilege escalation vulnerability in the Windows Telephony Service caused by a race condition due to improper synchronization of shared resources. An authorized attacker can exploit this flaw to execute code with elevated privileges on an affected Windows system.

Affected products:

  • Windows Telephony Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62729

Related in this roundup: CVE-2026-61353, CVE-2026-62723, CVE-2026-62724, CVE-2026-62748, CVE-2026-59122, CVE-2026-62701, CVE-2026-62725, CVE-2026-62726, CVE-2026-62732, CVE-2026-62734.

CVE-2026-62746

A buffer over-read vulnerability exists in the Windows Win32k component that allows an authorized local attacker to perform an information disclosure attack.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62746

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62740

The Windows Imaging Component contains an information disclosure vulnerability stemming from the use of an uninitialized resource. An authorized local attacker can exploit this flaw to read sensitive data, potentially leading to unauthorized information access.

Affected products:

  • Windows Imaging Component

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62740

Related in this roundup: CVE-2026-54984.

CVE-2026-62753

CVE-2026-62753 is a heap-based buffer overflow vulnerability in the Windows HTTP.sys kernel driver that allows an authorized local attacker to perform privilege escalation on affected Windows systems.

Affected products:

  • Windows HTTP.sys

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62753

CVE-2026-62735

CVE-2026-62735 describes a heap-based buffer overflow vulnerability in the Windows HTTP.sys kernel driver. An authenticated attacker can exploit this flaw to execute code with elevated privileges on the local system.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62735

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62737

An untrusted pointer dereference vulnerability exists in the Windows Kernel that can be exploited by an authenticated attacker to elevate their privileges to a higher level of access on the local system.

Affected products:

  • Windows Kernel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62737

Related in this roundup: CVE-2026-54113, CVE-2026-61930, CVE-2026-62708, CVE-2026-62749, CVE-2026-65773.

CVE-2026-62739

CVE-2026-62739 is a heap-based buffer overflow vulnerability in the Windows HTTP.sys driver. An authenticated local attacker can exploit this flaw to execute arbitrary code with elevated privileges, potentially leading to full system compromise.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62739

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62742

CVE-2026-62742 is an information disclosure vulnerability in the Windows DHCP Server caused by an integer underflow (wraparound) issue. An attacker on an adjacent network can exploit this flaw to gain unauthorized access to sensitive information processed by the DHCP service.

Affected products:

  • Windows DHCP Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62742

Related in this roundup: CVE-2026-62718, CVE-2026-62715, CVE-2026-62716, CVE-2026-62745, CVE-2026-62812, CVE-2026-62720, CVE-2026-62714, CVE-2026-62761, CVE-2026-62776, CVE-2026-62803, CVE-2026-62807, CVE-2026-62814, CVE-2026-62823.

CVE-2026-62745

CVE-2026-62745 is an information disclosure vulnerability in the Windows DHCP Server caused by an integer underflow condition. An unauthorized attacker located on an adjacent network can exploit this flaw to read sensitive data processed by the DHCP service.

Affected products:

  • Windows DHCP Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62745

Related in this roundup: CVE-2026-62718, CVE-2026-62715, CVE-2026-62716, CVE-2026-62742, CVE-2026-62812, CVE-2026-62720, CVE-2026-62714, CVE-2026-62761, CVE-2026-62776, CVE-2026-62803, CVE-2026-62807, CVE-2026-62814, CVE-2026-62823.

CVE-2026-62747

CVE-2026-62747 is a heap-based buffer overflow vulnerability within the Windows Device Association Service. An attacker with local authorization can exploit this flaw to execute code with elevated system privileges.

Affected products:

  • Windows Device Association Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62747

Related in this roundup: CVE-2026-62710.

CVE-2026-62750

CVE-2026-62750 is a vulnerability in the Windows HTTP Protocol Stack involving partial string comparison. This flaw allows an unauthorized attacker located on an adjacent network to perform data tampering by exploiting the way the protocol stack processes HTTP requests.

Affected products:

  • Windows HTTP Protocol Stack

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62750

CVE-2026-62754

CVE-2026-62754 is a heap-based buffer overflow vulnerability in the Windows Kerberos component that allows an authorized local attacker to elevate their privileges on an affected system.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62754

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62783

CVE-2026-62783 is a heap-based buffer overflow vulnerability within the Windows Remote Access Connection Manager. An authenticated local attacker can exploit this flaw to execute code with elevated privileges, effectively resulting in local privilege escalation.

Affected products:

  • Windows Remote Access Connection Manager

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62783

Related in this roundup: CVE-2026-62758.

CVE-2026-62755

A stack-based buffer overflow vulnerability exists in the Windows DHCP Client that allows a locally authenticated attacker to escalate their privileges. This vulnerability is classified as a buffer-overflow and involves local exploitation.

Affected products:

  • Windows DHCP Client

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62755

Related in this roundup: CVE-2026-61361, CVE-2026-65785, CVE-2026-62736.

CVE-2026-62758

CVE-2026-62758 is a heap-based buffer overflow vulnerability in the Windows Remote Access Connection Manager that permits an authorized local attacker to elevate their privileges on an affected Windows system.

Affected products:

  • Windows Remote Access Connection Manager

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62758

Related in this roundup: CVE-2026-62783.

CVE-2026-62766

CVE-2026-62766 is a privilege escalation vulnerability in the Windows Kerberos component caused by a double free memory management flaw. An attacker with local authorization can exploit this vulnerability to elevate their privileges on an affected system.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62766

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62773

A use-after-free vulnerability in the Windows Kerberos component allows an authorized local attacker to elevate their privileges to a higher level of access on the affected system.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62773

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62772

CVE-2026-62772 describes a heap-based buffer overflow vulnerability in the Windows Container Isolation FS Filter Driver (unionfs.sys). An authenticated attacker can exploit this flaw to execute code with elevated privileges on the host system, typically within the context of the container management stack.

Affected products:

  • Windows Container Isolation FS Filter Driver

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62772

Related in this roundup: CVE-2026-72971, CVE-2026-62775.

CVE-2026-62774

CVE-2026-62774 describes a use-after-free vulnerability within the Windows Graphics Kernel. This flaw allows an authenticated local attacker to execute arbitrary code with elevated privileges on the affected system.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62774

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62785

CVE-2026-62785 is a heap-based buffer overflow vulnerability in the Windows Lightweight Directory Access Protocol (LDAP) implementation. The vulnerability allows an unauthenticated, remote attacker to execute arbitrary code on the target system by sending a specially crafted request over the network.

Affected products:

  • Windows LDAP

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62785

CVE-2026-62777

CVE-2026-62777 describes an elevation of privilege vulnerability in the Windows License Manager due to missing authentication for a critical function. An attacker who is already authorized on the local system can exploit this flaw to execute code or perform operations with higher privileges than those they currently hold.

Affected products:

  • Windows License Manager

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62777

CVE-2026-62779

A use-after-free vulnerability in the Windows Schannel component allows a locally authenticated attacker to escalate their privileges. This vulnerability requires the attacker to have existing access to the system to exploit the flaw.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62779

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62792

CVE-2026-62792 is a stack-based buffer overflow vulnerability in the Windows TCP/IP stack that enables a remote, unauthorized attacker to achieve remote code execution on affected Windows systems by sending malicious network packets.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62792

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62784

CVE-2026-62784 is a heap-based buffer overflow vulnerability in the Microsoft Local Security Authority Server (lsasrv) that enables an authorized network-based attacker to achieve remote code execution.

Affected products:

  • Local Security Authority Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62784

CVE-2026-62787

CVE-2026-62787 is a use-after-free vulnerability in the Windows DNS Server component that allows an authorized attacker to achieve remote code execution over a network. Detection engineers should monitor for anomalous DNS traffic or exploitation attempts directed at DNS service processes.

Affected products:

  • Windows DNS Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62787

Related in this roundup: CVE-2026-62817, CVE-2026-62820, CVE-2026-62878, CVE-2026-65789, CVE-2026-61920.

CVE-2026-62798

CVE-2026-62798 describes an untrusted pointer dereference vulnerability within the Windows Win32k subsystem. Successful exploitation of this vulnerability allows an authenticated attacker to disclose sensitive information from the local system.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62798

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62795

CVE-2026-62795 is a remote code execution vulnerability in the Windows Lightweight Directory Access Protocol (LDAP) implementation. The vulnerability stems from a use-after-free condition that can be triggered by an unauthorized attacker over a network, potentially allowing arbitrary code execution on the target system.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62795

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62796

CVE-2026-62796 is an out-of-bounds read vulnerability in the Windows NTFS file system that enables an authenticated attacker to perform local information disclosure. Detection engineers should monitor for abnormal activity or errors related to NTFS file system requests that may trigger OOB reads.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62796

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62797

CVE-2026-62797 describes a heap-based buffer overflow vulnerability in the Windows NTFS file system driver. This flaw allows an authenticated local attacker to execute arbitrary code with elevated privileges, effectively performing local privilege escalation.

Affected products:

  • Windows NTFS

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62797

CVE-2026-62812

CVE-2026-62812 is a local privilege escalation vulnerability in the Windows DHCP Server service, stemming from improper link resolution before file access. An attacker with existing local access can exploit this 'link following' flaw to gain elevated system privileges.

Affected products:

  • Windows DHCP Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62812

Related in this roundup: CVE-2026-62718, CVE-2026-62715, CVE-2026-62716, CVE-2026-62742, CVE-2026-62745, CVE-2026-62720, CVE-2026-62714, CVE-2026-62761, CVE-2026-62776, CVE-2026-62803, CVE-2026-62807, CVE-2026-62814, CVE-2026-62823.

CVE-2026-62815

CVE-2026-62815 is a use-after-free vulnerability in Microsoft QUIC that permits an unauthenticated, remote attacker to achieve remote code execution (RCE) by sending specially crafted packets over a network to a vulnerable target.

Affected products:

  • Microsoft QUIC

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62815

Related in this roundup: CVE-2026-62898.

CVE-2026-62816

CVE-2026-62816 is a heap-based buffer overflow vulnerability in the Windows Reliable Multicast Transport Driver (RMCAST). An unauthorized attacker positioned on an adjacent network can leverage this flaw to achieve remote code execution, highlighting a critical weakness in kernel-level network packet handling.

Affected products:

  • Reliable Multicast Transport Driver (RMCAST)

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62816

CVE-2026-62817

CVE-2026-62817 is an out-of-bounds write vulnerability in the Windows DNS Server component that enables an unauthenticated attacker on an adjacent network to execute arbitrary code. The vulnerability stems from improper handling of memory operations within the DNS service, which can be triggered by specially crafted requests.

Affected products:

  • Windows DNS Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62817

Related in this roundup: CVE-2026-62787, CVE-2026-62820, CVE-2026-62878, CVE-2026-65789, CVE-2026-61920.

CVE-2026-62818

CVE-2026-62818 is a remote code execution vulnerability in Windows Active Directory Certificate Services (AD CS) caused by a use-after-free condition. An authorized attacker can exploit this vulnerability over a network to execute arbitrary code on the affected server.

Affected products:

  • Active Directory Certificate Services

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62818

CVE-2026-62819

CVE-2026-62819 is a remote code execution vulnerability in the Windows Routing and Remote Access Service (RRAS). An unauthenticated attacker can exploit this flaw to gain unauthorized access and execute arbitrary code on a vulnerable Windows machine.

Affected products:

  • Routing and Remote Access Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62819

CVE-2026-62820

CVE-2026-62820 is a remote code execution vulnerability in the Windows DNS Server component caused by a race condition during concurrent execution. An unauthenticated attacker can exploit this flaw by sending specifically crafted network requests to the DNS service, potentially allowing for arbitrary code execution on the server.

Affected products:

  • Windows DNS Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62820

Related in this roundup: CVE-2026-62787, CVE-2026-62817, CVE-2026-62878, CVE-2026-65789, CVE-2026-61920.

CVE-2026-62876

CVE-2026-62876 describes an out-of-bounds read vulnerability in the Windows Win32k subsystem that permits a locally authenticated attacker to escalate their privileges to a higher integrity level.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62876

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62877

CVE-2026-62877 is a stack-based buffer overflow vulnerability residing in the Windows Win32K kernel component. This vulnerability allows an authenticated attacker to execute code with elevated privileges, specifically targeting the kernel-mode driver, which facilitates local privilege escalation.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62877

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62878

CVE-2026-62878 describes a stack-based buffer overflow vulnerability in the Windows DNS Server component that enables remote code execution. An unauthenticated attacker can trigger this vulnerability over the network, potentially leading to full system compromise.

Affected products:

  • Windows DNS Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62878

Related in this roundup: CVE-2026-62787, CVE-2026-62817, CVE-2026-62820, CVE-2026-65789, CVE-2026-61920.

CVE-2026-62889

CVE-2026-62889 is a double free vulnerability in the Windows Secure Socket Tunneling Protocol (SSTP) that allows a remote, unauthenticated attacker to achieve remote code execution (RCE) by sending specially crafted packets over the network.

Affected products:

  • Windows Secure Socket Tunneling Protocol

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62889

CVE-2026-62890

CVE-2026-62890 is a heap-based buffer overflow vulnerability in Windows GDI+ that allows an authenticated local attacker to escalate privileges and execute arbitrary code on the affected Windows system.

Affected products:

  • Windows GDI+

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62890

Related in this roundup: CVE-2026-62709, CVE-2026-62822.

CVE-2026-62892

The Capability Access Management Service (camsvc) in Microsoft Windows contains a use-after-free vulnerability that allows an authorized local attacker to achieve privilege escalation.

Affected products:

  • Capability Access Management Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62892

CVE-2026-62893

A use-after-free vulnerability in the Windows Deployment Services TFTP server allows an unauthenticated, remote attacker to execute arbitrary code over the network. Detection should focus on monitoring anomalous TFTP traffic and unexpected process spawns originating from the Windows Deployment Services service.

Affected products:

  • Windows Deployment Services

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62893

CVE-2026-62894

CVE-2026-62894 describes a heap-based buffer overflow vulnerability in the Windows DWM Core Library. An authenticated local attacker can exploit this flaw to achieve elevation of privilege on vulnerable Windows systems.

Affected products:

  • Windows DWM Core Library

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62894

Related in this roundup: CVE-2026-61932, CVE-2026-62703.

CVE-2026-62899

CVE-2026-62899 is a security feature bypass vulnerability in .NET caused by inconsistent interpretation of HTTP requests, enabling HTTP request/response smuggling. An attacker can exploit this over a network to circumvent security controls.

Affected products:

  • .NET

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62899

Related in this roundup: CVE-2026-62900, CVE-2026-62901, CVE-2026-62902, CVE-2026-62909, CVE-2026-58641, CVE-2026-62871, CVE-2026-62886, CVE-2026-62897.

CVE-2026-62900

CVE-2026-62900 is an information disclosure vulnerability in the .NET framework caused by improper sanitization of sensitive data prior to storage or network transfer, potentially allowing unauthorized attackers to access sensitive information.

Affected products:

  • .NET

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62900

Related in this roundup: CVE-2026-62899, CVE-2026-62901, CVE-2026-62902, CVE-2026-62909, CVE-2026-58641, CVE-2026-62871, CVE-2026-62886, CVE-2026-62897.

CVE-2026-62901

A denial of service vulnerability exists in .NET due to an unchecked input in a loop condition, which allows a remote, unauthorized attacker to consume excessive resources and render the service unavailable over a network.

Affected products:

  • .NET

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62901

Related in this roundup: CVE-2026-62899, CVE-2026-62900, CVE-2026-62902, CVE-2026-62909, CVE-2026-58641, CVE-2026-62871, CVE-2026-62886, CVE-2026-62897.

CVE-2026-62902

CVE-2026-62902 describes an information disclosure vulnerability in .NET arising from the inclusion of functionality from an untrusted control sphere. This allows an unauthorized remote attacker to access sensitive information over the network, necessitating an investigation into anomalous network traffic or unauthorized data egress from .NET-based applications.

Affected products:

  • .NET

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62902

Related in this roundup: CVE-2026-62899, CVE-2026-62900, CVE-2026-62901, CVE-2026-62909, CVE-2026-58641, CVE-2026-62871, CVE-2026-62886, CVE-2026-62897.

CVE-2026-62908

CVE-2026-62908 describes a race condition vulnerability within the Windows Backup Engine. This flaw allows an already authorized local attacker to exploit improper synchronization of shared resources, leading to the escalation of privileges on the host system.

Affected products:

  • Windows Backup Engine

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62908

CVE-2026-62909

CVE-2026-62909 is a privilege escalation vulnerability in the .NET framework caused by an uncaught exception, which can be exploited by an authenticated local attacker to gain elevated privileges.

Affected products:

  • .NET

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62909

Related in this roundup: CVE-2026-62899, CVE-2026-62900, CVE-2026-62901, CVE-2026-62902, CVE-2026-58641, CVE-2026-62871, CVE-2026-62886, CVE-2026-62897.

CVE-2026-62910

Microsoft Exchange Server contains an improper control of resource identifiers vulnerability that enables an authenticated attacker to perform a privilege escalation attack over the network.

Affected products:

  • Exchange Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62910

Related in this roundup: CVE-2026-62912, CVE-2026-62913, CVE-2026-62914, CVE-2026-62915, CVE-2026-65813, CVE-2026-62911.

CVE-2026-62912

CVE-2026-62912 is a denial of service vulnerability in Microsoft Exchange Server caused by the insecure deserialization of untrusted data. An authenticated attacker can exploit this flaw over the network to crash the service or render it unavailable.

Affected products:

  • Exchange Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62912

Related in this roundup: CVE-2026-62910, CVE-2026-62913, CVE-2026-62914, CVE-2026-62915, CVE-2026-65813, CVE-2026-62911.

CVE-2026-62913

Microsoft Exchange Server contains a heap-based buffer overflow vulnerability that allows an authenticated attacker to achieve remote code execution via network-based exploitation.

Affected products:

  • Exchange Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62913

Related in this roundup: CVE-2026-62910, CVE-2026-62912, CVE-2026-62914, CVE-2026-62915, CVE-2026-65813, CVE-2026-62911.

CVE-2026-62914

Microsoft Exchange Server is affected by a spoofing vulnerability due to improper neutralization of input, which allows an authorized attacker to perform cross-site scripting (XSS) attacks over a network.

Affected products:

  • Exchange Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62914

Related in this roundup: CVE-2026-62910, CVE-2026-62912, CVE-2026-62913, CVE-2026-62915, CVE-2026-65813, CVE-2026-62911.

CVE-2026-62915

CVE-2026-62915 is a security feature bypass vulnerability in Microsoft Exchange Server resulting from a missing authorization check. An authenticated attacker can exploit this flaw over the network to circumvent specific security controls within the application.

Affected products:

  • Exchange Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62915

Related in this roundup: CVE-2026-62910, CVE-2026-62912, CVE-2026-62913, CVE-2026-62914, CVE-2026-65813, CVE-2026-62911.

CVE-2026-54123

CVE-2026-54123 is an information disclosure vulnerability in Microsoft Defender for Endpoint for macOS, allowing an authorized local attacker to gain unauthorized access to sensitive information.

Affected products:

  • Defender for Endpoint

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54123

CVE-2026-63513

CVE-2026-63513 is a heap-based buffer overflow vulnerability within the Microsoft Office Graphics Component that allows an unauthorized attacker to achieve remote code execution. The vulnerability is triggered when processing malicious content, necessitating monitoring for unexpected process behavior or memory corruption patterns within Office applications.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63513

Related in this roundup: CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-63515

CVE-2026-63515 is an out-of-bounds read vulnerability in Microsoft Office that can be exploited by an unauthorized attacker to achieve remote code execution. Detection engineers should monitor for abnormal process behavior or memory access violations associated with Office applications.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63515

Related in this roundup: CVE-2026-63513, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-63517

CVE-2026-63517 describes an out-of-bounds read vulnerability in the Microsoft Office Graphics Component that allows an unauthorized local attacker to perform information disclosure. The vulnerability is exploited by processing maliciously crafted content in Office applications.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63517

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-63518

CVE-2026-63518 describes a heap-based buffer overflow vulnerability in Microsoft Office Word that enables a remote attacker to execute arbitrary code. The vulnerability is triggered when the application processes a malformed document, potentially allowing an attacker to gain control of the system by enticing a user to open a malicious file.

Affected products:

  • Office Word

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63518

Related in this roundup: CVE-2026-70311, CVE-2026-70319, CVE-2026-63528, CVE-2026-63527, CVE-2026-63531, CVE-2026-64905, CVE-2026-64907, CVE-2026-64915, CVE-2026-64917, CVE-2026-66806, CVE-2026-66810.

CVE-2026-63521

CVE-2026-63521 is an out-of-bounds read vulnerability in Microsoft Office Word that enables an unauthorized local attacker to perform information disclosure.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63521

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-63519

CVE-2026-63519 describes a heap-based buffer overflow vulnerability within the Microsoft Office Graphics Component. An unauthenticated attacker can exploit this flaw to achieve remote code execution by tricking a user into opening a specially crafted document, leading to local code execution under the context of the current user.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63519

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-64922

CVE-2026-64922 describes a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server caused by improper neutralization of user-supplied input during web page generation. An authenticated attacker can exploit this flaw over a network to conduct spoofing attacks, potentially allowing the execution of arbitrary scripts in the victim's browser session.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64922

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-65657

CVE-2026-65657 is a use-after-free vulnerability in Microsoft Office that enables an attacker to achieve remote code execution on a target system. Exploitation requires the victim to interact with a specially crafted file, leading to memory corruption that the attacker can leverage for arbitrary code execution.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65657

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-65656

CVE-2026-65656 describes a command injection vulnerability in Microsoft Office that enables an unauthorized attacker to achieve remote code execution. The vulnerability stems from improper neutralization of special elements used in commands, allowing for arbitrary code execution when a malicious file or element is processed by the application.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65656

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-65658

CVE-2026-65658 is a remote code execution vulnerability in Microsoft SharePoint Server caused by improper deserialization of untrusted data. An authorized attacker can exploit this flaw by sending specially crafted input to the server, leading to arbitrary code execution in the context of the SharePoint application.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65658

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-65661

CVE-2026-65661 is a heap-based buffer overflow vulnerability in Microsoft Office that enables an unauthorized attacker to achieve remote code execution on the local machine.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65661

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-65663

CVE-2026-65663 describes a remote code execution vulnerability in Microsoft SharePoint Server arising from the insecure deserialization of untrusted data. An authorized attacker can leverage this flaw to execute arbitrary code over the network, potentially leading to full system compromise.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65663

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-65660

CVE-2026-65660 is a spoofing vulnerability in Microsoft SharePoint Server caused by improper control of code generation, allowing an authorized attacker to perform spoofing attacks over a network via code injection.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-65664

CVE-2026-65664 is a heap-based buffer overflow vulnerability within the Microsoft Office Graphics Component that permits an unauthorized attacker to achieve remote code execution on the target system.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65664

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-65665

CVE-2026-65665 is a remote code execution vulnerability in Microsoft SharePoint Server caused by improper deserialization of untrusted data. An authorized attacker can exploit this flaw over the network to execute arbitrary code on the affected server.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65665

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-65662

CVE-2026-65662 is an out-of-bounds read vulnerability in the Windows Graphics Device Interface (GDI) component. An authorized, local attacker can exploit this flaw to perform an unauthorized information disclosure, potentially leaking sensitive data from memory.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65662

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-65671

CVE-2026-65671 is a heap-based buffer overflow vulnerability within the Windows Remote Access API that enables an authenticated local attacker to perform privilege escalation on affected Windows systems.

Affected products:

  • Windows Remote Access API

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65671

CVE-2026-65672

CVE-2026-65672 is a heap-based buffer overflow vulnerability in the Windows Remote Access API that allows an authenticated local attacker to elevate their privileges on the host system.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65672

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-65675

CVE-2026-65675 is a security feature bypass vulnerability in the Visual Studio Code CoPilot Chat Extension. An unauthorized attacker can leverage this flaw over a network to circumvent established security controls within the extension's environment.

Affected products:

  • Visual Studio Code CoPilot Chat Extension

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65675

CVE-2026-65678

A use-after-free vulnerability exists in the Windows Win32k subsystem that enables a local, authorized attacker to elevate their privileges to higher levels of access on the system.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65678

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-65785

CVE-2026-65785 is a denial-of-service vulnerability in the Windows DHCP Client service. The vulnerability allows an unauthorized attacker positioned on an adjacent network to trigger uncontrolled resource consumption, leading to a service outage on the affected Windows system.

Affected products:

  • Windows DHCP Client

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65785

Related in this roundup: CVE-2026-61361, CVE-2026-62755, CVE-2026-62736.

CVE-2026-65784

CVE-2026-65784 is an information disclosure vulnerability in the Windows NTFS filesystem driver caused by an out-of-bounds read condition. An authenticated local attacker can leverage this flaw to access sensitive memory contents.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65784

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-65786

CVE-2026-65786 is a heap-based buffer overflow vulnerability in the Windows Desktop Window Manager (DWM) component. An attacker who has already achieved local execution can exploit this flaw to escalate privileges to a higher integrity level on the affected system.

Affected products:

  • Desktop Window Manager

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65786

Related in this roundup: CVE-2026-65787, CVE-2026-65788.

CVE-2026-65789

CVE-2026-65789 describes a use-after-free vulnerability within the Windows DNS Server component. The vulnerability allows an unauthenticated, remote attacker to trigger memory corruption and achieve remote code execution (RCE) by sending specially crafted packets to a vulnerable DNS server.

Affected products:

  • Windows DNS Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65789

Related in this roundup: CVE-2026-62787, CVE-2026-62817, CVE-2026-62820, CVE-2026-62878, CVE-2026-61920.

CVE-2026-65787

CVE-2026-65787 is a heap-based buffer overflow vulnerability in the Desktop Window Manager component of Windows. An authenticated local attacker can leverage this flaw to elevate their privileges on the host system.

Affected products:

  • Desktop Window Manager

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65787

Related in this roundup: CVE-2026-65786, CVE-2026-65788.

CVE-2026-65788

A use-after-free vulnerability in the Windows Desktop Window Manager allows a locally authenticated attacker to gain elevated privileges on the system.

Affected products:

  • Desktop Window Manager

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65788

Related in this roundup: CVE-2026-65786, CVE-2026-65787.

CVE-2026-65807

CVE-2026-65807 is a type confusion vulnerability in Microsoft Excel that allows a remote, unauthorized attacker to achieve remote code execution. The vulnerability is triggered when the application handles incompatible types, potentially leading to arbitrary code execution if a user opens a maliciously crafted file.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65807

Related in this roundup: CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-65811

CVE-2026-65811 describes a remote code execution vulnerability in Microsoft Power BI caused by improper input validation. An authorized attacker can exploit this flaw over the network to execute arbitrary code, requiring security updates to remediate the lack of input sanitization.

Affected products:

  • Power BI

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65811

CVE-2026-65813

CVE-2026-65813 is a server-side request forgery (SSRF) vulnerability in Microsoft Exchange Server that enables an already authorized attacker to perform privilege escalation across a network.

Affected products:

  • Exchange Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65813

Related in this roundup: CVE-2026-62910, CVE-2026-62912, CVE-2026-62913, CVE-2026-62914, CVE-2026-62915, CVE-2026-62911.

CVE-2026-65814

A heap-based buffer overflow vulnerability in the Windows Storage Port Driver allows a local, authorized attacker to achieve privilege escalation by exploiting the vulnerable driver component.

Affected products:

  • Windows Storage Port Driver

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65814

CVE-2026-65815

CVE-2026-65815 is a remote code execution vulnerability in Microsoft Dynamics 365 on-premises installations. The flaw arises from insecure deserialization of untrusted data, which can be exploited by an authenticated attacker over a network to execute arbitrary code on the affected server.

Affected products:

  • Dynamics 365

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65815

Related in this roundup: CVE-2026-66301.

CVE-2026-66799

CVE-2026-66799 is a heap-based buffer overflow vulnerability in the Windows Key Guard component that enables an authorized local attacker to elevate their privileges on the host system.

Affected products:

  • Windows Key Guard

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66799

CVE-2026-68792

CVE-2026-68792 describes a command injection vulnerability within Microsoft Office that enables an authorized local attacker to elevate their privileges. Detection engineers should monitor for unauthorized or suspicious command executions originating from Office application processes.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68792

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-68793

CVE-2026-68793 describes an out-of-bounds read vulnerability in Microsoft Excel that can be leveraged by an unauthorized attacker to achieve remote code execution, typically through the processing of a maliciously crafted file.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68793

Related in this roundup: CVE-2026-65807, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68794

CVE-2026-68794 is a heap-based buffer overflow vulnerability in Microsoft Excel that can be exploited by an unauthorized attacker to achieve remote code execution. The vulnerability is triggered by processing malicious files, allowing for arbitrary code execution in the context of the current user.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68794

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68795

CVE-2026-68795 is a stack-based buffer overflow vulnerability in Microsoft Excel that allows a local, unauthorized attacker to execute arbitrary code. The vulnerability stems from improper memory handling within the application, and exploitation could lead to full code execution under the privileges of the current user.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68795

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68796

A heap-based buffer overflow vulnerability exists in Microsoft Excel that allows an attacker to execute arbitrary code. The vulnerability occurs during the processing of malformed Excel files, potentially leading to remote code execution if a user opens a specially crafted document.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68796

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68800

CVE-2026-68800 is a heap-based buffer overflow vulnerability in Microsoft Excel that allows an unauthorized attacker to execute arbitrary code locally. Detection should focus on monitoring anomalous process spawning or memory access patterns within the Excel application process.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68800

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68802

CVE-2026-68802 is an out-of-bounds read vulnerability in Microsoft Excel that enables a local unauthorized attacker to disclose sensitive information. The vulnerability occurs due to improper memory handling, which could be exploited by an attacker to read data outside the intended memory bounds of the application.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68802

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68807

CVE-2026-68807 is a heap-based buffer overflow vulnerability in Microsoft Excel that allows an unauthorized attacker to achieve remote code execution on the local system.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68807

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68806

CVE-2026-68806 is an out-of-bounds write vulnerability in Microsoft Excel that allows an unauthorized attacker to achieve remote code execution. The vulnerability is triggered when processing specifically crafted files, leading to memory corruption issues.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68806

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68808

CVE-2026-68808 is an out-of-bounds read vulnerability in Microsoft Excel that allows an unauthorized attacker to perform information disclosure on a local system.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68808

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68809

CVE-2026-68809 is an information disclosure vulnerability in Microsoft PowerPoint caused by incomplete cleanup processes, potentially allowing unauthorized local attackers to access sensitive data.

Affected products:

  • PowerPoint

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68809

Related in this roundup: CVE-2026-70312, CVE-2026-70313, CVE-2026-70316, CVE-2026-70325, CVE-2026-70320, CVE-2026-70322.

CVE-2026-68810

CVE-2026-68810 is a remote code execution vulnerability in Microsoft Excel caused by an untrusted pointer dereference. An attacker can exploit this flaw by enticing a user to open a specially crafted malicious file, leading to arbitrary code execution on the host system.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68810

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68811

A type confusion vulnerability exists in Microsoft Excel that allows an unauthorized attacker to achieve remote code execution on the host machine by inducing the application to access a resource with an incompatible type.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68811

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68813

CVE-2026-68813 describes an out-of-bounds read vulnerability in Microsoft Excel that enables a local attacker to perform unauthorized information disclosure. This vulnerability stems from improper memory handling within the application, potentially allowing access to sensitive data processed by the software.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68813

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68815

CVE-2026-68815 is a heap-based buffer overflow vulnerability in Microsoft Excel that allows an unauthorized attacker to achieve remote code execution on the local system.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68815

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68816

A stack-based buffer overflow vulnerability exists in Microsoft Excel that can be exploited by an unauthorized attacker to achieve remote code execution via a specially crafted document file.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68816

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68819

CVE-2026-68819 describes a buffer over-read vulnerability in the Windows Network File System (NFS) component, which can be exploited by an unauthenticated remote attacker to trigger a denial-of-service (DoS) condition on the affected system.

Affected products:

  • Windows Network File System

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68819

CVE-2026-68820

CVE-2026-68820 is a use-after-free vulnerability within the Windows Ancillary Function Driver for WinSock (afdsys.sys). An authenticated local attacker can exploit this flaw to execute arbitrary code in the context of the kernel, resulting in privilege escalation.

Affected products:

  • Windows Ancillary Function Driver for WinSock

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820

Related in this roundup: CVE-2026-61348.

CVE-2026-68821

An elevation of privilege vulnerability exists in Windows Package Manager due to improper privilege management. An authorized local attacker can exploit this flaw to execute code or perform operations with higher privileges than currently permitted on the system.

Affected products:

  • Windows Package Manager

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68821

CVE-2026-69320

CVE-2026-69320 describes an OS command injection vulnerability in Visual Studio Code that permits an unauthorized remote attacker to execute arbitrary code. The flaw stems from improper neutralization of special elements used in system commands, potentially leading to full compromise of the application environment.

Affected products:

  • Visual Studio Code

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69320

Related in this roundup: CVE-2026-58650, CVE-2026-59113, CVE-2026-47285, CVE-2026-69278, CVE-2026-69306, CVE-2026-70336, CVE-2026-54981.

CVE-2026-69278

CVE-2026-69278 is a security feature bypass vulnerability in Visual Studio Code caused by incorrect authorization logic. The vulnerability allows an unauthorized local attacker to bypass existing security controls, potentially facilitating further malicious activities on the host system.

Affected products:

  • Visual Studio Code

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69278

Related in this roundup: CVE-2026-58650, CVE-2026-59113, CVE-2026-47285, CVE-2026-69320, CVE-2026-69306, CVE-2026-70336, CVE-2026-54981.

CVE-2026-69306

CVE-2026-69306 is a security feature bypass vulnerability in Visual Studio Code caused by an insecure failure state. An attacker can exploit this flaw over a network to bypass security restrictions by triggering a failure that defaults to an open access state.

Affected products:

  • Visual Studio Code

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69306

Related in this roundup: CVE-2026-58650, CVE-2026-59113, CVE-2026-47285, CVE-2026-69320, CVE-2026-69278, CVE-2026-70336, CVE-2026-54981.

CVE-2026-70307

A use-after-free vulnerability exists in the Windows Ancillary Function Driver for WinSock (afdsys) that allows a locally authenticated attacker to elevate their privileges to system level.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70307

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-66301

Microsoft Dynamics 365 (on-premises) contains an information disclosure vulnerability that allows an authenticated attacker to gain unauthorized access to sensitive information over a network. The vulnerability exists due to improper exposure of sensitive data.

Affected products:

  • Dynamics 365

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66301

Related in this roundup: CVE-2026-65815.

CVE-2026-70312

CVE-2026-70312 is an information disclosure vulnerability in Microsoft PowerPoint caused by improper input validation. An unauthorized attacker can exploit this flaw to disclose sensitive local information.

Affected products:

  • PowerPoint

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70312

Related in this roundup: CVE-2026-68809, CVE-2026-70313, CVE-2026-70316, CVE-2026-70325, CVE-2026-70320, CVE-2026-70322.

CVE-2026-70311

CVE-2026-70311 describes a use-after-free vulnerability in Microsoft Office Word that enables an unauthorized attacker to achieve remote code execution. The vulnerability allows an attacker to manipulate memory management in the application to execute arbitrary code, necessitating immediate patching of affected Office installations.

Affected products:

  • Office Word

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70311

Related in this roundup: CVE-2026-63518, CVE-2026-70319, CVE-2026-63528, CVE-2026-63527, CVE-2026-63531, CVE-2026-64905, CVE-2026-64907, CVE-2026-64915, CVE-2026-64917, CVE-2026-66806, CVE-2026-66810.

CVE-2026-70313

Microsoft PowerPoint is vulnerable to an information disclosure flaw due to improper input validation, which can be leveraged by an unauthorized attacker to access sensitive local information via a maliciously crafted file.

Affected products:

  • PowerPoint

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70313

Related in this roundup: CVE-2026-68809, CVE-2026-70312, CVE-2026-70316, CVE-2026-70325, CVE-2026-70320, CVE-2026-70322.

CVE-2026-70310

CVE-2026-70310 is an out-of-bounds read vulnerability in Microsoft Word that allows an unauthorized attacker to perform local information disclosure. The vulnerability occurs due to improper memory handling during document processing.

Affected products:

  • Office
  • Word

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70310

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-70316

CVE-2026-70316 is an information disclosure vulnerability in Microsoft PowerPoint caused by improper input validation. An attacker could exploit this flaw to gain unauthorized access to sensitive information stored locally on the system.

Affected products:

  • PowerPoint

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70316

Related in this roundup: CVE-2026-68809, CVE-2026-70312, CVE-2026-70313, CVE-2026-70325, CVE-2026-70320, CVE-2026-70322.

CVE-2026-70315

CVE-2026-70315 is an out-of-bounds read vulnerability in Microsoft Office that enables an unauthorized attacker to perform local information disclosure. The vulnerability is triggered when the application fails to correctly handle memory access, allowing data to be read outside of the intended buffer.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70315

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-70321

CVE-2026-70321 is a remote code execution vulnerability in Microsoft SharePoint caused by the insecure deserialization of untrusted data. An authorized attacker can leverage this flaw to execute arbitrary code over the network, requiring security teams to prioritize patching of SharePoint instances.

Affected products:

  • SharePoint

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70321

Related in this roundup: CVE-2026-57105, CVE-2026-70324, CVE-2026-70306.

CVE-2026-70318

Microsoft Excel contains an information disclosure vulnerability caused by improper input validation. This vulnerability allows an unauthorized local attacker to access sensitive information by exploiting the flaw during the processing of specially crafted files.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70318

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-70314

CVE-2026-70314 describes an information disclosure vulnerability in Microsoft Office caused by improper input validation. An unauthorized attacker can leverage this flaw to access sensitive information locally.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70314

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-70317

CVE-2026-70317 describes an information disclosure vulnerability in Microsoft Office resulting from the use of an uninitialized resource. This flaw allows an unauthorized attacker to access sensitive information locally on an affected system.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70317

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-70325

A vulnerability in Microsoft PowerPoint exists due to improper input validation, allowing an attacker to perform information disclosure locally. Detection engineers should monitor for anomalous file access patterns or suspicious process activity originating from the PowerPoint application.

Affected products:

  • PowerPoint

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70325

Related in this roundup: CVE-2026-68809, CVE-2026-70312, CVE-2026-70313, CVE-2026-70316, CVE-2026-70320, CVE-2026-70322.

CVE-2026-70319

CVE-2026-70319 is an information disclosure vulnerability in Microsoft Office Word caused by improper input validation. The vulnerability allows an unauthorized attacker to potentially gain access to sensitive information stored locally on the user's system through the application's processing of specially crafted files.

Affected products:

  • Office Word

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70319

Related in this roundup: CVE-2026-63518, CVE-2026-70311, CVE-2026-63528, CVE-2026-63527, CVE-2026-63531, CVE-2026-64905, CVE-2026-64907, CVE-2026-64915, CVE-2026-64917, CVE-2026-66806, CVE-2026-66810.

CVE-2026-70320

An information disclosure vulnerability exists in Microsoft PowerPoint due to improper input validation, allowing an attacker to access sensitive local information.

Affected products:

  • PowerPoint

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70320

Related in this roundup: CVE-2026-68809, CVE-2026-70312, CVE-2026-70313, CVE-2026-70316, CVE-2026-70325, CVE-2026-70322.

CVE-2026-70323

CVE-2026-70323 is an information disclosure vulnerability in Microsoft Office resulting from improper input validation. An unauthorized attacker can leverage this flaw to access sensitive information on the local system.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70323

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-70322

CVE-2026-70322 describes an information disclosure vulnerability in Microsoft PowerPoint caused by improper input validation. An unauthorized attacker can exploit this flaw to access sensitive information locally on the host system.

Affected products:

  • PowerPoint

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70322

Related in this roundup: CVE-2026-68809, CVE-2026-70312, CVE-2026-70313, CVE-2026-70316, CVE-2026-70325, CVE-2026-70320.

CVE-2026-70324

An elevation of privilege vulnerability exists in Microsoft SharePoint due to a server-side request forgery (SSRF) flaw. An authorized attacker can exploit this vulnerability over a network to elevate their privileges within the environment.

Affected products:

  • SharePoint

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70324

Related in this roundup: CVE-2026-57105, CVE-2026-70321, CVE-2026-70306.

CVE-2026-70327

CVE-2026-70327 is an out-of-bounds read vulnerability in Microsoft Excel that allows an attacker to perform unauthorized information disclosure. Successful exploitation requires an attacker to leverage the memory access issue to read sensitive data over a network, potentially exposing information processed within the application context.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70327

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-70328

CVE-2026-70328 describes an out-of-bounds read vulnerability in Microsoft Excel that can be exploited by an unauthorized attacker to disclose sensitive information over the network.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70328

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-70329

CVE-2026-70329 is a remote code execution vulnerability in Microsoft Outlook caused by an integer overflow or wraparound condition. An unauthenticated attacker can exploit this flaw by sending a specially crafted message or file to execute arbitrary code on the target system over the network.

Affected products:

  • Outlook

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70329

Related in this roundup: CVE-2026-62882.

CVE-2026-70304

CVE-2026-70304 is a heap-based buffer overflow vulnerability in the Windows DNS component that allows a locally authenticated attacker to escalate their privileges. The vulnerability occurs due to improper memory management, enabling code execution with higher permissions.

Affected products:

  • Windows DNS

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70304

Related in this roundup: CVE-2026-70330, CVE-2026-62769, CVE-2026-62778, CVE-2026-62881, CVE-2026-62883, CVE-2026-65795, CVE-2026-65797, CVE-2026-65799, CVE-2026-65798.

CVE-2026-70330

CVE-2026-70330 is a heap-based buffer overflow vulnerability in the Windows DNS component that enables an already authorized attacker to perform local privilege escalation.

Affected products:

  • Windows DNS

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70330

Related in this roundup: CVE-2026-70304, CVE-2026-62769, CVE-2026-62778, CVE-2026-62881, CVE-2026-62883, CVE-2026-65795, CVE-2026-65797, CVE-2026-65799, CVE-2026-65798.

CVE-2026-70335

CVE-2026-70335 describes an OS command injection vulnerability in GitHub Copilot and Visual Studio Code that allows a local, unauthorized attacker to perform privilege escalation. The vulnerability stems from improper neutralization of special elements used in system commands, enabling arbitrary code execution with higher privileges.

Affected products:

  • GitHub Copilot
  • Visual Studio Code

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70335

CVE-2026-70336

CVE-2026-70336 is a code injection vulnerability in Visual Studio Code that permits an unauthorized remote attacker to achieve arbitrary code execution over a network. The flaw stems from improper control of code generation processes within the application.

Affected products:

  • Visual Studio Code

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70336

Related in this roundup: CVE-2026-58650, CVE-2026-59113, CVE-2026-47285, CVE-2026-69320, CVE-2026-69278, CVE-2026-69306, CVE-2026-54981.

CVE-2026-57104

CVE-2026-57104 is an elevation of privilege vulnerability in Azure Storage Explorer caused by improper neutralization of input, leading to a stored cross-site scripting (XSS) condition that an attacker can exploit over a network.

Affected products:

  • Azure Storage Explorer

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57104

CVE-2026-70340

CVE-2026-70340 is a privilege escalation vulnerability in Microsoft Azure CycleCloud caused by a missing authorization check. This vulnerability allows an already authorized attacker to escalate their privileges within the environment over a network connection.

Affected products:

  • Azure CycleCloud

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70340

Related in this roundup: CVE-2026-65806.

CVE-2026-65806

CVE-2026-65806 is an information disclosure vulnerability in Microsoft Azure CycleCloud resulting from missing authorization checks. An authenticated attacker can exploit this flaw to access sensitive information over a network.

Affected products:

  • Azure CycleCloud

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65806

Related in this roundup: CVE-2026-70340.

CVE-2026-61352

CVE-2026-61352 is a remote code execution vulnerability in the Microsoft Remote Desktop Client caused by a race condition due to improper synchronization when using shared resources. An unauthenticated attacker can exploit this flaw over a network to execute arbitrary code on the victim's machine.

Affected products:

  • Remote Desktop Client

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61352

Related in this roundup: CVE-2026-59134, CVE-2026-61924, CVE-2026-61363, CVE-2026-61918, CVE-2026-61921, CVE-2026-62824.

CVE-2026-65783

A use-after-free vulnerability exists in Windows Autopilot that allows a locally authenticated attacker to elevate their privileges to a higher level of access.

Affected products:

  • Windows Autopilot

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65783

Related in this roundup: CVE-2026-65779, CVE-2026-65780, CVE-2026-65778, CVE-2026-65782, CVE-2026-65781.

CVE-2026-66804

CVE-2026-66804 describes an elevation of privilege vulnerability in the Windows Cross Device Service caused by improper access control. An authorized local attacker can exploit this flaw to gain elevated privileges on the affected system.

Affected products:

  • Windows Cross Device Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66804

CVE-2026-70344

CVE-2026-70344 is a local privilege escalation vulnerability in the Windows Installer component, stemming from a stack-based buffer overflow. An attacker with local access is required to successfully exploit this vulnerability to elevate their privileges on the target system.

Affected products:

  • Windows Installer

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70344

Related in this roundup: CVE-2026-59127, CVE-2026-61925, CVE-2026-70345, CVE-2026-70346, CVE-2026-70347, CVE-2026-61938, CVE-2026-62768, CVE-2026-65774.

CVE-2026-70345

CVE-2026-70345 is a heap-based buffer overflow vulnerability in the Windows Installer service that enables an authenticated local attacker to execute code with elevated privileges, resulting in local privilege escalation.

Affected products:

  • Windows Installer

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70345

Related in this roundup: CVE-2026-59127, CVE-2026-61925, CVE-2026-70344, CVE-2026-70346, CVE-2026-70347, CVE-2026-61938, CVE-2026-62768, CVE-2026-65774.

CVE-2026-70346

CVE-2026-70346 is a stack-based buffer overflow vulnerability within the Windows Installer service that allows an authenticated local attacker to achieve privilege escalation. This vulnerability indicates a flaw in how the service handles input, potentially allowing execution of arbitrary code with elevated system permissions.

Affected products:

  • Windows Installer

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70346

Related in this roundup: CVE-2026-59127, CVE-2026-61925, CVE-2026-70344, CVE-2026-70345, CVE-2026-70347, CVE-2026-61938, CVE-2026-62768, CVE-2026-65774.

CVE-2026-70347

CVE-2026-70347 is a heap-based buffer overflow vulnerability in the Windows Installer service that enables an authorized local attacker to achieve privilege escalation by exploiting the memory corruption flaw.

Affected products:

  • Windows Installer

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70347

Related in this roundup: CVE-2026-59127, CVE-2026-61925, CVE-2026-70344, CVE-2026-70345, CVE-2026-70346, CVE-2026-61938, CVE-2026-62768, CVE-2026-65774.

CVE-2026-70348

CVE-2026-70348 is a denial-of-service vulnerability in Windows Management Services caused by improper link resolution before file access. An authenticated attacker can exploit this local vulnerability to disrupt service availability by manipulating file system links.

Affected products:

  • Windows Management Services

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70348

CVE-2026-70355

Microsoft SharePoint Server contains an improper neutralization of input vulnerability (XSS) that allows an authorized attacker to escalate their privileges over the network.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70355

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-72971

CVE-2026-72971 describes an improper link resolution vulnerability (link following) within the Windows Container Isolation FS Filter Driver (unionfs.sys). An authenticated local attacker can leverage this flaw to perform file tampering, potentially resulting in unauthorized modifications to the file system due to the driver's failure to properly validate file access paths.

Affected products:

  • Windows Container Isolation FS Filter Driver

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72971

Related in this roundup: CVE-2026-62772, CVE-2026-62775.

CVE-2026-42976

A privilege escalation vulnerability exists in the Windows RPC API due to missing authentication for a critical function. An authenticated attacker can exploit this flaw to elevate privileges locally on the affected system.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42976

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-54981

CVE-2026-54981 is a security feature bypass vulnerability in the Visual Studio Code Python extension. The flaw arises from the inclusion of functionality from an untrusted control sphere, which can be exploited by an unauthorized local attacker to bypass security mechanisms implemented within the extension.

Affected products:

  • Visual Studio Code

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54981

Related in this roundup: CVE-2026-58650, CVE-2026-59113, CVE-2026-47285, CVE-2026-69320, CVE-2026-69278, CVE-2026-69306, CVE-2026-70336.

CVE-2026-6726

CVE-2026-6726 is a spoofing vulnerability identified in the Trusted Computing Group's TPM 2.0 reference implementation, resulting from improper object-slot reuse. Microsoft has issued security updates for the Windows operating system to address this flaw.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-6726

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-58641

CVE-2026-58641 is a vulnerability in .NET caused by an integer overflow or wraparound condition. This flaw allows a local, unauthorized attacker to execute code or manipulate system states to achieve elevation of privilege on the host system.

Affected products:

  • .NET

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58641

Related in this roundup: CVE-2026-62899, CVE-2026-62900, CVE-2026-62901, CVE-2026-62902, CVE-2026-62909, CVE-2026-62871, CVE-2026-62886, CVE-2026-62897.

CVE-2026-58651

A heap-based buffer overflow vulnerability in Microsoft Word allows a remote attacker to achieve arbitrary code execution. The vulnerability is triggered when the application processes a specially crafted file, potentially leading to a system compromise if a user opens a malicious document.

Affected products:

  • Word

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58651

CVE-2026-59122

CVE-2026-59122 is a local privilege escalation vulnerability in the Windows Telephony Service caused by a race condition during concurrent execution with shared resources. An authenticated attacker can exploit this synchronization flaw to gain elevated permissions on the host system.

Affected products:

  • Windows Telephony Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59122

Related in this roundup: CVE-2026-61353, CVE-2026-62723, CVE-2026-62724, CVE-2026-62748, CVE-2026-62729, CVE-2026-62701, CVE-2026-62725, CVE-2026-62726, CVE-2026-62732, CVE-2026-62734.

CVE-2026-59125

CVE-2026-59125 is a use-after-free vulnerability within the Windows Virtual Hard Disk (VHD) Miniport Driver. An authorized local attacker can exploit this flaw to execute code or perform operations with elevated privileges on the affected system.

Affected products:

  • Virtual Hard Disk (VHD) Miniport Driver

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59125

CVE-2026-59126

The Windows Event Logging Service contains a race condition vulnerability due to improper synchronization when using shared resources. This vulnerability allows an authenticated attacker to perform local privilege escalation on the affected system.

Affected products:

  • Windows Event Logging Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59126

Related in this roundup: CVE-2026-59137, CVE-2026-61347.

CVE-2026-61349

CVE-2026-61349 is a use-after-free vulnerability in the Windows Work Folder Service that allows a locally authenticated attacker to elevate their privileges to a higher integrity level.

Affected products:

  • Windows Work Folder Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61349

CVE-2026-61363

CVE-2026-61363 is a heap-based buffer overflow vulnerability in the Microsoft Remote Desktop Client. An unauthenticated attacker can exploit this flaw over a network to achieve remote code execution on a target system.

Affected products:

  • Remote Desktop Client

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61363

Related in this roundup: CVE-2026-59134, CVE-2026-61924, CVE-2026-61352, CVE-2026-61918, CVE-2026-61921, CVE-2026-62824.

CVE-2026-61359

A heap-based buffer overflow vulnerability in Windows Storage allows a locally authenticated attacker to elevate their privileges. Successful exploitation requires the attacker to have existing authorization on the system, which they can then leverage to gain higher privileges through this flaw.

Affected products:

  • Windows Storage

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61359

Related in this roundup: CVE-2026-62695.

CVE-2026-61355

CVE-2026-61355 is a heap-based buffer overflow vulnerability within the Windows Sensor Data Service. An authorized local attacker can exploit this flaw to execute code with elevated privileges, potentially gaining administrative control over the affected system.

Affected products:

  • Windows Sensor Data Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61355

CVE-2026-61364

CVE-2026-61364 is a privilege escalation vulnerability in Windows Remote Desktop Services caused by improper authentication handling. An authorized local attacker can exploit this flaw to elevate their privileges on the target system.

Affected products:

  • Windows Remote Desktop Services

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61364

CVE-2026-61365

CVE-2026-61365 is an elevation of privilege vulnerability in Windows Remote Desktop Services caused by missing authentication for a critical function. An attacker who has already achieved local access to the system can exploit this flaw to escalate their privileges.

Affected products:

  • Remote Desktop Services

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61365

Related in this roundup: CVE-2026-61356, CVE-2026-61367, CVE-2026-62692.

CVE-2026-61357

A use-after-free vulnerability in the Application Information Services component allows an authorized local attacker to achieve privilege escalation on the affected system.

Affected products:

  • Application Information Services

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61357

CVE-2026-61358

CVE-2026-61358 is a privilege escalation vulnerability in the Windows Accessibility Infrastructure component, specifically ATBroker.exe. The vulnerability stems from improper link resolution before file access, allowing a local, authorized attacker to exploit the flaw to gain elevated privileges on the affected system.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61358

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-61360

CVE-2026-61360 is an information disclosure vulnerability in the Windows Graphics Device Interface (GDI) component. The flaw arises from an untrusted pointer dereference, which can be exploited by an authorized local attacker to read sensitive memory contents.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61360

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-61920

CVE-2026-61920 is a race condition vulnerability in the Windows DNS Server component that allows an authorized attacker to achieve remote code execution over the network. Detection should focus on monitoring DNS server process behavior and unusual execution patterns originating from network-based requests.

Affected products:

  • Windows DNS Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61920

Related in this roundup: CVE-2026-62787, CVE-2026-62817, CVE-2026-62820, CVE-2026-62878, CVE-2026-65789.

CVE-2026-61926

The Windows USB Driver is vulnerable to a heap-based buffer overflow that can be exploited by an authorized local attacker to achieve privilege escalation.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61926

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-61918

CVE-2026-61918 is an out-of-bounds read vulnerability in the Microsoft Windows Remote Desktop Client. An unauthenticated remote attacker can exploit this flaw to perform unauthorized information disclosure, potentially leading to the leakage of sensitive data residing in the application's memory space.

Affected products:

  • Remote Desktop Client

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61918

Related in this roundup: CVE-2026-59134, CVE-2026-61924, CVE-2026-61352, CVE-2026-61363, CVE-2026-61921, CVE-2026-62824.

CVE-2026-61921

CVE-2026-61921 describes an out-of-bounds read vulnerability in the Windows Remote Desktop Client. An unauthenticated attacker can exploit this flaw to perform unauthorized information disclosure over a network, potentially exposing sensitive data processed by the client.

Affected products:

  • Remote Desktop Client

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61921

Related in this roundup: CVE-2026-59134, CVE-2026-61924, CVE-2026-61352, CVE-2026-61363, CVE-2026-61918, CVE-2026-62824.

CVE-2026-61929

CVE-2026-61929 describes a use-after-free vulnerability within the Windows Kernel. An attacker who has already obtained local access can exploit this flaw to execute code with elevated privileges on the affected Windows system.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61929

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-61938

A use-after-free vulnerability in the Windows Installer service allows a locally authenticated attacker to escalate their privileges to a higher integrity level. The vulnerability exists within the component responsible for handling installer packages, and successful exploitation requires an attacker to already possess local access to the system.

Affected products:

  • Windows Installer

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61938

Related in this roundup: CVE-2026-59127, CVE-2026-61925, CVE-2026-70344, CVE-2026-70345, CVE-2026-70346, CVE-2026-70347, CVE-2026-62768, CVE-2026-65774.

CVE-2026-62698

A numeric truncation vulnerability in the Microsoft Digest Authentication component allows a locally authenticated attacker to escalate privileges. The vulnerability exists due to improper handling of input data within the authentication process.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62698

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62700

A heap-based buffer overflow vulnerability exists in the Windows NTFS file system, which can be exploited by an authenticated attacker to perform a local privilege escalation. Successful exploitation requires the attacker to be logged on to the system and run a specially crafted application.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62700

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62701

CVE-2026-62701 is a privilege escalation vulnerability in the Windows Telephony Service caused by a use-after-free defect. An authorized local attacker can exploit this flaw to gain elevated privileges on the affected system.

Affected products:

  • Windows Telephony Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62701

Related in this roundup: CVE-2026-61353, CVE-2026-62723, CVE-2026-62724, CVE-2026-62748, CVE-2026-62729, CVE-2026-59122, CVE-2026-62725, CVE-2026-62726, CVE-2026-62732, CVE-2026-62734.

CVE-2026-62708

CVE-2026-62708 describes a use-after-free vulnerability in the Windows Kernel that enables an attacker with physical access to the target machine to perform local privilege escalation.

Affected products:

  • Windows Kernel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62708

Related in this roundup: CVE-2026-54113, CVE-2026-61930, CVE-2026-62737, CVE-2026-62749, CVE-2026-65773.

CVE-2026-62709

CVE-2026-62709 is an information disclosure vulnerability in Windows GDI+ caused by the use of an uninitialized resource. An authorized local attacker can exploit this flaw to read sensitive data from the system memory.

Affected products:

  • Windows GDI+

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62709

Related in this roundup: CVE-2026-62890, CVE-2026-62822.

CVE-2026-62710

The Windows Device Association Service contains a heap-based buffer overflow vulnerability that can be exploited by an authorized local attacker to achieve privilege escalation.

Affected products:

  • Windows Device Association Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62710

Related in this roundup: CVE-2026-62747.

CVE-2026-62711

CVE-2026-62711 is a use-after-free vulnerability located in the Windows Win32k kernel component. An attacker with local access to a vulnerable system can exploit this flaw to execute code with elevated privileges, potentially gaining administrative or system-level control.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62711

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62720

CVE-2026-62720 is an information disclosure vulnerability in the Windows DHCP Server caused by an integer underflow. An unauthenticated attacker on an adjacent network can exploit this flaw to read sensitive data from server memory.

Affected products:

  • Windows DHCP Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62720

Related in this roundup: CVE-2026-62718, CVE-2026-62715, CVE-2026-62716, CVE-2026-62742, CVE-2026-62745, CVE-2026-62812, CVE-2026-62714, CVE-2026-62761, CVE-2026-62776, CVE-2026-62803, CVE-2026-62807, CVE-2026-62814, CVE-2026-62823.

CVE-2026-62714

An integer underflow vulnerability in the Windows DHCP Server component allows a remote, unauthenticated attacker on an adjacent network to disclose sensitive memory information by sending specially crafted packets.

Affected products:

  • Windows DHCP Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62714

Related in this roundup: CVE-2026-62718, CVE-2026-62715, CVE-2026-62716, CVE-2026-62742, CVE-2026-62745, CVE-2026-62812, CVE-2026-62720, CVE-2026-62761, CVE-2026-62776, CVE-2026-62803, CVE-2026-62807, CVE-2026-62814, CVE-2026-62823.

CVE-2026-62717

CVE-2026-62717 is a heap-based buffer overflow vulnerability in the Windows Message Queuing component, which can be exploited by an authorized local attacker to elevate their privileges on an affected system.

Affected products:

  • Windows Message Queuing

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62717

Related in this roundup: CVE-2026-62719, CVE-2026-65790.

CVE-2026-62721

CVE-2026-62721 is a local privilege escalation vulnerability in the Windows User-Mode Power Service (UMPS). The flaw stems from insufficient granularity in access control, which allows an attacker who already has authorized access to the system to exploit the service and elevate their privileges to a higher level of authority.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62721

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62725

A use-after-free vulnerability in the Windows Telephony Service allows a local, authorized attacker to elevate their privileges on an affected system.

Affected products:

  • Windows Telephony Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62725

Related in this roundup: CVE-2026-61353, CVE-2026-62723, CVE-2026-62724, CVE-2026-62748, CVE-2026-62729, CVE-2026-59122, CVE-2026-62701, CVE-2026-62726, CVE-2026-62732, CVE-2026-62734.

CVE-2026-62726

CVE-2026-62726 describes a use-after-free vulnerability within the Windows Telephony Service that can be exploited by an authorized local attacker to gain elevated privileges on a Windows system.

Affected products:

  • Windows Telephony Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62726

Related in this roundup: CVE-2026-61353, CVE-2026-62723, CVE-2026-62724, CVE-2026-62748, CVE-2026-62729, CVE-2026-59122, CVE-2026-62701, CVE-2026-62725, CVE-2026-62732, CVE-2026-62734.

CVE-2026-62728

The Windows Common Log File System (CLFS) driver contains a time-of-check time-of-use (TOCTOU) race condition vulnerability. An attacker with local access and authorization can exploit this flaw to execute code or manipulate system processes with elevated privileges, bypassing standard security restrictions.

Affected products:

  • Windows Common Log File System Driver

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62728

CVE-2026-62733

CVE-2026-62733 is a local privilege escalation vulnerability residing in the Windows Win32k subsystem. The vulnerability is triggered by an out-of-bounds read condition, which an authenticated attacker can leverage to gain elevated system privileges.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62733

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62743

CVE-2026-62743 describes an out-of-bounds read vulnerability within the Windows Win32k subsystem. The flaw allows an authenticated local attacker to bypass memory protections and disclose sensitive information from the kernel space.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62743

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62730

CVE-2026-62730 describes a buffer over-read vulnerability within the Windows Wired AutoConfig Service. The vulnerability allows an authorized local attacker to potentially disclose sensitive information from the system by leveraging the improper memory handling in the service.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62730

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62732

CVE-2026-62732 is a heap-based buffer overflow vulnerability in the Windows Telephony Service that can be exploited by an authorized local attacker to achieve privilege escalation.

Affected products:

  • Windows Telephony Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62732

Related in this roundup: CVE-2026-61353, CVE-2026-62723, CVE-2026-62724, CVE-2026-62748, CVE-2026-62729, CVE-2026-59122, CVE-2026-62701, CVE-2026-62725, CVE-2026-62726, CVE-2026-62734.

CVE-2026-62734

CVE-2026-62734 describes a local privilege escalation vulnerability in the Windows Telephony Service caused by a race condition during concurrent execution with shared resources. An authorized attacker can exploit this synchronization flaw to execute code with elevated permissions on the target Windows system.

Affected products:

  • Windows Telephony Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62734

Related in this roundup: CVE-2026-61353, CVE-2026-62723, CVE-2026-62724, CVE-2026-62748, CVE-2026-62729, CVE-2026-59122, CVE-2026-62701, CVE-2026-62725, CVE-2026-62726, CVE-2026-62732.

CVE-2026-62736

CVE-2026-62736 is a heap-based buffer overflow vulnerability in the Windows DHCP Client that allows a local, authorized attacker to elevate their privileges on the host system.

Affected products:

  • Windows DHCP Client

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62736

Related in this roundup: CVE-2026-61361, CVE-2026-62755, CVE-2026-65785.

CVE-2026-62757

CVE-2026-62757 describes a security feature bypass vulnerability in the Windows Schannel component due to improper cryptographic signature verification. An unauthorized attacker can exploit this flaw over a network to bypass security controls associated with TLS/SSL connections handled by Schannel.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62757

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62741

An integer underflow vulnerability in the Windows HTTP.sys kernel driver allows an authorized local attacker to perform a privilege escalation attack. The vulnerability arises from improper handling of integer arithmetic during system calls, potentially leading to unauthorized system-level operations.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62741

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62749

CVE-2026-62749 is a use-after-free vulnerability within the Windows Kernel that enables a local, authenticated attacker to escalate their privileges to a higher level. Successful exploitation requires an attacker to already have local access to the target system.

Affected products:

  • Windows Kernel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62749

Related in this roundup: CVE-2026-54113, CVE-2026-61930, CVE-2026-62737, CVE-2026-62708, CVE-2026-65773.

CVE-2026-62751

CVE-2026-62751 describes an elevation of privilege vulnerability in the Windows Projected File System caused by an integer overflow or wraparound condition. A local, authorized attacker could exploit this vulnerability to escalate their privilege level on the affected system.

Affected products:

  • Windows Projected File System

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62751

CVE-2026-62752

CVE-2026-62752 is a heap-based buffer overflow vulnerability within the Windows Kerberos implementation that enables an already authenticated local attacker to escalate their privileges. Detection should focus on monitoring for abnormal local system processes or unauthorized changes to user permission structures.

Affected products:

  • Windows Kerberos

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62752

CVE-2026-62769

CVE-2026-62769 is a local privilege escalation vulnerability in the Windows DNS service caused by a numeric truncation error. An authorized attacker can exploit this flaw to elevate their privileges on an affected system.

Affected products:

  • Windows DNS

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62769

Related in this roundup: CVE-2026-70304, CVE-2026-70330, CVE-2026-62778, CVE-2026-62881, CVE-2026-62883, CVE-2026-65795, CVE-2026-65797, CVE-2026-65799, CVE-2026-65798.

CVE-2026-62771

CVE-2026-62771 is a heap-based buffer overflow vulnerability within the Windows Cloud Files Mini Filter Driver. An authenticated local attacker can leverage this flaw to elevate their privileges on an affected Windows system.

Affected products:

  • Windows Cloud Files Mini Filter Driver

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62771

Related in this roundup: CVE-2026-62713.

CVE-2026-62761

CVE-2026-62761 is a privilege escalation vulnerability in the Windows DHCP Server caused by improper link resolution before file access (link following). An authorized local attacker can exploit this flaw to elevate their privileges on the target system.

Affected products:

  • Windows DHCP Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62761

Related in this roundup: CVE-2026-62718, CVE-2026-62715, CVE-2026-62716, CVE-2026-62742, CVE-2026-62745, CVE-2026-62812, CVE-2026-62720, CVE-2026-62714, CVE-2026-62776, CVE-2026-62803, CVE-2026-62807, CVE-2026-62814, CVE-2026-62823.

CVE-2026-62768

CVE-2026-62768 is a stack-based buffer overflow vulnerability in the Windows Installer service that enables an authenticated attacker to perform a local privilege escalation. Security teams should monitor for anomalous system calls or process execution originating from the Windows Installer service that indicate memory corruption or unexpected privilege transitions.

Affected products:

  • Windows Installer

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62768

Related in this roundup: CVE-2026-59127, CVE-2026-61925, CVE-2026-70344, CVE-2026-70345, CVE-2026-70346, CVE-2026-70347, CVE-2026-61938, CVE-2026-65774.

CVE-2026-62770

CVE-2026-62770 is a heap-based buffer overflow vulnerability within the Windows Shell component. An attacker with local authorization can exploit this flaw to execute code with elevated system privileges.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62770

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62775

The Windows Container Isolation FS Filter Driver (unionfs.sys) contains an information disclosure vulnerability stemming from incorrect authorization. A locally authenticated attacker could exploit this flaw to read sensitive data.

Affected products:

  • Windows Container Isolation FS Filter Driver

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62775

Related in this roundup: CVE-2026-62772, CVE-2026-72971.

CVE-2026-62799

CVE-2026-62799 describes a heap-based buffer overflow vulnerability in the Windows SMB Client that allows an authorized local attacker to elevate their privileges. The vulnerability facilitates unauthorized privilege escalation within the Windows operating system environment.

Affected products:

  • Windows SMB Client

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62799

Related in this roundup: CVE-2026-62782.

CVE-2026-62776

CVE-2026-62776 describes a privilege escalation vulnerability in the Windows DHCP Server service caused by improper link resolution before file access. An authorized local attacker can exploit this 'link following' vulnerability to gain elevated privileges on the affected host.

Affected products:

  • Windows DHCP Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62776

Related in this roundup: CVE-2026-62718, CVE-2026-62715, CVE-2026-62716, CVE-2026-62742, CVE-2026-62745, CVE-2026-62812, CVE-2026-62720, CVE-2026-62714, CVE-2026-62761, CVE-2026-62803, CVE-2026-62807, CVE-2026-62814, CVE-2026-62823.

CVE-2026-62778

CVE-2026-62778 is a use-after-free vulnerability within the Windows DNS component that enables a remote, unauthorized attacker to perform privilege escalation on affected systems.

Affected products:

  • Windows DNS

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62778

Related in this roundup: CVE-2026-70304, CVE-2026-70330, CVE-2026-62769, CVE-2026-62881, CVE-2026-62883, CVE-2026-65795, CVE-2026-65797, CVE-2026-65799, CVE-2026-65798.

CVE-2026-62780

CVE-2026-62780 is a use-after-free vulnerability in the Windows Kernel that can be exploited by a locally authenticated attacker to escalate privileges. Detection engineering should focus on monitoring for anomalous kernel-mode memory operations or unexpected attempts to modify security tokens and process privileges.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62780

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62782

CVE-2026-62782 is an out-of-bounds read vulnerability in the Windows SMB Client that enables an unauthenticated attacker to perform information disclosure over a network. Detection engineers should monitor for anomalous SMB traffic patterns or unusual requests originating from untrusted network segments directed at SMB-enabled Windows hosts.

Affected products:

  • Windows SMB Client

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62782

Related in this roundup: CVE-2026-62799.

CVE-2026-62781

A heap-based buffer overflow vulnerability in the RPC Runtime Library allows a remote, unauthorized attacker to achieve remote code execution. The vulnerability is triggered over the network, making it a critical risk for systems utilizing RPC services.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62781

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62800

CVE-2026-62800 describes a heap-based buffer overflow vulnerability in the Windows SMBv3 Server component. An authenticated attacker on the local network could trigger this vulnerability to achieve remote code execution, potentially leading to full system compromise.

Affected products:

  • Windows SMB Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62800

Related in this roundup: CVE-2026-62790.

CVE-2026-62786

CVE-2026-62786 is an out-of-bounds read vulnerability in the Windows Win32k subsystem. An authorized local attacker can exploit this vulnerability to disclose sensitive information from the system memory.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62786

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62788

CVE-2026-62788 is a use-after-free vulnerability within the Windows Kernel that allows a locally authenticated attacker to elevate their privileges to a higher level, potentially gaining system-level access.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62788

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62790

CVE-2026-62790 is a heap-based buffer overflow vulnerability residing in the Windows SMBv3 Server component. An authenticated attacker can exploit this flaw to achieve remote code execution by sending specifically crafted packets to the targeted SMB service over the network.

Affected products:

  • Windows SMB Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62790

Related in this roundup: CVE-2026-62800.

CVE-2026-62793

CVE-2026-62793 describes a buffer over-read vulnerability within the Windows NTFS file system driver. An authorized local attacker can exploit this flaw to perform unauthorized memory reads, leading to the disclosure of sensitive information.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62793

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62803

CVE-2026-62803 is a local privilege escalation vulnerability in the Windows DHCP Server service. The issue stems from improper link resolution before file access, which allows an attacker with existing authorized access to escalate their privileges on the host system.

Affected products:

  • Windows DHCP Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62803

Related in this roundup: CVE-2026-62718, CVE-2026-62715, CVE-2026-62716, CVE-2026-62742, CVE-2026-62745, CVE-2026-62812, CVE-2026-62720, CVE-2026-62714, CVE-2026-62761, CVE-2026-62776, CVE-2026-62807, CVE-2026-62814, CVE-2026-62823.

CVE-2026-62807

CVE-2026-62807 describes a local privilege escalation vulnerability in the Windows DHCP Server service caused by improper link resolution before file access (link following). An attacker with existing authorized access can exploit this flaw to execute operations with higher privileges on the host system.

Affected products:

  • Windows DHCP Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62807

Related in this roundup: CVE-2026-62718, CVE-2026-62715, CVE-2026-62716, CVE-2026-62742, CVE-2026-62745, CVE-2026-62812, CVE-2026-62720, CVE-2026-62714, CVE-2026-62761, CVE-2026-62776, CVE-2026-62803, CVE-2026-62814, CVE-2026-62823.

CVE-2026-62811

A heap-based buffer overflow vulnerability in the Windows HTTP.sys driver allows a locally authenticated attacker to elevate their privileges to a higher integrity level. The vulnerability involves improper memory management when processing requests, which can be exploited to achieve unauthorized privilege escalation.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62811

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62814

CVE-2026-62814 is an information disclosure vulnerability in the Windows DHCP Server caused by an integer underflow flaw. The vulnerability allows an unauthorized attacker on an adjacent network to read sensitive data, which could facilitate further reconnaissance or exploitation.

Affected products:

  • Windows DHCP Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62814

Related in this roundup: CVE-2026-62718, CVE-2026-62715, CVE-2026-62716, CVE-2026-62742, CVE-2026-62745, CVE-2026-62812, CVE-2026-62720, CVE-2026-62714, CVE-2026-62761, CVE-2026-62776, CVE-2026-62803, CVE-2026-62807, CVE-2026-62823.

CVE-2026-62823

A heap-based buffer overflow vulnerability in the Windows DHCP Server component allows an unauthorized, adjacent attacker to achieve remote code execution. The vulnerability is triggered during the processing of network packets, posing a risk to Windows environments running the DHCP server role.

Affected products:

  • Windows DHCP Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62823

Related in this roundup: CVE-2026-62718, CVE-2026-62715, CVE-2026-62716, CVE-2026-62742, CVE-2026-62745, CVE-2026-62812, CVE-2026-62720, CVE-2026-62714, CVE-2026-62761, CVE-2026-62776, CVE-2026-62803, CVE-2026-62807, CVE-2026-62814.

CVE-2026-62824

CVE-2026-62824 is a stack-based buffer overflow vulnerability in the Microsoft Remote Desktop Client, allowing an unauthorized remote attacker to execute arbitrary code over the network. Detection should focus on monitoring for abnormal process behavior or crashes within the RDP client application.

Affected products:

  • Remote Desktop Client

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62824

Related in this roundup: CVE-2026-59134, CVE-2026-61924, CVE-2026-61352, CVE-2026-61363, CVE-2026-61918, CVE-2026-61921.

CVE-2026-62822

An integer overflow or wraparound vulnerability in Windows GDI+ enables a remote, unauthorized attacker to achieve arbitrary code execution via network-based vectors. This vulnerability represents a significant risk for remote system compromise and requires patching of affected Windows components.

Affected products:

  • Windows GDI+

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62822

Related in this roundup: CVE-2026-62890, CVE-2026-62709.

CVE-2026-62832

CVE-2026-62832 is a privilege escalation vulnerability in the Windows User Profile Service caused by improper link resolution before file access. An attacker with existing local access can exploit this flaw to elevate their privileges on the system.

Affected products:

  • Windows User Profile Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62832

CVE-2026-62871

CVE-2026-62871 describes an out-of-bounds write vulnerability within the .NET framework that can be leveraged by a local, unauthorized attacker to achieve elevation of privilege and execute arbitrary code.

Affected products:

  • .NET

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62871

Related in this roundup: CVE-2026-62899, CVE-2026-62900, CVE-2026-62901, CVE-2026-62902, CVE-2026-62909, CVE-2026-58641, CVE-2026-62886, CVE-2026-62897.

CVE-2026-62880

A vulnerability exists in the Windows NTFS file system where an out-of-bounds read allows an authenticated local attacker to escalate their privileges on the target system.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62880

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62881

CVE-2026-62881 is an elevation of privilege vulnerability in Windows DNS resulting from a numeric truncation error. An attacker with local authorization can exploit this flaw to escalate privileges on the target system.

Affected products:

  • Windows DNS

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62881

Related in this roundup: CVE-2026-70304, CVE-2026-70330, CVE-2026-62769, CVE-2026-62778, CVE-2026-62883, CVE-2026-65795, CVE-2026-65797, CVE-2026-65799, CVE-2026-65798.

CVE-2026-62883

CVE-2026-62883 is a local privilege escalation vulnerability in the Windows DNS component caused by a numeric truncation error. An authorized attacker can exploit this flaw to elevate their privileges on the affected system.

Affected products:

  • Windows DNS

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62883

Related in this roundup: CVE-2026-70304, CVE-2026-70330, CVE-2026-62769, CVE-2026-62778, CVE-2026-62881, CVE-2026-65795, CVE-2026-65797, CVE-2026-65799, CVE-2026-65798.

CVE-2026-62885

A heap-based buffer overflow vulnerability in the Windows Win32k subsystem allows an authorized local attacker to elevate their privileges to a higher level of access.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62885

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62886

CVE-2026-62886 is an elevation of privilege vulnerability in .NET caused by an integer overflow or wraparound. This vulnerability allows an unauthorized local attacker to escalate their privileges within the context of the .NET runtime.

Affected products:

  • .NET

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62886

Related in this roundup: CVE-2026-62899, CVE-2026-62900, CVE-2026-62901, CVE-2026-62902, CVE-2026-62909, CVE-2026-58641, CVE-2026-62871, CVE-2026-62897.

CVE-2026-62887

CVE-2026-62887 is an out-of-bounds read vulnerability in the Windows NTFS driver that allows a locally authenticated attacker to perform an information disclosure attack by reading sensitive data from memory.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62887

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62888

CVE-2026-62888 is a local privilege escalation vulnerability in the Windows Desktop Window Manager (DWM) Core Library caused by a use-after-free flaw. An authenticated attacker can exploit this vulnerability to gain higher privileges on the target system.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62888

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-62911

CVE-2026-62911 describes an elevation of privilege vulnerability in Microsoft Exchange Server stemming from an authentication bypass via a capture-replay mechanism. An attacker with authorized network access can exploit this flaw to perform unauthorized actions with elevated privileges on the target server.

Affected products:

  • Exchange Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911

Related in this roundup: CVE-2026-62910, CVE-2026-62912, CVE-2026-62913, CVE-2026-62914, CVE-2026-62915, CVE-2026-65813.

CVE-2026-62842

CVE-2026-62842 describes an out-of-bounds read vulnerability within the Microsoft Office Graphics Component. An attacker could exploit this flaw to perform unauthorized information disclosure on a local system.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62842

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-63524

CVE-2026-63524 is an out-of-bounds read vulnerability in Microsoft Office that allows a local, unauthorized attacker to perform information disclosure.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63524

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-63525

Microsoft Office Word contains a numeric truncation vulnerability that can be exploited by an unauthorized attacker to achieve remote code execution. The vulnerability stems from an error in memory handling, allowing for code execution upon opening a specially crafted malicious file.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63525

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-63526

A stack-based buffer overflow vulnerability in the Microsoft Office Graphics Component allows an unauthorized attacker to achieve remote code execution. Successful exploitation requires an attacker to convince a user to open a specially crafted malicious file.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63526

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-63528

CVE-2026-63528 is an out-of-bounds read vulnerability in Microsoft Office Word that enables an attacker to perform unauthorized local information disclosure.

Affected products:

  • Office Word

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63528

Related in this roundup: CVE-2026-63518, CVE-2026-70311, CVE-2026-70319, CVE-2026-63527, CVE-2026-63531, CVE-2026-64905, CVE-2026-64907, CVE-2026-64915, CVE-2026-64917, CVE-2026-66806, CVE-2026-66810.

CVE-2026-63527

CVE-2026-63527 is a stack-based buffer overflow vulnerability in Microsoft Office Word that allows an unauthorized attacker to execute arbitrary code locally. Detection should focus on monitoring for abnormal behavior or unexpected child processes spawned by the winword.exe process.

Affected products:

  • Office Word

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63527

Related in this roundup: CVE-2026-63518, CVE-2026-70311, CVE-2026-70319, CVE-2026-63528, CVE-2026-63531, CVE-2026-64905, CVE-2026-64907, CVE-2026-64915, CVE-2026-64917, CVE-2026-66806, CVE-2026-66810.

CVE-2026-63529

CVE-2026-63529 describes an out-of-bounds read vulnerability in Microsoft Office that enables an attacker to perform local information disclosure. The vulnerability allows unauthorized access to sensitive data due to improper memory handling during read operations.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63529

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-63530

CVE-2026-63530 describes an out-of-bounds read vulnerability in Microsoft Office Word that enables an unauthorized local attacker to perform information disclosure. Detection should focus on anomalous file access patterns or memory access violations within the Word process.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63530

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-63531

CVE-2026-63531 is an out-of-bounds read vulnerability in Microsoft Office Word that enables an unauthorized attacker to perform local information disclosure. The vulnerability allows the attacker to read memory contents beyond the intended boundaries of the application.

Affected products:

  • Office Word

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63531

Related in this roundup: CVE-2026-63518, CVE-2026-70311, CVE-2026-70319, CVE-2026-63528, CVE-2026-63527, CVE-2026-64905, CVE-2026-64907, CVE-2026-64915, CVE-2026-64917, CVE-2026-66806, CVE-2026-66810.

CVE-2026-63532

CVE-2026-63532 is a remote code execution vulnerability in Microsoft Office resulting from an integer overflow or wraparound condition, which may allow an unauthorized attacker to execute arbitrary code locally.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63532

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-63533

CVE-2026-63533 is a heap-based buffer overflow vulnerability in Microsoft Office that allows an unauthorized attacker to execute arbitrary code locally on a victim's machine.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63533

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-64897

CVE-2026-64897 describes a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server. The flaw arises from improper neutralization of user-supplied input during the generation of web pages, which allows an authorized attacker to conduct spoofing attacks over the network.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64897

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-64898

CVE-2026-64898 is a heap-based buffer overflow vulnerability in Microsoft Office that enables an unauthorized attacker to execute arbitrary code locally on a target system. This vulnerability typically requires user interaction, such as opening a specially crafted file, to trigger the heap corruption.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64898

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-64900

CVE-2026-64900 is a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server that enables an authorized attacker to perform spoofing attacks over a network by injecting malicious scripts into web pages generated by the application.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64900

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-64902

CVE-2026-64902 is a spoofing vulnerability in Microsoft SharePoint Server caused by improper neutralization of input during web page generation, specifically categorized as cross-site scripting (XSS). An authorized attacker can exploit this flaw over a network to perform spoofing attacks.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64902

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-64899

CVE-2026-64899 is an out-of-bounds read vulnerability in Microsoft Office that enables an unauthorized local attacker to perform information disclosure. Detection efforts should focus on anomalous read operations or memory access patterns within the Office suite processes.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64899

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-64903

CVE-2026-64903 is an integer overflow vulnerability in Microsoft Office that enables an attacker to achieve remote code execution. The flaw stems from improper handling of integer values during processing, which can be leveraged to execute arbitrary code on the host system.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64903

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-64901

CVE-2026-64901 is a remote code execution vulnerability in Microsoft SharePoint Server caused by improper deserialization of untrusted data. An authorized attacker can leverage this flaw to execute arbitrary code over the network, potentially leading to full system compromise.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64901

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-64904

A type confusion vulnerability in Microsoft Office allows a local, unauthorized attacker to execute arbitrary code. The vulnerability is triggered through the improper handling of incompatible resource types.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64904

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-64905

A buffer over-read vulnerability in Microsoft Office Word allows an attacker to execute arbitrary code locally. Detection should focus on monitoring anomalous process creation or memory access patterns associated with Microsoft Word application files.

Affected products:

  • Office Word

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64905

Related in this roundup: CVE-2026-63518, CVE-2026-70311, CVE-2026-70319, CVE-2026-63528, CVE-2026-63527, CVE-2026-63531, CVE-2026-64907, CVE-2026-64915, CVE-2026-64917, CVE-2026-66806, CVE-2026-66810.

CVE-2026-64907

CVE-2026-64907 describes a stack-based buffer overflow vulnerability in Microsoft Office Word that enables an unauthorized attacker to achieve remote code execution on the host system. The vulnerability is triggered when the application processes specially crafted content, allowing for arbitrary code execution.

Affected products:

  • Office Word

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64907

Related in this roundup: CVE-2026-63518, CVE-2026-70311, CVE-2026-70319, CVE-2026-63528, CVE-2026-63527, CVE-2026-63531, CVE-2026-64905, CVE-2026-64915, CVE-2026-64917, CVE-2026-66806, CVE-2026-66810.

CVE-2026-64906

CVE-2026-64906 is a heap-based buffer overflow vulnerability in Microsoft Access that allows an unauthorized attacker to achieve remote code execution. The vulnerability is triggered by processing malicious input within the application, enabling local code execution.

Affected products:

  • Access

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64906

Related in this roundup: CVE-2026-64912, CVE-2026-64914, CVE-2026-64920, CVE-2026-64919.

CVE-2026-64909

CVE-2026-64909 describes an integer underflow vulnerability in Microsoft Office that enables an attacker to achieve remote code execution. The vulnerability stems from improper handling of integer wraparound, allowing for malicious code execution on the targeted system.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64909

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-64910

CVE-2026-64910 is a remote code execution vulnerability in Microsoft Office caused by an untrusted pointer dereference. An attacker could exploit this flaw to execute arbitrary code locally on a victim's machine, typically requiring the user to interact with a malicious file.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64910

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-64912

A stack-based buffer overflow vulnerability in Microsoft Access allows an unauthorized attacker to achieve remote code execution. Successful exploitation requires the application to process a specially crafted file, potentially leading to arbitrary code execution within the context of the current user.

Affected products:

  • Access

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64912

Related in this roundup: CVE-2026-64906, CVE-2026-64914, CVE-2026-64920, CVE-2026-64919.

CVE-2026-64911

CVE-2026-64911 is a remote code execution vulnerability in Microsoft Office caused by an integer overflow or wraparound condition, allowing an attacker to execute arbitrary code locally.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64911

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130.

CVE-2026-64908

CVE-2026-64908 describes a heap-based buffer overflow vulnerability in Microsoft Office Access. An unauthorized attacker can leverage this flaw to achieve remote code execution on the local machine by enticing a user to open a specially crafted file.

Affected products:

  • Office Access

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64908

CVE-2026-64914

CVE-2026-64914 is a heap-based buffer overflow vulnerability in Microsoft Access that allows an unauthorized attacker to execute arbitrary code locally.

Affected products:

  • Access

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64914

Related in this roundup: CVE-2026-64906, CVE-2026-64912, CVE-2026-64920, CVE-2026-64919.

CVE-2026-64915

CVE-2026-64915 is a heap-based buffer overflow vulnerability in Microsoft Office Word that enables an unauthorized attacker to execute arbitrary code on the host system. Successful exploitation typically requires a user to open a malicious document, leading to remote code execution within the context of the application.

Affected products:

  • Office Word

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64915

Related in this roundup: CVE-2026-63518, CVE-2026-70311, CVE-2026-70319, CVE-2026-63528, CVE-2026-63527, CVE-2026-63531, CVE-2026-64905, CVE-2026-64907, CVE-2026-64917, CVE-2026-66806, CVE-2026-66810.

CVE-2026-64916

CVE-2026-64916 describes a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server that allows an authenticated attacker to perform spoofing attacks over the network. The vulnerability arises due to improper input neutralization during the generation of web pages.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64916

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-64920

CVE-2026-64920 is a heap-based buffer overflow vulnerability in Microsoft Access that can be exploited by an unauthorized local attacker to achieve remote code execution on a target system.

Affected products:

  • Access

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64920

Related in this roundup: CVE-2026-64906, CVE-2026-64912, CVE-2026-64914, CVE-2026-64919.

CVE-2026-64917

CVE-2026-64917 is an out-of-bounds read vulnerability in Microsoft Office Word that enables an unauthorized local attacker to perform information disclosure by reading sensitive data from memory.

Affected products:

  • Office Word

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64917

Related in this roundup: CVE-2026-63518, CVE-2026-70311, CVE-2026-70319, CVE-2026-63528, CVE-2026-63527, CVE-2026-63531, CVE-2026-64905, CVE-2026-64907, CVE-2026-64915, CVE-2026-66806, CVE-2026-66810.

CVE-2026-64919

CVE-2026-64919 is a stack-based buffer overflow vulnerability in Microsoft Office Access that can be exploited by an unauthorized attacker to achieve local remote code execution.

Affected products:

  • Access

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64919

Related in this roundup: CVE-2026-64906, CVE-2026-64912, CVE-2026-64914, CVE-2026-64920.

CVE-2026-64921

CVE-2026-64921 is a privilege escalation vulnerability in Microsoft SharePoint Server caused by missing authentication for a critical function. An authenticated attacker can exploit this flaw over the network to elevate their privileges within the application environment.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64921

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-62882

CVE-2026-62882 is a spoofing vulnerability in Microsoft Outlook caused by insufficiently protected credentials, which can be exploited by an unauthorized attacker over a network to impersonate legitimate sources.

Affected products:

  • Outlook

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62882

Related in this roundup: CVE-2026-70329.

CVE-2026-65673

CVE-2026-65673 is a privilege escalation vulnerability affecting Microsoft Entra Connect. This flaw allows a local, authenticated attacker to escalate their privileges within the context of the affected service.

Affected products:

  • Entra Connect

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65673

CVE-2026-65681

A denial of service vulnerability exists in the Windows iSCSI Target Service, which may allow a remote, unauthenticated attacker to disrupt service availability by sending specially crafted network requests to the target service.

Affected products:

  • Windows iSCSI Target Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65681

Related in this roundup: CVE-2026-65679, CVE-2026-65791, CVE-2026-65796.

CVE-2026-65679

CVE-2026-65679 is a heap-based buffer overflow vulnerability in the Windows iSCSI Target Service. An unauthorized remote attacker can exploit this flaw to achieve remote code execution by sending specifically crafted network packets to the service.

Affected products:

  • Windows iSCSI Target Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65679

Related in this roundup: CVE-2026-65681, CVE-2026-65791, CVE-2026-65796.

CVE-2026-65773

An improper access control vulnerability exists in the Windows Kernel that allows a local, authenticated attacker to escalate privileges on the affected system.

Affected products:

  • Windows Kernel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65773

Related in this roundup: CVE-2026-54113, CVE-2026-61930, CVE-2026-62737, CVE-2026-62708, CVE-2026-62749.

CVE-2026-65774

A heap-based buffer overflow vulnerability in Windows Installer permits a locally authenticated attacker to gain elevated privileges on the target system.

Affected products:

  • Windows Installer

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65774

Related in this roundup: CVE-2026-59127, CVE-2026-61925, CVE-2026-70344, CVE-2026-70345, CVE-2026-70346, CVE-2026-70347, CVE-2026-61938, CVE-2026-62768.

CVE-2026-65775

A use-after-free vulnerability exists in the Windows Win32k component that allows an authenticated local attacker to achieve privilege escalation by triggering the flaw.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65775

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65776, CVE-2026-65794, CVE-2026-56179.

CVE-2026-65776

A use-after-free vulnerability in the Windows Win32k kernel component allows a locally authenticated attacker to elevate their privileges. Successful exploitation requires an attacker to already have local access to the system.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65776

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65794, CVE-2026-56179.

CVE-2026-65779

A use-after-free vulnerability in Windows Autopilot allows an authorized, local attacker to escalate their privileges. Successful exploitation could grant the attacker higher-level access to the affected system.

Affected products:

  • Windows Autopilot

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65779

Related in this roundup: CVE-2026-65783, CVE-2026-65780, CVE-2026-65778, CVE-2026-65782, CVE-2026-65781.

CVE-2026-65780

A double free vulnerability in Windows Autopilot allows an attacker with local authorization to elevate their privileges on the affected system.

Affected products:

  • Windows Autopilot

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65780

Related in this roundup: CVE-2026-65783, CVE-2026-65779, CVE-2026-65778, CVE-2026-65782, CVE-2026-65781.

CVE-2026-65778

CVE-2026-65778 is a privilege escalation vulnerability in Windows Autopilot caused by a use-after-free flaw. An authenticated local attacker can leverage this vulnerability to elevate their privileges on an affected Windows system.

Affected products:

  • Windows Autopilot

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65778

Related in this roundup: CVE-2026-65783, CVE-2026-65779, CVE-2026-65780, CVE-2026-65782, CVE-2026-65781.

CVE-2026-65782

CVE-2026-65782 is a privilege escalation vulnerability in Windows Autopilot caused by a use-after-free condition. An authorized local attacker can exploit this flaw to execute code with elevated privileges on the affected Windows system.

Affected products:

  • Windows Autopilot

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65782

Related in this roundup: CVE-2026-65783, CVE-2026-65779, CVE-2026-65780, CVE-2026-65778, CVE-2026-65781.

CVE-2026-65781

A use-after-free vulnerability in Windows Autopilot allows a locally authenticated attacker to elevate their privileges on the host system.

Affected products:

  • Windows Autopilot

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65781

Related in this roundup: CVE-2026-65783, CVE-2026-65779, CVE-2026-65780, CVE-2026-65778, CVE-2026-65782.

CVE-2026-65790

CVE-2026-65790 is a heap-based buffer overflow vulnerability in the Windows Message Queuing component. An authorized local attacker can exploit this flaw to elevate their privileges on the target system.

Affected products:

  • Windows Message Queuing

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65790

Related in this roundup: CVE-2026-62719, CVE-2026-62717.

CVE-2026-65791

A heap-based buffer overflow vulnerability in the Windows iSCSI Target Service allows an unauthenticated remote attacker to execute arbitrary code on the target system. The vulnerability exists within the service's request handling, potentially leading to remote code execution.

Affected products:

  • Windows iSCSI Target Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65791

Related in this roundup: CVE-2026-65681, CVE-2026-65679, CVE-2026-65796.

CVE-2026-65795

An elevation of privilege vulnerability exists in the Windows DNS component that allows an authorized local attacker to escalate their privileges. Successful exploitation requires the attacker to already have a foothold on the system.

Affected products:

  • Windows DNS

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65795

Related in this roundup: CVE-2026-70304, CVE-2026-70330, CVE-2026-62769, CVE-2026-62778, CVE-2026-62881, CVE-2026-62883, CVE-2026-65797, CVE-2026-65799, CVE-2026-65798.

CVE-2026-65794

A buffer over-read vulnerability in the Windows SMB Client allows an unauthorized remote attacker to disclose sensitive information over the network by exploiting the client's handling of specific SMB traffic patterns.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65794

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-56179.

CVE-2026-65797

CVE-2026-65797 is a local privilege escalation vulnerability in the Windows DNS component caused by a numeric truncation error. An authorized attacker can exploit this flaw to elevate their privileges on an affected system.

Affected products:

  • Windows DNS

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65797

Related in this roundup: CVE-2026-70304, CVE-2026-70330, CVE-2026-62769, CVE-2026-62778, CVE-2026-62881, CVE-2026-62883, CVE-2026-65795, CVE-2026-65799, CVE-2026-65798.

CVE-2026-65799

CVE-2026-65799 is a local privilege escalation vulnerability in Windows DNS stemming from an integer overflow or wraparound condition, allowing an authenticated attacker to gain higher privileges on the target system.

Affected products:

  • Windows DNS

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65799

Related in this roundup: CVE-2026-70304, CVE-2026-70330, CVE-2026-62769, CVE-2026-62778, CVE-2026-62881, CVE-2026-62883, CVE-2026-65795, CVE-2026-65797, CVE-2026-65798.

CVE-2026-65798

CVE-2026-65798 is a local privilege escalation vulnerability in the Windows DNS component caused by a numeric truncation error. An authorized attacker can exploit this flaw to elevate their privileges on the host system.

Affected products:

  • Windows DNS

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65798

Related in this roundup: CVE-2026-70304, CVE-2026-70330, CVE-2026-62769, CVE-2026-62778, CVE-2026-62881, CVE-2026-62883, CVE-2026-65795, CVE-2026-65797, CVE-2026-65799.

CVE-2026-65796

A heap-based buffer overflow vulnerability in the Windows iSCSI Target Service allows a remote, unauthorized attacker to trigger a denial of service condition on affected systems.

Affected products:

  • Windows iSCSI Target Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65796

Related in this roundup: CVE-2026-65681, CVE-2026-65679, CVE-2026-65791.

CVE-2026-66802

The Microsoft Azure Attestation and Device Health Attestation services are vulnerable to a race condition (concurrent execution with improper synchronization) that enables an unauthenticated attacker to achieve remote code execution over a network.

Affected products:

  • Azure Attestation
  • Device Health Attestation Service

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66802

Related in this roundup: CVE-2026-71331.

CVE-2026-66805

CVE-2026-66805 is a remote code execution vulnerability in Microsoft SharePoint Server caused by improper deserialization of untrusted data. An authorized attacker can exploit this flaw to execute arbitrary code over the network.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66805

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-66806

CVE-2026-66806 is an off-by-one vulnerability in Microsoft Office Word that enables an unauthorized attacker to perform local information disclosure. The vulnerability resides within the application's memory handling logic.

Affected products:

  • Office Word

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66806

Related in this roundup: CVE-2026-63518, CVE-2026-70311, CVE-2026-70319, CVE-2026-63528, CVE-2026-63527, CVE-2026-63531, CVE-2026-64905, CVE-2026-64907, CVE-2026-64915, CVE-2026-64917, CVE-2026-66810.

CVE-2026-66807

A stack-based buffer overflow vulnerability exists in the Microsoft Office Graphics Component that allows an unauthorized attacker to achieve remote code execution on the local machine through the processing of malformed files.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66807

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66809, CVE-2026-70130.

CVE-2026-66808

CVE-2026-66808 is a remote code execution vulnerability in Microsoft SharePoint Server caused by improper deserialization of untrusted data. An authorized attacker can leverage this flaw to execute arbitrary code over the network, posing a significant risk to the integrity and availability of the SharePoint environment.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66808

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-66810

CVE-2026-66810 is an information disclosure vulnerability in Microsoft Office Word caused by a heap-based buffer overflow. An attacker can exploit this flaw to read sensitive data locally.

Affected products:

  • Office Word

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66810

Related in this roundup: CVE-2026-63518, CVE-2026-70311, CVE-2026-70319, CVE-2026-63528, CVE-2026-63527, CVE-2026-63531, CVE-2026-64905, CVE-2026-64907, CVE-2026-64915, CVE-2026-64917, CVE-2026-66806.

CVE-2026-66809

An out-of-bounds read vulnerability exists in the Microsoft Office Graphics Component that could allow a local attacker to disclose sensitive information from the application's memory space.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66809

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-70130.

CVE-2026-68797

CVE-2026-68797 describes an out-of-bounds read vulnerability in Microsoft Excel that allows a local unauthorized attacker to disclose sensitive information. The vulnerability occurs due to improper memory handling within the application, and detection efforts should focus on anomalous file access patterns or unexpected memory read operations involving Excel processes.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68797

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68798

A heap-based buffer overflow vulnerability in Microsoft Excel allows an attacker to achieve remote code execution. Successful exploitation requires the user to open a specially crafted malicious file, which can lead to the execution of arbitrary code with the privileges of the current user.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68798

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68799

Microsoft Excel is vulnerable to an information disclosure flaw due to the use of an uninitialized resource. An attacker can exploit this vulnerability locally to gain unauthorized access to sensitive information.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68799

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68801

CVE-2026-68801 describes a heap-based buffer overflow vulnerability in Microsoft Excel that can be exploited by an unauthorized attacker to achieve remote code execution. Detection efforts should focus on monitoring for anomalous file handling behaviors or malicious macro/script execution originating from Excel processes.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68801

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68803

CVE-2026-68803 is a type confusion vulnerability in Microsoft Excel that allows an attacker to achieve remote code execution. The vulnerability is triggered when a user opens a specially crafted file, leading to memory corruption that can be leveraged to execute arbitrary code with the privileges of the current user.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68803

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68804

CVE-2026-68804 is a remote code execution vulnerability in Microsoft Excel caused by a numeric truncation error. An attacker can exploit this flaw to execute arbitrary code on a victim's system, typically requiring user interaction by opening a maliciously crafted file.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68804

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68805

CVE-2026-68805 describes a heap-based buffer overflow vulnerability in Microsoft Excel that can be exploited by an unauthorized attacker to achieve remote code execution. Detection efforts should focus on monitoring for anomalous child processes spawned by Excel and identifying attempts to parse malformed spreadsheet files.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68805

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68812

CVE-2026-68812 is a heap-based buffer overflow vulnerability in Microsoft Excel that enables a remote, unauthorized attacker to execute arbitrary code locally on the victim's machine, typically through the user opening a malicious file.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68812

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68814, CVE-2026-68817.

CVE-2026-68814

CVE-2026-68814 is an out-of-bounds read vulnerability in Microsoft Excel that can be leveraged by an unauthorized attacker to achieve remote code execution on the target system.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68814

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68817.

CVE-2026-68817

CVE-2026-68817 is a stack-based buffer overflow vulnerability in Microsoft Excel that allows an unauthorized attacker to achieve remote code execution on the target system when a user opens a specially crafted file.

Affected products:

  • Excel

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68817

Related in this roundup: CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814.

CVE-2026-56179

CVE-2026-56179 describes an origin validation error in the Windows Network Address Translation (NAT) driver. This vulnerability allows an unauthorized attacker positioned on an adjacent network to perform spoofing attacks, potentially leading to unauthorized data interception or manipulation.

Affected products:

  • Windows

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56179

Related in this roundup: CVE-2026-68480, CVE-2026-64564, CVE-2026-54876, CVE-2026-68388, CVE-2026-68189, CVE-2026-68312, CVE-2026-68176, CVE-2026-68118, CVE-2026-68175, CVE-2026-68328, CVE-2026-68406, CVE-2026-68317, CVE-2026-68354, CVE-2026-68326, CVE-2026-68151, CVE-2026-68343, CVE-2026-68184, CVE-2026-68322, CVE-2026-68214, CVE-2026-68188, CVE-2026-68132, CVE-2026-68304, CVE-2026-68348, CVE-2026-68195, CVE-2026-68419, CVE-2026-68171, CVE-2025-37938, CVE-2026-68207, CVE-2026-50472, CVE-2026-59132, CVE-2026-61927, CVE-2026-61937, CVE-2026-61933, CVE-2026-61934, CVE-2026-61936, CVE-2026-62702, CVE-2026-62712, CVE-2026-62746, CVE-2026-62735, CVE-2026-62739, CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62774, CVE-2026-62779, CVE-2026-62792, CVE-2026-62798, CVE-2026-62795, CVE-2026-62796, CVE-2026-62876, CVE-2026-62877, CVE-2026-65662, CVE-2026-65672, CVE-2026-65678, CVE-2026-65784, CVE-2026-70307, CVE-2026-42976, CVE-2026-6726, CVE-2026-61358, CVE-2026-61360, CVE-2026-61926, CVE-2026-61929, CVE-2026-62698, CVE-2026-62700, CVE-2026-62711, CVE-2026-62721, CVE-2026-62733, CVE-2026-62743, CVE-2026-62730, CVE-2026-62757, CVE-2026-62741, CVE-2026-62770, CVE-2026-62780, CVE-2026-62781, CVE-2026-62786, CVE-2026-62788, CVE-2026-62793, CVE-2026-62811, CVE-2026-62880, CVE-2026-62885, CVE-2026-62887, CVE-2026-62888, CVE-2026-65775, CVE-2026-65776, CVE-2026-65794.

CVE-2026-70130

CVE-2026-70130 describes a heap-based buffer overflow vulnerability in Microsoft Office that enables an unauthorized attacker to achieve remote code execution. Detection efforts should focus on monitoring for anomalous process behavior or crashes occurring during the parsing of malformed Office documents.

Affected products:

  • Office

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70130

Related in this roundup: CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63521, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70310, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63525, CVE-2026-63526, CVE-2026-63529, CVE-2026-63530, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809.

CVE-2026-70306

CVE-2026-70306 is a cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint that allows an unauthorized remote attacker to conduct spoofing attacks by improperly neutralizing user-supplied input during web page generation.

Affected products:

  • SharePoint

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70306

Related in this roundup: CVE-2026-57105, CVE-2026-70321, CVE-2026-70324.

CVE-2026-70326

CVE-2026-70326 describes an elevation of privilege vulnerability in Microsoft SharePoint Server arising from a server-side request forgery (SSRF) flaw. An authenticated attacker can exploit this over the network to gain elevated privileges, highlighting the need to restrict network access to SharePoint management interfaces.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70326

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917.

CVE-2026-70337

CVE-2026-70337 describes a relative path traversal vulnerability within Microsoft PowerShell Core. This flaw allows a remote, unauthorized attacker to achieve remote code execution (RCE) by leveraging the traversal vulnerability over a network.

Affected products:

  • PowerShell Core

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70337

Related in this roundup: CVE-2026-58612.

CVE-2026-70354

An out-of-bounds write vulnerability in .NET Core allows a local unauthorized attacker to execute arbitrary code. The vulnerability exists due to improper bounds checking, which could lead to memory corruption.

Affected products:

  • .NET Core

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70354

CVE-2026-71331

CVE-2026-71331 is a critical vulnerability identified in Microsoft's Azure Attestation and Device Health Attestation services. The flaw stems from an integer overflow or wraparound condition, which enables an unauthenticated remote attacker to execute arbitrary code within the context of the service. Security teams should prioritize patching or applying vendor-provided mitigations to these cloud-based attestation services to prevent potential remote compromise.

Affected products:

  • Azure Attestation
  • Device Health Attestation

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71331

Related in this roundup: CVE-2026-66802.

CVE-2026-62738

CVE-2026-62738 describes an out-of-bounds read vulnerability within the Windows Management Instrumentation (WMI) component. An authorized, local attacker can leverage this flaw to disclose sensitive information from the system.

Affected products:

  • Windows Management Instrumentation

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62738

CVE-2026-62898

CVE-2026-62898 describes a use-after-free vulnerability in Microsoft QUIC that can be leveraged by a remote, unauthorized attacker to perform information disclosure over a network connection.

Affected products:

  • Microsoft QUIC

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62898

Related in this roundup: CVE-2026-62815.

CVE-2026-65767

CVE-2026-65767 is a cross-site scripting (XSS) vulnerability in Microsoft Teams for Android that allows an attacker to perform spoofing attacks over a network by failing to properly neutralize input during web page generation.

Affected products:

  • Teams

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65767

Related in this roundup: CVE-2026-65768.

CVE-2026-58639

CVE-2026-58639 describes a Server-Side Request Forgery (SSRF) vulnerability in Microsoft SharePoint Server that enables an authorized attacker to conduct spoofing attacks over a network.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58639

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-62839, CVE-2026-62917.

CVE-2026-62839

CVE-2026-62839 is a spoofing vulnerability in Microsoft SharePoint Server caused by insufficiently protected credentials. An attacker with existing authorized network access can exploit this flaw to perform spoofing attacks, potentially leading to unauthorized manipulation or impersonation of content within the SharePoint environment.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62839

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62917.

CVE-2026-62917

CVE-2026-62917 is a spoofing vulnerability in Microsoft SharePoint Server caused by improper input validation. An authorized attacker on the network can leverage this flaw to perform spoofing attacks against the affected server.

Affected products:

  • SharePoint Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62917

Related in this roundup: CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70326, CVE-2026-58639, CVE-2026-62839.

CVE-2026-65680

CVE-2026-65680 describes an elevation of privilege vulnerability in Microsoft OneDrive for macOS caused by improper link resolution before file access. An attacker with local access can exploit this vulnerability to gain elevated privileges on the affected system.

Affected products:

  • OneDrive

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65680

CVE-2026-50516

CVE-2026-50516 describes a critical vulnerability in Microsoft Azure Kubernetes Service (AKS) where a missing authentication for a critical function allows an unauthenticated, remote attacker to escalate privileges over the network. This vulnerability carries a CVSS base score of 9.4, indicating a high risk of unauthorized access and system compromise.

Affected products:

  • Azure Kubernetes Service

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-50516

CVE-2026-62869

CVE-2026-62869 is a vulnerability in Microsoft Entra ID involving insufficient verification of data authenticity. This flaw allows an authorized attacker to perform spoofing over a network, potentially leading to unauthorized data manipulation or unauthorized access within the identity management environment.

Affected products:

  • Microsoft Entra

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62869

Related in this roundup: CVE-2026-69836, CVE-2026-69851.

CVE-2026-62872

An incorrect authorization vulnerability in the Microsoft .NET Framework allows an authenticated attacker to perform a privilege escalation attack over the network. The vulnerability, tracked as CVE-2026-62872, is categorized as an improper authorization issue and can be exploited by an attacker with low privileges, impacting the confidentiality, integrity, and availability of the affected system.

Affected products:

  • Microsoft .NET Framework

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62872

CVE-2026-62897

CVE-2026-62897 is an integer overflow or wraparound vulnerability in various versions of the .NET Framework and Visual Studio. An unauthorized attacker could exploit this vulnerability to execute arbitrary code locally on an affected system. The vulnerability requires local access and user interaction to be triggered.

Affected products:

  • .NET (< 10.0.11)
  • .NET (< 8.0.30)
  • .NET (< 9.0.19)
  • Microsoft .NET Framework 3.5 (< 2.0.50727.9183)
  • Microsoft .NET Framework 4.7.2 (< 4.7.4144.0)
  • Microsoft .NET Framework 4.8 (< 4.8.4805.0)
  • Microsoft .NET Framework 4.8.1 (< 4.8.9344.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62897

Related in this roundup: CVE-2026-62899, CVE-2026-62900, CVE-2026-62901, CVE-2026-62902, CVE-2026-62909, CVE-2026-58641, CVE-2026-62871, CVE-2026-62886.

CVE-2026-63522

A vulnerability in Azure SQL Database involves an incorrect permission assignment for a critical resource. This flaw allows an already authorized attacker to perform a local privilege escalation within the affected service environment.

Affected products:

  • Azure SQL Database

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-63522

Related in this roundup: CVE-2026-68789, CVE-2026-66309, CVE-2026-68782, CVE-2026-69502.

CVE-2026-70339

Microsoft Edge (Chromium-based) is vulnerable to a type confusion vulnerability, which can be exploited by a remote attacker to achieve code execution over the network. The vulnerability arises from an incorrect handling of resource types within the browser's engine.

Affected products:

  • Edge

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70339

Related in this roundup: CVE-2026-70331, CVE-2026-58616, CVE-2026-62904, CVE-2026-66323, CVE-2026-66324, CVE-2026-66798, CVE-2026-70341, CVE-2026-72984.

CVE-2026-50523

CVE-2026-50523 is a command injection vulnerability in Microsoft PowerShell that allows an authenticated local attacker to execute arbitrary code. The vulnerability stems from improper neutralization of special elements used in commands.

Affected products:

  • PowerShell (7.4.0 < 7.4.19.0)
  • PowerShell (7.5.0 < 7.5.10.0)
  • PowerShell (7.6.0 < 7.6.5)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-50523

CVE-2026-69414

CVE-2026-69414, also known as 'ShieldBreak', is a high-severity elevation of privilege vulnerability in the Microsoft Malware Protection Engine within Microsoft Defender. The vulnerability allows a local, authenticated attacker to escalate privileges. Microsoft is currently developing a security update to remediate this flaw.

Affected products:

  • Microsoft Malware Protection Engine

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-69414

CVE-2026-24301

CVE-2026-24301 is a command injection vulnerability in Microsoft Copilot that enables an unauthorized remote attacker to disclose sensitive information over a network due to improper neutralization of special elements.

Affected products:

  • Copilot

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24301

CVE-2026-62727

CVE-2026-62727 is a race condition vulnerability in the Windows Telephony Service that allows a locally authenticated attacker to elevate their privileges on the host system. The vulnerability stems from improper synchronization when accessing shared resources, which could lead to unauthorized system access.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62727

CVE-2026-62834

CVE-2026-62834 is a critical vulnerability in Microsoft Azure Data Factory resulting from improper verification of cryptographic signatures. This flaw allows an unauthorized attacker to perform privilege escalation over a network. Detection engineers should monitor for anomalous service access patterns or unauthorized attempts to leverage improperly signed data or tokens within the Azure Data Factory environment.

Affected products:

  • Azure Data Factory

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62834

Related in this roundup: CVE-2026-66800.

CVE-2026-63509

Microsoft Fabric contains a relative path traversal vulnerability (CWE-23) that allows an authenticated attacker to perform privilege escalation over a network. The vulnerability is rated critical with a CVSS score of 9.9.

Affected products:

  • Microsoft Fabric

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-63509

CVE-2026-65770

CVE-2026-65770 is an argument injection vulnerability in Microsoft's Azure Managed Instance for Apache Cassandra. An unauthorized network-based attacker can leverage improper neutralization of argument delimiters to achieve remote code execution on the affected service.

Affected products:

  • Azure Managed Instance for Apache Cassandra

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-65770

CVE-2026-65816

CVE-2026-65816 is a critical vulnerability in Microsoft Azure Arc involving the use of incorrectly-resolved names or references. This flaw allows an unauthenticated, unauthorized attacker to perform a privilege escalation attack over the network. The vulnerability is characterized as a critical security risk with a CVSS 3.1 base score of 10.0.

Affected products:

  • Azure Arc

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-65816

Related in this roundup: CVE-2026-69555.

CVE-2026-69400

CVE-2026-69400 is a critical path traversal vulnerability in Microsoft Azure Logic Apps. An unauthorized attacker can leverage this flaw to perform privilege escalation over a network, potentially impacting the confidentiality, integrity, and availability of the service.

Affected products:

  • Azure Logic Apps

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-69400

Related in this roundup: CVE-2026-56161.

CVE-2026-69555

CVE-2026-69555 is a critical vulnerability in Microsoft Azure Arc involving incorrect authorization. The flaw allows an unauthenticated, unauthorized remote attacker to perform privilege escalation over a network, potentially leading to unauthorized access to system resources. The vulnerability carries a CVSS base score of 10.0.

Affected products:

  • Azure Arc

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-69555

Related in this roundup: CVE-2026-65816.

CVE-2026-69836

Microsoft Entra ID is vulnerable to a deserialization of untrusted data attack (CWE-502), which allows an unauthenticated remote attacker to achieve remote code execution over the network. This critical vulnerability (CVSS 10.0) stems from improper handling of serialized objects, potentially enabling full system compromise.

Affected products:

  • Microsoft Entra

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-69836

Related in this roundup: CVE-2026-62869, CVE-2026-69851.

CVE-2026-69851

A server-side request forgery (SSRF) vulnerability exists in Microsoft Entra (formerly Azure Active Directory), which allows an authorized attacker to escalate their privileges over the network.

Affected products:

  • Microsoft Entra

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-69851

Related in this roundup: CVE-2026-62869, CVE-2026-69836.

CVE-2026-55013

CVE-2026-55013 is a vulnerability in Windows Remote Help where an uncontrolled search path element allows a local, authorized attacker to achieve local privilege escalation or spoofing by manipulating the search path used by the application to load components.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-55013

CVE-2026-66800

CVE-2026-66800 is a server-side request forgery (SSRF) vulnerability in Azure Data Factory that allows an unauthenticated, remote attacker to disclose sensitive information from the internal cloud environment over the network.

Affected products:

  • Azure Data Factory

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-66800

Related in this roundup: CVE-2026-62834.

CVE-2026-69419

CVE-2026-69419 describes an integer overflow or wraparound vulnerability in Microsoft's Azure Data Manager for Energy. This vulnerability allows an authenticated attacker to achieve remote code execution over a network. The vulnerability carries a high CVSS score of 8.5, indicating significant potential impact.

Affected products:

  • Azure Data Manager for Energy

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-69419

CVE-2026-69519

CVE-2026-69519 is an observable response discrepancy vulnerability in Microsoft Azure Stack HCI that allows an unauthorized, remote attacker to disclose sensitive information over the network. The vulnerability has a CVSS base score of 8.6 and is categorized under CWE-204.

Affected products:

  • Azure Stack HCI

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-69519

CVE-2026-69543

CVE-2026-69543 is a Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Virtual Machines. An authorized attacker can exploit this flaw to achieve privilege escalation over a network.

Affected products:

  • Azure Virtual Machines

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-69543

CVE-2026-69558

Microsoft Partner Center is vulnerable to an authorization bypass caused by improper handling of a user-controlled key. This vulnerability allows an unauthenticated remote attacker to access sensitive information by manipulating input parameters in network requests, resulting in unauthorized data disclosure.

Affected products:

  • Microsoft Partner Center

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-69558

CVE-2026-69855

CVE-2026-69855 is a server-side request forgery (SSRF) vulnerability in Microsoft Copilot in Azure. It allows an authorized attacker to disclose sensitive information over a network by leveraging the SSRF weakness, which is classified as CWE-918.

Affected products:

  • Microsoft Copilot in Azure

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-69855

CVE-2026-65801

CVE-2026-65801 describes a server-side request forgery (SSRF) vulnerability in Microsoft Exchange Online that can be exploited by an unauthorized remote attacker to achieve privilege escalation over the network.

Affected products:

  • Exchange Online

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65801

CVE-2026-68789

CVE-2026-68789 describes an elevation of privilege vulnerability in Azure SQL Database caused by improper neutralization of special elements used in SQL commands. An authorized attacker can leverage this SQL injection vulnerability to escalate their privileges within the database environment over a network.

Affected products:

  • Azure SQL Database

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68789

Related in this roundup: CVE-2026-63522, CVE-2026-66309, CVE-2026-68782, CVE-2026-69502.

CVE-2026-55015

A vulnerability exists in Microsoft Remote Help where an uncontrolled search path element allows an authorized local attacker to trigger a denial of service condition.

Affected products:

  • Remote Help

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55015

CVE-2026-66309

CVE-2026-66309 is an elevation of privilege vulnerability in Azure SQL Database caused by improper access control. An authorized attacker with network access to the database service could exploit this flaw to gain higher privileges than their assigned role, potentially leading to unauthorized data access or administrative control.

Affected products:

  • Azure SQL Database

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66309

Related in this roundup: CVE-2026-63522, CVE-2026-68789, CVE-2026-68782, CVE-2026-69502.

CVE-2026-68782

CVE-2026-68782 is a privilege escalation vulnerability in Azure SQL Database caused by improper neutralization of special elements used in SQL commands. An authorized attacker can exploit this SQL injection vulnerability over a network to gain elevated privileges within the service.

Affected products:

  • Azure SQL Database

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68782

Related in this roundup: CVE-2026-63522, CVE-2026-68789, CVE-2026-66309, CVE-2026-69502.

CVE-2026-69502

CVE-2026-69502 describes a server-side request forgery (SSRF) vulnerability in Microsoft Azure SQL Database that can be exploited by an unauthorized remote attacker to achieve privilege escalation over a network.

Affected products:

  • Azure SQL Database

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69502

Related in this roundup: CVE-2026-63522, CVE-2026-68789, CVE-2026-66309, CVE-2026-68782.

CVE-2019-1068

Microsoft SQL Server contains a remote code execution vulnerability that allows an authenticated attacker to execute arbitrary code with the privileges of the SQL Server Database Engine service account due to improper validation of input by the database engine.

Affected products:

  • SQL Server

Source: https://www.cve.org/CVERecord?id=CVE-2019-1068

CVE-2026-70331

Microsoft Edge for iOS contains a vulnerability involving improper neutralization of LLM prompt input, which can be exploited by an unauthorized remote attacker to perform spoofing attacks over a network.

Affected products:

  • Edge

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70331

Related in this roundup: CVE-2026-70339, CVE-2026-58616, CVE-2026-62904, CVE-2026-66323, CVE-2026-66324, CVE-2026-66798, CVE-2026-70341, CVE-2026-72984.

CVE-2026-58616

CVE-2026-58616 is an information disclosure vulnerability in the Microsoft Edge Copilot Chat feature. The flaw arises from a race condition during concurrent execution with shared resources, which an authorized attacker can exploit to potentially access sensitive information over the network.

Affected products:

  • Edge

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58616

Related in this roundup: CVE-2026-70339, CVE-2026-70331, CVE-2026-62904, CVE-2026-66323, CVE-2026-66324, CVE-2026-66798, CVE-2026-70341, CVE-2026-72984.

CVE-2026-62904

CVE-2026-62904 describes an information disclosure vulnerability in Microsoft Edge (Chromium-based) due to incorrect authorization. This flaw permits an unauthorized remote attacker to access sensitive information over a network connection.

Affected products:

  • Edge

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62904

Related in this roundup: CVE-2026-70339, CVE-2026-70331, CVE-2026-58616, CVE-2026-66323, CVE-2026-66324, CVE-2026-66798, CVE-2026-70341, CVE-2026-72984.

CVE-2026-66323

CVE-2026-66323 is a remote code execution vulnerability in Microsoft Edge (Chromium-based) resulting from improper neutralization of parameter and argument delimiters. An unauthenticated attacker can exploit this flaw over a network to execute arbitrary code on a user's system.

Affected products:

  • Edge

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66323

Related in this roundup: CVE-2026-70339, CVE-2026-70331, CVE-2026-58616, CVE-2026-62904, CVE-2026-66324, CVE-2026-66798, CVE-2026-70341, CVE-2026-72984.

CVE-2026-66324

CVE-2026-66324 is a spoofing vulnerability in Microsoft Edge (Chromium-based) stemming from improper external control of file names or paths, which can be exploited by an unauthorized remote attacker to deceive users.

Affected products:

  • Edge

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66324

Related in this roundup: CVE-2026-70339, CVE-2026-70331, CVE-2026-58616, CVE-2026-62904, CVE-2026-66323, CVE-2026-66798, CVE-2026-70341, CVE-2026-72984.

CVE-2026-66798

Microsoft Edge (Chromium-based) contains a use-after-free vulnerability that allows a remote attacker to achieve code execution over a network. This flaw represents a significant risk as it could lead to arbitrary code execution within the context of the browser process.

Affected products:

  • Edge

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66798

Related in this roundup: CVE-2026-70339, CVE-2026-70331, CVE-2026-58616, CVE-2026-62904, CVE-2026-66323, CVE-2026-66324, CVE-2026-70341, CVE-2026-72984.

CVE-2026-70341

CVE-2026-70341 is a use-after-free vulnerability in the Chromium-based Microsoft Edge browser that enables a remote attacker to achieve code execution over a network. Detection engineers should focus on monitoring browser process behavior and memory management patterns associated with Edge to identify potential exploitation attempts.

Affected products:

  • Edge

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70341

Related in this roundup: CVE-2026-70339, CVE-2026-70331, CVE-2026-58616, CVE-2026-62904, CVE-2026-66323, CVE-2026-66324, CVE-2026-66798, CVE-2026-72984.

CVE-2026-72984

Microsoft Edge (Chromium-based) contains a type confusion vulnerability that allows an unauthenticated remote attacker to achieve remote code execution via a network vector.

Affected products:

  • Edge

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72984

Related in this roundup: CVE-2026-70339, CVE-2026-70331, CVE-2026-58616, CVE-2026-62904, CVE-2026-66323, CVE-2026-66324, CVE-2026-66798, CVE-2026-70341.