<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cpe:2.3:a:microsoft:purview_ediscovery:-:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3amicrosoftpurview_ediscovery-/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 01 Aug 2026 01:41:40 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3amicrosoftpurview_ediscovery-/feed.xml" rel="self" type="application/rss+xml"/><item><title>Microsoft Security Updates — August 2026</title><link>https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/</link><pubDate>Sat, 01 Aug 2026 01:41:40 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/</guid><description>Roundup of Microsoft security advisories published in August 2026.</description><content:encoded><![CDATA[<p>This roundup covers 457 Microsoft security vulnerabilities. CVSS base scores range from 4.3 to 10.0. None are reported as actively exploited at the time of release. The issues affect .NET, .NET Core, AMT, Access, Active Directory Certificate Services, Active Directory Domain Services, Application Information Services, Application Insights Profiler, Azure Active Directory, Azure Attestation, Azure Confidential Ledger, Azure CycleCloud, Azure Kubernetes Service, Azure Logic Apps, Azure Monitor Agent, Azure SQL Managed Instance, Azure SRE Agent, Azure Service Bus, Azure Storage Explorer, Bluetooth, COM, Capability Access Management Service, Defender for Endpoint, Desktop Window Manager, Dynamics 365, Dynamics Business Central, Entra Connect, Excel, Exchange Server, GitHub Copilot, HDF5, High Performance Computing, High Performance Computing Pack, Hyper-V, Local Security Authority Server, Microsoft .NET Framework, Microsoft 365 Admin Center, Microsoft Entra, Microsoft Entra Provisioning Service, Microsoft Planetary Computer Pro, Microsoft Purview eDiscovery, Microsoft QUIC, Microsoft Teams, Office, Office Access, Office Word, OneDrive, Outlook, Power Apps, Power BI, PowerPoint, PowerShell Core, Reliable Multicast Transport Driver, Remote Desktop Client, Remote Desktop Services, Remote Registry Service, Routing and Remote Access Service, Rpm, SMB Client, SharePoint, SharePoint Online, SharePoint Server, Teams, Virtual Hard Disk, Visual Studio Code, Visual Studio Code CoPilot Chat Extension, Windows, Windows Ancillary Function Driver for WinSock, Windows Autopilot, Windows Backup Engine, Windows Bind Filter Driver, Windows Cloud Files Mini Filter Driver, Windows Common Log File System Driver, Windows Container Isolation FS Filter Driver, Windows Cross Device Service, Windows DHCP Client, Windows DHCP Server, Windows DNS, Windows DNS Server, Windows DWM Core Library, Windows Deployment Services, Windows Device Association Service, Windows Display Enhancement Service, Windows Encrypting File System, Windows Event Logging Service, Windows GDI+, Windows Graphics Kernel, Windows HTTP Protocol Stack, Windows HTTP.sys, Windows Hello, Windows Imaging Component, Windows Installer, Windows Kerberos, Windows Kernel, Windows Key Guard, Windows LDAP, Windows License Manager, Windows MIDI Service, Windows MIDI Service Module, Windows Management Instrumentation, Windows Management Services, Windows Message Queuing, Windows Modern Device Management, Windows NTFS, Windows Narrator, Windows Network Connection Broker, Windows Network File System, Windows Package Manager, Windows Program Compatibility Assistant Service, Windows Projected File System, Windows Push Notifications, Windows Remote Access API, Windows Remote Access Connection Manager, Windows Remote Desktop Services, Windows SMB Client, Windows SMB Server, Windows Search Component, Windows Secure Socket Tunneling Protocol, Windows Sensor Data Service, Windows Storage, Windows Storage Port Driver, Windows Telephony Service, Windows Universal Disk Format File System Driver, Windows User Profile Service, Windows Work Folder Service, Windows iSCSI Target Service, Winlogon, Word, dma-buf/udmabuf, firmware, ims-pcu, iomap, ksmbd, mctp, net/handshake, pds_core, wanxl.</p>
<h2 id="summary">Summary</h2>
<table>
	<thead>
			<tr>
					<th>CVE</th>
					<th>Product</th>
					<th>Severity</th>
					<th>CVSS</th>
					<th>EPSS</th>
					<th>KEV</th>
					<th>Source</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><a href="#cve-2026-50481">CVE-2026-50481</a></td>
					<td>Azure Active Directory</td>
					<td>Critical</td>
					<td>9.9</td>
					<td>0.46%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50481">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-50515">CVE-2026-50515</a></td>
					<td>Azure Service Bus</td>
					<td>Critical</td>
					<td>9.9</td>
					<td>0.91%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50515">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-56161">CVE-2026-56161</a></td>
					<td>Azure Logic Apps</td>
					<td>Critical</td>
					<td>9.6</td>
					<td>0.38%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-56161">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-59115">CVE-2026-59115</a></td>
					<td>Microsoft Entra Provisioning Service</td>
					<td>Critical</td>
					<td>9.9</td>
					<td>0.64%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-59115">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-59118">CVE-2026-59118</a></td>
					<td>Power Apps</td>
					<td>Critical</td>
					<td>9.3</td>
					<td>0.39%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-59118">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62830">CVE-2026-62830</a></td>
					<td>Azure SRE Agent</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62830">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62873">CVE-2026-62873</a></td>
					<td>Microsoft 365 Admin Center</td>
					<td>Critical</td>
					<td>9.8</td>
					<td>0.34%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62873">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62896">CVE-2026-62896</a></td>
					<td>Microsoft Teams</td>
					<td>Critical</td>
					<td>9.6</td>
					<td>0.38%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62896">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63508">CVE-2026-63508</a></td>
					<td>Microsoft Planetary Computer Pro (GeoCatalog)</td>
					<td>Critical</td>
					<td>10.0</td>
					<td>0.44%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-63508">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65667">CVE-2026-65667</a></td>
					<td>Microsoft Teams</td>
					<td>Critical</td>
					<td>10.0</td>
					<td>0.44%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-65667">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68823">CVE-2026-68823</a></td>
					<td>Azure Confidential Ledger</td>
					<td>Critical</td>
					<td>9.1</td>
					<td>0.50%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-68823">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70332">CVE-2026-70332</a></td>
					<td>SharePoint Online</td>
					<td>Critical</td>
					<td>9.6</td>
					<td>0.48%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-70332">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-49163">CVE-2026-49163</a></td>
					<td>Application Insights Profiler</td>
					<td>High</td>
					<td>8.8</td>
					<td>0.62%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49163">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62836">CVE-2026-62836</a></td>
					<td>Azure SQL Managed Instance</td>
					<td>High</td>
					<td>8.7</td>
					<td>0.36%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62836">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62918">CVE-2026-62918</a></td>
					<td>Microsoft Teams</td>
					<td>High</td>
					<td>7.5</td>
					<td>0.29%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62918">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65668">CVE-2026-65668</a></td>
					<td>Microsoft Purview eDiscovery</td>
					<td>High</td>
					<td>8.8</td>
					<td>0.42%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-65668">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68480">CVE-2026-68480</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.23%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68480">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64564">CVE-2026-64564</a></td>
					<td>Windows</td>
					<td>Critical</td>
					<td>9.8</td>
					<td>0.48%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64564">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64590">CVE-2026-64590</a></td>
					<td>dma-buf/udmabuf</td>
					<td></td>
					<td></td>
					<td>0.16%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64590">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-54876">CVE-2026-54876</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.5</td>
					<td>0.26%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54876">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-44605">CVE-2026-44605</a></td>
					<td>Rpm</td>
					<td>Medium</td>
					<td>5.5</td>
					<td>0.14%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44605">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64573">CVE-2026-64573</a></td>
					<td>Bluetooth</td>
					<td></td>
					<td></td>
					<td>0.16%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64573">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64565">CVE-2026-64565</a></td>
					<td>ims-pcu</td>
					<td></td>
					<td></td>
					<td>0.17%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64565">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64578">CVE-2026-64578</a></td>
					<td>ksmbd</td>
					<td>High</td>
					<td>8.2</td>
					<td>0.32%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64578">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2024-21380">CVE-2024-21380</a></td>
					<td>Dynamics Business Central</td>
					<td>High</td>
					<td>8.0</td>
					<td>1.73%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21380">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2025-2308">CVE-2025-2308</a></td>
					<td>HDF5</td>
					<td>Medium</td>
					<td>5.3</td>
					<td>0.40%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-2308">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2025-2309">CVE-2025-2309</a></td>
					<td>HDF5</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-2309">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68097">CVE-2026-68097</a></td>
					<td>ksmbd</td>
					<td></td>
					<td></td>
					<td>0.17%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68097">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68388">CVE-2026-68388</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.17%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68388">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68187">CVE-2026-68187</a></td>
					<td>n/a</td>
					<td></td>
					<td></td>
					<td>0.21%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68187">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68152">CVE-2026-68152</a></td>
					<td>AMT</td>
					<td></td>
					<td></td>
					<td>0.18%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68152">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68189">CVE-2026-68189</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.20%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68189">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68312">CVE-2026-68312</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.19%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68312">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68130">CVE-2026-68130</a></td>
					<td>ksmbd</td>
					<td></td>
					<td></td>
					<td>0.21%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68130">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68176">CVE-2026-68176</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.20%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68176">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68145">CVE-2026-68145</a></td>
					<td>iomap</td>
					<td></td>
					<td></td>
					<td>0.18%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68145">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68318">CVE-2026-68318</a></td>
					<td>pds_core</td>
					<td></td>
					<td></td>
					<td>0.17%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68318">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68118">CVE-2026-68118</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.17%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68118">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68175">CVE-2026-68175</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.20%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68175">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68328">CVE-2026-68328</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.17%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68328">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68406">CVE-2026-68406</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.18%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68406">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68317">CVE-2026-68317</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.17%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68317">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68099">CVE-2026-68099</a></td>
					<td>ksmbd</td>
					<td></td>
					<td></td>
					<td>0.17%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68099">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68354">CVE-2026-68354</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.18%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68354">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68326">CVE-2026-68326</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.17%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68326">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68151">CVE-2026-68151</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.18%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68151">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68343">CVE-2026-68343</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68343">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68184">CVE-2026-68184</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.20%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68184">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68124">CVE-2026-68124</a></td>
					<td>mctp</td>
					<td></td>
					<td></td>
					<td>0.19%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68124">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68401">CVE-2026-68401</a></td>
					<td>firmware</td>
					<td></td>
					<td></td>
					<td>0.17%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68401">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68322">CVE-2026-68322</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.20%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68322">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68214">CVE-2026-68214</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.21%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68214">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68327">CVE-2026-68327</a></td>
					<td>wanxl</td>
					<td></td>
					<td></td>
					<td>0.17%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68327">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68188">CVE-2026-68188</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.20%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68188">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68132">CVE-2026-68132</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.17%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68132">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68304">CVE-2026-68304</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.20%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68304">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68098">CVE-2026-68098</a></td>
					<td>ksmbd</td>
					<td></td>
					<td></td>
					<td>0.17%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68098">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68348">CVE-2026-68348</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.18%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68348">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68195">CVE-2026-68195</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.20%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68195">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68419">CVE-2026-68419</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.16%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68419">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68171">CVE-2026-68171</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68171">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64523">CVE-2026-64523</a></td>
					<td>net/handshake</td>
					<td>Critical</td>
					<td>9.8</td>
					<td>0.36%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64523">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64388">CVE-2026-64388</a></td>
					<td>SMB Client</td>
					<td>High</td>
					<td>7.8</td>
					<td>0.12%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64388">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2025-37938">CVE-2025-37938</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.1</td>
					<td>0.18%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-37938">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68207">CVE-2026-68207</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td>0.21%</td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68207">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-50472">CVE-2026-50472</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50472">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-56174">CVE-2026-56174</a></td>
					<td>Windows Narrator</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56174">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-58650">CVE-2026-58650</a></td>
					<td>Visual Studio Code</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58650">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65768">CVE-2026-65768</a></td>
					<td>Teams</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65768">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-57105">CVE-2026-57105</a></td>
					<td>SharePoint</td>
					<td>High</td>
					<td>8.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57105">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62829">CVE-2026-62829</a></td>
					<td>SharePoint Server</td>
					<td>Medium</td>
					<td>4.6</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62829">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62827">CVE-2026-62827</a></td>
					<td>SharePoint Server</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62827">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62837">CVE-2026-62837</a></td>
					<td>SharePoint Server</td>
					<td>Medium</td>
					<td>6.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62837">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63514">CVE-2026-63514</a></td>
					<td>SharePoint Server</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63514">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63512">CVE-2026-63512</a></td>
					<td>SharePoint Server</td>
					<td>Medium</td>
					<td>6.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63512">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63516">CVE-2026-63516</a></td>
					<td>SharePoint Server</td>
					<td>Medium</td>
					<td>6.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63516">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63520">CVE-2026-63520</a></td>
					<td>SharePoint Server</td>
					<td>High</td>
					<td>8.1</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63520">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-40375">CVE-2026-40375</a></td>
					<td>Dynamics Business Central</td>
					<td>Medium</td>
					<td>6.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40375">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-54113">CVE-2026-54113</a></td>
					<td>Windows Kernel</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54113">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-54984">CVE-2026-54984</a></td>
					<td>Windows Imaging Component</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54984">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-49179">CVE-2026-49179</a></td>
					<td>Active Directory Domain Services</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49179">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-58612">CVE-2026-58612</a></td>
					<td>PowerShell Core</td>
					<td>High</td>
					<td>7.4</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58612">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-59113">CVE-2026-59113</a></td>
					<td>Visual Studio Code</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59113">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-47299">CVE-2026-47299</a></td>
					<td>Azure Monitor Agent</td>
					<td>High</td>
					<td>7.2</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47299">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-47285">CVE-2026-47285</a></td>
					<td>Visual Studio Code</td>
					<td>Medium</td>
					<td>6.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47285">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-59124">CVE-2026-59124</a></td>
					<td>High Performance Computing Pack</td>
					<td>Critical</td>
					<td>9.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59124">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-59127">CVE-2026-59127</a></td>
					<td>Windows Installer</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59127">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-59128">CVE-2026-59128</a></td>
					<td>Windows Encrypting File System</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59128">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-59133">CVE-2026-59133</a></td>
					<td>High Performance Computing (HPC) Pack</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59133">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-59132">CVE-2026-59132</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59132">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-59135">CVE-2026-59135</a></td>
					<td>Windows Search Component</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59135">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-59134">CVE-2026-59134</a></td>
					<td>Remote Desktop Client</td>
					<td>High</td>
					<td>7.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59134">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-59136">CVE-2026-59136</a></td>
					<td>COM</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59136">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-59137">CVE-2026-59137</a></td>
					<td>Windows Event Logging Service</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59137">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-59138">CVE-2026-59138</a></td>
					<td>Remote Registry Service</td>
					<td>Medium</td>
					<td>6.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59138">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61345">CVE-2026-61345</a></td>
					<td>Remote Registry Service</td>
					<td>Medium</td>
					<td>6.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61345">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61346">CVE-2026-61346</a></td>
					<td>Windows Graphics Kernel</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61346">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61353">CVE-2026-61353</a></td>
					<td>Windows Telephony Service</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61353">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61347">CVE-2026-61347</a></td>
					<td>Windows Event Logging Service</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61347">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61361">CVE-2026-61361</a></td>
					<td>Windows DHCP Client</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61361">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61348">CVE-2026-61348</a></td>
					<td>Windows Ancillary Function Driver for WinSock</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61348">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61356">CVE-2026-61356</a></td>
					<td>Remote Desktop Services</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61356">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61367">CVE-2026-61367</a></td>
					<td>Remote Desktop Services</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61367">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61923">CVE-2026-61923</a></td>
					<td>Windows Display Enhancement Service</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61923">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61366">CVE-2026-61366</a></td>
					<td>Windows Network Connection Broker</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61366">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61368">CVE-2026-61368</a></td>
					<td>Hyper-V</td>
					<td>Medium</td>
					<td>5.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61368">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61924">CVE-2026-61924</a></td>
					<td>Remote Desktop Client</td>
					<td>Medium</td>
					<td>6.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61924">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61925">CVE-2026-61925</a></td>
					<td>Windows Installer</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61925">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61927">CVE-2026-61927</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61927">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61928">CVE-2026-61928</a></td>
					<td>Windows Hello</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61928">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61930">CVE-2026-61930</a></td>
					<td>Windows Kernel</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61930">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61937">CVE-2026-61937</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61937">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62692">CVE-2026-62692</a></td>
					<td>Remote Desktop Services</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62692">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61932">CVE-2026-61932</a></td>
					<td>Windows DWM Core Library</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61932">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61933">CVE-2026-61933</a></td>
					<td>Windows</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61933">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61934">CVE-2026-61934</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61934">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61936">CVE-2026-61936</a></td>
					<td>Windows</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61936">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61939">CVE-2026-61939</a></td>
					<td>Winlogon</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61939">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62695">CVE-2026-62695</a></td>
					<td>Windows Storage</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62695">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62688">CVE-2026-62688</a></td>
					<td>Windows MIDI Service</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62688">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62690">CVE-2026-62690</a></td>
					<td>Windows Push Notifications</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62690">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62693">CVE-2026-62693</a></td>
					<td>Windows MIDI Service Module</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62693">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62696">CVE-2026-62696</a></td>
					<td>Windows Program Compatibility Assistant Service</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62696">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62702">CVE-2026-62702</a></td>
					<td>Windows</td>
					<td>Medium</td>
					<td>6.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62702">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62699">CVE-2026-62699</a></td>
					<td>Windows Universal Disk Format File System Driver</td>
					<td>Medium</td>
					<td>6.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62699">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62703">CVE-2026-62703</a></td>
					<td>Windows DWM Core Library</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62703">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62705">CVE-2026-62705</a></td>
					<td>Windows Bind Filter Driver</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62705">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62707">CVE-2026-62707</a></td>
					<td>Windows Modern Device Management</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62707">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62713">CVE-2026-62713</a></td>
					<td>Windows Cloud Files Mini Filter Driver</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62713">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62712">CVE-2026-62712</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62712">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62718">CVE-2026-62718</a></td>
					<td>Windows DHCP Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62718">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62715">CVE-2026-62715</a></td>
					<td>Windows DHCP Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62715">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62716">CVE-2026-62716</a></td>
					<td>Windows DHCP Server</td>
					<td>Medium</td>
					<td>6.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62716">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62719">CVE-2026-62719</a></td>
					<td>Windows Message Queuing</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62719">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62722">CVE-2026-62722</a></td>
					<td>Windows Bind Filter Driver</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62722">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62723">CVE-2026-62723</a></td>
					<td>Windows Telephony Service</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62723">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62724">CVE-2026-62724</a></td>
					<td>Windows Telephony Service</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62724">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62748">CVE-2026-62748</a></td>
					<td>Windows Telephony Service</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62748">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62729">CVE-2026-62729</a></td>
					<td>Windows Telephony Service</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62729">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62746">CVE-2026-62746</a></td>
					<td>Windows</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62746">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62740">CVE-2026-62740</a></td>
					<td>Windows Imaging Component</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62740">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62753">CVE-2026-62753</a></td>
					<td>Windows HTTP.sys</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62753">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62735">CVE-2026-62735</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62735">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62737">CVE-2026-62737</a></td>
					<td>Windows Kernel</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62737">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62739">CVE-2026-62739</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62739">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62742">CVE-2026-62742</a></td>
					<td>Windows DHCP Server</td>
					<td>Medium</td>
					<td>6.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62742">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62745">CVE-2026-62745</a></td>
					<td>Windows DHCP Server</td>
					<td>Medium</td>
					<td>6.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62745">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62747">CVE-2026-62747</a></td>
					<td>Windows Device Association Service</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62747">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62750">CVE-2026-62750</a></td>
					<td>Windows HTTP Protocol Stack</td>
					<td>Medium</td>
					<td>6.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62750">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62754">CVE-2026-62754</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62754">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62783">CVE-2026-62783</a></td>
					<td>Windows Remote Access Connection Manager</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62783">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62755">CVE-2026-62755</a></td>
					<td>Windows DHCP Client</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62755">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62758">CVE-2026-62758</a></td>
					<td>Windows Remote Access Connection Manager</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62758">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62766">CVE-2026-62766</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62766">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62773">CVE-2026-62773</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62773">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62772">CVE-2026-62772</a></td>
					<td>Windows Container Isolation FS Filter Driver</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62772">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62774">CVE-2026-62774</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62774">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62785">CVE-2026-62785</a></td>
					<td>Windows LDAP</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62785">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62777">CVE-2026-62777</a></td>
					<td>Windows License Manager</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62777">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62779">CVE-2026-62779</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62779">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62792">CVE-2026-62792</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>8.1</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62792">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62784">CVE-2026-62784</a></td>
					<td>Local Security Authority Server</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62784">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62787">CVE-2026-62787</a></td>
					<td>Windows DNS Server</td>
					<td>High</td>
					<td>7.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62787">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62798">CVE-2026-62798</a></td>
					<td>Windows</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62798">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62795">CVE-2026-62795</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62795">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62796">CVE-2026-62796</a></td>
					<td>Windows</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62796">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62797">CVE-2026-62797</a></td>
					<td>Windows NTFS</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62797">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62812">CVE-2026-62812</a></td>
					<td>Windows DHCP Server</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62812">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62815">CVE-2026-62815</a></td>
					<td>Microsoft QUIC</td>
					<td>Critical</td>
					<td>9.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62815">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62816">CVE-2026-62816</a></td>
					<td>Reliable Multicast Transport Driver (RMCAST)</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62816">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62817">CVE-2026-62817</a></td>
					<td>Windows DNS Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62817">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62818">CVE-2026-62818</a></td>
					<td>Active Directory Certificate Services</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62818">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62819">CVE-2026-62819</a></td>
					<td>Routing and Remote Access Service</td>
					<td>High</td>
					<td>8.1</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62819">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62820">CVE-2026-62820</a></td>
					<td>Windows DNS Server</td>
					<td>High</td>
					<td>8.1</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62820">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62876">CVE-2026-62876</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62876">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62877">CVE-2026-62877</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62877">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62878">CVE-2026-62878</a></td>
					<td>Windows DNS Server</td>
					<td>Critical</td>
					<td>9.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62878">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62889">CVE-2026-62889</a></td>
					<td>Windows Secure Socket Tunneling Protocol</td>
					<td>High</td>
					<td>8.1</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62889">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62890">CVE-2026-62890</a></td>
					<td>Windows GDI+</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62890">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62892">CVE-2026-62892</a></td>
					<td>Capability Access Management Service</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62892">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62893">CVE-2026-62893</a></td>
					<td>Windows Deployment Services</td>
					<td>Critical</td>
					<td>9.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62893">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62894">CVE-2026-62894</a></td>
					<td>Windows DWM Core Library</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62894">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62899">CVE-2026-62899</a></td>
					<td>.NET</td>
					<td>Medium</td>
					<td>5.9</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62899">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62900">CVE-2026-62900</a></td>
					<td>.NET</td>
					<td>Medium</td>
					<td>5.9</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62900">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62901">CVE-2026-62901</a></td>
					<td>.NET</td>
					<td>High</td>
					<td>7.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62901">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62902">CVE-2026-62902</a></td>
					<td>.NET</td>
					<td>Medium</td>
					<td>6.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62902">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62908">CVE-2026-62908</a></td>
					<td>Windows Backup Engine</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62908">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62909">CVE-2026-62909</a></td>
					<td>.NET</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62909">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62910">CVE-2026-62910</a></td>
					<td>Exchange Server</td>
					<td>High</td>
					<td>7.2</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62910">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62912">CVE-2026-62912</a></td>
					<td>Exchange Server</td>
					<td>Medium</td>
					<td>6.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62912">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62913">CVE-2026-62913</a></td>
					<td>Exchange Server</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62913">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62914">CVE-2026-62914</a></td>
					<td>Exchange Server</td>
					<td>High</td>
					<td>7.3</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62914">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62915">CVE-2026-62915</a></td>
					<td>Exchange Server</td>
					<td>Medium</td>
					<td>6.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62915">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-54123">CVE-2026-54123</a></td>
					<td>Defender for Endpoint</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54123">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63513">CVE-2026-63513</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63513">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63515">CVE-2026-63515</a></td>
					<td>Office</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63515">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63517">CVE-2026-63517</a></td>
					<td>Office</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63517">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63518">CVE-2026-63518</a></td>
					<td>Office Word</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63518">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63521">CVE-2026-63521</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63521">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63519">CVE-2026-63519</a></td>
					<td>Office</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63519">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64922">CVE-2026-64922</a></td>
					<td>SharePoint Server</td>
					<td>Medium</td>
					<td>4.6</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64922">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65657">CVE-2026-65657</a></td>
					<td>Office</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65657">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65656">CVE-2026-65656</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65656">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65658">CVE-2026-65658</a></td>
					<td>SharePoint Server</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65658">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65661">CVE-2026-65661</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65661">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65663">CVE-2026-65663</a></td>
					<td>SharePoint Server</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65663">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65660">CVE-2026-65660</a></td>
					<td>SharePoint Server</td>
					<td>Medium</td>
					<td>6.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65664">CVE-2026-65664</a></td>
					<td>Office</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65664">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65665">CVE-2026-65665</a></td>
					<td>SharePoint Server</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65665">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65662">CVE-2026-65662</a></td>
					<td>Windows</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65662">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65671">CVE-2026-65671</a></td>
					<td>Windows Remote Access API</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65671">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65672">CVE-2026-65672</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65672">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65675">CVE-2026-65675</a></td>
					<td>Visual Studio Code CoPilot Chat Extension</td>
					<td>High</td>
					<td>7.1</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65675">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65678">CVE-2026-65678</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65678">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65785">CVE-2026-65785</a></td>
					<td>Windows DHCP Client</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65785">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65784">CVE-2026-65784</a></td>
					<td>Windows</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65784">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65786">CVE-2026-65786</a></td>
					<td>Desktop Window Manager</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65786">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65789">CVE-2026-65789</a></td>
					<td>Windows DNS Server</td>
					<td>High</td>
					<td>8.1</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65789">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65787">CVE-2026-65787</a></td>
					<td>Desktop Window Manager</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65787">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65788">CVE-2026-65788</a></td>
					<td>Desktop Window Manager</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65788">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65807">CVE-2026-65807</a></td>
					<td>Excel</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65807">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65811">CVE-2026-65811</a></td>
					<td>Power BI</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65811">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65813">CVE-2026-65813</a></td>
					<td>Exchange Server</td>
					<td>Medium</td>
					<td>6.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65813">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65814">CVE-2026-65814</a></td>
					<td>Windows Storage Port Driver</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65814">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65815">CVE-2026-65815</a></td>
					<td>Dynamics 365</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65815">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-66799">CVE-2026-66799</a></td>
					<td>Windows Key Guard</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66799">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68792">CVE-2026-68792</a></td>
					<td>Office</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68792">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68793">CVE-2026-68793</a></td>
					<td>Excel</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68793">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68794">CVE-2026-68794</a></td>
					<td>Excel</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68794">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68795">CVE-2026-68795</a></td>
					<td>Excel</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68795">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68796">CVE-2026-68796</a></td>
					<td>Excel</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68796">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68800">CVE-2026-68800</a></td>
					<td>Excel</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68800">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68802">CVE-2026-68802</a></td>
					<td>Excel</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68802">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68807">CVE-2026-68807</a></td>
					<td>Excel</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68807">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68806">CVE-2026-68806</a></td>
					<td>Excel</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68806">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68808">CVE-2026-68808</a></td>
					<td>Excel</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68808">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68809">CVE-2026-68809</a></td>
					<td>PowerPoint</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68809">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68810">CVE-2026-68810</a></td>
					<td>Excel</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68810">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68811">CVE-2026-68811</a></td>
					<td>Excel</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68811">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68813">CVE-2026-68813</a></td>
					<td>Excel</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68813">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68815">CVE-2026-68815</a></td>
					<td>Excel</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68815">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68816">CVE-2026-68816</a></td>
					<td>Excel</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68816">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68819">CVE-2026-68819</a></td>
					<td>Windows Network File System</td>
					<td>Medium</td>
					<td>5.9</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68819">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68820">CVE-2026-68820</a></td>
					<td>Windows Ancillary Function Driver for WinSock</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68821">CVE-2026-68821</a></td>
					<td>Windows Package Manager</td>
					<td>High</td>
					<td>7.3</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68821">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-69320">CVE-2026-69320</a></td>
					<td>Visual Studio Code</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69320">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-69278">CVE-2026-69278</a></td>
					<td>Visual Studio Code</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69278">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-69306">CVE-2026-69306</a></td>
					<td>Visual Studio Code</td>
					<td>High</td>
					<td>8.2</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69306">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70307">CVE-2026-70307</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70307">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-66301">CVE-2026-66301</a></td>
					<td>Dynamics 365</td>
					<td>Medium</td>
					<td>6.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66301">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70312">CVE-2026-70312</a></td>
					<td>PowerPoint</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70312">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70311">CVE-2026-70311</a></td>
					<td>Office Word</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70311">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70313">CVE-2026-70313</a></td>
					<td>PowerPoint</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70313">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70310">CVE-2026-70310</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70310">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70316">CVE-2026-70316</a></td>
					<td>PowerPoint</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70316">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70315">CVE-2026-70315</a></td>
					<td>Office</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70315">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70321">CVE-2026-70321</a></td>
					<td>SharePoint</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70321">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70318">CVE-2026-70318</a></td>
					<td>Excel</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70318">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70314">CVE-2026-70314</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70314">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70317">CVE-2026-70317</a></td>
					<td>Office</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70317">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70325">CVE-2026-70325</a></td>
					<td>PowerPoint</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70325">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70319">CVE-2026-70319</a></td>
					<td>Office Word</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70319">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70320">CVE-2026-70320</a></td>
					<td>PowerPoint</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70320">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70323">CVE-2026-70323</a></td>
					<td>Office</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70323">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70322">CVE-2026-70322</a></td>
					<td>PowerPoint</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70322">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70324">CVE-2026-70324</a></td>
					<td>SharePoint</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70324">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70327">CVE-2026-70327</a></td>
					<td>Excel</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70327">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70328">CVE-2026-70328</a></td>
					<td>Excel</td>
					<td>Medium</td>
					<td>6.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70328">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70329">CVE-2026-70329</a></td>
					<td>Outlook</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70329">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70304">CVE-2026-70304</a></td>
					<td>Windows DNS</td>
					<td>Medium</td>
					<td>6.7</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70304">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70330">CVE-2026-70330</a></td>
					<td>Windows DNS</td>
					<td>Medium</td>
					<td>6.7</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70330">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70335">CVE-2026-70335</a></td>
					<td>GitHub Copilot</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70335">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70336">CVE-2026-70336</a></td>
					<td>Visual Studio Code</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70336">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-57104">CVE-2026-57104</a></td>
					<td>Azure Storage Explorer</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57104">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70340">CVE-2026-70340</a></td>
					<td>Azure CycleCloud</td>
					<td>High</td>
					<td>8.1</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70340">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65806">CVE-2026-65806</a></td>
					<td>Azure CycleCloud</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65806">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61352">CVE-2026-61352</a></td>
					<td>Remote Desktop Client</td>
					<td>High</td>
					<td>7.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61352">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65783">CVE-2026-65783</a></td>
					<td>Windows Autopilot</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65783">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-66804">CVE-2026-66804</a></td>
					<td>Windows Cross Device Service</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66804">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70344">CVE-2026-70344</a></td>
					<td>Windows Installer</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70344">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70345">CVE-2026-70345</a></td>
					<td>Windows Installer</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70345">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70346">CVE-2026-70346</a></td>
					<td>Windows Installer</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70346">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70347">CVE-2026-70347</a></td>
					<td>Windows Installer</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70347">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70348">CVE-2026-70348</a></td>
					<td>Windows Management Services</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70348">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70355">CVE-2026-70355</a></td>
					<td>SharePoint Server</td>
					<td>High</td>
					<td>7.3</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70355">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-72971">CVE-2026-72971</a></td>
					<td>Windows Container Isolation FS Filter Driver</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72971">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-42976">CVE-2026-42976</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42976">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-54981">CVE-2026-54981</a></td>
					<td>Visual Studio Code</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54981">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-6726">CVE-2026-6726</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-6726">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-58641">CVE-2026-58641</a></td>
					<td>.NET</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58641">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-58651">CVE-2026-58651</a></td>
					<td>Word</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58651">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-59122">CVE-2026-59122</a></td>
					<td>Windows Telephony Service</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59122">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-59125">CVE-2026-59125</a></td>
					<td>Virtual Hard Disk (VHD) Miniport Driver</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59125">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-59126">CVE-2026-59126</a></td>
					<td>Windows Event Logging Service</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59126">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61349">CVE-2026-61349</a></td>
					<td>Windows Work Folder Service</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61349">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61363">CVE-2026-61363</a></td>
					<td>Remote Desktop Client</td>
					<td>High</td>
					<td>7.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61363">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61359">CVE-2026-61359</a></td>
					<td>Windows Storage</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61359">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61355">CVE-2026-61355</a></td>
					<td>Windows Sensor Data Service</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61355">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61364">CVE-2026-61364</a></td>
					<td>Windows Remote Desktop Services</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61364">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61365">CVE-2026-61365</a></td>
					<td>Remote Desktop Services</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61365">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61357">CVE-2026-61357</a></td>
					<td>Application Information Services</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61357">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61358">CVE-2026-61358</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61358">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61360">CVE-2026-61360</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61360">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61920">CVE-2026-61920</a></td>
					<td>Windows DNS Server</td>
					<td>Medium</td>
					<td>6.6</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61920">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61926">CVE-2026-61926</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61926">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61918">CVE-2026-61918</a></td>
					<td>Remote Desktop Client</td>
					<td>Medium</td>
					<td>6.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61918">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61921">CVE-2026-61921</a></td>
					<td>Remote Desktop Client</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61921">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61929">CVE-2026-61929</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61929">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-61938">CVE-2026-61938</a></td>
					<td>Windows Installer</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61938">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62698">CVE-2026-62698</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62698">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62700">CVE-2026-62700</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62700">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62701">CVE-2026-62701</a></td>
					<td>Windows Telephony Service</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62701">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62708">CVE-2026-62708</a></td>
					<td>Windows Kernel</td>
					<td>Medium</td>
					<td>6.4</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62708">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62709">CVE-2026-62709</a></td>
					<td>Windows GDI+</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62709">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62710">CVE-2026-62710</a></td>
					<td>Windows Device Association Service</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62710">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62711">CVE-2026-62711</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62711">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62720">CVE-2026-62720</a></td>
					<td>Windows DHCP Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62720">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62714">CVE-2026-62714</a></td>
					<td>Windows DHCP Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62714">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62717">CVE-2026-62717</a></td>
					<td>Windows Message Queuing</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62717">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62721">CVE-2026-62721</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62721">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62725">CVE-2026-62725</a></td>
					<td>Windows Telephony Service</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62725">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62726">CVE-2026-62726</a></td>
					<td>Windows Telephony Service</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62726">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62728">CVE-2026-62728</a></td>
					<td>Windows Common Log File System Driver</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62728">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62733">CVE-2026-62733</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62733">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62743">CVE-2026-62743</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62743">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62730">CVE-2026-62730</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62730">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62732">CVE-2026-62732</a></td>
					<td>Windows Telephony Service</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62732">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62734">CVE-2026-62734</a></td>
					<td>Windows Telephony Service</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62734">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62736">CVE-2026-62736</a></td>
					<td>Windows DHCP Client</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62736">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62757">CVE-2026-62757</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62757">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62741">CVE-2026-62741</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62741">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62749">CVE-2026-62749</a></td>
					<td>Windows Kernel</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62749">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62751">CVE-2026-62751</a></td>
					<td>Windows Projected File System</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62751">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62752">CVE-2026-62752</a></td>
					<td>Windows Kerberos</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62752">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62769">CVE-2026-62769</a></td>
					<td>Windows DNS</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62769">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62771">CVE-2026-62771</a></td>
					<td>Windows Cloud Files Mini Filter Driver</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62771">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62761">CVE-2026-62761</a></td>
					<td>Windows DHCP Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62761">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62768">CVE-2026-62768</a></td>
					<td>Windows Installer</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62768">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62770">CVE-2026-62770</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62770">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62775">CVE-2026-62775</a></td>
					<td>Windows Container Isolation FS Filter Driver</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62775">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62799">CVE-2026-62799</a></td>
					<td>Windows SMB Client</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62799">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62776">CVE-2026-62776</a></td>
					<td>Windows DHCP Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62776">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62778">CVE-2026-62778</a></td>
					<td>Windows DNS</td>
					<td>High</td>
					<td>8.1</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62778">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62780">CVE-2026-62780</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62780">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62782">CVE-2026-62782</a></td>
					<td>Windows SMB Client</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62782">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62781">CVE-2026-62781</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62781">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62800">CVE-2026-62800</a></td>
					<td>Windows SMB Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62800">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62786">CVE-2026-62786</a></td>
					<td>Windows</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62786">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62788">CVE-2026-62788</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62788">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62790">CVE-2026-62790</a></td>
					<td>Windows SMB Server</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62790">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62793">CVE-2026-62793</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62793">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62803">CVE-2026-62803</a></td>
					<td>Windows DHCP Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62803">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62807">CVE-2026-62807</a></td>
					<td>Windows DHCP Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62807">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62811">CVE-2026-62811</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62811">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62814">CVE-2026-62814</a></td>
					<td>Windows DHCP Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62814">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62823">CVE-2026-62823</a></td>
					<td>Windows DHCP Server</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62823">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62824">CVE-2026-62824</a></td>
					<td>Remote Desktop Client</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62824">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62822">CVE-2026-62822</a></td>
					<td>Windows GDI+</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62822">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62832">CVE-2026-62832</a></td>
					<td>Windows User Profile Service</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62832">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62871">CVE-2026-62871</a></td>
					<td>.NET</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62871">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62880">CVE-2026-62880</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62880">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62881">CVE-2026-62881</a></td>
					<td>Windows DNS</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62881">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62883">CVE-2026-62883</a></td>
					<td>Windows DNS</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62883">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62885">CVE-2026-62885</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62885">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62886">CVE-2026-62886</a></td>
					<td>.NET</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62886">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62887">CVE-2026-62887</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62887">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62888">CVE-2026-62888</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62888">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62911">CVE-2026-62911</a></td>
					<td>Exchange Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62842">CVE-2026-62842</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62842">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63524">CVE-2026-63524</a></td>
					<td>Office</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63524">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63525">CVE-2026-63525</a></td>
					<td>Office</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63525">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63526">CVE-2026-63526</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63526">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63528">CVE-2026-63528</a></td>
					<td>Office Word</td>
					<td>Medium</td>
					<td>5.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63528">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63527">CVE-2026-63527</a></td>
					<td>Office Word</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63527">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63529">CVE-2026-63529</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63529">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63530">CVE-2026-63530</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63530">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63531">CVE-2026-63531</a></td>
					<td>Office Word</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63531">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63532">CVE-2026-63532</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63532">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-63533">CVE-2026-63533</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63533">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64897">CVE-2026-64897</a></td>
					<td>SharePoint Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64897">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64898">CVE-2026-64898</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64898">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64900">CVE-2026-64900</a></td>
					<td>SharePoint Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64900">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64902">CVE-2026-64902</a></td>
					<td>SharePoint Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64902">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64899">CVE-2026-64899</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64899">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64903">CVE-2026-64903</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64903">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64901">CVE-2026-64901</a></td>
					<td>SharePoint Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64901">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64904">CVE-2026-64904</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64904">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64905">CVE-2026-64905</a></td>
					<td>Office Word</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64905">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64907">CVE-2026-64907</a></td>
					<td>Office Word</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64907">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64906">CVE-2026-64906</a></td>
					<td>Access</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64906">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64909">CVE-2026-64909</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64909">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64910">CVE-2026-64910</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64910">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64912">CVE-2026-64912</a></td>
					<td>Access</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64912">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64911">CVE-2026-64911</a></td>
					<td>Office</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64911">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64908">CVE-2026-64908</a></td>
					<td>Office Access</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64908">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64914">CVE-2026-64914</a></td>
					<td>Access</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64914">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64915">CVE-2026-64915</a></td>
					<td>Office Word</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64915">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64916">CVE-2026-64916</a></td>
					<td>SharePoint Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64916">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64920">CVE-2026-64920</a></td>
					<td>Access</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64920">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64917">CVE-2026-64917</a></td>
					<td>Office Word</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64917">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64919">CVE-2026-64919</a></td>
					<td>Access</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64919">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-64921">CVE-2026-64921</a></td>
					<td>SharePoint Server</td>
					<td>High</td>
					<td>8.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64921">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62882">CVE-2026-62882</a></td>
					<td>Outlook</td>
					<td>Medium</td>
					<td>4.3</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62882">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65673">CVE-2026-65673</a></td>
					<td>Entra Connect</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65673">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65681">CVE-2026-65681</a></td>
					<td>Windows iSCSI Target Service</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65681">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65679">CVE-2026-65679</a></td>
					<td>Windows iSCSI Target Service</td>
					<td>High</td>
					<td>8.1</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65679">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65773">CVE-2026-65773</a></td>
					<td>Windows Kernel</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65773">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65774">CVE-2026-65774</a></td>
					<td>Windows Installer</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65774">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65775">CVE-2026-65775</a></td>
					<td>Windows</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65775">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65776">CVE-2026-65776</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65776">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65779">CVE-2026-65779</a></td>
					<td>Windows Autopilot</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65779">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65780">CVE-2026-65780</a></td>
					<td>Windows Autopilot</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65780">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65778">CVE-2026-65778</a></td>
					<td>Windows Autopilot</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65778">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65782">CVE-2026-65782</a></td>
					<td>Windows Autopilot</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65782">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65781">CVE-2026-65781</a></td>
					<td>Windows Autopilot</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65781">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65790">CVE-2026-65790</a></td>
					<td>Windows Message Queuing</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65790">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65791">CVE-2026-65791</a></td>
					<td>Windows iSCSI Target Service</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65791">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65795">CVE-2026-65795</a></td>
					<td>Windows DNS</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65795">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65794">CVE-2026-65794</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65794">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65797">CVE-2026-65797</a></td>
					<td>Windows DNS</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65797">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65799">CVE-2026-65799</a></td>
					<td>Windows DNS</td>
					<td>Medium</td>
					<td>6.7</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65799">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65798">CVE-2026-65798</a></td>
					<td>Windows DNS</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65798">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65796">CVE-2026-65796</a></td>
					<td>Windows iSCSI Target Service</td>
					<td>Medium</td>
					<td>5.9</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65796">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-66802">CVE-2026-66802</a></td>
					<td>Azure Attestation</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66802">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-66805">CVE-2026-66805</a></td>
					<td>SharePoint Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66805">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-66806">CVE-2026-66806</a></td>
					<td>Office Word</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66806">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-66807">CVE-2026-66807</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66807">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-66808">CVE-2026-66808</a></td>
					<td>SharePoint Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66808">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-66810">CVE-2026-66810</a></td>
					<td>Office Word</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66810">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-66809">CVE-2026-66809</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66809">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68797">CVE-2026-68797</a></td>
					<td>Excel</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68797">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68798">CVE-2026-68798</a></td>
					<td>Excel</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68798">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68799">CVE-2026-68799</a></td>
					<td>Excel</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68799">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68801">CVE-2026-68801</a></td>
					<td>Excel</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68801">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68803">CVE-2026-68803</a></td>
					<td>Excel</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68803">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68804">CVE-2026-68804</a></td>
					<td>Excel</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68804">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68805">CVE-2026-68805</a></td>
					<td>Excel</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68805">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68812">CVE-2026-68812</a></td>
					<td>Excel</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68812">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68814">CVE-2026-68814</a></td>
					<td>Excel</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68814">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-68817">CVE-2026-68817</a></td>
					<td>Excel</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68817">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-56179">CVE-2026-56179</a></td>
					<td>Windows</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56179">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70130">CVE-2026-70130</a></td>
					<td>Office</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70130">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70306">CVE-2026-70306</a></td>
					<td>SharePoint</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70306">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70326">CVE-2026-70326</a></td>
					<td>SharePoint Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70326">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70337">CVE-2026-70337</a></td>
					<td>PowerShell Core</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70337">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-70354">CVE-2026-70354</a></td>
					<td>.NET Core</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70354">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-71331">CVE-2026-71331</a></td>
					<td>Azure Attestation</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71331">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62738">CVE-2026-62738</a></td>
					<td>Windows Management Instrumentation</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62738">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62898">CVE-2026-62898</a></td>
					<td>Microsoft QUIC</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62898">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65767">CVE-2026-65767</a></td>
					<td>Teams</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65767">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-58639">CVE-2026-58639</a></td>
					<td>SharePoint Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58639">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62839">CVE-2026-62839</a></td>
					<td>SharePoint Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62839">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62917">CVE-2026-62917</a></td>
					<td>SharePoint Server</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62917">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-65680">CVE-2026-65680</a></td>
					<td>OneDrive</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65680">MSRC</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-50516">CVE-2026-50516</a></td>
					<td>Azure Kubernetes Service</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50516">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62869">CVE-2026-62869</a></td>
					<td>Microsoft Entra</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62869">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-62872">CVE-2026-62872</a></td>
					<td>Microsoft .NET Framework</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62872">NVD</a> (authoritative)</td>
			</tr>
	</tbody>
</table>
<h2 id="cve-2026-50481">CVE-2026-50481</h2>
<p>CVE-2026-50481 is a critical vulnerability in Microsoft Azure Active Directory involving the modification of assumed-immutable data (MAID). An authorized attacker can exploit this flaw to escalate privileges within the environment over a network, potentially leading to unauthorized administrative access.</p>
<p>Affected products:</p>
<ul>
<li>Azure Active Directory</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50481">https://nvd.nist.gov/vuln/detail/CVE-2026-50481</a></p>
<h2 id="cve-2026-50515">CVE-2026-50515</h2>
<p>CVE-2026-50515 is a critical deserialization of untrusted data vulnerability in Azure Service Bus that permits an authenticated attacker with low privileges to achieve remote code execution. Detection efforts should focus on monitoring anomalous serialized data payloads sent to service bus endpoints and unexpected process execution spawned by the Azure Service Bus service account.</p>
<p>Affected products:</p>
<ul>
<li>Azure Service Bus</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50515">https://nvd.nist.gov/vuln/detail/CVE-2026-50515</a></p>
<h2 id="cve-2026-56161">CVE-2026-56161</h2>
<p>CVE-2026-56161 describes an improper access control vulnerability in Microsoft Azure Logic Apps. An authenticated attacker can exploit this vulnerability to disclose sensitive information over a network. The vulnerability carries a CVSS 3.1 base score of 9.6, indicating a critical risk.</p>
<p>Affected products:</p>
<ul>
<li>Azure Logic Apps</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-56161">https://nvd.nist.gov/vuln/detail/CVE-2026-56161</a></p>
<h2 id="cve-2026-59115">CVE-2026-59115</h2>
<p>CVE-2026-59115 is a critical path traversal vulnerability in the Microsoft Entra Provisioning Service (SyncFabric). An authorized attacker can leverage this vulnerability by using a specific input string ('.../...//') to elevate their privileges over a network. The vulnerability has a CVSS base score of 9.9, indicating a significant risk to the integrity, confidentiality, and availability of the affected cloud service.</p>
<p>Affected products:</p>
<ul>
<li>Microsoft Entra Provisioning Service</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-59115">https://nvd.nist.gov/vuln/detail/CVE-2026-59115</a></p>
<h2 id="cve-2026-59118">CVE-2026-59118</h2>
<p>CVE-2026-59118 is an improper authorization vulnerability in Microsoft Power Apps that allows an unauthorized attacker to perform a privilege escalation over a network. The vulnerability carries a CVSS 3.1 base score of 9.3, indicating a critical severity impact on confidentiality and integrity, necessitating restricted access controls within the affected cloud service.</p>
<p>Affected products:</p>
<ul>
<li>Power Apps</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-59118">https://nvd.nist.gov/vuln/detail/CVE-2026-59118</a></p>
<h2 id="cve-2026-62830">CVE-2026-62830</h2>
<p>A vulnerability in the Azure SRE Agent stemming from missing authorization (CWE-862) allows an already authorized network attacker to perform privilege escalation. The vulnerability is rated critical with a CVSS 3.1 score of 9.9, as it enables full scope impact across confidentiality, integrity, and availability within the cloud environment.</p>
<p>Affected products:</p>
<ul>
<li>Azure SRE Agent</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62830">https://nvd.nist.gov/vuln/detail/CVE-2026-62830</a></p>
<h2 id="cve-2026-62873">CVE-2026-62873</h2>
<p>The Microsoft 365 Admin Center is vulnerable to an improper verification of cryptographic signature vulnerability (CWE-347). This flaw allows a remote, unauthorized attacker to elevate their privileges over a network, potentially leading to full compromise of confidentiality, integrity, and availability.</p>
<p>Affected products:</p>
<ul>
<li>Microsoft 365 Admin Center</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62873">https://nvd.nist.gov/vuln/detail/CVE-2026-62873</a></p>
<h2 id="cve-2026-62896">CVE-2026-62896</h2>
<p>Microsoft Teams contains an improper authentication vulnerability that allows an authenticated attacker to perform privilege escalation over a network. This flaw represents a critical security risk due to the potential for unauthorized access elevation within the application environment.</p>
<p>Affected products:</p>
<ul>
<li>Microsoft Teams</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62896">https://nvd.nist.gov/vuln/detail/CVE-2026-62896</a></p>
<p>Related in this roundup: <a href="#cve-2026-65667">CVE-2026-65667</a>, <a href="#cve-2026-62918">CVE-2026-62918</a>.</p>
<h2 id="cve-2026-63508">CVE-2026-63508</h2>
<p>Microsoft Planetary Computer Pro (GeoCatalog) contains a vulnerability due to missing authentication for a critical function. This allows an unauthorized attacker to perform privilege escalation over a network. The vulnerability is classified as critical and has a CVSS base score of 10.0.</p>
<p>Affected products:</p>
<ul>
<li>Microsoft Planetary Computer Pro (GeoCatalog)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-63508">https://nvd.nist.gov/vuln/detail/CVE-2026-63508</a></p>
<h2 id="cve-2026-65667">CVE-2026-65667</h2>
<p>CVE-2026-65667 is a critical security vulnerability in Microsoft Teams involving missing authorization (CWE-862). This flaw allows a remote, unauthenticated attacker to elevate privileges over a network, potentially leading to unauthorized access to sensitive information and system integrity compromises.</p>
<p>Affected products:</p>
<ul>
<li>Microsoft Teams</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-65667">https://nvd.nist.gov/vuln/detail/CVE-2026-65667</a></p>
<p>Related in this roundup: <a href="#cve-2026-62896">CVE-2026-62896</a>, <a href="#cve-2026-62918">CVE-2026-62918</a>.</p>
<h2 id="cve-2026-68823">CVE-2026-68823</h2>
<p>CVE-2026-68823 involves an exposed dangerous method or function in the Azure Confidential Ledger service, which allows an authorized attacker to achieve remote code execution over a network. The vulnerability is classified as CWE-749 and carries a critical CVSS base score of 9.1.</p>
<p>Affected products:</p>
<ul>
<li>Azure Confidential Ledger</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-68823">https://nvd.nist.gov/vuln/detail/CVE-2026-68823</a></p>
<h2 id="cve-2026-70332">CVE-2026-70332</h2>
<p>CVE-2026-70332 is a Server-Side Request Forgery (SSRF) vulnerability in Microsoft SharePoint Online. An unauthenticated attacker can exploit this flaw to perform spoofing over a network, potentially leading to unauthorized information disclosure, interaction with internal services, or further lateral movement within the cloud environment.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Online</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-70332">https://nvd.nist.gov/vuln/detail/CVE-2026-70332</a></p>
<h2 id="cve-2026-49163">CVE-2026-49163</h2>
<p>Application Insights Profiler is vulnerable to a path traversal flaw (CWE-22) that allows an authorized attacker to elevate their privileges over a network. This vulnerability indicates improper limitation of a pathname to a restricted directory.</p>
<p>Affected products:</p>
<ul>
<li>Application Insights Profiler</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49163">https://nvd.nist.gov/vuln/detail/CVE-2026-49163</a></p>
<h2 id="cve-2026-62836">CVE-2026-62836</h2>
<p>CVE-2026-62836 identifies a vulnerability in Azure SQL Managed Instance due to improper restriction of communication channels to intended endpoints. This flaw allows an unauthenticated, remote attacker to escalate privileges over a network connection by exploiting the misconfigured communication path.</p>
<p>Affected products:</p>
<ul>
<li>Azure SQL Managed Instance</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62836">https://nvd.nist.gov/vuln/detail/CVE-2026-62836</a></p>
<h2 id="cve-2026-62918">CVE-2026-62918</h2>
<p>CVE-2026-62918 is a vulnerability in Microsoft Teams involving improper verification of cryptographic signatures. This flaw allows an unauthorized remote attacker to perform spoofing attacks over a network, potentially leading to unauthorized data manipulation or masquerading within the platform.</p>
<p>Affected products:</p>
<ul>
<li>Microsoft Teams</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62918">https://nvd.nist.gov/vuln/detail/CVE-2026-62918</a></p>
<p>Related in this roundup: <a href="#cve-2026-62896">CVE-2026-62896</a>, <a href="#cve-2026-65667">CVE-2026-65667</a>.</p>
<h2 id="cve-2026-65668">CVE-2026-65668</h2>
<p>Microsoft Purview eDiscovery contains an improper access control vulnerability that allows an authenticated attacker to perform a privilege escalation attack over the network. Detection should focus on monitoring unauthorized account role modifications or unexpected administrative actions within the Purview compliance console.</p>
<p>Affected products:</p>
<ul>
<li>Microsoft Purview eDiscovery</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-65668">https://nvd.nist.gov/vuln/detail/CVE-2026-65668</a></p>
<h2 id="cve-2026-68480">CVE-2026-68480</h2>
<p>CVE-2026-68480 relates to a vulnerability in the x86 Safe-RET implementation regarding interrupt injection, which could allow a local attacker to potentially bypass security protections or escalate privileges. Security updates for affected versions of the Windows operating system address the robustness of the return mechanism against these specific interrupt vectors.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68480">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68480</a></p>
<p>Related in this roundup: <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-64564">CVE-2026-64564</h2>
<p>CVE-2026-64564 involves a vulnerability in the SCTP (Stream Control Transmission Protocol) implementation within Microsoft Windows. The issue occurs during DEL-IP processing, where the ASCONF (Address Configuration Change Chunk) packet handling incorrectly attempts to free its own transport, potentially leading to a use-after-free or memory management error.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64564">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64564</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-64590">CVE-2026-64590</h2>
<p>CVE-2026-64590 identifies an issue within the dma-buf/udmabuf component where a redundant CPU synchronization triggers a cacheline EEXIST warning. This update addresses the underlying logic to ensure proper synchronization handling.</p>
<p>Affected products:</p>
<ul>
<li>dma-buf/udmabuf</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64590">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64590</a></p>
<h2 id="cve-2026-54876">CVE-2026-54876</h2>
<p>CVE-2026-54876 describes a client-side memory leak vulnerability within the OCSP (Online Certificate Status Protocol) response checking mechanism in Microsoft Windows products.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54876">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54876</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-44605">CVE-2026-44605</h2>
<p>CVE-2026-44605 describes a heap-based buffer overflow vulnerability located in the ndb slot table parsing logic within Rpm. This vulnerability could potentially allow for arbitrary code execution or memory corruption when processing malformed slot tables.</p>
<p>Affected products:</p>
<ul>
<li>Rpm</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44605">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44605</a></p>
<h2 id="cve-2026-64573">CVE-2026-64573</h2>
<p>A vulnerability identified in the Bluetooth NVM tag length TLV parser leads to an underflow condition. This security update from Microsoft addresses the flaw to prevent potential memory corruption or exploitation within the Bluetooth component.</p>
<p>Affected products:</p>
<ul>
<li>Bluetooth</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64573">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64573</a></p>
<h2 id="cve-2026-64565">CVE-2026-64565</h2>
<p>CVE-2026-64565 refers to a heap-based buffer overflow vulnerability located within the ims_pcu_process_data() function of the ims-pcu component, potentially allowing for memory corruption or arbitrary code execution.</p>
<p>Affected products:</p>
<ul>
<li>ims-pcu</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64565">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64565</a></p>
<h2 id="cve-2026-64578">CVE-2026-64578</h2>
<p>CVE-2026-64578 identifies a vulnerability in the ksmbd kernel-mode SMB server, where insufficient validation of compound request sizes before reading StructureSize2 can lead to memory safety issues. Detection engineering should focus on monitoring SMB traffic patterns for malformed or oversized requests that could trigger improper bounds handling.</p>
<p>Affected products:</p>
<ul>
<li>ksmbd</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64578">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64578</a></p>
<p>Related in this roundup: <a href="#cve-2026-68097">CVE-2026-68097</a>, <a href="#cve-2026-68130">CVE-2026-68130</a>, <a href="#cve-2026-68099">CVE-2026-68099</a>, <a href="#cve-2026-68098">CVE-2026-68098</a>.</p>
<h2 id="cve-2024-21380">CVE-2024-21380</h2>
<p>CVE-2024-21380 is an information disclosure vulnerability affecting Microsoft Dynamics Business Central and Dynamics NAV. The disclosure indicates an informational update to build numbers provided by Microsoft in the Security Update Guide, with no functional changes described in the provided content.</p>
<p>Affected products:</p>
<ul>
<li>Dynamics Business Central</li>
<li>Dynamics NAV</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21380">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21380</a></p>
<p>Related in this roundup: <a href="#cve-2026-40375">CVE-2026-40375</a>.</p>
<h2 id="cve-2025-2308">CVE-2025-2308</h2>
<p>CVE-2025-2308 is a heap-based buffer overflow vulnerability residing in the H5Z__scaleoffset_decompress_one_byte function within the HDF5 scale-offset filter, potentially allowing for arbitrary code execution if a maliciously crafted HDF5 file is processed.</p>
<p>Affected products:</p>
<ul>
<li>HDF5</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-2308">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-2308</a></p>
<p>Related in this roundup: <a href="#cve-2025-2309">CVE-2025-2309</a>.</p>
<h2 id="cve-2025-2309">CVE-2025-2309</h2>
<p>CVE-2025-2309 refers to a heap-based buffer overflow vulnerability identified in the HDF5 library specifically within the H5T__bit_copy type conversion logic. The vulnerability could potentially lead to memory corruption or arbitrary code execution if an attacker provides a maliciously crafted HDF5 file to an application utilizing the affected library code for data processing.</p>
<p>Affected products:</p>
<ul>
<li>HDF5</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-2309">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-2309</a></p>
<p>Related in this roundup: <a href="#cve-2025-2308">CVE-2025-2308</a>.</p>
<h2 id="cve-2026-68097">CVE-2026-68097</h2>
<p>CVE-2026-68097 identifies a vulnerability in ksmbd where the software fails to properly validate the size of an Access Control Entry (ACE) against the number of Security Identifier (SID) sub-authorities. This vulnerability could potentially lead to memory corruption or other instability issues when processing malicious SMB traffic.</p>
<p>Affected products:</p>
<ul>
<li>ksmbd</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68097">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68097</a></p>
<p>Related in this roundup: <a href="#cve-2026-64578">CVE-2026-64578</a>, <a href="#cve-2026-68130">CVE-2026-68130</a>, <a href="#cve-2026-68099">CVE-2026-68099</a>, <a href="#cve-2026-68098">CVE-2026-68098</a>.</p>
<h2 id="cve-2026-68388">CVE-2026-68388</h2>
<p>CVE-2026-68388 addresses a vulnerability in the SMB client component of the Windows operating system related to the improper handling of overlapping allocated ranges during fallocate operations, which may lead to memory corruption or instability.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68388">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68388</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68187">CVE-2026-68187</h2>
<p>CVE-2026-68187 describes an unsigned loop counter wrap vulnerability within the transfer_args_to_stack() function in Microsoft software, potentially allowing for memory corruption or unstable execution states.</p>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68187">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68187</a></p>
<h2 id="cve-2026-68152">CVE-2026-68152</h2>
<p>CVE-2026-68152 addresses a use-after-free vulnerability within the AMT delayed works component in Microsoft products, which could potentially lead to system instability or arbitrary code execution.</p>
<p>Affected products:</p>
<ul>
<li>AMT</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68152">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68152</a></p>
<h2 id="cve-2026-68189">CVE-2026-68189</h2>
<p>CVE-2026-68189 refers to a vulnerability within the Bluetooth hci_sync component in Microsoft Windows. The issue involves a lack of protection during UUID list traversal, which may lead to memory safety issues or instability during Bluetooth stack operations.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68189">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68189</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68312">CVE-2026-68312</h2>
<p>CVE-2026-68312 describes a memory leak vulnerability in the CIFS (Common Internet File System) implementation within the Windows kernel. The issue specifically occurs in the deferred close drain paths when a kmalloc memory allocation fails, leading to a cifsFileInfo object leak, which could potentially be leveraged for denial-of-service conditions.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68312">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68312</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68130">CVE-2026-68130</h2>
<p>CVE-2026-68130 identifies a security vulnerability in the ksmbd component within Microsoft Windows Server. The flaw involves the premature destruction of the previous session before NTLM authentication is fully completed, which could lead to authentication bypass or session handling errors. Security teams should ensure that the provided update is applied to affected server environments to enforce proper session lifecycle management during the authentication handshake.</p>
<p>Affected products:</p>
<ul>
<li>ksmbd</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68130">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68130</a></p>
<p>Related in this roundup: <a href="#cve-2026-64578">CVE-2026-64578</a>, <a href="#cve-2026-68097">CVE-2026-68097</a>, <a href="#cve-2026-68099">CVE-2026-68099</a>, <a href="#cve-2026-68098">CVE-2026-68098</a>.</p>
<h2 id="cve-2026-68176">CVE-2026-68176</h2>
<p>CVE-2026-68176 describes a vulnerability in mmiotrace involving a potential NULL pointer dereferencing issue regarding the hiter-&gt;dev pointer. This flaw could lead to a system crash or unstable behavior when handled improperly during tracing operations.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68176">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68176</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68145">CVE-2026-68145</h2>
<p>CVE-2026-68145 concerns an out-of-bounds vulnerability in the iomap component, specifically triggered during bitmap_set operations involving zero-length ranges. This flaw could potentially allow for memory corruption, impacting system stability or security.</p>
<p>Affected products:</p>
<ul>
<li>iomap</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68145">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68145</a></p>
<h2 id="cve-2026-68318">CVE-2026-68318</h2>
<p>CVE-2026-68318 is a vulnerability in pds_core involving a use-after-free condition triggered during the removal process of a workqueue. The issue arises due to improper memory management, which could potentially be exploited to cause a system crash or arbitrary code execution.</p>
<p>Affected products:</p>
<ul>
<li>pds_core</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68318">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68318</a></p>
<h2 id="cve-2026-68118">CVE-2026-68118</h2>
<p>CVE-2026-68118 describes a vulnerability in the TCP stack implementation where improper handling of challenge ACKs for non-exact RST packets in the SYN-RECEIVED state can be exploited to cause a denial-of-service condition or disrupt network connections.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68118">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68118</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68175">CVE-2026-68175</h2>
<p>CVE-2026-68175 refers to a resource leak vulnerability identified within the mmiotrace trace_pipe close function in Microsoft Windows, which could potentially be leveraged for local denial-of-service conditions or resource exhaustion.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68175">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68175</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68328">CVE-2026-68328</h2>
<p>CVE-2026-68328 identifies a vulnerability within the Windows nfp (Near-Field Proximity) driver related to resource mutex allocation, as reported by the Microsoft Security Response Center.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68328">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68328</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68406">CVE-2026-68406</h2>
<p>CVE-2026-68406 identifies a vulnerability in the wifi cfg80211 subsystem where the PMSR FTM preamble range is improperly validated. This flaw can potentially lead to memory corruption or instability within the wireless driver stack, necessitating a security update to ensure proper bounds checking for wireless frame parameters.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68406">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68406</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68317">CVE-2026-68317</h2>
<p>CVE-2026-68317 refers to a vulnerability in pds_core involving race conditions during auxiliary device addition or deletion. The issue requires patching to ensure stability and prevent potential exploitation via race conditions.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68317">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68317</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68099">CVE-2026-68099</h2>
<p>CVE-2026-68099 is a vulnerability in the ksmbd component within Microsoft Windows, where an integer overflow check in check_add_overflow() fails to correctly restore DACL size, potentially leading to the processing of malformed ACLs. This flaw could be exploited to cause memory corruption or denial of service conditions by submitting specially crafted SMB packets.</p>
<p>Affected products:</p>
<ul>
<li>ksmbd</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68099">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68099</a></p>
<p>Related in this roundup: <a href="#cve-2026-64578">CVE-2026-64578</a>, <a href="#cve-2026-68097">CVE-2026-68097</a>, <a href="#cve-2026-68130">CVE-2026-68130</a>, <a href="#cve-2026-68098">CVE-2026-68098</a>.</p>
<h2 id="cve-2026-68354">CVE-2026-68354</h2>
<p>CVE-2026-68354 refers to a vulnerability within the Windows firewire network driver stack involving improper handling of fragmented datagram reassembly, which may allow for potential exploitation during network packet processing.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68354">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68354</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68326">CVE-2026-68326</h2>
<p>CVE-2026-68326 is a vulnerability within the mwifiex Wi-Fi driver, specifically involving improper bounds checking of uAP association event Information Elements (IEs) against the event buffer. This flaw could potentially allow for memory corruption or other impacts depending on how the driver processes malformed association packets.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68326">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68326</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68151">CVE-2026-68151</h2>
<p>CVE-2026-68151 identifies a vulnerability within the binfmt_elf_fdpic loader, which incorrectly handles multiple PT_INTERP segments in an ELF file. By only honoring the first PT_INTERP, the implementation may lead to inconsistencies in how executable files are parsed and executed, potentially impacting system security and loader integrity.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68151">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68151</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68343">CVE-2026-68343</h2>
<p>CVE-2026-68343 describes a vulnerability in the Microsoft SMB client related to the validation of DFS referral PathConsumed. This flaw potentially allows an attacker to manipulate path validation logic within SMB communications.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68343">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68343</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68184">CVE-2026-68184</h2>
<p>CVE-2026-68184 describes a stack-based out-of-bounds read vulnerability within the CDROMVOLCTRL functionality of the Windows CD-ROM driver. This flaw could potentially be leveraged by an attacker to read sensitive data from the stack, though specific exploitation vectors are not detailed beyond the vulnerability type.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68184">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68184</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68124">CVE-2026-68124</h2>
<p>CVE-2026-68124 identifies a buffer overflow vulnerability within the MCTP serial driver components, triggered by the improper handling of zero-length frames. An attacker could potentially exploit this flaw to cause memory corruption or a system crash.</p>
<p>Affected products:</p>
<ul>
<li>mctp</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68124">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68124</a></p>
<h2 id="cve-2026-68401">CVE-2026-68401</h2>
<p>CVE-2026-68401 describes an out-of-bounds write vulnerability within the arm_ffa component of Microsoft firmware, specifically located in the ffa_setup_and_transmit() function, which requires a security update to remediate.</p>
<p>Affected products:</p>
<ul>
<li>firmware</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68401">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68401</a></p>
<h2 id="cve-2026-68322">CVE-2026-68322</h2>
<p>CVE-2026-68322 describes a NULL pointer dereference vulnerability within the rds (Reliable Datagram Sockets) component of Microsoft Windows, specifically occurring when IPv6 is disabled. This vulnerability can lead to a system crash, resulting in a denial of service condition.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68322">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68322</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68214">CVE-2026-68214</h2>
<p>CVE-2026-68214 identifies a use-after-free vulnerability located in the rtl2832 driver's remove function (rtl2832_remove) within the Windows kernel. This flaw could potentially be leveraged to trigger system instability or lead to memory corruption, requiring a kernel-level security update to address the lifetime management of the driver object.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68214">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68214</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68327">CVE-2026-68327</h2>
<p>CVE-2026-68327 is a vulnerability identified in the Microsoft wanxl WAN driver component. The vulnerability relates to the handling of hardware reset sequences in relation to Base Address Register (BAR) mapping. Successful exploitation of this issue could potentially lead to undefined system behavior or stability issues within the network driver stack.</p>
<p>Affected products:</p>
<ul>
<li>wanxl</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68327">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68327</a></p>
<h2 id="cve-2026-68188">CVE-2026-68188</h2>
<p>CVE-2026-68188 describes a use-after-free (UAF) vulnerability within the RFCOMM protocol implementation of the Bluetooth stack, specifically triggered during the set_termios operation.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68188">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68188</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68132">CVE-2026-68132</h2>
<p>CVE-2026-68132 is a vulnerability addressed by Microsoft that involves a deadlock condition occurring during the emergency thaw process on frozen block devices within the Windows operating system.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68132">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68132</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68304">CVE-2026-68304</h2>
<p>CVE-2026-68304 addresses a call trace warning in the brcmfmac wireless driver related to 802.1X-SHA256 authentication processing. While technical details are limited, the issue involves handling of authentication frames within the Broadcom wireless stack.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68304">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68304</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68098">CVE-2026-68098</h2>
<p>CVE-2026-68098 is a vulnerability in the ksmbd kernel-mode SMB server component within Microsoft Windows. The issue involves improper handling of DACL (Discretionary Access Control List) deduplication during ACE (Access Control Entry) copying operations, which may lead to memory safety issues when processing malformed requests.</p>
<p>Affected products:</p>
<ul>
<li>ksmbd</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68098">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68098</a></p>
<p>Related in this roundup: <a href="#cve-2026-64578">CVE-2026-64578</a>, <a href="#cve-2026-68097">CVE-2026-68097</a>, <a href="#cve-2026-68130">CVE-2026-68130</a>, <a href="#cve-2026-68099">CVE-2026-68099</a>.</p>
<h2 id="cve-2026-68348">CVE-2026-68348</h2>
<p>CVE-2026-68348 involves an issue in the ASoC (ALSA System on Chip) subsystem specifically related to the tas2781 audio amplifier driver, where firmware description string parsing is not properly bounded, potentially leading to memory corruption or related stability issues.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68348">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68348</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68195">CVE-2026-68195</h2>
<p>CVE-2026-68195 describes a vulnerability in the mt76 driver for MediaTek WiFi chipsets, specifically affecting the mt7615 module. The vulnerability involves improper handling of TXRX_NOTIFY events on non-MMIO buses, requiring a patch to drop these notifications to maintain stability and security.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68195">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68195</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68419">CVE-2026-68419</h2>
<p>CVE-2026-68419 is a vulnerability in the Linux kernel's irdma (RDMA) subsystem. The flaw specifically pertains to the rereg_mr function, which fails to properly validate that the memory region being re-registered is a valid memory region, potentially leading to unauthorized memory access or system instability.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68419">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68419</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68171">CVE-2026-68171</h2>
<p>CVE-2026-68171 refers to a vulnerability in the Linux kernel for the arm64 architecture, specifically related to syscall handling. The flaw involves a synchronization issue where the saved x0 register may not correctly reflect updates made by a tracer during a system call, potentially leading to security boundary bypasses or incorrect syscall execution context.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68171">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68171</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-64523">CVE-2026-64523</h2>
<p>CVE-2026-64523 is a vulnerability in the Microsoft net/handshake component involving the handling of long-lived file references during submission processes, which has been identified and addressed by Microsoft via the Security Update Guide.</p>
<p>Affected products:</p>
<ul>
<li>net/handshake</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64523">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64523</a></p>
<h2 id="cve-2026-64388">CVE-2026-64388</h2>
<p>CVE-2026-64388 refers to a security update for the Microsoft SMB client component, specifically addressing improper handling of POSIX chown/chgrp operations when using SMB3 POSIX Extensions.</p>
<p>Affected products:</p>
<ul>
<li>SMB Client</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64388">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64388</a></p>
<h2 id="cve-2025-37938">CVE-2025-37938</h2>
<p>CVE-2025-37938 refers to a security vulnerability related to the tracing of event formats containing '%*p' sequences. The provided content is a placeholder index for a Microsoft Security Response Center advisory, and specific technical details regarding the vulnerability's impact, affected products, or exploitation vectors are not currently available within the source text.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-37938">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-37938</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-68207">CVE-2026-68207</h2>
<p>CVE-2026-68207 involves an error in the Video4Linux2 (v4l2) device registration process within the Linux kernel, specifically related to improper cleanup during probe errors. This flaw could potentially lead to inconsistent system states or kernel-level instability upon initialization failure.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68207">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68207</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-50472">CVE-2026-50472</h2>
<p>A heap-based buffer overflow vulnerability in the Windows LUA File Virtualization (LUAFV) filter driver allows a locally authenticated attacker to escalate privileges to the level of the kernel or system.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50472">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50472</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-56174">CVE-2026-56174</h2>
<p>CVE-2026-56174 describes an elevation of privilege vulnerability in Windows Narrator Braille caused by an untrusted search path. An attacker with local access can exploit this vulnerability to execute code or perform operations with higher privileges than their account typically permits.</p>
<p>Affected products:</p>
<ul>
<li>Windows Narrator</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56174">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56174</a></p>
<h2 id="cve-2026-58650">CVE-2026-58650</h2>
<p>CVE-2026-58650 describes an authorization bypass vulnerability in Visual Studio Code where a user-controlled key can be leveraged to bypass security features locally. An unauthorized attacker requires local access to exploit this flaw, which stems from improper handling of authorization keys.</p>
<p>Affected products:</p>
<ul>
<li>Visual Studio Code</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58650">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58650</a></p>
<p>Related in this roundup: <a href="#cve-2026-59113">CVE-2026-59113</a>, <a href="#cve-2026-47285">CVE-2026-47285</a>, <a href="#cve-2026-69320">CVE-2026-69320</a>, <a href="#cve-2026-69278">CVE-2026-69278</a>, <a href="#cve-2026-69306">CVE-2026-69306</a>, <a href="#cve-2026-70336">CVE-2026-70336</a>, <a href="#cve-2026-54981">CVE-2026-54981</a>.</p>
<h2 id="cve-2026-65768">CVE-2026-65768</h2>
<p>Microsoft Teams for Android contains a path traversal vulnerability that allows a remote, unauthorized attacker to execute arbitrary code on the target device via network-based exploitation.</p>
<p>Affected products:</p>
<ul>
<li>Teams</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65768">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65768</a></p>
<p>Related in this roundup: <a href="#cve-2026-65767">CVE-2026-65767</a>.</p>
<h2 id="cve-2026-57105">CVE-2026-57105</h2>
<p>CVE-2026-57105 is a spoofing vulnerability in Microsoft Office SharePoint caused by improper neutralization of input during web page generation. An authenticated attacker can exploit this cross-site scripting vulnerability to conduct spoofing attacks over the network.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57105">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57105</a></p>
<p>Related in this roundup: <a href="#cve-2026-70321">CVE-2026-70321</a>, <a href="#cve-2026-70324">CVE-2026-70324</a>, <a href="#cve-2026-70306">CVE-2026-70306</a>.</p>
<h2 id="cve-2026-62829">CVE-2026-62829</h2>
<p>CVE-2026-62829 is a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server that allows an authenticated attacker to perform spoofing attacks over a network by injecting malicious input during web page generation.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62829">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62829</a></p>
<p>Related in this roundup: <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-62827">CVE-2026-62827</h2>
<p>CVE-2026-62827 is an elevation of privilege vulnerability in Microsoft SharePoint Server caused by improper authentication, allowing an authenticated attacker to elevate their privileges over a network.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62827">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62827</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-62837">CVE-2026-62837</h2>
<p>CVE-2026-62837 describes a relative path traversal vulnerability in Microsoft SharePoint Server that allows an authenticated attacker to perform unauthorized information disclosure over the network.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62837">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62837</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-63514">CVE-2026-63514</h2>
<p>CVE-2026-63514 is a remote code execution vulnerability in Microsoft SharePoint Server caused by improper deserialization of untrusted data. An authorized attacker can exploit this flaw over the network to execute arbitrary code within the context of the application.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63514">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63514</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-63512">CVE-2026-63512</h2>
<p>CVE-2026-63512 is a security vulnerability in Microsoft SharePoint Server that results from incorrect authorization handling. An attacker who has obtained authorized access to the system can exploit this flaw to perform unauthorized tampering with data or configuration over a network, potentially undermining system integrity.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63512">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63512</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-63516">CVE-2026-63516</h2>
<p>Microsoft SharePoint Server contains a vulnerability due to deserialization of untrusted data. An authorized attacker can leverage this flaw to perform spoofing attacks over a network.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63516">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63516</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-63520">CVE-2026-63520</h2>
<p>CVE-2026-63520 is a remote code execution vulnerability in Microsoft SharePoint Server caused by improper input validation. An unauthenticated attacker can exploit this flaw over a network to execute arbitrary code on the affected server.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63520">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63520</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-40375">CVE-2026-40375</h2>
<p>CVE-2026-40375 is an information disclosure vulnerability in Microsoft Dynamics Business Central resulting from a missing authorization check. An authenticated attacker on the network can leverage this flaw to access sensitive information without proper authorization.</p>
<p>Affected products:</p>
<ul>
<li>Dynamics Business Central</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40375">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40375</a></p>
<p>Related in this roundup: <a href="#cve-2024-21380">CVE-2024-21380</a>.</p>
<h2 id="cve-2026-54113">CVE-2026-54113</h2>
<p>CVE-2026-54113 is a denial of service vulnerability in the Windows Kernel due to improper resource allocation limits within the Remote Procedure Call (RPC) implementation. An unauthorized network-based attacker can exploit this flaw to exhaust system resources, leading to a crash or service disruption.</p>
<p>Affected products:</p>
<ul>
<li>Windows Kernel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54113">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54113</a></p>
<p>Related in this roundup: <a href="#cve-2026-61930">CVE-2026-61930</a>, <a href="#cve-2026-62737">CVE-2026-62737</a>, <a href="#cve-2026-62708">CVE-2026-62708</a>, <a href="#cve-2026-62749">CVE-2026-62749</a>, <a href="#cve-2026-65773">CVE-2026-65773</a>.</p>
<h2 id="cve-2026-54984">CVE-2026-54984</h2>
<p>A heap-based buffer overflow vulnerability in the Windows Imaging Component allows an unauthorized local attacker to achieve remote code execution by processing specially crafted image files.</p>
<p>Affected products:</p>
<ul>
<li>Windows Imaging Component</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54984">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54984</a></p>
<p>Related in this roundup: <a href="#cve-2026-62740">CVE-2026-62740</a>.</p>
<h2 id="cve-2026-49179">CVE-2026-49179</h2>
<p>CVE-2026-49179 describes a command injection vulnerability in Windows Active Directory Domain Services that enables unauthorized network-based remote code execution. Attackers can leverage this flaw to execute arbitrary commands by sending specially crafted inputs to the affected directory service.</p>
<p>Affected products:</p>
<ul>
<li>Active Directory Domain Services</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49179">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49179</a></p>
<h2 id="cve-2026-58612">CVE-2026-58612</h2>
<p>CVE-2026-58612 is a server-side request forgery (SSRF) vulnerability in Microsoft PowerShell Core that allows an unauthorized attacker to perform unauthorized network requests to disclose sensitive information.</p>
<p>Affected products:</p>
<ul>
<li>PowerShell Core</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58612">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58612</a></p>
<p>Related in this roundup: <a href="#cve-2026-70337">CVE-2026-70337</a>.</p>
<h2 id="cve-2026-59113">CVE-2026-59113</h2>
<p>CVE-2026-59113 describes a missing authorization vulnerability in Visual Studio Code that allows a remote, unauthenticated attacker to execute arbitrary code via the network.</p>
<p>Affected products:</p>
<ul>
<li>Visual Studio Code</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59113">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59113</a></p>
<p>Related in this roundup: <a href="#cve-2026-58650">CVE-2026-58650</a>, <a href="#cve-2026-47285">CVE-2026-47285</a>, <a href="#cve-2026-69320">CVE-2026-69320</a>, <a href="#cve-2026-69278">CVE-2026-69278</a>, <a href="#cve-2026-69306">CVE-2026-69306</a>, <a href="#cve-2026-70336">CVE-2026-70336</a>, <a href="#cve-2026-54981">CVE-2026-54981</a>.</p>
<h2 id="cve-2026-47299">CVE-2026-47299</h2>
<p>CVE-2026-47299 is an elevation of privilege vulnerability in the Azure Monitor Agent caused by improper neutralization of special elements used in a command (command injection). An authorized attacker can exploit this flaw over a network to elevate their privileges on the targeted system.</p>
<p>Affected products:</p>
<ul>
<li>Azure Monitor Agent</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47299">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47299</a></p>
<h2 id="cve-2026-47285">CVE-2026-47285</h2>
<p>CVE-2026-47285 is a command injection vulnerability in Visual Studio Code that permits an unauthorized attacker to disclose sensitive information over the network due to improper neutralization of special command elements.</p>
<p>Affected products:</p>
<ul>
<li>Visual Studio Code</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47285">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47285</a></p>
<p>Related in this roundup: <a href="#cve-2026-58650">CVE-2026-58650</a>, <a href="#cve-2026-59113">CVE-2026-59113</a>, <a href="#cve-2026-69320">CVE-2026-69320</a>, <a href="#cve-2026-69278">CVE-2026-69278</a>, <a href="#cve-2026-69306">CVE-2026-69306</a>, <a href="#cve-2026-70336">CVE-2026-70336</a>, <a href="#cve-2026-54981">CVE-2026-54981</a>.</p>
<h2 id="cve-2026-59124">CVE-2026-59124</h2>
<p>Microsoft High Performance Computing (HPC) Pack is vulnerable to remote code execution due to improper deserialization of untrusted data, allowing an unauthorized attacker to execute arbitrary code over the network.</p>
<p>Affected products:</p>
<ul>
<li>High Performance Computing Pack</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59124">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59124</a></p>
<h2 id="cve-2026-59127">CVE-2026-59127</h2>
<p>CVE-2026-59127 describes an elevation of privilege vulnerability in the Windows Installer service caused by an integer overflow or wraparound condition. A local attacker with low-level authorization can exploit this flaw to gain elevated privileges on the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Installer</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59127">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59127</a></p>
<p>Related in this roundup: <a href="#cve-2026-61925">CVE-2026-61925</a>, <a href="#cve-2026-70344">CVE-2026-70344</a>, <a href="#cve-2026-70345">CVE-2026-70345</a>, <a href="#cve-2026-70346">CVE-2026-70346</a>, <a href="#cve-2026-70347">CVE-2026-70347</a>, <a href="#cve-2026-61938">CVE-2026-61938</a>, <a href="#cve-2026-62768">CVE-2026-62768</a>, <a href="#cve-2026-65774">CVE-2026-65774</a>.</p>
<h2 id="cve-2026-59128">CVE-2026-59128</h2>
<p>CVE-2026-59128 is an out-of-bounds read vulnerability in the Windows Encrypting File System (EFS). An authorized attacker with local access can exploit this flaw to disclose sensitive information, potentially bypassing security controls related to file encryption.</p>
<p>Affected products:</p>
<ul>
<li>Windows Encrypting File System</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59128">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59128</a></p>
<h2 id="cve-2026-59133">CVE-2026-59133</h2>
<p>CVE-2026-59133 describes a vulnerability in Microsoft High Performance Computing (HPC) Pack that allows an authenticated attacker to perform a privilege escalation over the network due to the application executing with unnecessary elevated privileges.</p>
<p>Affected products:</p>
<ul>
<li>High Performance Computing (HPC) Pack</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59133">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59133</a></p>
<h2 id="cve-2026-59132">CVE-2026-59132</h2>
<p>CVE-2026-59132 describes a denial of service vulnerability in the Windows TCP/IP stack. An unauthenticated attacker could trigger this vulnerability by sending specially crafted packets to a target system, resulting in a system crash or service disruption.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59132">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59132</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-59135">CVE-2026-59135</h2>
<p>CVE-2026-59135 is an information disclosure vulnerability within the Microsoft Windows Search Component. The vulnerability stems from weak authentication mechanisms, which can be exploited by a locally authorized attacker to gain unauthorized access to sensitive information.</p>
<p>Affected products:</p>
<ul>
<li>Windows Search Component</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59135">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59135</a></p>
<h2 id="cve-2026-59134">CVE-2026-59134</h2>
<p>CVE-2026-59134 is a heap-based buffer overflow vulnerability within the Microsoft Remote Desktop Client, which permits an unauthorized remote attacker to achieve arbitrary code execution over a network connection.</p>
<p>Affected products:</p>
<ul>
<li>Remote Desktop Client</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59134">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59134</a></p>
<p>Related in this roundup: <a href="#cve-2026-61924">CVE-2026-61924</a>, <a href="#cve-2026-61352">CVE-2026-61352</a>, <a href="#cve-2026-61363">CVE-2026-61363</a>, <a href="#cve-2026-61918">CVE-2026-61918</a>, <a href="#cve-2026-61921">CVE-2026-61921</a>, <a href="#cve-2026-62824">CVE-2026-62824</a>.</p>
<h2 id="cve-2026-59136">CVE-2026-59136</h2>
<p>CVE-2026-59136 is an information disclosure vulnerability in Microsoft COM for Windows. It stems from the use of an uninitialized resource, which allows an authorized local attacker to access sensitive information by exploiting the way the component handles memory or resources during execution.</p>
<p>Affected products:</p>
<ul>
<li>COM</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59136">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59136</a></p>
<h2 id="cve-2026-59137">CVE-2026-59137</h2>
<p>The Windows Event Logging Service contains a vulnerability involving the use of an uninitialized resource. This flaw allows an authenticated local attacker to perform an information disclosure attack against the service.</p>
<p>Affected products:</p>
<ul>
<li>Windows Event Logging Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59137">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59137</a></p>
<p>Related in this roundup: <a href="#cve-2026-61347">CVE-2026-61347</a>, <a href="#cve-2026-59126">CVE-2026-59126</a>.</p>
<h2 id="cve-2026-59138">CVE-2026-59138</h2>
<p>CVE-2026-59138 refers to a Denial of Service (DoS) vulnerability within the Microsoft Remote Registry Service, potentially allowing an attacker to disrupt the service functionality.</p>
<p>Affected products:</p>
<ul>
<li>Remote Registry Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59138">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59138</a></p>
<p>Related in this roundup: <a href="#cve-2026-61345">CVE-2026-61345</a>.</p>
<h2 id="cve-2026-61345">CVE-2026-61345</h2>
<p>CVE-2026-61345 is a denial-of-service vulnerability affecting the Microsoft Remote Registry Service. Successful exploitation allows an attacker to cause the service to become unresponsive, disrupting remote registry management capabilities on the affected Windows system.</p>
<p>Affected products:</p>
<ul>
<li>Remote Registry Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61345">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61345</a></p>
<p>Related in this roundup: <a href="#cve-2026-59138">CVE-2026-59138</a>.</p>
<h2 id="cve-2026-61346">CVE-2026-61346</h2>
<p>A use-after-free vulnerability exists in the Windows Graphics Kernel that allows a locally authenticated attacker to escalate privileges. Successful exploitation requires an attacker to have local access and perform specific actions to trigger the use-after-free condition.</p>
<p>Affected products:</p>
<ul>
<li>Windows Graphics Kernel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61346">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61346</a></p>
<h2 id="cve-2026-61353">CVE-2026-61353</h2>
<p>A heap-based buffer overflow vulnerability exists in the Windows Telephony Service, allowing an authenticated attacker to perform local privilege escalation. Successful exploitation requires the attacker to have sufficient local access to interact with the service, resulting in elevated system privileges.</p>
<p>Affected products:</p>
<ul>
<li>Windows Telephony Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61353">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61353</a></p>
<p>Related in this roundup: <a href="#cve-2026-62723">CVE-2026-62723</a>, <a href="#cve-2026-62724">CVE-2026-62724</a>, <a href="#cve-2026-62748">CVE-2026-62748</a>, <a href="#cve-2026-62729">CVE-2026-62729</a>, <a href="#cve-2026-59122">CVE-2026-59122</a>, <a href="#cve-2026-62701">CVE-2026-62701</a>, <a href="#cve-2026-62725">CVE-2026-62725</a>, <a href="#cve-2026-62726">CVE-2026-62726</a>, <a href="#cve-2026-62732">CVE-2026-62732</a>, <a href="#cve-2026-62734">CVE-2026-62734</a>.</p>
<h2 id="cve-2026-61347">CVE-2026-61347</h2>
<p>The Windows Event Logging Service contains a buffer over-read vulnerability that can be exploited by an authorized attacker to disclose sensitive information from the system locally.</p>
<p>Affected products:</p>
<ul>
<li>Windows Event Logging Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61347">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61347</a></p>
<p>Related in this roundup: <a href="#cve-2026-59137">CVE-2026-59137</a>, <a href="#cve-2026-59126">CVE-2026-59126</a>.</p>
<h2 id="cve-2026-61361">CVE-2026-61361</h2>
<p>CVE-2026-61361 is a use-after-free vulnerability within the Windows DHCP Client that allows an authorized attacker to achieve remote code execution on the target system.</p>
<p>Affected products:</p>
<ul>
<li>Windows DHCP Client</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61361">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61361</a></p>
<p>Related in this roundup: <a href="#cve-2026-62755">CVE-2026-62755</a>, <a href="#cve-2026-65785">CVE-2026-65785</a>, <a href="#cve-2026-62736">CVE-2026-62736</a>.</p>
<h2 id="cve-2026-61348">CVE-2026-61348</h2>
<p>CVE-2026-61348 is a use-after-free vulnerability within the Windows Ancillary Function Driver for WinSock (afdsys.sys). This vulnerability allows a locally authenticated attacker to gain escalated privileges on the host system, necessitating a patch to prevent exploitation of the driver's memory management.</p>
<p>Affected products:</p>
<ul>
<li>Windows Ancillary Function Driver for WinSock</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61348">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61348</a></p>
<p>Related in this roundup: <a href="#cve-2026-68820">CVE-2026-68820</a>.</p>
<h2 id="cve-2026-61356">CVE-2026-61356</h2>
<p>CVE-2026-61356 describes an elevation of privilege vulnerability in Windows Remote Desktop Services caused by missing authentication for a critical function. An attacker who has already gained local access can exploit this flaw to escalate their privileges within the system.</p>
<p>Affected products:</p>
<ul>
<li>Remote Desktop Services</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61356">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61356</a></p>
<p>Related in this roundup: <a href="#cve-2026-61367">CVE-2026-61367</a>, <a href="#cve-2026-62692">CVE-2026-62692</a>, <a href="#cve-2026-61365">CVE-2026-61365</a>.</p>
<h2 id="cve-2026-61367">CVE-2026-61367</h2>
<p>CVE-2026-61367 is a local privilege escalation vulnerability in Microsoft Windows Remote Desktop Services caused by improper authentication handling. An attacker who has already gained authorized access to the system can exploit this flaw to execute code or perform actions with elevated privileges.</p>
<p>Affected products:</p>
<ul>
<li>Remote Desktop Services</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61367">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61367</a></p>
<p>Related in this roundup: <a href="#cve-2026-61356">CVE-2026-61356</a>, <a href="#cve-2026-62692">CVE-2026-62692</a>, <a href="#cve-2026-61365">CVE-2026-61365</a>.</p>
<h2 id="cve-2026-61923">CVE-2026-61923</h2>
<p>CVE-2026-61923 describes a heap-based buffer overflow vulnerability within the Windows Display Enhancement Service. This flaw allows a locally authenticated attacker to escalate their privileges to a higher level of authority on the target system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Display Enhancement Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61923">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61923</a></p>
<h2 id="cve-2026-61366">CVE-2026-61366</h2>
<p>A double free vulnerability in the Windows Network Connection Broker component allows a locally authenticated attacker to elevate their privileges on the host system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Network Connection Broker</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61366">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61366</a></p>
<h2 id="cve-2026-61368">CVE-2026-61368</h2>
<p>CVE-2026-61368 is a heap-based buffer overflow vulnerability in Windows Hyper-V that enables an authorized local attacker to perform an information disclosure attack.</p>
<p>Affected products:</p>
<ul>
<li>Hyper-V</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61368">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61368</a></p>
<h2 id="cve-2026-61924">CVE-2026-61924</h2>
<p>CVE-2026-61924 describes an out-of-bounds read vulnerability in the Microsoft Remote Desktop Client, which can be leveraged by a remote unauthorized attacker to disclose sensitive information over a network. Detection efforts should focus on anomalous traffic patterns involving the RDP protocol and monitoring for exploitation attempts targeting the Remote Desktop Client service.</p>
<p>Affected products:</p>
<ul>
<li>Remote Desktop Client</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61924">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61924</a></p>
<p>Related in this roundup: <a href="#cve-2026-59134">CVE-2026-59134</a>, <a href="#cve-2026-61352">CVE-2026-61352</a>, <a href="#cve-2026-61363">CVE-2026-61363</a>, <a href="#cve-2026-61918">CVE-2026-61918</a>, <a href="#cve-2026-61921">CVE-2026-61921</a>, <a href="#cve-2026-62824">CVE-2026-62824</a>.</p>
<h2 id="cve-2026-61925">CVE-2026-61925</h2>
<p>CVE-2026-61925 describes a local privilege escalation vulnerability in the Windows Installer service caused by incorrect authorization. An attacker who has already gained local access to a system can exploit this vulnerability to escalate their privileges.</p>
<p>Affected products:</p>
<ul>
<li>Windows Installer</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61925">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61925</a></p>
<p>Related in this roundup: <a href="#cve-2026-59127">CVE-2026-59127</a>, <a href="#cve-2026-70344">CVE-2026-70344</a>, <a href="#cve-2026-70345">CVE-2026-70345</a>, <a href="#cve-2026-70346">CVE-2026-70346</a>, <a href="#cve-2026-70347">CVE-2026-70347</a>, <a href="#cve-2026-61938">CVE-2026-61938</a>, <a href="#cve-2026-62768">CVE-2026-62768</a>, <a href="#cve-2026-65774">CVE-2026-65774</a>.</p>
<h2 id="cve-2026-61927">CVE-2026-61927</h2>
<p>A use-after-free vulnerability exists in the Windows Bind Filter Driver that allows a locally authenticated attacker to elevate their privileges to a higher level within the system.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61927">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61927</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-61928">CVE-2026-61928</h2>
<p>A vulnerability exists in Windows Hello where sensitive information is stored in cleartext, allowing an attacker with local access to perform tampering operations against the authentication mechanism.</p>
<p>Affected products:</p>
<ul>
<li>Windows Hello</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61928">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61928</a></p>
<h2 id="cve-2026-61930">CVE-2026-61930</h2>
<p>CVE-2026-61930 is a heap-based buffer overflow vulnerability in the Windows Kernel that allows an authorized local attacker to elevate their privileges on an affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Kernel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61930">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61930</a></p>
<p>Related in this roundup: <a href="#cve-2026-54113">CVE-2026-54113</a>, <a href="#cve-2026-62737">CVE-2026-62737</a>, <a href="#cve-2026-62708">CVE-2026-62708</a>, <a href="#cve-2026-62749">CVE-2026-62749</a>, <a href="#cve-2026-65773">CVE-2026-65773</a>.</p>
<h2 id="cve-2026-61937">CVE-2026-61937</h2>
<p>An integer overflow or wraparound vulnerability in the Windows HTTP.sys kernel driver allows a locally authenticated attacker to elevate their privileges to a higher integrity level. The vulnerability involves improper handling of arithmetic operations within the HTTP protocol stack.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61937">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61937</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62692">CVE-2026-62692</h2>
<p>CVE-2026-62692 is a heap-based buffer overflow vulnerability in Windows Remote Desktop Services. An authenticated attacker can exploit this flaw to execute code with elevated privileges on the target system.</p>
<p>Affected products:</p>
<ul>
<li>Remote Desktop Services</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62692">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62692</a></p>
<p>Related in this roundup: <a href="#cve-2026-61356">CVE-2026-61356</a>, <a href="#cve-2026-61367">CVE-2026-61367</a>, <a href="#cve-2026-61365">CVE-2026-61365</a>.</p>
<h2 id="cve-2026-61932">CVE-2026-61932</h2>
<p>The Windows DWM Core Library is susceptible to a type confusion vulnerability, which can be exploited by an authorized local attacker to achieve privilege escalation.</p>
<p>Affected products:</p>
<ul>
<li>Windows DWM Core Library</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61932">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61932</a></p>
<p>Related in this roundup: <a href="#cve-2026-62703">CVE-2026-62703</a>, <a href="#cve-2026-62894">CVE-2026-62894</a>.</p>
<h2 id="cve-2026-61933">CVE-2026-61933</h2>
<p>CVE-2026-61933 is an out-of-bounds read vulnerability in the Windows Desktop Window Manager (DWM) Core Library that enables a locally authenticated attacker to perform unauthorized information disclosure.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61933">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61933</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-61934">CVE-2026-61934</h2>
<p>The Windows Bind Filter Driver contains a use-after-free vulnerability that enables a locally authenticated attacker to escalate their privileges. This flaw resides within the kernel-mode driver, allowing for unauthorized privilege escalation on affected Windows systems.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61934">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61934</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-61936">CVE-2026-61936</h2>
<p>A security feature bypass vulnerability exists in the Windows Defender Firewall Service due to missing authorization checks. An attacker with local access can exploit this vulnerability to bypass firewall restrictions, potentially allowing unauthorized network traffic or service interaction.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61936">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61936</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-61939">CVE-2026-61939</h2>
<p>CVE-2026-61939 is a local privilege escalation vulnerability in the Windows Winlogon component caused by a use-after-free flaw. An authenticated attacker can exploit this vulnerability to gain elevated privileges on an affected Windows system.</p>
<p>Affected products:</p>
<ul>
<li>Winlogon</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61939">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61939</a></p>
<h2 id="cve-2026-62695">CVE-2026-62695</h2>
<p>CVE-2026-62695 is a local privilege escalation vulnerability resulting from a heap-based buffer overflow in the Windows Storage component. An authenticated attacker can exploit this flaw to gain elevated privileges on the target system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Storage</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62695">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62695</a></p>
<p>Related in this roundup: <a href="#cve-2026-61359">CVE-2026-61359</a>.</p>
<h2 id="cve-2026-62688">CVE-2026-62688</h2>
<p>A heap-based buffer overflow vulnerability in the Windows MIDI Service Module allows an authenticated local attacker to escalate their privileges to a higher level of authority on the host system.</p>
<p>Affected products:</p>
<ul>
<li>Windows MIDI Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62688">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62688</a></p>
<h2 id="cve-2026-62690">CVE-2026-62690</h2>
<p>A race condition vulnerability in the Windows Push Notifications service allows an authorized local attacker to achieve privilege escalation due to improper synchronization during concurrent resource access.</p>
<p>Affected products:</p>
<ul>
<li>Windows Push Notifications</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62690">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62690</a></p>
<h2 id="cve-2026-62693">CVE-2026-62693</h2>
<p>A race condition vulnerability exists within the Windows MIDI Service Module that allows a locally authenticated attacker to elevate privileges. The flaw arises from improper synchronization when using shared resources during concurrent execution.</p>
<p>Affected products:</p>
<ul>
<li>Windows MIDI Service Module</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62693">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62693</a></p>
<h2 id="cve-2026-62696">CVE-2026-62696</h2>
<p>CVE-2026-62696 describes an integer underflow vulnerability in the Windows Program Compatibility Assistant Service that allows an authorized local attacker to achieve privilege escalation by exploiting the arithmetic error during service processing.</p>
<p>Affected products:</p>
<ul>
<li>Windows Program Compatibility Assistant Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62696">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62696</a></p>
<h2 id="cve-2026-62702">CVE-2026-62702</h2>
<p>CVE-2026-62702 is a vulnerability within the Windows Graphics Kernel that allows a local attacker to cause a denial of service condition on affected Windows systems.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62702">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62702</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62699">CVE-2026-62699</h2>
<p>The Windows Universal Disk Format File System Driver (UDFS) is vulnerable to a heap-based buffer overflow that can be exploited by an unauthorized attacker to achieve remote code execution via a physical attack vector.</p>
<p>Affected products:</p>
<ul>
<li>Windows Universal Disk Format File System Driver</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62699">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62699</a></p>
<h2 id="cve-2026-62703">CVE-2026-62703</h2>
<p>CVE-2026-62703 describes an out-of-bounds read vulnerability in the Windows DWM Core Library. An authorized local attacker can exploit this flaw to disclose sensitive information from the system, potentially aiding in further exploitation phases.</p>
<p>Affected products:</p>
<ul>
<li>Windows DWM Core Library</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62703">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62703</a></p>
<p>Related in this roundup: <a href="#cve-2026-61932">CVE-2026-61932</a>, <a href="#cve-2026-62894">CVE-2026-62894</a>.</p>
<h2 id="cve-2026-62705">CVE-2026-62705</h2>
<p>CVE-2026-62705 is a race condition vulnerability within the Windows Bind Filter Driver that allows an authorized local attacker to gain elevated system privileges. The flaw stems from improper synchronization when accessing shared resources, which could be exploited to compromise system integrity.</p>
<p>Affected products:</p>
<ul>
<li>Windows Bind Filter Driver</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62705">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62705</a></p>
<p>Related in this roundup: <a href="#cve-2026-62722">CVE-2026-62722</a>.</p>
<h2 id="cve-2026-62707">CVE-2026-62707</h2>
<p>A use-after-free vulnerability exists in the Windows Modern Device Management (MDM) component that can be exploited by an authenticated attacker to perform a local privilege escalation. Successful exploitation requires the attacker to have existing access to the system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Modern Device Management</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62707">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62707</a></p>
<h2 id="cve-2026-62713">CVE-2026-62713</h2>
<p>CVE-2026-62713 describes a heap-based buffer overflow vulnerability in the Windows Cloud Files Mini Filter Driver that allows a locally authenticated attacker to gain elevated privileges. Detection strategies should focus on monitoring for unusual process creation or memory manipulation involving the Cloud Files Mini Filter driver, which may indicate exploitation attempts.</p>
<p>Affected products:</p>
<ul>
<li>Windows Cloud Files Mini Filter Driver</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62713">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62713</a></p>
<p>Related in this roundup: <a href="#cve-2026-62771">CVE-2026-62771</a>.</p>
<h2 id="cve-2026-62712">CVE-2026-62712</h2>
<p>CVE-2026-62712 is a heap-based buffer overflow vulnerability in the Win32k component of Windows. An attacker who has already gained local authorization can exploit this vulnerability to execute arbitrary code with elevated privileges on the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62712">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62712</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62718">CVE-2026-62718</h2>
<p>An integer underflow vulnerability in the Windows DHCP Server allows an unauthorized attacker to disclose sensitive information from the server by sending specially crafted packets over an adjacent network segment.</p>
<p>Affected products:</p>
<ul>
<li>Windows DHCP Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62718">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62718</a></p>
<p>Related in this roundup: <a href="#cve-2026-62715">CVE-2026-62715</a>, <a href="#cve-2026-62716">CVE-2026-62716</a>, <a href="#cve-2026-62742">CVE-2026-62742</a>, <a href="#cve-2026-62745">CVE-2026-62745</a>, <a href="#cve-2026-62812">CVE-2026-62812</a>, <a href="#cve-2026-62720">CVE-2026-62720</a>, <a href="#cve-2026-62714">CVE-2026-62714</a>, <a href="#cve-2026-62761">CVE-2026-62761</a>, <a href="#cve-2026-62776">CVE-2026-62776</a>, <a href="#cve-2026-62803">CVE-2026-62803</a>, <a href="#cve-2026-62807">CVE-2026-62807</a>, <a href="#cve-2026-62814">CVE-2026-62814</a>, <a href="#cve-2026-62823">CVE-2026-62823</a>.</p>
<h2 id="cve-2026-62715">CVE-2026-62715</h2>
<p>CVE-2026-62715 describes an integer underflow vulnerability in the Windows DHCP Server service. This flaw enables an unauthorized attacker on an adjacent network to potentially disclose sensitive information due to improper handling of integer arithmetic during network packet processing.</p>
<p>Affected products:</p>
<ul>
<li>Windows DHCP Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62715">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62715</a></p>
<p>Related in this roundup: <a href="#cve-2026-62718">CVE-2026-62718</a>, <a href="#cve-2026-62716">CVE-2026-62716</a>, <a href="#cve-2026-62742">CVE-2026-62742</a>, <a href="#cve-2026-62745">CVE-2026-62745</a>, <a href="#cve-2026-62812">CVE-2026-62812</a>, <a href="#cve-2026-62720">CVE-2026-62720</a>, <a href="#cve-2026-62714">CVE-2026-62714</a>, <a href="#cve-2026-62761">CVE-2026-62761</a>, <a href="#cve-2026-62776">CVE-2026-62776</a>, <a href="#cve-2026-62803">CVE-2026-62803</a>, <a href="#cve-2026-62807">CVE-2026-62807</a>, <a href="#cve-2026-62814">CVE-2026-62814</a>, <a href="#cve-2026-62823">CVE-2026-62823</a>.</p>
<h2 id="cve-2026-62716">CVE-2026-62716</h2>
<p>CVE-2026-62716 is an information disclosure vulnerability in the Windows DHCP Server component caused by an integer underflow condition. An unauthorized attacker located on an adjacent network can exploit this flaw to read sensitive data.</p>
<p>Affected products:</p>
<ul>
<li>Windows DHCP Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62716">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62716</a></p>
<p>Related in this roundup: <a href="#cve-2026-62718">CVE-2026-62718</a>, <a href="#cve-2026-62715">CVE-2026-62715</a>, <a href="#cve-2026-62742">CVE-2026-62742</a>, <a href="#cve-2026-62745">CVE-2026-62745</a>, <a href="#cve-2026-62812">CVE-2026-62812</a>, <a href="#cve-2026-62720">CVE-2026-62720</a>, <a href="#cve-2026-62714">CVE-2026-62714</a>, <a href="#cve-2026-62761">CVE-2026-62761</a>, <a href="#cve-2026-62776">CVE-2026-62776</a>, <a href="#cve-2026-62803">CVE-2026-62803</a>, <a href="#cve-2026-62807">CVE-2026-62807</a>, <a href="#cve-2026-62814">CVE-2026-62814</a>, <a href="#cve-2026-62823">CVE-2026-62823</a>.</p>
<h2 id="cve-2026-62719">CVE-2026-62719</h2>
<p>CVE-2026-62719 is a heap-based buffer overflow vulnerability in Windows Message Queuing that allows an attacker with authorized access to elevate privileges locally on the target system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Message Queuing</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62719">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62719</a></p>
<p>Related in this roundup: <a href="#cve-2026-62717">CVE-2026-62717</a>, <a href="#cve-2026-65790">CVE-2026-65790</a>.</p>
<h2 id="cve-2026-62722">CVE-2026-62722</h2>
<p>A heap-based buffer overflow vulnerability in the Windows Bind Filter Driver allows an authenticated attacker to perform local privilege escalation. The vulnerability exists within the driver's handling of memory operations, which can be triggered by a local user to execute code with elevated permissions.</p>
<p>Affected products:</p>
<ul>
<li>Windows Bind Filter Driver</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62722">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62722</a></p>
<p>Related in this roundup: <a href="#cve-2026-62705">CVE-2026-62705</a>.</p>
<h2 id="cve-2026-62723">CVE-2026-62723</h2>
<p>A vulnerability in the Windows Telephony Service allows a local, authenticated attacker to gain elevated privileges through a use-after-free flaw. Successful exploitation enables the attacker to execute code or perform operations with higher permissions than their initial account allows.</p>
<p>Affected products:</p>
<ul>
<li>Windows Telephony Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62723">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62723</a></p>
<p>Related in this roundup: <a href="#cve-2026-61353">CVE-2026-61353</a>, <a href="#cve-2026-62724">CVE-2026-62724</a>, <a href="#cve-2026-62748">CVE-2026-62748</a>, <a href="#cve-2026-62729">CVE-2026-62729</a>, <a href="#cve-2026-59122">CVE-2026-59122</a>, <a href="#cve-2026-62701">CVE-2026-62701</a>, <a href="#cve-2026-62725">CVE-2026-62725</a>, <a href="#cve-2026-62726">CVE-2026-62726</a>, <a href="#cve-2026-62732">CVE-2026-62732</a>, <a href="#cve-2026-62734">CVE-2026-62734</a>.</p>
<h2 id="cve-2026-62724">CVE-2026-62724</h2>
<p>A use-after-free vulnerability in the Windows Telephony Service allows a local, authorized attacker to escalate privileges on a compromised Windows system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Telephony Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62724">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62724</a></p>
<p>Related in this roundup: <a href="#cve-2026-61353">CVE-2026-61353</a>, <a href="#cve-2026-62723">CVE-2026-62723</a>, <a href="#cve-2026-62748">CVE-2026-62748</a>, <a href="#cve-2026-62729">CVE-2026-62729</a>, <a href="#cve-2026-59122">CVE-2026-59122</a>, <a href="#cve-2026-62701">CVE-2026-62701</a>, <a href="#cve-2026-62725">CVE-2026-62725</a>, <a href="#cve-2026-62726">CVE-2026-62726</a>, <a href="#cve-2026-62732">CVE-2026-62732</a>, <a href="#cve-2026-62734">CVE-2026-62734</a>.</p>
<h2 id="cve-2026-62748">CVE-2026-62748</h2>
<p>The Windows Telephony Service contains a race condition vulnerability during concurrent execution involving shared resources. A locally authenticated attacker can exploit this improper synchronization to execute arbitrary code or gain elevated privileges on the target system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Telephony Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62748">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62748</a></p>
<p>Related in this roundup: <a href="#cve-2026-61353">CVE-2026-61353</a>, <a href="#cve-2026-62723">CVE-2026-62723</a>, <a href="#cve-2026-62724">CVE-2026-62724</a>, <a href="#cve-2026-62729">CVE-2026-62729</a>, <a href="#cve-2026-59122">CVE-2026-59122</a>, <a href="#cve-2026-62701">CVE-2026-62701</a>, <a href="#cve-2026-62725">CVE-2026-62725</a>, <a href="#cve-2026-62726">CVE-2026-62726</a>, <a href="#cve-2026-62732">CVE-2026-62732</a>, <a href="#cve-2026-62734">CVE-2026-62734</a>.</p>
<h2 id="cve-2026-62729">CVE-2026-62729</h2>
<p>CVE-2026-62729 describes a local privilege escalation vulnerability in the Windows Telephony Service caused by a race condition due to improper synchronization of shared resources. An authorized attacker can exploit this flaw to execute code with elevated privileges on an affected Windows system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Telephony Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62729">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62729</a></p>
<p>Related in this roundup: <a href="#cve-2026-61353">CVE-2026-61353</a>, <a href="#cve-2026-62723">CVE-2026-62723</a>, <a href="#cve-2026-62724">CVE-2026-62724</a>, <a href="#cve-2026-62748">CVE-2026-62748</a>, <a href="#cve-2026-59122">CVE-2026-59122</a>, <a href="#cve-2026-62701">CVE-2026-62701</a>, <a href="#cve-2026-62725">CVE-2026-62725</a>, <a href="#cve-2026-62726">CVE-2026-62726</a>, <a href="#cve-2026-62732">CVE-2026-62732</a>, <a href="#cve-2026-62734">CVE-2026-62734</a>.</p>
<h2 id="cve-2026-62746">CVE-2026-62746</h2>
<p>A buffer over-read vulnerability exists in the Windows Win32k component that allows an authorized local attacker to perform an information disclosure attack.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62746">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62746</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62740">CVE-2026-62740</h2>
<p>The Windows Imaging Component contains an information disclosure vulnerability stemming from the use of an uninitialized resource. An authorized local attacker can exploit this flaw to read sensitive data, potentially leading to unauthorized information access.</p>
<p>Affected products:</p>
<ul>
<li>Windows Imaging Component</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62740">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62740</a></p>
<p>Related in this roundup: <a href="#cve-2026-54984">CVE-2026-54984</a>.</p>
<h2 id="cve-2026-62753">CVE-2026-62753</h2>
<p>CVE-2026-62753 is a heap-based buffer overflow vulnerability in the Windows HTTP.sys kernel driver that allows an authorized local attacker to perform privilege escalation on affected Windows systems.</p>
<p>Affected products:</p>
<ul>
<li>Windows HTTP.sys</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62753">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62753</a></p>
<h2 id="cve-2026-62735">CVE-2026-62735</h2>
<p>CVE-2026-62735 describes a heap-based buffer overflow vulnerability in the Windows HTTP.sys kernel driver. An authenticated attacker can exploit this flaw to execute code with elevated privileges on the local system.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62735">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62735</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62737">CVE-2026-62737</h2>
<p>An untrusted pointer dereference vulnerability exists in the Windows Kernel that can be exploited by an authenticated attacker to elevate their privileges to a higher level of access on the local system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Kernel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62737">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62737</a></p>
<p>Related in this roundup: <a href="#cve-2026-54113">CVE-2026-54113</a>, <a href="#cve-2026-61930">CVE-2026-61930</a>, <a href="#cve-2026-62708">CVE-2026-62708</a>, <a href="#cve-2026-62749">CVE-2026-62749</a>, <a href="#cve-2026-65773">CVE-2026-65773</a>.</p>
<h2 id="cve-2026-62739">CVE-2026-62739</h2>
<p>CVE-2026-62739 is a heap-based buffer overflow vulnerability in the Windows HTTP.sys driver. An authenticated local attacker can exploit this flaw to execute arbitrary code with elevated privileges, potentially leading to full system compromise.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62739">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62739</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62742">CVE-2026-62742</h2>
<p>CVE-2026-62742 is an information disclosure vulnerability in the Windows DHCP Server caused by an integer underflow (wraparound) issue. An attacker on an adjacent network can exploit this flaw to gain unauthorized access to sensitive information processed by the DHCP service.</p>
<p>Affected products:</p>
<ul>
<li>Windows DHCP Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62742">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62742</a></p>
<p>Related in this roundup: <a href="#cve-2026-62718">CVE-2026-62718</a>, <a href="#cve-2026-62715">CVE-2026-62715</a>, <a href="#cve-2026-62716">CVE-2026-62716</a>, <a href="#cve-2026-62745">CVE-2026-62745</a>, <a href="#cve-2026-62812">CVE-2026-62812</a>, <a href="#cve-2026-62720">CVE-2026-62720</a>, <a href="#cve-2026-62714">CVE-2026-62714</a>, <a href="#cve-2026-62761">CVE-2026-62761</a>, <a href="#cve-2026-62776">CVE-2026-62776</a>, <a href="#cve-2026-62803">CVE-2026-62803</a>, <a href="#cve-2026-62807">CVE-2026-62807</a>, <a href="#cve-2026-62814">CVE-2026-62814</a>, <a href="#cve-2026-62823">CVE-2026-62823</a>.</p>
<h2 id="cve-2026-62745">CVE-2026-62745</h2>
<p>CVE-2026-62745 is an information disclosure vulnerability in the Windows DHCP Server caused by an integer underflow condition. An unauthorized attacker located on an adjacent network can exploit this flaw to read sensitive data processed by the DHCP service.</p>
<p>Affected products:</p>
<ul>
<li>Windows DHCP Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62745">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62745</a></p>
<p>Related in this roundup: <a href="#cve-2026-62718">CVE-2026-62718</a>, <a href="#cve-2026-62715">CVE-2026-62715</a>, <a href="#cve-2026-62716">CVE-2026-62716</a>, <a href="#cve-2026-62742">CVE-2026-62742</a>, <a href="#cve-2026-62812">CVE-2026-62812</a>, <a href="#cve-2026-62720">CVE-2026-62720</a>, <a href="#cve-2026-62714">CVE-2026-62714</a>, <a href="#cve-2026-62761">CVE-2026-62761</a>, <a href="#cve-2026-62776">CVE-2026-62776</a>, <a href="#cve-2026-62803">CVE-2026-62803</a>, <a href="#cve-2026-62807">CVE-2026-62807</a>, <a href="#cve-2026-62814">CVE-2026-62814</a>, <a href="#cve-2026-62823">CVE-2026-62823</a>.</p>
<h2 id="cve-2026-62747">CVE-2026-62747</h2>
<p>CVE-2026-62747 is a heap-based buffer overflow vulnerability within the Windows Device Association Service. An attacker with local authorization can exploit this flaw to execute code with elevated system privileges.</p>
<p>Affected products:</p>
<ul>
<li>Windows Device Association Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62747">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62747</a></p>
<p>Related in this roundup: <a href="#cve-2026-62710">CVE-2026-62710</a>.</p>
<h2 id="cve-2026-62750">CVE-2026-62750</h2>
<p>CVE-2026-62750 is a vulnerability in the Windows HTTP Protocol Stack involving partial string comparison. This flaw allows an unauthorized attacker located on an adjacent network to perform data tampering by exploiting the way the protocol stack processes HTTP requests.</p>
<p>Affected products:</p>
<ul>
<li>Windows HTTP Protocol Stack</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62750">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62750</a></p>
<h2 id="cve-2026-62754">CVE-2026-62754</h2>
<p>CVE-2026-62754 is a heap-based buffer overflow vulnerability in the Windows Kerberos component that allows an authorized local attacker to elevate their privileges on an affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62754">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62754</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62783">CVE-2026-62783</h2>
<p>CVE-2026-62783 is a heap-based buffer overflow vulnerability within the Windows Remote Access Connection Manager. An authenticated local attacker can exploit this flaw to execute code with elevated privileges, effectively resulting in local privilege escalation.</p>
<p>Affected products:</p>
<ul>
<li>Windows Remote Access Connection Manager</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62783">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62783</a></p>
<p>Related in this roundup: <a href="#cve-2026-62758">CVE-2026-62758</a>.</p>
<h2 id="cve-2026-62755">CVE-2026-62755</h2>
<p>A stack-based buffer overflow vulnerability exists in the Windows DHCP Client that allows a locally authenticated attacker to escalate their privileges. This vulnerability is classified as a buffer-overflow and involves local exploitation.</p>
<p>Affected products:</p>
<ul>
<li>Windows DHCP Client</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62755">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62755</a></p>
<p>Related in this roundup: <a href="#cve-2026-61361">CVE-2026-61361</a>, <a href="#cve-2026-65785">CVE-2026-65785</a>, <a href="#cve-2026-62736">CVE-2026-62736</a>.</p>
<h2 id="cve-2026-62758">CVE-2026-62758</h2>
<p>CVE-2026-62758 is a heap-based buffer overflow vulnerability in the Windows Remote Access Connection Manager that permits an authorized local attacker to elevate their privileges on an affected Windows system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Remote Access Connection Manager</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62758">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62758</a></p>
<p>Related in this roundup: <a href="#cve-2026-62783">CVE-2026-62783</a>.</p>
<h2 id="cve-2026-62766">CVE-2026-62766</h2>
<p>CVE-2026-62766 is a privilege escalation vulnerability in the Windows Kerberos component caused by a double free memory management flaw. An attacker with local authorization can exploit this vulnerability to elevate their privileges on an affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62766">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62766</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62773">CVE-2026-62773</h2>
<p>A use-after-free vulnerability in the Windows Kerberos component allows an authorized local attacker to elevate their privileges to a higher level of access on the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62773">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62773</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62772">CVE-2026-62772</h2>
<p>CVE-2026-62772 describes a heap-based buffer overflow vulnerability in the Windows Container Isolation FS Filter Driver (unionfs.sys). An authenticated attacker can exploit this flaw to execute code with elevated privileges on the host system, typically within the context of the container management stack.</p>
<p>Affected products:</p>
<ul>
<li>Windows Container Isolation FS Filter Driver</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62772">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62772</a></p>
<p>Related in this roundup: <a href="#cve-2026-72971">CVE-2026-72971</a>, <a href="#cve-2026-62775">CVE-2026-62775</a>.</p>
<h2 id="cve-2026-62774">CVE-2026-62774</h2>
<p>CVE-2026-62774 describes a use-after-free vulnerability within the Windows Graphics Kernel. This flaw allows an authenticated local attacker to execute arbitrary code with elevated privileges on the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62774">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62774</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62785">CVE-2026-62785</h2>
<p>CVE-2026-62785 is a heap-based buffer overflow vulnerability in the Windows Lightweight Directory Access Protocol (LDAP) implementation. The vulnerability allows an unauthenticated, remote attacker to execute arbitrary code on the target system by sending a specially crafted request over the network.</p>
<p>Affected products:</p>
<ul>
<li>Windows LDAP</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62785">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62785</a></p>
<h2 id="cve-2026-62777">CVE-2026-62777</h2>
<p>CVE-2026-62777 describes an elevation of privilege vulnerability in the Windows License Manager due to missing authentication for a critical function. An attacker who is already authorized on the local system can exploit this flaw to execute code or perform operations with higher privileges than those they currently hold.</p>
<p>Affected products:</p>
<ul>
<li>Windows License Manager</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62777">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62777</a></p>
<h2 id="cve-2026-62779">CVE-2026-62779</h2>
<p>A use-after-free vulnerability in the Windows Schannel component allows a locally authenticated attacker to escalate their privileges. This vulnerability requires the attacker to have existing access to the system to exploit the flaw.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62779">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62779</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62792">CVE-2026-62792</h2>
<p>CVE-2026-62792 is a stack-based buffer overflow vulnerability in the Windows TCP/IP stack that enables a remote, unauthorized attacker to achieve remote code execution on affected Windows systems by sending malicious network packets.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62792">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62792</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62784">CVE-2026-62784</h2>
<p>CVE-2026-62784 is a heap-based buffer overflow vulnerability in the Microsoft Local Security Authority Server (lsasrv) that enables an authorized network-based attacker to achieve remote code execution.</p>
<p>Affected products:</p>
<ul>
<li>Local Security Authority Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62784">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62784</a></p>
<h2 id="cve-2026-62787">CVE-2026-62787</h2>
<p>CVE-2026-62787 is a use-after-free vulnerability in the Windows DNS Server component that allows an authorized attacker to achieve remote code execution over a network. Detection engineers should monitor for anomalous DNS traffic or exploitation attempts directed at DNS service processes.</p>
<p>Affected products:</p>
<ul>
<li>Windows DNS Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62787">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62787</a></p>
<p>Related in this roundup: <a href="#cve-2026-62817">CVE-2026-62817</a>, <a href="#cve-2026-62820">CVE-2026-62820</a>, <a href="#cve-2026-62878">CVE-2026-62878</a>, <a href="#cve-2026-65789">CVE-2026-65789</a>, <a href="#cve-2026-61920">CVE-2026-61920</a>.</p>
<h2 id="cve-2026-62798">CVE-2026-62798</h2>
<p>CVE-2026-62798 describes an untrusted pointer dereference vulnerability within the Windows Win32k subsystem. Successful exploitation of this vulnerability allows an authenticated attacker to disclose sensitive information from the local system.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62798">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62798</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62795">CVE-2026-62795</h2>
<p>CVE-2026-62795 is a remote code execution vulnerability in the Windows Lightweight Directory Access Protocol (LDAP) implementation. The vulnerability stems from a use-after-free condition that can be triggered by an unauthorized attacker over a network, potentially allowing arbitrary code execution on the target system.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62795">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62795</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62796">CVE-2026-62796</h2>
<p>CVE-2026-62796 is an out-of-bounds read vulnerability in the Windows NTFS file system that enables an authenticated attacker to perform local information disclosure. Detection engineers should monitor for abnormal activity or errors related to NTFS file system requests that may trigger OOB reads.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62796">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62796</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62797">CVE-2026-62797</h2>
<p>CVE-2026-62797 describes a heap-based buffer overflow vulnerability in the Windows NTFS file system driver. This flaw allows an authenticated local attacker to execute arbitrary code with elevated privileges, effectively performing local privilege escalation.</p>
<p>Affected products:</p>
<ul>
<li>Windows NTFS</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62797">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62797</a></p>
<h2 id="cve-2026-62812">CVE-2026-62812</h2>
<p>CVE-2026-62812 is a local privilege escalation vulnerability in the Windows DHCP Server service, stemming from improper link resolution before file access. An attacker with existing local access can exploit this 'link following' flaw to gain elevated system privileges.</p>
<p>Affected products:</p>
<ul>
<li>Windows DHCP Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62812">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62812</a></p>
<p>Related in this roundup: <a href="#cve-2026-62718">CVE-2026-62718</a>, <a href="#cve-2026-62715">CVE-2026-62715</a>, <a href="#cve-2026-62716">CVE-2026-62716</a>, <a href="#cve-2026-62742">CVE-2026-62742</a>, <a href="#cve-2026-62745">CVE-2026-62745</a>, <a href="#cve-2026-62720">CVE-2026-62720</a>, <a href="#cve-2026-62714">CVE-2026-62714</a>, <a href="#cve-2026-62761">CVE-2026-62761</a>, <a href="#cve-2026-62776">CVE-2026-62776</a>, <a href="#cve-2026-62803">CVE-2026-62803</a>, <a href="#cve-2026-62807">CVE-2026-62807</a>, <a href="#cve-2026-62814">CVE-2026-62814</a>, <a href="#cve-2026-62823">CVE-2026-62823</a>.</p>
<h2 id="cve-2026-62815">CVE-2026-62815</h2>
<p>CVE-2026-62815 is a use-after-free vulnerability in Microsoft QUIC that permits an unauthenticated, remote attacker to achieve remote code execution (RCE) by sending specially crafted packets over a network to a vulnerable target.</p>
<p>Affected products:</p>
<ul>
<li>Microsoft QUIC</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62815">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62815</a></p>
<p>Related in this roundup: <a href="#cve-2026-62898">CVE-2026-62898</a>.</p>
<h2 id="cve-2026-62816">CVE-2026-62816</h2>
<p>CVE-2026-62816 is a heap-based buffer overflow vulnerability in the Windows Reliable Multicast Transport Driver (RMCAST). An unauthorized attacker positioned on an adjacent network can leverage this flaw to achieve remote code execution, highlighting a critical weakness in kernel-level network packet handling.</p>
<p>Affected products:</p>
<ul>
<li>Reliable Multicast Transport Driver (RMCAST)</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62816">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62816</a></p>
<h2 id="cve-2026-62817">CVE-2026-62817</h2>
<p>CVE-2026-62817 is an out-of-bounds write vulnerability in the Windows DNS Server component that enables an unauthenticated attacker on an adjacent network to execute arbitrary code. The vulnerability stems from improper handling of memory operations within the DNS service, which can be triggered by specially crafted requests.</p>
<p>Affected products:</p>
<ul>
<li>Windows DNS Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62817">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62817</a></p>
<p>Related in this roundup: <a href="#cve-2026-62787">CVE-2026-62787</a>, <a href="#cve-2026-62820">CVE-2026-62820</a>, <a href="#cve-2026-62878">CVE-2026-62878</a>, <a href="#cve-2026-65789">CVE-2026-65789</a>, <a href="#cve-2026-61920">CVE-2026-61920</a>.</p>
<h2 id="cve-2026-62818">CVE-2026-62818</h2>
<p>CVE-2026-62818 is a remote code execution vulnerability in Windows Active Directory Certificate Services (AD CS) caused by a use-after-free condition. An authorized attacker can exploit this vulnerability over a network to execute arbitrary code on the affected server.</p>
<p>Affected products:</p>
<ul>
<li>Active Directory Certificate Services</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62818">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62818</a></p>
<h2 id="cve-2026-62819">CVE-2026-62819</h2>
<p>CVE-2026-62819 is a remote code execution vulnerability in the Windows Routing and Remote Access Service (RRAS). An unauthenticated attacker can exploit this flaw to gain unauthorized access and execute arbitrary code on a vulnerable Windows machine.</p>
<p>Affected products:</p>
<ul>
<li>Routing and Remote Access Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62819">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62819</a></p>
<h2 id="cve-2026-62820">CVE-2026-62820</h2>
<p>CVE-2026-62820 is a remote code execution vulnerability in the Windows DNS Server component caused by a race condition during concurrent execution. An unauthenticated attacker can exploit this flaw by sending specifically crafted network requests to the DNS service, potentially allowing for arbitrary code execution on the server.</p>
<p>Affected products:</p>
<ul>
<li>Windows DNS Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62820">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62820</a></p>
<p>Related in this roundup: <a href="#cve-2026-62787">CVE-2026-62787</a>, <a href="#cve-2026-62817">CVE-2026-62817</a>, <a href="#cve-2026-62878">CVE-2026-62878</a>, <a href="#cve-2026-65789">CVE-2026-65789</a>, <a href="#cve-2026-61920">CVE-2026-61920</a>.</p>
<h2 id="cve-2026-62876">CVE-2026-62876</h2>
<p>CVE-2026-62876 describes an out-of-bounds read vulnerability in the Windows Win32k subsystem that permits a locally authenticated attacker to escalate their privileges to a higher integrity level.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62876">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62876</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62877">CVE-2026-62877</h2>
<p>CVE-2026-62877 is a stack-based buffer overflow vulnerability residing in the Windows Win32K kernel component. This vulnerability allows an authenticated attacker to execute code with elevated privileges, specifically targeting the kernel-mode driver, which facilitates local privilege escalation.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62877">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62877</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62878">CVE-2026-62878</h2>
<p>CVE-2026-62878 describes a stack-based buffer overflow vulnerability in the Windows DNS Server component that enables remote code execution. An unauthenticated attacker can trigger this vulnerability over the network, potentially leading to full system compromise.</p>
<p>Affected products:</p>
<ul>
<li>Windows DNS Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62878">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62878</a></p>
<p>Related in this roundup: <a href="#cve-2026-62787">CVE-2026-62787</a>, <a href="#cve-2026-62817">CVE-2026-62817</a>, <a href="#cve-2026-62820">CVE-2026-62820</a>, <a href="#cve-2026-65789">CVE-2026-65789</a>, <a href="#cve-2026-61920">CVE-2026-61920</a>.</p>
<h2 id="cve-2026-62889">CVE-2026-62889</h2>
<p>CVE-2026-62889 is a double free vulnerability in the Windows Secure Socket Tunneling Protocol (SSTP) that allows a remote, unauthenticated attacker to achieve remote code execution (RCE) by sending specially crafted packets over the network.</p>
<p>Affected products:</p>
<ul>
<li>Windows Secure Socket Tunneling Protocol</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62889">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62889</a></p>
<h2 id="cve-2026-62890">CVE-2026-62890</h2>
<p>CVE-2026-62890 is a heap-based buffer overflow vulnerability in Windows GDI+ that allows an authenticated local attacker to escalate privileges and execute arbitrary code on the affected Windows system.</p>
<p>Affected products:</p>
<ul>
<li>Windows GDI+</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62890">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62890</a></p>
<p>Related in this roundup: <a href="#cve-2026-62709">CVE-2026-62709</a>, <a href="#cve-2026-62822">CVE-2026-62822</a>.</p>
<h2 id="cve-2026-62892">CVE-2026-62892</h2>
<p>The Capability Access Management Service (camsvc) in Microsoft Windows contains a use-after-free vulnerability that allows an authorized local attacker to achieve privilege escalation.</p>
<p>Affected products:</p>
<ul>
<li>Capability Access Management Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62892">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62892</a></p>
<h2 id="cve-2026-62893">CVE-2026-62893</h2>
<p>A use-after-free vulnerability in the Windows Deployment Services TFTP server allows an unauthenticated, remote attacker to execute arbitrary code over the network. Detection should focus on monitoring anomalous TFTP traffic and unexpected process spawns originating from the Windows Deployment Services service.</p>
<p>Affected products:</p>
<ul>
<li>Windows Deployment Services</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62893">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62893</a></p>
<h2 id="cve-2026-62894">CVE-2026-62894</h2>
<p>CVE-2026-62894 describes a heap-based buffer overflow vulnerability in the Windows DWM Core Library. An authenticated local attacker can exploit this flaw to achieve elevation of privilege on vulnerable Windows systems.</p>
<p>Affected products:</p>
<ul>
<li>Windows DWM Core Library</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62894">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62894</a></p>
<p>Related in this roundup: <a href="#cve-2026-61932">CVE-2026-61932</a>, <a href="#cve-2026-62703">CVE-2026-62703</a>.</p>
<h2 id="cve-2026-62899">CVE-2026-62899</h2>
<p>CVE-2026-62899 is a security feature bypass vulnerability in .NET caused by inconsistent interpretation of HTTP requests, enabling HTTP request/response smuggling. An attacker can exploit this over a network to circumvent security controls.</p>
<p>Affected products:</p>
<ul>
<li>.NET</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62899">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62899</a></p>
<p>Related in this roundup: <a href="#cve-2026-62900">CVE-2026-62900</a>, <a href="#cve-2026-62901">CVE-2026-62901</a>, <a href="#cve-2026-62902">CVE-2026-62902</a>, <a href="#cve-2026-62909">CVE-2026-62909</a>, <a href="#cve-2026-58641">CVE-2026-58641</a>, <a href="#cve-2026-62871">CVE-2026-62871</a>, <a href="#cve-2026-62886">CVE-2026-62886</a>.</p>
<h2 id="cve-2026-62900">CVE-2026-62900</h2>
<p>CVE-2026-62900 is an information disclosure vulnerability in the .NET framework caused by improper sanitization of sensitive data prior to storage or network transfer, potentially allowing unauthorized attackers to access sensitive information.</p>
<p>Affected products:</p>
<ul>
<li>.NET</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62900">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62900</a></p>
<p>Related in this roundup: <a href="#cve-2026-62899">CVE-2026-62899</a>, <a href="#cve-2026-62901">CVE-2026-62901</a>, <a href="#cve-2026-62902">CVE-2026-62902</a>, <a href="#cve-2026-62909">CVE-2026-62909</a>, <a href="#cve-2026-58641">CVE-2026-58641</a>, <a href="#cve-2026-62871">CVE-2026-62871</a>, <a href="#cve-2026-62886">CVE-2026-62886</a>.</p>
<h2 id="cve-2026-62901">CVE-2026-62901</h2>
<p>A denial of service vulnerability exists in .NET due to an unchecked input in a loop condition, which allows a remote, unauthorized attacker to consume excessive resources and render the service unavailable over a network.</p>
<p>Affected products:</p>
<ul>
<li>.NET</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62901">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62901</a></p>
<p>Related in this roundup: <a href="#cve-2026-62899">CVE-2026-62899</a>, <a href="#cve-2026-62900">CVE-2026-62900</a>, <a href="#cve-2026-62902">CVE-2026-62902</a>, <a href="#cve-2026-62909">CVE-2026-62909</a>, <a href="#cve-2026-58641">CVE-2026-58641</a>, <a href="#cve-2026-62871">CVE-2026-62871</a>, <a href="#cve-2026-62886">CVE-2026-62886</a>.</p>
<h2 id="cve-2026-62902">CVE-2026-62902</h2>
<p>CVE-2026-62902 describes an information disclosure vulnerability in .NET arising from the inclusion of functionality from an untrusted control sphere. This allows an unauthorized remote attacker to access sensitive information over the network, necessitating an investigation into anomalous network traffic or unauthorized data egress from .NET-based applications.</p>
<p>Affected products:</p>
<ul>
<li>.NET</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62902">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62902</a></p>
<p>Related in this roundup: <a href="#cve-2026-62899">CVE-2026-62899</a>, <a href="#cve-2026-62900">CVE-2026-62900</a>, <a href="#cve-2026-62901">CVE-2026-62901</a>, <a href="#cve-2026-62909">CVE-2026-62909</a>, <a href="#cve-2026-58641">CVE-2026-58641</a>, <a href="#cve-2026-62871">CVE-2026-62871</a>, <a href="#cve-2026-62886">CVE-2026-62886</a>.</p>
<h2 id="cve-2026-62908">CVE-2026-62908</h2>
<p>CVE-2026-62908 describes a race condition vulnerability within the Windows Backup Engine. This flaw allows an already authorized local attacker to exploit improper synchronization of shared resources, leading to the escalation of privileges on the host system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Backup Engine</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62908">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62908</a></p>
<h2 id="cve-2026-62909">CVE-2026-62909</h2>
<p>CVE-2026-62909 is a privilege escalation vulnerability in the .NET framework caused by an uncaught exception, which can be exploited by an authenticated local attacker to gain elevated privileges.</p>
<p>Affected products:</p>
<ul>
<li>.NET</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62909">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62909</a></p>
<p>Related in this roundup: <a href="#cve-2026-62899">CVE-2026-62899</a>, <a href="#cve-2026-62900">CVE-2026-62900</a>, <a href="#cve-2026-62901">CVE-2026-62901</a>, <a href="#cve-2026-62902">CVE-2026-62902</a>, <a href="#cve-2026-58641">CVE-2026-58641</a>, <a href="#cve-2026-62871">CVE-2026-62871</a>, <a href="#cve-2026-62886">CVE-2026-62886</a>.</p>
<h2 id="cve-2026-62910">CVE-2026-62910</h2>
<p>Microsoft Exchange Server contains an improper control of resource identifiers vulnerability that enables an authenticated attacker to perform a privilege escalation attack over the network.</p>
<p>Affected products:</p>
<ul>
<li>Exchange Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62910">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62910</a></p>
<p>Related in this roundup: <a href="#cve-2026-62912">CVE-2026-62912</a>, <a href="#cve-2026-62913">CVE-2026-62913</a>, <a href="#cve-2026-62914">CVE-2026-62914</a>, <a href="#cve-2026-62915">CVE-2026-62915</a>, <a href="#cve-2026-65813">CVE-2026-65813</a>, <a href="#cve-2026-62911">CVE-2026-62911</a>.</p>
<h2 id="cve-2026-62912">CVE-2026-62912</h2>
<p>CVE-2026-62912 is a denial of service vulnerability in Microsoft Exchange Server caused by the insecure deserialization of untrusted data. An authenticated attacker can exploit this flaw over the network to crash the service or render it unavailable.</p>
<p>Affected products:</p>
<ul>
<li>Exchange Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62912">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62912</a></p>
<p>Related in this roundup: <a href="#cve-2026-62910">CVE-2026-62910</a>, <a href="#cve-2026-62913">CVE-2026-62913</a>, <a href="#cve-2026-62914">CVE-2026-62914</a>, <a href="#cve-2026-62915">CVE-2026-62915</a>, <a href="#cve-2026-65813">CVE-2026-65813</a>, <a href="#cve-2026-62911">CVE-2026-62911</a>.</p>
<h2 id="cve-2026-62913">CVE-2026-62913</h2>
<p>Microsoft Exchange Server contains a heap-based buffer overflow vulnerability that allows an authenticated attacker to achieve remote code execution via network-based exploitation.</p>
<p>Affected products:</p>
<ul>
<li>Exchange Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62913">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62913</a></p>
<p>Related in this roundup: <a href="#cve-2026-62910">CVE-2026-62910</a>, <a href="#cve-2026-62912">CVE-2026-62912</a>, <a href="#cve-2026-62914">CVE-2026-62914</a>, <a href="#cve-2026-62915">CVE-2026-62915</a>, <a href="#cve-2026-65813">CVE-2026-65813</a>, <a href="#cve-2026-62911">CVE-2026-62911</a>.</p>
<h2 id="cve-2026-62914">CVE-2026-62914</h2>
<p>Microsoft Exchange Server is affected by a spoofing vulnerability due to improper neutralization of input, which allows an authorized attacker to perform cross-site scripting (XSS) attacks over a network.</p>
<p>Affected products:</p>
<ul>
<li>Exchange Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62914">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62914</a></p>
<p>Related in this roundup: <a href="#cve-2026-62910">CVE-2026-62910</a>, <a href="#cve-2026-62912">CVE-2026-62912</a>, <a href="#cve-2026-62913">CVE-2026-62913</a>, <a href="#cve-2026-62915">CVE-2026-62915</a>, <a href="#cve-2026-65813">CVE-2026-65813</a>, <a href="#cve-2026-62911">CVE-2026-62911</a>.</p>
<h2 id="cve-2026-62915">CVE-2026-62915</h2>
<p>CVE-2026-62915 is a security feature bypass vulnerability in Microsoft Exchange Server resulting from a missing authorization check. An authenticated attacker can exploit this flaw over the network to circumvent specific security controls within the application.</p>
<p>Affected products:</p>
<ul>
<li>Exchange Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62915">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62915</a></p>
<p>Related in this roundup: <a href="#cve-2026-62910">CVE-2026-62910</a>, <a href="#cve-2026-62912">CVE-2026-62912</a>, <a href="#cve-2026-62913">CVE-2026-62913</a>, <a href="#cve-2026-62914">CVE-2026-62914</a>, <a href="#cve-2026-65813">CVE-2026-65813</a>, <a href="#cve-2026-62911">CVE-2026-62911</a>.</p>
<h2 id="cve-2026-54123">CVE-2026-54123</h2>
<p>CVE-2026-54123 is an information disclosure vulnerability in Microsoft Defender for Endpoint for macOS, allowing an authorized local attacker to gain unauthorized access to sensitive information.</p>
<p>Affected products:</p>
<ul>
<li>Defender for Endpoint</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54123">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54123</a></p>
<h2 id="cve-2026-63513">CVE-2026-63513</h2>
<p>CVE-2026-63513 is a heap-based buffer overflow vulnerability within the Microsoft Office Graphics Component that allows an unauthorized attacker to achieve remote code execution. The vulnerability is triggered when processing malicious content, necessitating monitoring for unexpected process behavior or memory corruption patterns within Office applications.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63513">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63513</a></p>
<p>Related in this roundup: <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-63515">CVE-2026-63515</h2>
<p>CVE-2026-63515 is an out-of-bounds read vulnerability in Microsoft Office that can be exploited by an unauthorized attacker to achieve remote code execution. Detection engineers should monitor for abnormal process behavior or memory access violations associated with Office applications.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63515">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63515</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-63517">CVE-2026-63517</h2>
<p>CVE-2026-63517 describes an out-of-bounds read vulnerability in the Microsoft Office Graphics Component that allows an unauthorized local attacker to perform information disclosure. The vulnerability is exploited by processing maliciously crafted content in Office applications.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63517">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63517</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-63518">CVE-2026-63518</h2>
<p>CVE-2026-63518 describes a heap-based buffer overflow vulnerability in Microsoft Office Word that enables a remote attacker to execute arbitrary code. The vulnerability is triggered when the application processes a malformed document, potentially allowing an attacker to gain control of the system by enticing a user to open a malicious file.</p>
<p>Affected products:</p>
<ul>
<li>Office Word</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63518">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63518</a></p>
<p>Related in this roundup: <a href="#cve-2026-70311">CVE-2026-70311</a>, <a href="#cve-2026-70319">CVE-2026-70319</a>, <a href="#cve-2026-63528">CVE-2026-63528</a>, <a href="#cve-2026-63527">CVE-2026-63527</a>, <a href="#cve-2026-63531">CVE-2026-63531</a>, <a href="#cve-2026-64905">CVE-2026-64905</a>, <a href="#cve-2026-64907">CVE-2026-64907</a>, <a href="#cve-2026-64915">CVE-2026-64915</a>, <a href="#cve-2026-64917">CVE-2026-64917</a>, <a href="#cve-2026-66806">CVE-2026-66806</a>, <a href="#cve-2026-66810">CVE-2026-66810</a>.</p>
<h2 id="cve-2026-63521">CVE-2026-63521</h2>
<p>CVE-2026-63521 is an out-of-bounds read vulnerability in Microsoft Office Word that enables an unauthorized local attacker to perform information disclosure.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63521">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63521</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-63519">CVE-2026-63519</h2>
<p>CVE-2026-63519 describes a heap-based buffer overflow vulnerability within the Microsoft Office Graphics Component. An unauthenticated attacker can exploit this flaw to achieve remote code execution by tricking a user into opening a specially crafted document, leading to local code execution under the context of the current user.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63519">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63519</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-64922">CVE-2026-64922</h2>
<p>CVE-2026-64922 describes a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server caused by improper neutralization of user-supplied input during web page generation. An authenticated attacker can exploit this flaw over a network to conduct spoofing attacks, potentially allowing the execution of arbitrary scripts in the victim's browser session.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64922">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64922</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-65657">CVE-2026-65657</h2>
<p>CVE-2026-65657 is a use-after-free vulnerability in Microsoft Office that enables an attacker to achieve remote code execution on a target system. Exploitation requires the victim to interact with a specially crafted file, leading to memory corruption that the attacker can leverage for arbitrary code execution.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65657">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65657</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-65656">CVE-2026-65656</h2>
<p>CVE-2026-65656 describes a command injection vulnerability in Microsoft Office that enables an unauthorized attacker to achieve remote code execution. The vulnerability stems from improper neutralization of special elements used in commands, allowing for arbitrary code execution when a malicious file or element is processed by the application.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65656">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65656</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-65658">CVE-2026-65658</h2>
<p>CVE-2026-65658 is a remote code execution vulnerability in Microsoft SharePoint Server caused by improper deserialization of untrusted data. An authorized attacker can exploit this flaw by sending specially crafted input to the server, leading to arbitrary code execution in the context of the SharePoint application.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65658">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65658</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-65661">CVE-2026-65661</h2>
<p>CVE-2026-65661 is a heap-based buffer overflow vulnerability in Microsoft Office that enables an unauthorized attacker to achieve remote code execution on the local machine.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65661">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65661</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-65663">CVE-2026-65663</h2>
<p>CVE-2026-65663 describes a remote code execution vulnerability in Microsoft SharePoint Server arising from the insecure deserialization of untrusted data. An authorized attacker can leverage this flaw to execute arbitrary code over the network, potentially leading to full system compromise.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65663">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65663</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-65660">CVE-2026-65660</h2>
<p>CVE-2026-65660 is a spoofing vulnerability in Microsoft SharePoint Server caused by improper control of code generation, allowing an authorized attacker to perform spoofing attacks over a network via code injection.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-65664">CVE-2026-65664</h2>
<p>CVE-2026-65664 is a heap-based buffer overflow vulnerability within the Microsoft Office Graphics Component that permits an unauthorized attacker to achieve remote code execution on the target system.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65664">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65664</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-65665">CVE-2026-65665</h2>
<p>CVE-2026-65665 is a remote code execution vulnerability in Microsoft SharePoint Server caused by improper deserialization of untrusted data. An authorized attacker can exploit this flaw over the network to execute arbitrary code on the affected server.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65665">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65665</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-65662">CVE-2026-65662</h2>
<p>CVE-2026-65662 is an out-of-bounds read vulnerability in the Windows Graphics Device Interface (GDI) component. An authorized, local attacker can exploit this flaw to perform an unauthorized information disclosure, potentially leaking sensitive data from memory.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65662">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65662</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-65671">CVE-2026-65671</h2>
<p>CVE-2026-65671 is a heap-based buffer overflow vulnerability within the Windows Remote Access API that enables an authenticated local attacker to perform privilege escalation on affected Windows systems.</p>
<p>Affected products:</p>
<ul>
<li>Windows Remote Access API</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65671">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65671</a></p>
<h2 id="cve-2026-65672">CVE-2026-65672</h2>
<p>CVE-2026-65672 is a heap-based buffer overflow vulnerability in the Windows Remote Access API that allows an authenticated local attacker to elevate their privileges on the host system.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65672">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65672</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-65675">CVE-2026-65675</h2>
<p>CVE-2026-65675 is a security feature bypass vulnerability in the Visual Studio Code CoPilot Chat Extension. An unauthorized attacker can leverage this flaw over a network to circumvent established security controls within the extension's environment.</p>
<p>Affected products:</p>
<ul>
<li>Visual Studio Code CoPilot Chat Extension</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65675">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65675</a></p>
<h2 id="cve-2026-65678">CVE-2026-65678</h2>
<p>A use-after-free vulnerability exists in the Windows Win32k subsystem that enables a local, authorized attacker to elevate their privileges to higher levels of access on the system.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65678">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65678</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-65785">CVE-2026-65785</h2>
<p>CVE-2026-65785 is a denial-of-service vulnerability in the Windows DHCP Client service. The vulnerability allows an unauthorized attacker positioned on an adjacent network to trigger uncontrolled resource consumption, leading to a service outage on the affected Windows system.</p>
<p>Affected products:</p>
<ul>
<li>Windows DHCP Client</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65785">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65785</a></p>
<p>Related in this roundup: <a href="#cve-2026-61361">CVE-2026-61361</a>, <a href="#cve-2026-62755">CVE-2026-62755</a>, <a href="#cve-2026-62736">CVE-2026-62736</a>.</p>
<h2 id="cve-2026-65784">CVE-2026-65784</h2>
<p>CVE-2026-65784 is an information disclosure vulnerability in the Windows NTFS filesystem driver caused by an out-of-bounds read condition. An authenticated local attacker can leverage this flaw to access sensitive memory contents.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65784">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65784</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-65786">CVE-2026-65786</h2>
<p>CVE-2026-65786 is a heap-based buffer overflow vulnerability in the Windows Desktop Window Manager (DWM) component. An attacker who has already achieved local execution can exploit this flaw to escalate privileges to a higher integrity level on the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Desktop Window Manager</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65786">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65786</a></p>
<p>Related in this roundup: <a href="#cve-2026-65787">CVE-2026-65787</a>, <a href="#cve-2026-65788">CVE-2026-65788</a>.</p>
<h2 id="cve-2026-65789">CVE-2026-65789</h2>
<p>CVE-2026-65789 describes a use-after-free vulnerability within the Windows DNS Server component. The vulnerability allows an unauthenticated, remote attacker to trigger memory corruption and achieve remote code execution (RCE) by sending specially crafted packets to a vulnerable DNS server.</p>
<p>Affected products:</p>
<ul>
<li>Windows DNS Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65789">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65789</a></p>
<p>Related in this roundup: <a href="#cve-2026-62787">CVE-2026-62787</a>, <a href="#cve-2026-62817">CVE-2026-62817</a>, <a href="#cve-2026-62820">CVE-2026-62820</a>, <a href="#cve-2026-62878">CVE-2026-62878</a>, <a href="#cve-2026-61920">CVE-2026-61920</a>.</p>
<h2 id="cve-2026-65787">CVE-2026-65787</h2>
<p>CVE-2026-65787 is a heap-based buffer overflow vulnerability in the Desktop Window Manager component of Windows. An authenticated local attacker can leverage this flaw to elevate their privileges on the host system.</p>
<p>Affected products:</p>
<ul>
<li>Desktop Window Manager</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65787">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65787</a></p>
<p>Related in this roundup: <a href="#cve-2026-65786">CVE-2026-65786</a>, <a href="#cve-2026-65788">CVE-2026-65788</a>.</p>
<h2 id="cve-2026-65788">CVE-2026-65788</h2>
<p>A use-after-free vulnerability in the Windows Desktop Window Manager allows a locally authenticated attacker to gain elevated privileges on the system.</p>
<p>Affected products:</p>
<ul>
<li>Desktop Window Manager</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65788">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65788</a></p>
<p>Related in this roundup: <a href="#cve-2026-65786">CVE-2026-65786</a>, <a href="#cve-2026-65787">CVE-2026-65787</a>.</p>
<h2 id="cve-2026-65807">CVE-2026-65807</h2>
<p>CVE-2026-65807 is a type confusion vulnerability in Microsoft Excel that allows a remote, unauthorized attacker to achieve remote code execution. The vulnerability is triggered when the application handles incompatible types, potentially leading to arbitrary code execution if a user opens a maliciously crafted file.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65807">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65807</a></p>
<p>Related in this roundup: <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-65811">CVE-2026-65811</h2>
<p>CVE-2026-65811 describes a remote code execution vulnerability in Microsoft Power BI caused by improper input validation. An authorized attacker can exploit this flaw over the network to execute arbitrary code, requiring security updates to remediate the lack of input sanitization.</p>
<p>Affected products:</p>
<ul>
<li>Power BI</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65811">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65811</a></p>
<h2 id="cve-2026-65813">CVE-2026-65813</h2>
<p>CVE-2026-65813 is a server-side request forgery (SSRF) vulnerability in Microsoft Exchange Server that enables an already authorized attacker to perform privilege escalation across a network.</p>
<p>Affected products:</p>
<ul>
<li>Exchange Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65813">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65813</a></p>
<p>Related in this roundup: <a href="#cve-2026-62910">CVE-2026-62910</a>, <a href="#cve-2026-62912">CVE-2026-62912</a>, <a href="#cve-2026-62913">CVE-2026-62913</a>, <a href="#cve-2026-62914">CVE-2026-62914</a>, <a href="#cve-2026-62915">CVE-2026-62915</a>, <a href="#cve-2026-62911">CVE-2026-62911</a>.</p>
<h2 id="cve-2026-65814">CVE-2026-65814</h2>
<p>A heap-based buffer overflow vulnerability in the Windows Storage Port Driver allows a local, authorized attacker to achieve privilege escalation by exploiting the vulnerable driver component.</p>
<p>Affected products:</p>
<ul>
<li>Windows Storage Port Driver</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65814">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65814</a></p>
<h2 id="cve-2026-65815">CVE-2026-65815</h2>
<p>CVE-2026-65815 is a remote code execution vulnerability in Microsoft Dynamics 365 on-premises installations. The flaw arises from insecure deserialization of untrusted data, which can be exploited by an authenticated attacker over a network to execute arbitrary code on the affected server.</p>
<p>Affected products:</p>
<ul>
<li>Dynamics 365</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65815">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65815</a></p>
<p>Related in this roundup: <a href="#cve-2026-66301">CVE-2026-66301</a>.</p>
<h2 id="cve-2026-66799">CVE-2026-66799</h2>
<p>CVE-2026-66799 is a heap-based buffer overflow vulnerability in the Windows Key Guard component that enables an authorized local attacker to elevate their privileges on the host system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Key Guard</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66799">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66799</a></p>
<h2 id="cve-2026-68792">CVE-2026-68792</h2>
<p>CVE-2026-68792 describes a command injection vulnerability within Microsoft Office that enables an authorized local attacker to elevate their privileges. Detection engineers should monitor for unauthorized or suspicious command executions originating from Office application processes.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68792">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68792</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-68793">CVE-2026-68793</h2>
<p>CVE-2026-68793 describes an out-of-bounds read vulnerability in Microsoft Excel that can be leveraged by an unauthorized attacker to achieve remote code execution, typically through the processing of a maliciously crafted file.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68793">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68793</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68794">CVE-2026-68794</h2>
<p>CVE-2026-68794 is a heap-based buffer overflow vulnerability in Microsoft Excel that can be exploited by an unauthorized attacker to achieve remote code execution. The vulnerability is triggered by processing malicious files, allowing for arbitrary code execution in the context of the current user.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68794">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68794</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68795">CVE-2026-68795</h2>
<p>CVE-2026-68795 is a stack-based buffer overflow vulnerability in Microsoft Excel that allows a local, unauthorized attacker to execute arbitrary code. The vulnerability stems from improper memory handling within the application, and exploitation could lead to full code execution under the privileges of the current user.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68795">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68795</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68796">CVE-2026-68796</h2>
<p>A heap-based buffer overflow vulnerability exists in Microsoft Excel that allows an attacker to execute arbitrary code. The vulnerability occurs during the processing of malformed Excel files, potentially leading to remote code execution if a user opens a specially crafted document.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68796">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68796</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68800">CVE-2026-68800</h2>
<p>CVE-2026-68800 is a heap-based buffer overflow vulnerability in Microsoft Excel that allows an unauthorized attacker to execute arbitrary code locally. Detection should focus on monitoring anomalous process spawning or memory access patterns within the Excel application process.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68800">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68800</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68802">CVE-2026-68802</h2>
<p>CVE-2026-68802 is an out-of-bounds read vulnerability in Microsoft Excel that enables a local unauthorized attacker to disclose sensitive information. The vulnerability occurs due to improper memory handling, which could be exploited by an attacker to read data outside the intended memory bounds of the application.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68802">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68802</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68807">CVE-2026-68807</h2>
<p>CVE-2026-68807 is a heap-based buffer overflow vulnerability in Microsoft Excel that allows an unauthorized attacker to achieve remote code execution on the local system.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68807">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68807</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68806">CVE-2026-68806</h2>
<p>CVE-2026-68806 is an out-of-bounds write vulnerability in Microsoft Excel that allows an unauthorized attacker to achieve remote code execution. The vulnerability is triggered when processing specifically crafted files, leading to memory corruption issues.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68806">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68806</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68808">CVE-2026-68808</h2>
<p>CVE-2026-68808 is an out-of-bounds read vulnerability in Microsoft Excel that allows an unauthorized attacker to perform information disclosure on a local system.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68808">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68808</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68809">CVE-2026-68809</h2>
<p>CVE-2026-68809 is an information disclosure vulnerability in Microsoft PowerPoint caused by incomplete cleanup processes, potentially allowing unauthorized local attackers to access sensitive data.</p>
<p>Affected products:</p>
<ul>
<li>PowerPoint</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68809">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68809</a></p>
<p>Related in this roundup: <a href="#cve-2026-70312">CVE-2026-70312</a>, <a href="#cve-2026-70313">CVE-2026-70313</a>, <a href="#cve-2026-70316">CVE-2026-70316</a>, <a href="#cve-2026-70325">CVE-2026-70325</a>, <a href="#cve-2026-70320">CVE-2026-70320</a>, <a href="#cve-2026-70322">CVE-2026-70322</a>.</p>
<h2 id="cve-2026-68810">CVE-2026-68810</h2>
<p>CVE-2026-68810 is a remote code execution vulnerability in Microsoft Excel caused by an untrusted pointer dereference. An attacker can exploit this flaw by enticing a user to open a specially crafted malicious file, leading to arbitrary code execution on the host system.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68810">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68810</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68811">CVE-2026-68811</h2>
<p>A type confusion vulnerability exists in Microsoft Excel that allows an unauthorized attacker to achieve remote code execution on the host machine by inducing the application to access a resource with an incompatible type.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68811">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68811</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68813">CVE-2026-68813</h2>
<p>CVE-2026-68813 describes an out-of-bounds read vulnerability in Microsoft Excel that enables a local attacker to perform unauthorized information disclosure. This vulnerability stems from improper memory handling within the application, potentially allowing access to sensitive data processed by the software.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68813">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68813</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68815">CVE-2026-68815</h2>
<p>CVE-2026-68815 is a heap-based buffer overflow vulnerability in Microsoft Excel that allows an unauthorized attacker to achieve remote code execution on the local system.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68815">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68815</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68816">CVE-2026-68816</h2>
<p>A stack-based buffer overflow vulnerability exists in Microsoft Excel that can be exploited by an unauthorized attacker to achieve remote code execution via a specially crafted document file.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68816">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68816</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68819">CVE-2026-68819</h2>
<p>CVE-2026-68819 describes a buffer over-read vulnerability in the Windows Network File System (NFS) component, which can be exploited by an unauthenticated remote attacker to trigger a denial-of-service (DoS) condition on the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Network File System</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68819">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68819</a></p>
<h2 id="cve-2026-68820">CVE-2026-68820</h2>
<p>CVE-2026-68820 is a use-after-free vulnerability within the Windows Ancillary Function Driver for WinSock (afdsys.sys). An authenticated local attacker can exploit this flaw to execute arbitrary code in the context of the kernel, resulting in privilege escalation.</p>
<p>Affected products:</p>
<ul>
<li>Windows Ancillary Function Driver for WinSock</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820</a></p>
<p>Related in this roundup: <a href="#cve-2026-61348">CVE-2026-61348</a>.</p>
<h2 id="cve-2026-68821">CVE-2026-68821</h2>
<p>An elevation of privilege vulnerability exists in Windows Package Manager due to improper privilege management. An authorized local attacker can exploit this flaw to execute code or perform operations with higher privileges than currently permitted on the system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Package Manager</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68821">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68821</a></p>
<h2 id="cve-2026-69320">CVE-2026-69320</h2>
<p>CVE-2026-69320 describes an OS command injection vulnerability in Visual Studio Code that permits an unauthorized remote attacker to execute arbitrary code. The flaw stems from improper neutralization of special elements used in system commands, potentially leading to full compromise of the application environment.</p>
<p>Affected products:</p>
<ul>
<li>Visual Studio Code</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69320">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69320</a></p>
<p>Related in this roundup: <a href="#cve-2026-58650">CVE-2026-58650</a>, <a href="#cve-2026-59113">CVE-2026-59113</a>, <a href="#cve-2026-47285">CVE-2026-47285</a>, <a href="#cve-2026-69278">CVE-2026-69278</a>, <a href="#cve-2026-69306">CVE-2026-69306</a>, <a href="#cve-2026-70336">CVE-2026-70336</a>, <a href="#cve-2026-54981">CVE-2026-54981</a>.</p>
<h2 id="cve-2026-69278">CVE-2026-69278</h2>
<p>CVE-2026-69278 is a security feature bypass vulnerability in Visual Studio Code caused by incorrect authorization logic. The vulnerability allows an unauthorized local attacker to bypass existing security controls, potentially facilitating further malicious activities on the host system.</p>
<p>Affected products:</p>
<ul>
<li>Visual Studio Code</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69278">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69278</a></p>
<p>Related in this roundup: <a href="#cve-2026-58650">CVE-2026-58650</a>, <a href="#cve-2026-59113">CVE-2026-59113</a>, <a href="#cve-2026-47285">CVE-2026-47285</a>, <a href="#cve-2026-69320">CVE-2026-69320</a>, <a href="#cve-2026-69306">CVE-2026-69306</a>, <a href="#cve-2026-70336">CVE-2026-70336</a>, <a href="#cve-2026-54981">CVE-2026-54981</a>.</p>
<h2 id="cve-2026-69306">CVE-2026-69306</h2>
<p>CVE-2026-69306 is a security feature bypass vulnerability in Visual Studio Code caused by an insecure failure state. An attacker can exploit this flaw over a network to bypass security restrictions by triggering a failure that defaults to an open access state.</p>
<p>Affected products:</p>
<ul>
<li>Visual Studio Code</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69306">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69306</a></p>
<p>Related in this roundup: <a href="#cve-2026-58650">CVE-2026-58650</a>, <a href="#cve-2026-59113">CVE-2026-59113</a>, <a href="#cve-2026-47285">CVE-2026-47285</a>, <a href="#cve-2026-69320">CVE-2026-69320</a>, <a href="#cve-2026-69278">CVE-2026-69278</a>, <a href="#cve-2026-70336">CVE-2026-70336</a>, <a href="#cve-2026-54981">CVE-2026-54981</a>.</p>
<h2 id="cve-2026-70307">CVE-2026-70307</h2>
<p>A use-after-free vulnerability exists in the Windows Ancillary Function Driver for WinSock (afdsys) that allows a locally authenticated attacker to elevate their privileges to system level.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70307">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70307</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-66301">CVE-2026-66301</h2>
<p>Microsoft Dynamics 365 (on-premises) contains an information disclosure vulnerability that allows an authenticated attacker to gain unauthorized access to sensitive information over a network. The vulnerability exists due to improper exposure of sensitive data.</p>
<p>Affected products:</p>
<ul>
<li>Dynamics 365</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66301">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66301</a></p>
<p>Related in this roundup: <a href="#cve-2026-65815">CVE-2026-65815</a>.</p>
<h2 id="cve-2026-70312">CVE-2026-70312</h2>
<p>CVE-2026-70312 is an information disclosure vulnerability in Microsoft PowerPoint caused by improper input validation. An unauthorized attacker can exploit this flaw to disclose sensitive local information.</p>
<p>Affected products:</p>
<ul>
<li>PowerPoint</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70312">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70312</a></p>
<p>Related in this roundup: <a href="#cve-2026-68809">CVE-2026-68809</a>, <a href="#cve-2026-70313">CVE-2026-70313</a>, <a href="#cve-2026-70316">CVE-2026-70316</a>, <a href="#cve-2026-70325">CVE-2026-70325</a>, <a href="#cve-2026-70320">CVE-2026-70320</a>, <a href="#cve-2026-70322">CVE-2026-70322</a>.</p>
<h2 id="cve-2026-70311">CVE-2026-70311</h2>
<p>CVE-2026-70311 describes a use-after-free vulnerability in Microsoft Office Word that enables an unauthorized attacker to achieve remote code execution. The vulnerability allows an attacker to manipulate memory management in the application to execute arbitrary code, necessitating immediate patching of affected Office installations.</p>
<p>Affected products:</p>
<ul>
<li>Office Word</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70311">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70311</a></p>
<p>Related in this roundup: <a href="#cve-2026-63518">CVE-2026-63518</a>, <a href="#cve-2026-70319">CVE-2026-70319</a>, <a href="#cve-2026-63528">CVE-2026-63528</a>, <a href="#cve-2026-63527">CVE-2026-63527</a>, <a href="#cve-2026-63531">CVE-2026-63531</a>, <a href="#cve-2026-64905">CVE-2026-64905</a>, <a href="#cve-2026-64907">CVE-2026-64907</a>, <a href="#cve-2026-64915">CVE-2026-64915</a>, <a href="#cve-2026-64917">CVE-2026-64917</a>, <a href="#cve-2026-66806">CVE-2026-66806</a>, <a href="#cve-2026-66810">CVE-2026-66810</a>.</p>
<h2 id="cve-2026-70313">CVE-2026-70313</h2>
<p>Microsoft PowerPoint is vulnerable to an information disclosure flaw due to improper input validation, which can be leveraged by an unauthorized attacker to access sensitive local information via a maliciously crafted file.</p>
<p>Affected products:</p>
<ul>
<li>PowerPoint</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70313">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70313</a></p>
<p>Related in this roundup: <a href="#cve-2026-68809">CVE-2026-68809</a>, <a href="#cve-2026-70312">CVE-2026-70312</a>, <a href="#cve-2026-70316">CVE-2026-70316</a>, <a href="#cve-2026-70325">CVE-2026-70325</a>, <a href="#cve-2026-70320">CVE-2026-70320</a>, <a href="#cve-2026-70322">CVE-2026-70322</a>.</p>
<h2 id="cve-2026-70310">CVE-2026-70310</h2>
<p>CVE-2026-70310 is an out-of-bounds read vulnerability in Microsoft Word that allows an unauthorized attacker to perform local information disclosure. The vulnerability occurs due to improper memory handling during document processing.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
<li>Word</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70310">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70310</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-70316">CVE-2026-70316</h2>
<p>CVE-2026-70316 is an information disclosure vulnerability in Microsoft PowerPoint caused by improper input validation. An attacker could exploit this flaw to gain unauthorized access to sensitive information stored locally on the system.</p>
<p>Affected products:</p>
<ul>
<li>PowerPoint</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70316">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70316</a></p>
<p>Related in this roundup: <a href="#cve-2026-68809">CVE-2026-68809</a>, <a href="#cve-2026-70312">CVE-2026-70312</a>, <a href="#cve-2026-70313">CVE-2026-70313</a>, <a href="#cve-2026-70325">CVE-2026-70325</a>, <a href="#cve-2026-70320">CVE-2026-70320</a>, <a href="#cve-2026-70322">CVE-2026-70322</a>.</p>
<h2 id="cve-2026-70315">CVE-2026-70315</h2>
<p>CVE-2026-70315 is an out-of-bounds read vulnerability in Microsoft Office that enables an unauthorized attacker to perform local information disclosure. The vulnerability is triggered when the application fails to correctly handle memory access, allowing data to be read outside of the intended buffer.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70315">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70315</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-70321">CVE-2026-70321</h2>
<p>CVE-2026-70321 is a remote code execution vulnerability in Microsoft SharePoint caused by the insecure deserialization of untrusted data. An authorized attacker can leverage this flaw to execute arbitrary code over the network, requiring security teams to prioritize patching of SharePoint instances.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70321">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70321</a></p>
<p>Related in this roundup: <a href="#cve-2026-57105">CVE-2026-57105</a>, <a href="#cve-2026-70324">CVE-2026-70324</a>, <a href="#cve-2026-70306">CVE-2026-70306</a>.</p>
<h2 id="cve-2026-70318">CVE-2026-70318</h2>
<p>Microsoft Excel contains an information disclosure vulnerability caused by improper input validation. This vulnerability allows an unauthorized local attacker to access sensitive information by exploiting the flaw during the processing of specially crafted files.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70318">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70318</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-70314">CVE-2026-70314</h2>
<p>CVE-2026-70314 describes an information disclosure vulnerability in Microsoft Office caused by improper input validation. An unauthorized attacker can leverage this flaw to access sensitive information locally.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70314">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70314</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-70317">CVE-2026-70317</h2>
<p>CVE-2026-70317 describes an information disclosure vulnerability in Microsoft Office resulting from the use of an uninitialized resource. This flaw allows an unauthorized attacker to access sensitive information locally on an affected system.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70317">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70317</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-70325">CVE-2026-70325</h2>
<p>A vulnerability in Microsoft PowerPoint exists due to improper input validation, allowing an attacker to perform information disclosure locally. Detection engineers should monitor for anomalous file access patterns or suspicious process activity originating from the PowerPoint application.</p>
<p>Affected products:</p>
<ul>
<li>PowerPoint</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70325">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70325</a></p>
<p>Related in this roundup: <a href="#cve-2026-68809">CVE-2026-68809</a>, <a href="#cve-2026-70312">CVE-2026-70312</a>, <a href="#cve-2026-70313">CVE-2026-70313</a>, <a href="#cve-2026-70316">CVE-2026-70316</a>, <a href="#cve-2026-70320">CVE-2026-70320</a>, <a href="#cve-2026-70322">CVE-2026-70322</a>.</p>
<h2 id="cve-2026-70319">CVE-2026-70319</h2>
<p>CVE-2026-70319 is an information disclosure vulnerability in Microsoft Office Word caused by improper input validation. The vulnerability allows an unauthorized attacker to potentially gain access to sensitive information stored locally on the user's system through the application's processing of specially crafted files.</p>
<p>Affected products:</p>
<ul>
<li>Office Word</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70319">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70319</a></p>
<p>Related in this roundup: <a href="#cve-2026-63518">CVE-2026-63518</a>, <a href="#cve-2026-70311">CVE-2026-70311</a>, <a href="#cve-2026-63528">CVE-2026-63528</a>, <a href="#cve-2026-63527">CVE-2026-63527</a>, <a href="#cve-2026-63531">CVE-2026-63531</a>, <a href="#cve-2026-64905">CVE-2026-64905</a>, <a href="#cve-2026-64907">CVE-2026-64907</a>, <a href="#cve-2026-64915">CVE-2026-64915</a>, <a href="#cve-2026-64917">CVE-2026-64917</a>, <a href="#cve-2026-66806">CVE-2026-66806</a>, <a href="#cve-2026-66810">CVE-2026-66810</a>.</p>
<h2 id="cve-2026-70320">CVE-2026-70320</h2>
<p>An information disclosure vulnerability exists in Microsoft PowerPoint due to improper input validation, allowing an attacker to access sensitive local information.</p>
<p>Affected products:</p>
<ul>
<li>PowerPoint</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70320">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70320</a></p>
<p>Related in this roundup: <a href="#cve-2026-68809">CVE-2026-68809</a>, <a href="#cve-2026-70312">CVE-2026-70312</a>, <a href="#cve-2026-70313">CVE-2026-70313</a>, <a href="#cve-2026-70316">CVE-2026-70316</a>, <a href="#cve-2026-70325">CVE-2026-70325</a>, <a href="#cve-2026-70322">CVE-2026-70322</a>.</p>
<h2 id="cve-2026-70323">CVE-2026-70323</h2>
<p>CVE-2026-70323 is an information disclosure vulnerability in Microsoft Office resulting from improper input validation. An unauthorized attacker can leverage this flaw to access sensitive information on the local system.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70323">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70323</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-70322">CVE-2026-70322</h2>
<p>CVE-2026-70322 describes an information disclosure vulnerability in Microsoft PowerPoint caused by improper input validation. An unauthorized attacker can exploit this flaw to access sensitive information locally on the host system.</p>
<p>Affected products:</p>
<ul>
<li>PowerPoint</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70322">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70322</a></p>
<p>Related in this roundup: <a href="#cve-2026-68809">CVE-2026-68809</a>, <a href="#cve-2026-70312">CVE-2026-70312</a>, <a href="#cve-2026-70313">CVE-2026-70313</a>, <a href="#cve-2026-70316">CVE-2026-70316</a>, <a href="#cve-2026-70325">CVE-2026-70325</a>, <a href="#cve-2026-70320">CVE-2026-70320</a>.</p>
<h2 id="cve-2026-70324">CVE-2026-70324</h2>
<p>An elevation of privilege vulnerability exists in Microsoft SharePoint due to a server-side request forgery (SSRF) flaw. An authorized attacker can exploit this vulnerability over a network to elevate their privileges within the environment.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70324">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70324</a></p>
<p>Related in this roundup: <a href="#cve-2026-57105">CVE-2026-57105</a>, <a href="#cve-2026-70321">CVE-2026-70321</a>, <a href="#cve-2026-70306">CVE-2026-70306</a>.</p>
<h2 id="cve-2026-70327">CVE-2026-70327</h2>
<p>CVE-2026-70327 is an out-of-bounds read vulnerability in Microsoft Excel that allows an attacker to perform unauthorized information disclosure. Successful exploitation requires an attacker to leverage the memory access issue to read sensitive data over a network, potentially exposing information processed within the application context.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70327">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70327</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-70328">CVE-2026-70328</h2>
<p>CVE-2026-70328 describes an out-of-bounds read vulnerability in Microsoft Excel that can be exploited by an unauthorized attacker to disclose sensitive information over the network.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70328">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70328</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-70329">CVE-2026-70329</h2>
<p>CVE-2026-70329 is a remote code execution vulnerability in Microsoft Outlook caused by an integer overflow or wraparound condition. An unauthenticated attacker can exploit this flaw by sending a specially crafted message or file to execute arbitrary code on the target system over the network.</p>
<p>Affected products:</p>
<ul>
<li>Outlook</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70329">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70329</a></p>
<p>Related in this roundup: <a href="#cve-2026-62882">CVE-2026-62882</a>.</p>
<h2 id="cve-2026-70304">CVE-2026-70304</h2>
<p>CVE-2026-70304 is a heap-based buffer overflow vulnerability in the Windows DNS component that allows a locally authenticated attacker to escalate their privileges. The vulnerability occurs due to improper memory management, enabling code execution with higher permissions.</p>
<p>Affected products:</p>
<ul>
<li>Windows DNS</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70304">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70304</a></p>
<p>Related in this roundup: <a href="#cve-2026-70330">CVE-2026-70330</a>, <a href="#cve-2026-62769">CVE-2026-62769</a>, <a href="#cve-2026-62778">CVE-2026-62778</a>, <a href="#cve-2026-62881">CVE-2026-62881</a>, <a href="#cve-2026-62883">CVE-2026-62883</a>, <a href="#cve-2026-65795">CVE-2026-65795</a>, <a href="#cve-2026-65797">CVE-2026-65797</a>, <a href="#cve-2026-65799">CVE-2026-65799</a>, <a href="#cve-2026-65798">CVE-2026-65798</a>.</p>
<h2 id="cve-2026-70330">CVE-2026-70330</h2>
<p>CVE-2026-70330 is a heap-based buffer overflow vulnerability in the Windows DNS component that enables an already authorized attacker to perform local privilege escalation.</p>
<p>Affected products:</p>
<ul>
<li>Windows DNS</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70330">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70330</a></p>
<p>Related in this roundup: <a href="#cve-2026-70304">CVE-2026-70304</a>, <a href="#cve-2026-62769">CVE-2026-62769</a>, <a href="#cve-2026-62778">CVE-2026-62778</a>, <a href="#cve-2026-62881">CVE-2026-62881</a>, <a href="#cve-2026-62883">CVE-2026-62883</a>, <a href="#cve-2026-65795">CVE-2026-65795</a>, <a href="#cve-2026-65797">CVE-2026-65797</a>, <a href="#cve-2026-65799">CVE-2026-65799</a>, <a href="#cve-2026-65798">CVE-2026-65798</a>.</p>
<h2 id="cve-2026-70335">CVE-2026-70335</h2>
<p>CVE-2026-70335 describes an OS command injection vulnerability in GitHub Copilot and Visual Studio Code that allows a local, unauthorized attacker to perform privilege escalation. The vulnerability stems from improper neutralization of special elements used in system commands, enabling arbitrary code execution with higher privileges.</p>
<p>Affected products:</p>
<ul>
<li>GitHub Copilot</li>
<li>Visual Studio Code</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70335">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70335</a></p>
<h2 id="cve-2026-70336">CVE-2026-70336</h2>
<p>CVE-2026-70336 is a code injection vulnerability in Visual Studio Code that permits an unauthorized remote attacker to achieve arbitrary code execution over a network. The flaw stems from improper control of code generation processes within the application.</p>
<p>Affected products:</p>
<ul>
<li>Visual Studio Code</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70336">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70336</a></p>
<p>Related in this roundup: <a href="#cve-2026-58650">CVE-2026-58650</a>, <a href="#cve-2026-59113">CVE-2026-59113</a>, <a href="#cve-2026-47285">CVE-2026-47285</a>, <a href="#cve-2026-69320">CVE-2026-69320</a>, <a href="#cve-2026-69278">CVE-2026-69278</a>, <a href="#cve-2026-69306">CVE-2026-69306</a>, <a href="#cve-2026-54981">CVE-2026-54981</a>.</p>
<h2 id="cve-2026-57104">CVE-2026-57104</h2>
<p>CVE-2026-57104 is an elevation of privilege vulnerability in Azure Storage Explorer caused by improper neutralization of input, leading to a stored cross-site scripting (XSS) condition that an attacker can exploit over a network.</p>
<p>Affected products:</p>
<ul>
<li>Azure Storage Explorer</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57104">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57104</a></p>
<h2 id="cve-2026-70340">CVE-2026-70340</h2>
<p>CVE-2026-70340 is a privilege escalation vulnerability in Microsoft Azure CycleCloud caused by a missing authorization check. This vulnerability allows an already authorized attacker to escalate their privileges within the environment over a network connection.</p>
<p>Affected products:</p>
<ul>
<li>Azure CycleCloud</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70340">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70340</a></p>
<p>Related in this roundup: <a href="#cve-2026-65806">CVE-2026-65806</a>.</p>
<h2 id="cve-2026-65806">CVE-2026-65806</h2>
<p>CVE-2026-65806 is an information disclosure vulnerability in Microsoft Azure CycleCloud resulting from missing authorization checks. An authenticated attacker can exploit this flaw to access sensitive information over a network.</p>
<p>Affected products:</p>
<ul>
<li>Azure CycleCloud</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65806">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65806</a></p>
<p>Related in this roundup: <a href="#cve-2026-70340">CVE-2026-70340</a>.</p>
<h2 id="cve-2026-61352">CVE-2026-61352</h2>
<p>CVE-2026-61352 is a remote code execution vulnerability in the Microsoft Remote Desktop Client caused by a race condition due to improper synchronization when using shared resources. An unauthenticated attacker can exploit this flaw over a network to execute arbitrary code on the victim's machine.</p>
<p>Affected products:</p>
<ul>
<li>Remote Desktop Client</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61352">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61352</a></p>
<p>Related in this roundup: <a href="#cve-2026-59134">CVE-2026-59134</a>, <a href="#cve-2026-61924">CVE-2026-61924</a>, <a href="#cve-2026-61363">CVE-2026-61363</a>, <a href="#cve-2026-61918">CVE-2026-61918</a>, <a href="#cve-2026-61921">CVE-2026-61921</a>, <a href="#cve-2026-62824">CVE-2026-62824</a>.</p>
<h2 id="cve-2026-65783">CVE-2026-65783</h2>
<p>A use-after-free vulnerability exists in Windows Autopilot that allows a locally authenticated attacker to elevate their privileges to a higher level of access.</p>
<p>Affected products:</p>
<ul>
<li>Windows Autopilot</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65783">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65783</a></p>
<p>Related in this roundup: <a href="#cve-2026-65779">CVE-2026-65779</a>, <a href="#cve-2026-65780">CVE-2026-65780</a>, <a href="#cve-2026-65778">CVE-2026-65778</a>, <a href="#cve-2026-65782">CVE-2026-65782</a>, <a href="#cve-2026-65781">CVE-2026-65781</a>.</p>
<h2 id="cve-2026-66804">CVE-2026-66804</h2>
<p>CVE-2026-66804 describes an elevation of privilege vulnerability in the Windows Cross Device Service caused by improper access control. An authorized local attacker can exploit this flaw to gain elevated privileges on the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Cross Device Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66804">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66804</a></p>
<h2 id="cve-2026-70344">CVE-2026-70344</h2>
<p>CVE-2026-70344 is a local privilege escalation vulnerability in the Windows Installer component, stemming from a stack-based buffer overflow. An attacker with local access is required to successfully exploit this vulnerability to elevate their privileges on the target system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Installer</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70344">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70344</a></p>
<p>Related in this roundup: <a href="#cve-2026-59127">CVE-2026-59127</a>, <a href="#cve-2026-61925">CVE-2026-61925</a>, <a href="#cve-2026-70345">CVE-2026-70345</a>, <a href="#cve-2026-70346">CVE-2026-70346</a>, <a href="#cve-2026-70347">CVE-2026-70347</a>, <a href="#cve-2026-61938">CVE-2026-61938</a>, <a href="#cve-2026-62768">CVE-2026-62768</a>, <a href="#cve-2026-65774">CVE-2026-65774</a>.</p>
<h2 id="cve-2026-70345">CVE-2026-70345</h2>
<p>CVE-2026-70345 is a heap-based buffer overflow vulnerability in the Windows Installer service that enables an authenticated local attacker to execute code with elevated privileges, resulting in local privilege escalation.</p>
<p>Affected products:</p>
<ul>
<li>Windows Installer</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70345">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70345</a></p>
<p>Related in this roundup: <a href="#cve-2026-59127">CVE-2026-59127</a>, <a href="#cve-2026-61925">CVE-2026-61925</a>, <a href="#cve-2026-70344">CVE-2026-70344</a>, <a href="#cve-2026-70346">CVE-2026-70346</a>, <a href="#cve-2026-70347">CVE-2026-70347</a>, <a href="#cve-2026-61938">CVE-2026-61938</a>, <a href="#cve-2026-62768">CVE-2026-62768</a>, <a href="#cve-2026-65774">CVE-2026-65774</a>.</p>
<h2 id="cve-2026-70346">CVE-2026-70346</h2>
<p>CVE-2026-70346 is a stack-based buffer overflow vulnerability within the Windows Installer service that allows an authenticated local attacker to achieve privilege escalation. This vulnerability indicates a flaw in how the service handles input, potentially allowing execution of arbitrary code with elevated system permissions.</p>
<p>Affected products:</p>
<ul>
<li>Windows Installer</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70346">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70346</a></p>
<p>Related in this roundup: <a href="#cve-2026-59127">CVE-2026-59127</a>, <a href="#cve-2026-61925">CVE-2026-61925</a>, <a href="#cve-2026-70344">CVE-2026-70344</a>, <a href="#cve-2026-70345">CVE-2026-70345</a>, <a href="#cve-2026-70347">CVE-2026-70347</a>, <a href="#cve-2026-61938">CVE-2026-61938</a>, <a href="#cve-2026-62768">CVE-2026-62768</a>, <a href="#cve-2026-65774">CVE-2026-65774</a>.</p>
<h2 id="cve-2026-70347">CVE-2026-70347</h2>
<p>CVE-2026-70347 is a heap-based buffer overflow vulnerability in the Windows Installer service that enables an authorized local attacker to achieve privilege escalation by exploiting the memory corruption flaw.</p>
<p>Affected products:</p>
<ul>
<li>Windows Installer</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70347">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70347</a></p>
<p>Related in this roundup: <a href="#cve-2026-59127">CVE-2026-59127</a>, <a href="#cve-2026-61925">CVE-2026-61925</a>, <a href="#cve-2026-70344">CVE-2026-70344</a>, <a href="#cve-2026-70345">CVE-2026-70345</a>, <a href="#cve-2026-70346">CVE-2026-70346</a>, <a href="#cve-2026-61938">CVE-2026-61938</a>, <a href="#cve-2026-62768">CVE-2026-62768</a>, <a href="#cve-2026-65774">CVE-2026-65774</a>.</p>
<h2 id="cve-2026-70348">CVE-2026-70348</h2>
<p>CVE-2026-70348 is a denial-of-service vulnerability in Windows Management Services caused by improper link resolution before file access. An authenticated attacker can exploit this local vulnerability to disrupt service availability by manipulating file system links.</p>
<p>Affected products:</p>
<ul>
<li>Windows Management Services</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70348">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70348</a></p>
<h2 id="cve-2026-70355">CVE-2026-70355</h2>
<p>Microsoft SharePoint Server contains an improper neutralization of input vulnerability (XSS) that allows an authorized attacker to escalate their privileges over the network.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70355">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70355</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-72971">CVE-2026-72971</h2>
<p>CVE-2026-72971 describes an improper link resolution vulnerability (link following) within the Windows Container Isolation FS Filter Driver (unionfs.sys). An authenticated local attacker can leverage this flaw to perform file tampering, potentially resulting in unauthorized modifications to the file system due to the driver's failure to properly validate file access paths.</p>
<p>Affected products:</p>
<ul>
<li>Windows Container Isolation FS Filter Driver</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72971">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72971</a></p>
<p>Related in this roundup: <a href="#cve-2026-62772">CVE-2026-62772</a>, <a href="#cve-2026-62775">CVE-2026-62775</a>.</p>
<h2 id="cve-2026-42976">CVE-2026-42976</h2>
<p>A privilege escalation vulnerability exists in the Windows RPC API due to missing authentication for a critical function. An authenticated attacker can exploit this flaw to elevate privileges locally on the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42976">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42976</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-54981">CVE-2026-54981</h2>
<p>CVE-2026-54981 is a security feature bypass vulnerability in the Visual Studio Code Python extension. The flaw arises from the inclusion of functionality from an untrusted control sphere, which can be exploited by an unauthorized local attacker to bypass security mechanisms implemented within the extension.</p>
<p>Affected products:</p>
<ul>
<li>Visual Studio Code</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54981">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54981</a></p>
<p>Related in this roundup: <a href="#cve-2026-58650">CVE-2026-58650</a>, <a href="#cve-2026-59113">CVE-2026-59113</a>, <a href="#cve-2026-47285">CVE-2026-47285</a>, <a href="#cve-2026-69320">CVE-2026-69320</a>, <a href="#cve-2026-69278">CVE-2026-69278</a>, <a href="#cve-2026-69306">CVE-2026-69306</a>, <a href="#cve-2026-70336">CVE-2026-70336</a>.</p>
<h2 id="cve-2026-6726">CVE-2026-6726</h2>
<p>CVE-2026-6726 is a spoofing vulnerability identified in the Trusted Computing Group's TPM 2.0 reference implementation, resulting from improper object-slot reuse. Microsoft has issued security updates for the Windows operating system to address this flaw.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-6726">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-6726</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-58641">CVE-2026-58641</h2>
<p>CVE-2026-58641 is a vulnerability in .NET caused by an integer overflow or wraparound condition. This flaw allows a local, unauthorized attacker to execute code or manipulate system states to achieve elevation of privilege on the host system.</p>
<p>Affected products:</p>
<ul>
<li>.NET</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58641">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58641</a></p>
<p>Related in this roundup: <a href="#cve-2026-62899">CVE-2026-62899</a>, <a href="#cve-2026-62900">CVE-2026-62900</a>, <a href="#cve-2026-62901">CVE-2026-62901</a>, <a href="#cve-2026-62902">CVE-2026-62902</a>, <a href="#cve-2026-62909">CVE-2026-62909</a>, <a href="#cve-2026-62871">CVE-2026-62871</a>, <a href="#cve-2026-62886">CVE-2026-62886</a>.</p>
<h2 id="cve-2026-58651">CVE-2026-58651</h2>
<p>A heap-based buffer overflow vulnerability in Microsoft Word allows a remote attacker to achieve arbitrary code execution. The vulnerability is triggered when the application processes a specially crafted file, potentially leading to a system compromise if a user opens a malicious document.</p>
<p>Affected products:</p>
<ul>
<li>Word</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58651">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58651</a></p>
<h2 id="cve-2026-59122">CVE-2026-59122</h2>
<p>CVE-2026-59122 is a local privilege escalation vulnerability in the Windows Telephony Service caused by a race condition during concurrent execution with shared resources. An authenticated attacker can exploit this synchronization flaw to gain elevated permissions on the host system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Telephony Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59122">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59122</a></p>
<p>Related in this roundup: <a href="#cve-2026-61353">CVE-2026-61353</a>, <a href="#cve-2026-62723">CVE-2026-62723</a>, <a href="#cve-2026-62724">CVE-2026-62724</a>, <a href="#cve-2026-62748">CVE-2026-62748</a>, <a href="#cve-2026-62729">CVE-2026-62729</a>, <a href="#cve-2026-62701">CVE-2026-62701</a>, <a href="#cve-2026-62725">CVE-2026-62725</a>, <a href="#cve-2026-62726">CVE-2026-62726</a>, <a href="#cve-2026-62732">CVE-2026-62732</a>, <a href="#cve-2026-62734">CVE-2026-62734</a>.</p>
<h2 id="cve-2026-59125">CVE-2026-59125</h2>
<p>CVE-2026-59125 is a use-after-free vulnerability within the Windows Virtual Hard Disk (VHD) Miniport Driver. An authorized local attacker can exploit this flaw to execute code or perform operations with elevated privileges on the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Virtual Hard Disk (VHD) Miniport Driver</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59125">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59125</a></p>
<h2 id="cve-2026-59126">CVE-2026-59126</h2>
<p>The Windows Event Logging Service contains a race condition vulnerability due to improper synchronization when using shared resources. This vulnerability allows an authenticated attacker to perform local privilege escalation on the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Event Logging Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59126">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59126</a></p>
<p>Related in this roundup: <a href="#cve-2026-59137">CVE-2026-59137</a>, <a href="#cve-2026-61347">CVE-2026-61347</a>.</p>
<h2 id="cve-2026-61349">CVE-2026-61349</h2>
<p>CVE-2026-61349 is a use-after-free vulnerability in the Windows Work Folder Service that allows a locally authenticated attacker to elevate their privileges to a higher integrity level.</p>
<p>Affected products:</p>
<ul>
<li>Windows Work Folder Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61349">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61349</a></p>
<h2 id="cve-2026-61363">CVE-2026-61363</h2>
<p>CVE-2026-61363 is a heap-based buffer overflow vulnerability in the Microsoft Remote Desktop Client. An unauthenticated attacker can exploit this flaw over a network to achieve remote code execution on a target system.</p>
<p>Affected products:</p>
<ul>
<li>Remote Desktop Client</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61363">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61363</a></p>
<p>Related in this roundup: <a href="#cve-2026-59134">CVE-2026-59134</a>, <a href="#cve-2026-61924">CVE-2026-61924</a>, <a href="#cve-2026-61352">CVE-2026-61352</a>, <a href="#cve-2026-61918">CVE-2026-61918</a>, <a href="#cve-2026-61921">CVE-2026-61921</a>, <a href="#cve-2026-62824">CVE-2026-62824</a>.</p>
<h2 id="cve-2026-61359">CVE-2026-61359</h2>
<p>A heap-based buffer overflow vulnerability in Windows Storage allows a locally authenticated attacker to elevate their privileges. Successful exploitation requires the attacker to have existing authorization on the system, which they can then leverage to gain higher privileges through this flaw.</p>
<p>Affected products:</p>
<ul>
<li>Windows Storage</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61359">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61359</a></p>
<p>Related in this roundup: <a href="#cve-2026-62695">CVE-2026-62695</a>.</p>
<h2 id="cve-2026-61355">CVE-2026-61355</h2>
<p>CVE-2026-61355 is a heap-based buffer overflow vulnerability within the Windows Sensor Data Service. An authorized local attacker can exploit this flaw to execute code with elevated privileges, potentially gaining administrative control over the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Sensor Data Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61355">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61355</a></p>
<h2 id="cve-2026-61364">CVE-2026-61364</h2>
<p>CVE-2026-61364 is a privilege escalation vulnerability in Windows Remote Desktop Services caused by improper authentication handling. An authorized local attacker can exploit this flaw to elevate their privileges on the target system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Remote Desktop Services</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61364">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61364</a></p>
<h2 id="cve-2026-61365">CVE-2026-61365</h2>
<p>CVE-2026-61365 is an elevation of privilege vulnerability in Windows Remote Desktop Services caused by missing authentication for a critical function. An attacker who has already achieved local access to the system can exploit this flaw to escalate their privileges.</p>
<p>Affected products:</p>
<ul>
<li>Remote Desktop Services</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61365">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61365</a></p>
<p>Related in this roundup: <a href="#cve-2026-61356">CVE-2026-61356</a>, <a href="#cve-2026-61367">CVE-2026-61367</a>, <a href="#cve-2026-62692">CVE-2026-62692</a>.</p>
<h2 id="cve-2026-61357">CVE-2026-61357</h2>
<p>A use-after-free vulnerability in the Application Information Services component allows an authorized local attacker to achieve privilege escalation on the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Application Information Services</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61357">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61357</a></p>
<h2 id="cve-2026-61358">CVE-2026-61358</h2>
<p>CVE-2026-61358 is a privilege escalation vulnerability in the Windows Accessibility Infrastructure component, specifically ATBroker.exe. The vulnerability stems from improper link resolution before file access, allowing a local, authorized attacker to exploit the flaw to gain elevated privileges on the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61358">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61358</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-61360">CVE-2026-61360</h2>
<p>CVE-2026-61360 is an information disclosure vulnerability in the Windows Graphics Device Interface (GDI) component. The flaw arises from an untrusted pointer dereference, which can be exploited by an authorized local attacker to read sensitive memory contents.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61360">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61360</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-61920">CVE-2026-61920</h2>
<p>CVE-2026-61920 is a race condition vulnerability in the Windows DNS Server component that allows an authorized attacker to achieve remote code execution over the network. Detection should focus on monitoring DNS server process behavior and unusual execution patterns originating from network-based requests.</p>
<p>Affected products:</p>
<ul>
<li>Windows DNS Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61920">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61920</a></p>
<p>Related in this roundup: <a href="#cve-2026-62787">CVE-2026-62787</a>, <a href="#cve-2026-62817">CVE-2026-62817</a>, <a href="#cve-2026-62820">CVE-2026-62820</a>, <a href="#cve-2026-62878">CVE-2026-62878</a>, <a href="#cve-2026-65789">CVE-2026-65789</a>.</p>
<h2 id="cve-2026-61926">CVE-2026-61926</h2>
<p>The Windows USB Driver is vulnerable to a heap-based buffer overflow that can be exploited by an authorized local attacker to achieve privilege escalation.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61926">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61926</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-61918">CVE-2026-61918</h2>
<p>CVE-2026-61918 is an out-of-bounds read vulnerability in the Microsoft Windows Remote Desktop Client. An unauthenticated remote attacker can exploit this flaw to perform unauthorized information disclosure, potentially leading to the leakage of sensitive data residing in the application's memory space.</p>
<p>Affected products:</p>
<ul>
<li>Remote Desktop Client</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61918">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61918</a></p>
<p>Related in this roundup: <a href="#cve-2026-59134">CVE-2026-59134</a>, <a href="#cve-2026-61924">CVE-2026-61924</a>, <a href="#cve-2026-61352">CVE-2026-61352</a>, <a href="#cve-2026-61363">CVE-2026-61363</a>, <a href="#cve-2026-61921">CVE-2026-61921</a>, <a href="#cve-2026-62824">CVE-2026-62824</a>.</p>
<h2 id="cve-2026-61921">CVE-2026-61921</h2>
<p>CVE-2026-61921 describes an out-of-bounds read vulnerability in the Windows Remote Desktop Client. An unauthenticated attacker can exploit this flaw to perform unauthorized information disclosure over a network, potentially exposing sensitive data processed by the client.</p>
<p>Affected products:</p>
<ul>
<li>Remote Desktop Client</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61921">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61921</a></p>
<p>Related in this roundup: <a href="#cve-2026-59134">CVE-2026-59134</a>, <a href="#cve-2026-61924">CVE-2026-61924</a>, <a href="#cve-2026-61352">CVE-2026-61352</a>, <a href="#cve-2026-61363">CVE-2026-61363</a>, <a href="#cve-2026-61918">CVE-2026-61918</a>, <a href="#cve-2026-62824">CVE-2026-62824</a>.</p>
<h2 id="cve-2026-61929">CVE-2026-61929</h2>
<p>CVE-2026-61929 describes a use-after-free vulnerability within the Windows Kernel. An attacker who has already obtained local access can exploit this flaw to execute code with elevated privileges on the affected Windows system.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61929">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61929</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-61938">CVE-2026-61938</h2>
<p>A use-after-free vulnerability in the Windows Installer service allows a locally authenticated attacker to escalate their privileges to a higher integrity level. The vulnerability exists within the component responsible for handling installer packages, and successful exploitation requires an attacker to already possess local access to the system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Installer</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61938">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61938</a></p>
<p>Related in this roundup: <a href="#cve-2026-59127">CVE-2026-59127</a>, <a href="#cve-2026-61925">CVE-2026-61925</a>, <a href="#cve-2026-70344">CVE-2026-70344</a>, <a href="#cve-2026-70345">CVE-2026-70345</a>, <a href="#cve-2026-70346">CVE-2026-70346</a>, <a href="#cve-2026-70347">CVE-2026-70347</a>, <a href="#cve-2026-62768">CVE-2026-62768</a>, <a href="#cve-2026-65774">CVE-2026-65774</a>.</p>
<h2 id="cve-2026-62698">CVE-2026-62698</h2>
<p>A numeric truncation vulnerability in the Microsoft Digest Authentication component allows a locally authenticated attacker to escalate privileges. The vulnerability exists due to improper handling of input data within the authentication process.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62698">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62698</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62700">CVE-2026-62700</h2>
<p>A heap-based buffer overflow vulnerability exists in the Windows NTFS file system, which can be exploited by an authenticated attacker to perform a local privilege escalation. Successful exploitation requires the attacker to be logged on to the system and run a specially crafted application.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62700">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62700</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62701">CVE-2026-62701</h2>
<p>CVE-2026-62701 is a privilege escalation vulnerability in the Windows Telephony Service caused by a use-after-free defect. An authorized local attacker can exploit this flaw to gain elevated privileges on the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Telephony Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62701">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62701</a></p>
<p>Related in this roundup: <a href="#cve-2026-61353">CVE-2026-61353</a>, <a href="#cve-2026-62723">CVE-2026-62723</a>, <a href="#cve-2026-62724">CVE-2026-62724</a>, <a href="#cve-2026-62748">CVE-2026-62748</a>, <a href="#cve-2026-62729">CVE-2026-62729</a>, <a href="#cve-2026-59122">CVE-2026-59122</a>, <a href="#cve-2026-62725">CVE-2026-62725</a>, <a href="#cve-2026-62726">CVE-2026-62726</a>, <a href="#cve-2026-62732">CVE-2026-62732</a>, <a href="#cve-2026-62734">CVE-2026-62734</a>.</p>
<h2 id="cve-2026-62708">CVE-2026-62708</h2>
<p>CVE-2026-62708 describes a use-after-free vulnerability in the Windows Kernel that enables an attacker with physical access to the target machine to perform local privilege escalation.</p>
<p>Affected products:</p>
<ul>
<li>Windows Kernel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62708">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62708</a></p>
<p>Related in this roundup: <a href="#cve-2026-54113">CVE-2026-54113</a>, <a href="#cve-2026-61930">CVE-2026-61930</a>, <a href="#cve-2026-62737">CVE-2026-62737</a>, <a href="#cve-2026-62749">CVE-2026-62749</a>, <a href="#cve-2026-65773">CVE-2026-65773</a>.</p>
<h2 id="cve-2026-62709">CVE-2026-62709</h2>
<p>CVE-2026-62709 is an information disclosure vulnerability in Windows GDI+ caused by the use of an uninitialized resource. An authorized local attacker can exploit this flaw to read sensitive data from the system memory.</p>
<p>Affected products:</p>
<ul>
<li>Windows GDI+</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62709">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62709</a></p>
<p>Related in this roundup: <a href="#cve-2026-62890">CVE-2026-62890</a>, <a href="#cve-2026-62822">CVE-2026-62822</a>.</p>
<h2 id="cve-2026-62710">CVE-2026-62710</h2>
<p>The Windows Device Association Service contains a heap-based buffer overflow vulnerability that can be exploited by an authorized local attacker to achieve privilege escalation.</p>
<p>Affected products:</p>
<ul>
<li>Windows Device Association Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62710">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62710</a></p>
<p>Related in this roundup: <a href="#cve-2026-62747">CVE-2026-62747</a>.</p>
<h2 id="cve-2026-62711">CVE-2026-62711</h2>
<p>CVE-2026-62711 is a use-after-free vulnerability located in the Windows Win32k kernel component. An attacker with local access to a vulnerable system can exploit this flaw to execute code with elevated privileges, potentially gaining administrative or system-level control.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62711">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62711</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62720">CVE-2026-62720</h2>
<p>CVE-2026-62720 is an information disclosure vulnerability in the Windows DHCP Server caused by an integer underflow. An unauthenticated attacker on an adjacent network can exploit this flaw to read sensitive data from server memory.</p>
<p>Affected products:</p>
<ul>
<li>Windows DHCP Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62720">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62720</a></p>
<p>Related in this roundup: <a href="#cve-2026-62718">CVE-2026-62718</a>, <a href="#cve-2026-62715">CVE-2026-62715</a>, <a href="#cve-2026-62716">CVE-2026-62716</a>, <a href="#cve-2026-62742">CVE-2026-62742</a>, <a href="#cve-2026-62745">CVE-2026-62745</a>, <a href="#cve-2026-62812">CVE-2026-62812</a>, <a href="#cve-2026-62714">CVE-2026-62714</a>, <a href="#cve-2026-62761">CVE-2026-62761</a>, <a href="#cve-2026-62776">CVE-2026-62776</a>, <a href="#cve-2026-62803">CVE-2026-62803</a>, <a href="#cve-2026-62807">CVE-2026-62807</a>, <a href="#cve-2026-62814">CVE-2026-62814</a>, <a href="#cve-2026-62823">CVE-2026-62823</a>.</p>
<h2 id="cve-2026-62714">CVE-2026-62714</h2>
<p>An integer underflow vulnerability in the Windows DHCP Server component allows a remote, unauthenticated attacker on an adjacent network to disclose sensitive memory information by sending specially crafted packets.</p>
<p>Affected products:</p>
<ul>
<li>Windows DHCP Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62714">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62714</a></p>
<p>Related in this roundup: <a href="#cve-2026-62718">CVE-2026-62718</a>, <a href="#cve-2026-62715">CVE-2026-62715</a>, <a href="#cve-2026-62716">CVE-2026-62716</a>, <a href="#cve-2026-62742">CVE-2026-62742</a>, <a href="#cve-2026-62745">CVE-2026-62745</a>, <a href="#cve-2026-62812">CVE-2026-62812</a>, <a href="#cve-2026-62720">CVE-2026-62720</a>, <a href="#cve-2026-62761">CVE-2026-62761</a>, <a href="#cve-2026-62776">CVE-2026-62776</a>, <a href="#cve-2026-62803">CVE-2026-62803</a>, <a href="#cve-2026-62807">CVE-2026-62807</a>, <a href="#cve-2026-62814">CVE-2026-62814</a>, <a href="#cve-2026-62823">CVE-2026-62823</a>.</p>
<h2 id="cve-2026-62717">CVE-2026-62717</h2>
<p>CVE-2026-62717 is a heap-based buffer overflow vulnerability in the Windows Message Queuing component, which can be exploited by an authorized local attacker to elevate their privileges on an affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Message Queuing</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62717">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62717</a></p>
<p>Related in this roundup: <a href="#cve-2026-62719">CVE-2026-62719</a>, <a href="#cve-2026-65790">CVE-2026-65790</a>.</p>
<h2 id="cve-2026-62721">CVE-2026-62721</h2>
<p>CVE-2026-62721 is a local privilege escalation vulnerability in the Windows User-Mode Power Service (UMPS). The flaw stems from insufficient granularity in access control, which allows an attacker who already has authorized access to the system to exploit the service and elevate their privileges to a higher level of authority.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62721">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62721</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62725">CVE-2026-62725</h2>
<p>A use-after-free vulnerability in the Windows Telephony Service allows a local, authorized attacker to elevate their privileges on an affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Telephony Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62725">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62725</a></p>
<p>Related in this roundup: <a href="#cve-2026-61353">CVE-2026-61353</a>, <a href="#cve-2026-62723">CVE-2026-62723</a>, <a href="#cve-2026-62724">CVE-2026-62724</a>, <a href="#cve-2026-62748">CVE-2026-62748</a>, <a href="#cve-2026-62729">CVE-2026-62729</a>, <a href="#cve-2026-59122">CVE-2026-59122</a>, <a href="#cve-2026-62701">CVE-2026-62701</a>, <a href="#cve-2026-62726">CVE-2026-62726</a>, <a href="#cve-2026-62732">CVE-2026-62732</a>, <a href="#cve-2026-62734">CVE-2026-62734</a>.</p>
<h2 id="cve-2026-62726">CVE-2026-62726</h2>
<p>CVE-2026-62726 describes a use-after-free vulnerability within the Windows Telephony Service that can be exploited by an authorized local attacker to gain elevated privileges on a Windows system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Telephony Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62726">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62726</a></p>
<p>Related in this roundup: <a href="#cve-2026-61353">CVE-2026-61353</a>, <a href="#cve-2026-62723">CVE-2026-62723</a>, <a href="#cve-2026-62724">CVE-2026-62724</a>, <a href="#cve-2026-62748">CVE-2026-62748</a>, <a href="#cve-2026-62729">CVE-2026-62729</a>, <a href="#cve-2026-59122">CVE-2026-59122</a>, <a href="#cve-2026-62701">CVE-2026-62701</a>, <a href="#cve-2026-62725">CVE-2026-62725</a>, <a href="#cve-2026-62732">CVE-2026-62732</a>, <a href="#cve-2026-62734">CVE-2026-62734</a>.</p>
<h2 id="cve-2026-62728">CVE-2026-62728</h2>
<p>The Windows Common Log File System (CLFS) driver contains a time-of-check time-of-use (TOCTOU) race condition vulnerability. An attacker with local access and authorization can exploit this flaw to execute code or manipulate system processes with elevated privileges, bypassing standard security restrictions.</p>
<p>Affected products:</p>
<ul>
<li>Windows Common Log File System Driver</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62728">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62728</a></p>
<h2 id="cve-2026-62733">CVE-2026-62733</h2>
<p>CVE-2026-62733 is a local privilege escalation vulnerability residing in the Windows Win32k subsystem. The vulnerability is triggered by an out-of-bounds read condition, which an authenticated attacker can leverage to gain elevated system privileges.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62733">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62733</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62743">CVE-2026-62743</h2>
<p>CVE-2026-62743 describes an out-of-bounds read vulnerability within the Windows Win32k subsystem. The flaw allows an authenticated local attacker to bypass memory protections and disclose sensitive information from the kernel space.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62743">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62743</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62730">CVE-2026-62730</h2>
<p>CVE-2026-62730 describes a buffer over-read vulnerability within the Windows Wired AutoConfig Service. The vulnerability allows an authorized local attacker to potentially disclose sensitive information from the system by leveraging the improper memory handling in the service.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62730">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62730</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62732">CVE-2026-62732</h2>
<p>CVE-2026-62732 is a heap-based buffer overflow vulnerability in the Windows Telephony Service that can be exploited by an authorized local attacker to achieve privilege escalation.</p>
<p>Affected products:</p>
<ul>
<li>Windows Telephony Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62732">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62732</a></p>
<p>Related in this roundup: <a href="#cve-2026-61353">CVE-2026-61353</a>, <a href="#cve-2026-62723">CVE-2026-62723</a>, <a href="#cve-2026-62724">CVE-2026-62724</a>, <a href="#cve-2026-62748">CVE-2026-62748</a>, <a href="#cve-2026-62729">CVE-2026-62729</a>, <a href="#cve-2026-59122">CVE-2026-59122</a>, <a href="#cve-2026-62701">CVE-2026-62701</a>, <a href="#cve-2026-62725">CVE-2026-62725</a>, <a href="#cve-2026-62726">CVE-2026-62726</a>, <a href="#cve-2026-62734">CVE-2026-62734</a>.</p>
<h2 id="cve-2026-62734">CVE-2026-62734</h2>
<p>CVE-2026-62734 describes a local privilege escalation vulnerability in the Windows Telephony Service caused by a race condition during concurrent execution with shared resources. An authorized attacker can exploit this synchronization flaw to execute code with elevated permissions on the target Windows system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Telephony Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62734">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62734</a></p>
<p>Related in this roundup: <a href="#cve-2026-61353">CVE-2026-61353</a>, <a href="#cve-2026-62723">CVE-2026-62723</a>, <a href="#cve-2026-62724">CVE-2026-62724</a>, <a href="#cve-2026-62748">CVE-2026-62748</a>, <a href="#cve-2026-62729">CVE-2026-62729</a>, <a href="#cve-2026-59122">CVE-2026-59122</a>, <a href="#cve-2026-62701">CVE-2026-62701</a>, <a href="#cve-2026-62725">CVE-2026-62725</a>, <a href="#cve-2026-62726">CVE-2026-62726</a>, <a href="#cve-2026-62732">CVE-2026-62732</a>.</p>
<h2 id="cve-2026-62736">CVE-2026-62736</h2>
<p>CVE-2026-62736 is a heap-based buffer overflow vulnerability in the Windows DHCP Client that allows a local, authorized attacker to elevate their privileges on the host system.</p>
<p>Affected products:</p>
<ul>
<li>Windows DHCP Client</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62736">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62736</a></p>
<p>Related in this roundup: <a href="#cve-2026-61361">CVE-2026-61361</a>, <a href="#cve-2026-62755">CVE-2026-62755</a>, <a href="#cve-2026-65785">CVE-2026-65785</a>.</p>
<h2 id="cve-2026-62757">CVE-2026-62757</h2>
<p>CVE-2026-62757 describes a security feature bypass vulnerability in the Windows Schannel component due to improper cryptographic signature verification. An unauthorized attacker can exploit this flaw over a network to bypass security controls associated with TLS/SSL connections handled by Schannel.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62757">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62757</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62741">CVE-2026-62741</h2>
<p>An integer underflow vulnerability in the Windows HTTP.sys kernel driver allows an authorized local attacker to perform a privilege escalation attack. The vulnerability arises from improper handling of integer arithmetic during system calls, potentially leading to unauthorized system-level operations.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62741">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62741</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62749">CVE-2026-62749</h2>
<p>CVE-2026-62749 is a use-after-free vulnerability within the Windows Kernel that enables a local, authenticated attacker to escalate their privileges to a higher level. Successful exploitation requires an attacker to already have local access to the target system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Kernel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62749">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62749</a></p>
<p>Related in this roundup: <a href="#cve-2026-54113">CVE-2026-54113</a>, <a href="#cve-2026-61930">CVE-2026-61930</a>, <a href="#cve-2026-62737">CVE-2026-62737</a>, <a href="#cve-2026-62708">CVE-2026-62708</a>, <a href="#cve-2026-65773">CVE-2026-65773</a>.</p>
<h2 id="cve-2026-62751">CVE-2026-62751</h2>
<p>CVE-2026-62751 describes an elevation of privilege vulnerability in the Windows Projected File System caused by an integer overflow or wraparound condition. A local, authorized attacker could exploit this vulnerability to escalate their privilege level on the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Projected File System</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62751">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62751</a></p>
<h2 id="cve-2026-62752">CVE-2026-62752</h2>
<p>CVE-2026-62752 is a heap-based buffer overflow vulnerability within the Windows Kerberos implementation that enables an already authenticated local attacker to escalate their privileges. Detection should focus on monitoring for abnormal local system processes or unauthorized changes to user permission structures.</p>
<p>Affected products:</p>
<ul>
<li>Windows Kerberos</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62752">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62752</a></p>
<h2 id="cve-2026-62769">CVE-2026-62769</h2>
<p>CVE-2026-62769 is a local privilege escalation vulnerability in the Windows DNS service caused by a numeric truncation error. An authorized attacker can exploit this flaw to elevate their privileges on an affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows DNS</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62769">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62769</a></p>
<p>Related in this roundup: <a href="#cve-2026-70304">CVE-2026-70304</a>, <a href="#cve-2026-70330">CVE-2026-70330</a>, <a href="#cve-2026-62778">CVE-2026-62778</a>, <a href="#cve-2026-62881">CVE-2026-62881</a>, <a href="#cve-2026-62883">CVE-2026-62883</a>, <a href="#cve-2026-65795">CVE-2026-65795</a>, <a href="#cve-2026-65797">CVE-2026-65797</a>, <a href="#cve-2026-65799">CVE-2026-65799</a>, <a href="#cve-2026-65798">CVE-2026-65798</a>.</p>
<h2 id="cve-2026-62771">CVE-2026-62771</h2>
<p>CVE-2026-62771 is a heap-based buffer overflow vulnerability within the Windows Cloud Files Mini Filter Driver. An authenticated local attacker can leverage this flaw to elevate their privileges on an affected Windows system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Cloud Files Mini Filter Driver</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62771">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62771</a></p>
<p>Related in this roundup: <a href="#cve-2026-62713">CVE-2026-62713</a>.</p>
<h2 id="cve-2026-62761">CVE-2026-62761</h2>
<p>CVE-2026-62761 is a privilege escalation vulnerability in the Windows DHCP Server caused by improper link resolution before file access (link following). An authorized local attacker can exploit this flaw to elevate their privileges on the target system.</p>
<p>Affected products:</p>
<ul>
<li>Windows DHCP Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62761">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62761</a></p>
<p>Related in this roundup: <a href="#cve-2026-62718">CVE-2026-62718</a>, <a href="#cve-2026-62715">CVE-2026-62715</a>, <a href="#cve-2026-62716">CVE-2026-62716</a>, <a href="#cve-2026-62742">CVE-2026-62742</a>, <a href="#cve-2026-62745">CVE-2026-62745</a>, <a href="#cve-2026-62812">CVE-2026-62812</a>, <a href="#cve-2026-62720">CVE-2026-62720</a>, <a href="#cve-2026-62714">CVE-2026-62714</a>, <a href="#cve-2026-62776">CVE-2026-62776</a>, <a href="#cve-2026-62803">CVE-2026-62803</a>, <a href="#cve-2026-62807">CVE-2026-62807</a>, <a href="#cve-2026-62814">CVE-2026-62814</a>, <a href="#cve-2026-62823">CVE-2026-62823</a>.</p>
<h2 id="cve-2026-62768">CVE-2026-62768</h2>
<p>CVE-2026-62768 is a stack-based buffer overflow vulnerability in the Windows Installer service that enables an authenticated attacker to perform a local privilege escalation. Security teams should monitor for anomalous system calls or process execution originating from the Windows Installer service that indicate memory corruption or unexpected privilege transitions.</p>
<p>Affected products:</p>
<ul>
<li>Windows Installer</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62768">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62768</a></p>
<p>Related in this roundup: <a href="#cve-2026-59127">CVE-2026-59127</a>, <a href="#cve-2026-61925">CVE-2026-61925</a>, <a href="#cve-2026-70344">CVE-2026-70344</a>, <a href="#cve-2026-70345">CVE-2026-70345</a>, <a href="#cve-2026-70346">CVE-2026-70346</a>, <a href="#cve-2026-70347">CVE-2026-70347</a>, <a href="#cve-2026-61938">CVE-2026-61938</a>, <a href="#cve-2026-65774">CVE-2026-65774</a>.</p>
<h2 id="cve-2026-62770">CVE-2026-62770</h2>
<p>CVE-2026-62770 is a heap-based buffer overflow vulnerability within the Windows Shell component. An attacker with local authorization can exploit this flaw to execute code with elevated system privileges.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62770">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62770</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62775">CVE-2026-62775</h2>
<p>The Windows Container Isolation FS Filter Driver (unionfs.sys) contains an information disclosure vulnerability stemming from incorrect authorization. A locally authenticated attacker could exploit this flaw to read sensitive data.</p>
<p>Affected products:</p>
<ul>
<li>Windows Container Isolation FS Filter Driver</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62775">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62775</a></p>
<p>Related in this roundup: <a href="#cve-2026-62772">CVE-2026-62772</a>, <a href="#cve-2026-72971">CVE-2026-72971</a>.</p>
<h2 id="cve-2026-62799">CVE-2026-62799</h2>
<p>CVE-2026-62799 describes a heap-based buffer overflow vulnerability in the Windows SMB Client that allows an authorized local attacker to elevate their privileges. The vulnerability facilitates unauthorized privilege escalation within the Windows operating system environment.</p>
<p>Affected products:</p>
<ul>
<li>Windows SMB Client</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62799">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62799</a></p>
<p>Related in this roundup: <a href="#cve-2026-62782">CVE-2026-62782</a>.</p>
<h2 id="cve-2026-62776">CVE-2026-62776</h2>
<p>CVE-2026-62776 describes a privilege escalation vulnerability in the Windows DHCP Server service caused by improper link resolution before file access. An authorized local attacker can exploit this 'link following' vulnerability to gain elevated privileges on the affected host.</p>
<p>Affected products:</p>
<ul>
<li>Windows DHCP Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62776">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62776</a></p>
<p>Related in this roundup: <a href="#cve-2026-62718">CVE-2026-62718</a>, <a href="#cve-2026-62715">CVE-2026-62715</a>, <a href="#cve-2026-62716">CVE-2026-62716</a>, <a href="#cve-2026-62742">CVE-2026-62742</a>, <a href="#cve-2026-62745">CVE-2026-62745</a>, <a href="#cve-2026-62812">CVE-2026-62812</a>, <a href="#cve-2026-62720">CVE-2026-62720</a>, <a href="#cve-2026-62714">CVE-2026-62714</a>, <a href="#cve-2026-62761">CVE-2026-62761</a>, <a href="#cve-2026-62803">CVE-2026-62803</a>, <a href="#cve-2026-62807">CVE-2026-62807</a>, <a href="#cve-2026-62814">CVE-2026-62814</a>, <a href="#cve-2026-62823">CVE-2026-62823</a>.</p>
<h2 id="cve-2026-62778">CVE-2026-62778</h2>
<p>CVE-2026-62778 is a use-after-free vulnerability within the Windows DNS component that enables a remote, unauthorized attacker to perform privilege escalation on affected systems.</p>
<p>Affected products:</p>
<ul>
<li>Windows DNS</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62778">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62778</a></p>
<p>Related in this roundup: <a href="#cve-2026-70304">CVE-2026-70304</a>, <a href="#cve-2026-70330">CVE-2026-70330</a>, <a href="#cve-2026-62769">CVE-2026-62769</a>, <a href="#cve-2026-62881">CVE-2026-62881</a>, <a href="#cve-2026-62883">CVE-2026-62883</a>, <a href="#cve-2026-65795">CVE-2026-65795</a>, <a href="#cve-2026-65797">CVE-2026-65797</a>, <a href="#cve-2026-65799">CVE-2026-65799</a>, <a href="#cve-2026-65798">CVE-2026-65798</a>.</p>
<h2 id="cve-2026-62780">CVE-2026-62780</h2>
<p>CVE-2026-62780 is a use-after-free vulnerability in the Windows Kernel that can be exploited by a locally authenticated attacker to escalate privileges. Detection engineering should focus on monitoring for anomalous kernel-mode memory operations or unexpected attempts to modify security tokens and process privileges.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62780">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62780</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62782">CVE-2026-62782</h2>
<p>CVE-2026-62782 is an out-of-bounds read vulnerability in the Windows SMB Client that enables an unauthenticated attacker to perform information disclosure over a network. Detection engineers should monitor for anomalous SMB traffic patterns or unusual requests originating from untrusted network segments directed at SMB-enabled Windows hosts.</p>
<p>Affected products:</p>
<ul>
<li>Windows SMB Client</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62782">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62782</a></p>
<p>Related in this roundup: <a href="#cve-2026-62799">CVE-2026-62799</a>.</p>
<h2 id="cve-2026-62781">CVE-2026-62781</h2>
<p>A heap-based buffer overflow vulnerability in the RPC Runtime Library allows a remote, unauthorized attacker to achieve remote code execution. The vulnerability is triggered over the network, making it a critical risk for systems utilizing RPC services.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62781">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62781</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62800">CVE-2026-62800</h2>
<p>CVE-2026-62800 describes a heap-based buffer overflow vulnerability in the Windows SMBv3 Server component. An authenticated attacker on the local network could trigger this vulnerability to achieve remote code execution, potentially leading to full system compromise.</p>
<p>Affected products:</p>
<ul>
<li>Windows SMB Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62800">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62800</a></p>
<p>Related in this roundup: <a href="#cve-2026-62790">CVE-2026-62790</a>.</p>
<h2 id="cve-2026-62786">CVE-2026-62786</h2>
<p>CVE-2026-62786 is an out-of-bounds read vulnerability in the Windows Win32k subsystem. An authorized local attacker can exploit this vulnerability to disclose sensitive information from the system memory.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62786">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62786</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62788">CVE-2026-62788</h2>
<p>CVE-2026-62788 is a use-after-free vulnerability within the Windows Kernel that allows a locally authenticated attacker to elevate their privileges to a higher level, potentially gaining system-level access.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62788">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62788</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62790">CVE-2026-62790</h2>
<p>CVE-2026-62790 is a heap-based buffer overflow vulnerability residing in the Windows SMBv3 Server component. An authenticated attacker can exploit this flaw to achieve remote code execution by sending specifically crafted packets to the targeted SMB service over the network.</p>
<p>Affected products:</p>
<ul>
<li>Windows SMB Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62790">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62790</a></p>
<p>Related in this roundup: <a href="#cve-2026-62800">CVE-2026-62800</a>.</p>
<h2 id="cve-2026-62793">CVE-2026-62793</h2>
<p>CVE-2026-62793 describes a buffer over-read vulnerability within the Windows NTFS file system driver. An authorized local attacker can exploit this flaw to perform unauthorized memory reads, leading to the disclosure of sensitive information.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62793">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62793</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62803">CVE-2026-62803</h2>
<p>CVE-2026-62803 is a local privilege escalation vulnerability in the Windows DHCP Server service. The issue stems from improper link resolution before file access, which allows an attacker with existing authorized access to escalate their privileges on the host system.</p>
<p>Affected products:</p>
<ul>
<li>Windows DHCP Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62803">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62803</a></p>
<p>Related in this roundup: <a href="#cve-2026-62718">CVE-2026-62718</a>, <a href="#cve-2026-62715">CVE-2026-62715</a>, <a href="#cve-2026-62716">CVE-2026-62716</a>, <a href="#cve-2026-62742">CVE-2026-62742</a>, <a href="#cve-2026-62745">CVE-2026-62745</a>, <a href="#cve-2026-62812">CVE-2026-62812</a>, <a href="#cve-2026-62720">CVE-2026-62720</a>, <a href="#cve-2026-62714">CVE-2026-62714</a>, <a href="#cve-2026-62761">CVE-2026-62761</a>, <a href="#cve-2026-62776">CVE-2026-62776</a>, <a href="#cve-2026-62807">CVE-2026-62807</a>, <a href="#cve-2026-62814">CVE-2026-62814</a>, <a href="#cve-2026-62823">CVE-2026-62823</a>.</p>
<h2 id="cve-2026-62807">CVE-2026-62807</h2>
<p>CVE-2026-62807 describes a local privilege escalation vulnerability in the Windows DHCP Server service caused by improper link resolution before file access (link following). An attacker with existing authorized access can exploit this flaw to execute operations with higher privileges on the host system.</p>
<p>Affected products:</p>
<ul>
<li>Windows DHCP Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62807">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62807</a></p>
<p>Related in this roundup: <a href="#cve-2026-62718">CVE-2026-62718</a>, <a href="#cve-2026-62715">CVE-2026-62715</a>, <a href="#cve-2026-62716">CVE-2026-62716</a>, <a href="#cve-2026-62742">CVE-2026-62742</a>, <a href="#cve-2026-62745">CVE-2026-62745</a>, <a href="#cve-2026-62812">CVE-2026-62812</a>, <a href="#cve-2026-62720">CVE-2026-62720</a>, <a href="#cve-2026-62714">CVE-2026-62714</a>, <a href="#cve-2026-62761">CVE-2026-62761</a>, <a href="#cve-2026-62776">CVE-2026-62776</a>, <a href="#cve-2026-62803">CVE-2026-62803</a>, <a href="#cve-2026-62814">CVE-2026-62814</a>, <a href="#cve-2026-62823">CVE-2026-62823</a>.</p>
<h2 id="cve-2026-62811">CVE-2026-62811</h2>
<p>A heap-based buffer overflow vulnerability in the Windows HTTP.sys driver allows a locally authenticated attacker to elevate their privileges to a higher integrity level. The vulnerability involves improper memory management when processing requests, which can be exploited to achieve unauthorized privilege escalation.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62811">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62811</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62814">CVE-2026-62814</h2>
<p>CVE-2026-62814 is an information disclosure vulnerability in the Windows DHCP Server caused by an integer underflow flaw. The vulnerability allows an unauthorized attacker on an adjacent network to read sensitive data, which could facilitate further reconnaissance or exploitation.</p>
<p>Affected products:</p>
<ul>
<li>Windows DHCP Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62814">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62814</a></p>
<p>Related in this roundup: <a href="#cve-2026-62718">CVE-2026-62718</a>, <a href="#cve-2026-62715">CVE-2026-62715</a>, <a href="#cve-2026-62716">CVE-2026-62716</a>, <a href="#cve-2026-62742">CVE-2026-62742</a>, <a href="#cve-2026-62745">CVE-2026-62745</a>, <a href="#cve-2026-62812">CVE-2026-62812</a>, <a href="#cve-2026-62720">CVE-2026-62720</a>, <a href="#cve-2026-62714">CVE-2026-62714</a>, <a href="#cve-2026-62761">CVE-2026-62761</a>, <a href="#cve-2026-62776">CVE-2026-62776</a>, <a href="#cve-2026-62803">CVE-2026-62803</a>, <a href="#cve-2026-62807">CVE-2026-62807</a>, <a href="#cve-2026-62823">CVE-2026-62823</a>.</p>
<h2 id="cve-2026-62823">CVE-2026-62823</h2>
<p>A heap-based buffer overflow vulnerability in the Windows DHCP Server component allows an unauthorized, adjacent attacker to achieve remote code execution. The vulnerability is triggered during the processing of network packets, posing a risk to Windows environments running the DHCP server role.</p>
<p>Affected products:</p>
<ul>
<li>Windows DHCP Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62823">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62823</a></p>
<p>Related in this roundup: <a href="#cve-2026-62718">CVE-2026-62718</a>, <a href="#cve-2026-62715">CVE-2026-62715</a>, <a href="#cve-2026-62716">CVE-2026-62716</a>, <a href="#cve-2026-62742">CVE-2026-62742</a>, <a href="#cve-2026-62745">CVE-2026-62745</a>, <a href="#cve-2026-62812">CVE-2026-62812</a>, <a href="#cve-2026-62720">CVE-2026-62720</a>, <a href="#cve-2026-62714">CVE-2026-62714</a>, <a href="#cve-2026-62761">CVE-2026-62761</a>, <a href="#cve-2026-62776">CVE-2026-62776</a>, <a href="#cve-2026-62803">CVE-2026-62803</a>, <a href="#cve-2026-62807">CVE-2026-62807</a>, <a href="#cve-2026-62814">CVE-2026-62814</a>.</p>
<h2 id="cve-2026-62824">CVE-2026-62824</h2>
<p>CVE-2026-62824 is a stack-based buffer overflow vulnerability in the Microsoft Remote Desktop Client, allowing an unauthorized remote attacker to execute arbitrary code over the network. Detection should focus on monitoring for abnormal process behavior or crashes within the RDP client application.</p>
<p>Affected products:</p>
<ul>
<li>Remote Desktop Client</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62824">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62824</a></p>
<p>Related in this roundup: <a href="#cve-2026-59134">CVE-2026-59134</a>, <a href="#cve-2026-61924">CVE-2026-61924</a>, <a href="#cve-2026-61352">CVE-2026-61352</a>, <a href="#cve-2026-61363">CVE-2026-61363</a>, <a href="#cve-2026-61918">CVE-2026-61918</a>, <a href="#cve-2026-61921">CVE-2026-61921</a>.</p>
<h2 id="cve-2026-62822">CVE-2026-62822</h2>
<p>An integer overflow or wraparound vulnerability in Windows GDI+ enables a remote, unauthorized attacker to achieve arbitrary code execution via network-based vectors. This vulnerability represents a significant risk for remote system compromise and requires patching of affected Windows components.</p>
<p>Affected products:</p>
<ul>
<li>Windows GDI+</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62822">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62822</a></p>
<p>Related in this roundup: <a href="#cve-2026-62890">CVE-2026-62890</a>, <a href="#cve-2026-62709">CVE-2026-62709</a>.</p>
<h2 id="cve-2026-62832">CVE-2026-62832</h2>
<p>CVE-2026-62832 is a privilege escalation vulnerability in the Windows User Profile Service caused by improper link resolution before file access. An attacker with existing local access can exploit this flaw to elevate their privileges on the system.</p>
<p>Affected products:</p>
<ul>
<li>Windows User Profile Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62832">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62832</a></p>
<h2 id="cve-2026-62871">CVE-2026-62871</h2>
<p>CVE-2026-62871 describes an out-of-bounds write vulnerability within the .NET framework that can be leveraged by a local, unauthorized attacker to achieve elevation of privilege and execute arbitrary code.</p>
<p>Affected products:</p>
<ul>
<li>.NET</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62871">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62871</a></p>
<p>Related in this roundup: <a href="#cve-2026-62899">CVE-2026-62899</a>, <a href="#cve-2026-62900">CVE-2026-62900</a>, <a href="#cve-2026-62901">CVE-2026-62901</a>, <a href="#cve-2026-62902">CVE-2026-62902</a>, <a href="#cve-2026-62909">CVE-2026-62909</a>, <a href="#cve-2026-58641">CVE-2026-58641</a>, <a href="#cve-2026-62886">CVE-2026-62886</a>.</p>
<h2 id="cve-2026-62880">CVE-2026-62880</h2>
<p>A vulnerability exists in the Windows NTFS file system where an out-of-bounds read allows an authenticated local attacker to escalate their privileges on the target system.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62880">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62880</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62881">CVE-2026-62881</h2>
<p>CVE-2026-62881 is an elevation of privilege vulnerability in Windows DNS resulting from a numeric truncation error. An attacker with local authorization can exploit this flaw to escalate privileges on the target system.</p>
<p>Affected products:</p>
<ul>
<li>Windows DNS</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62881">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62881</a></p>
<p>Related in this roundup: <a href="#cve-2026-70304">CVE-2026-70304</a>, <a href="#cve-2026-70330">CVE-2026-70330</a>, <a href="#cve-2026-62769">CVE-2026-62769</a>, <a href="#cve-2026-62778">CVE-2026-62778</a>, <a href="#cve-2026-62883">CVE-2026-62883</a>, <a href="#cve-2026-65795">CVE-2026-65795</a>, <a href="#cve-2026-65797">CVE-2026-65797</a>, <a href="#cve-2026-65799">CVE-2026-65799</a>, <a href="#cve-2026-65798">CVE-2026-65798</a>.</p>
<h2 id="cve-2026-62883">CVE-2026-62883</h2>
<p>CVE-2026-62883 is a local privilege escalation vulnerability in the Windows DNS component caused by a numeric truncation error. An authorized attacker can exploit this flaw to elevate their privileges on the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows DNS</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62883">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62883</a></p>
<p>Related in this roundup: <a href="#cve-2026-70304">CVE-2026-70304</a>, <a href="#cve-2026-70330">CVE-2026-70330</a>, <a href="#cve-2026-62769">CVE-2026-62769</a>, <a href="#cve-2026-62778">CVE-2026-62778</a>, <a href="#cve-2026-62881">CVE-2026-62881</a>, <a href="#cve-2026-65795">CVE-2026-65795</a>, <a href="#cve-2026-65797">CVE-2026-65797</a>, <a href="#cve-2026-65799">CVE-2026-65799</a>, <a href="#cve-2026-65798">CVE-2026-65798</a>.</p>
<h2 id="cve-2026-62885">CVE-2026-62885</h2>
<p>A heap-based buffer overflow vulnerability in the Windows Win32k subsystem allows an authorized local attacker to elevate their privileges to a higher level of access.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62885">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62885</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62886">CVE-2026-62886</h2>
<p>CVE-2026-62886 is an elevation of privilege vulnerability in .NET caused by an integer overflow or wraparound. This vulnerability allows an unauthorized local attacker to escalate their privileges within the context of the .NET runtime.</p>
<p>Affected products:</p>
<ul>
<li>.NET</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62886">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62886</a></p>
<p>Related in this roundup: <a href="#cve-2026-62899">CVE-2026-62899</a>, <a href="#cve-2026-62900">CVE-2026-62900</a>, <a href="#cve-2026-62901">CVE-2026-62901</a>, <a href="#cve-2026-62902">CVE-2026-62902</a>, <a href="#cve-2026-62909">CVE-2026-62909</a>, <a href="#cve-2026-58641">CVE-2026-58641</a>, <a href="#cve-2026-62871">CVE-2026-62871</a>.</p>
<h2 id="cve-2026-62887">CVE-2026-62887</h2>
<p>CVE-2026-62887 is an out-of-bounds read vulnerability in the Windows NTFS driver that allows a locally authenticated attacker to perform an information disclosure attack by reading sensitive data from memory.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62887">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62887</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62888">CVE-2026-62888</h2>
<p>CVE-2026-62888 is a local privilege escalation vulnerability in the Windows Desktop Window Manager (DWM) Core Library caused by a use-after-free flaw. An authenticated attacker can exploit this vulnerability to gain higher privileges on the target system.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62888">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62888</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-62911">CVE-2026-62911</h2>
<p>CVE-2026-62911 describes an elevation of privilege vulnerability in Microsoft Exchange Server stemming from an authentication bypass via a capture-replay mechanism. An attacker with authorized network access can exploit this flaw to perform unauthorized actions with elevated privileges on the target server.</p>
<p>Affected products:</p>
<ul>
<li>Exchange Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911</a></p>
<p>Related in this roundup: <a href="#cve-2026-62910">CVE-2026-62910</a>, <a href="#cve-2026-62912">CVE-2026-62912</a>, <a href="#cve-2026-62913">CVE-2026-62913</a>, <a href="#cve-2026-62914">CVE-2026-62914</a>, <a href="#cve-2026-62915">CVE-2026-62915</a>, <a href="#cve-2026-65813">CVE-2026-65813</a>.</p>
<h2 id="cve-2026-62842">CVE-2026-62842</h2>
<p>CVE-2026-62842 describes an out-of-bounds read vulnerability within the Microsoft Office Graphics Component. An attacker could exploit this flaw to perform unauthorized information disclosure on a local system.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62842">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62842</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-63524">CVE-2026-63524</h2>
<p>CVE-2026-63524 is an out-of-bounds read vulnerability in Microsoft Office that allows a local, unauthorized attacker to perform information disclosure.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63524">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63524</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-63525">CVE-2026-63525</h2>
<p>Microsoft Office Word contains a numeric truncation vulnerability that can be exploited by an unauthorized attacker to achieve remote code execution. The vulnerability stems from an error in memory handling, allowing for code execution upon opening a specially crafted malicious file.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63525">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63525</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-63526">CVE-2026-63526</h2>
<p>A stack-based buffer overflow vulnerability in the Microsoft Office Graphics Component allows an unauthorized attacker to achieve remote code execution. Successful exploitation requires an attacker to convince a user to open a specially crafted malicious file.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63526">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63526</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-63528">CVE-2026-63528</h2>
<p>CVE-2026-63528 is an out-of-bounds read vulnerability in Microsoft Office Word that enables an attacker to perform unauthorized local information disclosure.</p>
<p>Affected products:</p>
<ul>
<li>Office Word</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63528">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63528</a></p>
<p>Related in this roundup: <a href="#cve-2026-63518">CVE-2026-63518</a>, <a href="#cve-2026-70311">CVE-2026-70311</a>, <a href="#cve-2026-70319">CVE-2026-70319</a>, <a href="#cve-2026-63527">CVE-2026-63527</a>, <a href="#cve-2026-63531">CVE-2026-63531</a>, <a href="#cve-2026-64905">CVE-2026-64905</a>, <a href="#cve-2026-64907">CVE-2026-64907</a>, <a href="#cve-2026-64915">CVE-2026-64915</a>, <a href="#cve-2026-64917">CVE-2026-64917</a>, <a href="#cve-2026-66806">CVE-2026-66806</a>, <a href="#cve-2026-66810">CVE-2026-66810</a>.</p>
<h2 id="cve-2026-63527">CVE-2026-63527</h2>
<p>CVE-2026-63527 is a stack-based buffer overflow vulnerability in Microsoft Office Word that allows an unauthorized attacker to execute arbitrary code locally. Detection should focus on monitoring for abnormal behavior or unexpected child processes spawned by the winword.exe process.</p>
<p>Affected products:</p>
<ul>
<li>Office Word</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63527">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63527</a></p>
<p>Related in this roundup: <a href="#cve-2026-63518">CVE-2026-63518</a>, <a href="#cve-2026-70311">CVE-2026-70311</a>, <a href="#cve-2026-70319">CVE-2026-70319</a>, <a href="#cve-2026-63528">CVE-2026-63528</a>, <a href="#cve-2026-63531">CVE-2026-63531</a>, <a href="#cve-2026-64905">CVE-2026-64905</a>, <a href="#cve-2026-64907">CVE-2026-64907</a>, <a href="#cve-2026-64915">CVE-2026-64915</a>, <a href="#cve-2026-64917">CVE-2026-64917</a>, <a href="#cve-2026-66806">CVE-2026-66806</a>, <a href="#cve-2026-66810">CVE-2026-66810</a>.</p>
<h2 id="cve-2026-63529">CVE-2026-63529</h2>
<p>CVE-2026-63529 describes an out-of-bounds read vulnerability in Microsoft Office that enables an attacker to perform local information disclosure. The vulnerability allows unauthorized access to sensitive data due to improper memory handling during read operations.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63529">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63529</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-63530">CVE-2026-63530</h2>
<p>CVE-2026-63530 describes an out-of-bounds read vulnerability in Microsoft Office Word that enables an unauthorized local attacker to perform information disclosure. Detection should focus on anomalous file access patterns or memory access violations within the Word process.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63530">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63530</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-63531">CVE-2026-63531</h2>
<p>CVE-2026-63531 is an out-of-bounds read vulnerability in Microsoft Office Word that enables an unauthorized attacker to perform local information disclosure. The vulnerability allows the attacker to read memory contents beyond the intended boundaries of the application.</p>
<p>Affected products:</p>
<ul>
<li>Office Word</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63531">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63531</a></p>
<p>Related in this roundup: <a href="#cve-2026-63518">CVE-2026-63518</a>, <a href="#cve-2026-70311">CVE-2026-70311</a>, <a href="#cve-2026-70319">CVE-2026-70319</a>, <a href="#cve-2026-63528">CVE-2026-63528</a>, <a href="#cve-2026-63527">CVE-2026-63527</a>, <a href="#cve-2026-64905">CVE-2026-64905</a>, <a href="#cve-2026-64907">CVE-2026-64907</a>, <a href="#cve-2026-64915">CVE-2026-64915</a>, <a href="#cve-2026-64917">CVE-2026-64917</a>, <a href="#cve-2026-66806">CVE-2026-66806</a>, <a href="#cve-2026-66810">CVE-2026-66810</a>.</p>
<h2 id="cve-2026-63532">CVE-2026-63532</h2>
<p>CVE-2026-63532 is a remote code execution vulnerability in Microsoft Office resulting from an integer overflow or wraparound condition, which may allow an unauthorized attacker to execute arbitrary code locally.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63532">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63532</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-63533">CVE-2026-63533</h2>
<p>CVE-2026-63533 is a heap-based buffer overflow vulnerability in Microsoft Office that allows an unauthorized attacker to execute arbitrary code locally on a victim's machine.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63533">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63533</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-64897">CVE-2026-64897</h2>
<p>CVE-2026-64897 describes a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server. The flaw arises from improper neutralization of user-supplied input during the generation of web pages, which allows an authorized attacker to conduct spoofing attacks over the network.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64897">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64897</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-64898">CVE-2026-64898</h2>
<p>CVE-2026-64898 is a heap-based buffer overflow vulnerability in Microsoft Office that enables an unauthorized attacker to execute arbitrary code locally on a target system. This vulnerability typically requires user interaction, such as opening a specially crafted file, to trigger the heap corruption.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64898">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64898</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-64900">CVE-2026-64900</h2>
<p>CVE-2026-64900 is a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server that enables an authorized attacker to perform spoofing attacks over a network by injecting malicious scripts into web pages generated by the application.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64900">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64900</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-64902">CVE-2026-64902</h2>
<p>CVE-2026-64902 is a spoofing vulnerability in Microsoft SharePoint Server caused by improper neutralization of input during web page generation, specifically categorized as cross-site scripting (XSS). An authorized attacker can exploit this flaw over a network to perform spoofing attacks.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64902">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64902</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-64899">CVE-2026-64899</h2>
<p>CVE-2026-64899 is an out-of-bounds read vulnerability in Microsoft Office that enables an unauthorized local attacker to perform information disclosure. Detection efforts should focus on anomalous read operations or memory access patterns within the Office suite processes.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64899">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64899</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-64903">CVE-2026-64903</h2>
<p>CVE-2026-64903 is an integer overflow vulnerability in Microsoft Office that enables an attacker to achieve remote code execution. The flaw stems from improper handling of integer values during processing, which can be leveraged to execute arbitrary code on the host system.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64903">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64903</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-64901">CVE-2026-64901</h2>
<p>CVE-2026-64901 is a remote code execution vulnerability in Microsoft SharePoint Server caused by improper deserialization of untrusted data. An authorized attacker can leverage this flaw to execute arbitrary code over the network, potentially leading to full system compromise.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64901">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64901</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-64904">CVE-2026-64904</h2>
<p>A type confusion vulnerability in Microsoft Office allows a local, unauthorized attacker to execute arbitrary code. The vulnerability is triggered through the improper handling of incompatible resource types.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64904">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64904</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-64905">CVE-2026-64905</h2>
<p>A buffer over-read vulnerability in Microsoft Office Word allows an attacker to execute arbitrary code locally. Detection should focus on monitoring anomalous process creation or memory access patterns associated with Microsoft Word application files.</p>
<p>Affected products:</p>
<ul>
<li>Office Word</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64905">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64905</a></p>
<p>Related in this roundup: <a href="#cve-2026-63518">CVE-2026-63518</a>, <a href="#cve-2026-70311">CVE-2026-70311</a>, <a href="#cve-2026-70319">CVE-2026-70319</a>, <a href="#cve-2026-63528">CVE-2026-63528</a>, <a href="#cve-2026-63527">CVE-2026-63527</a>, <a href="#cve-2026-63531">CVE-2026-63531</a>, <a href="#cve-2026-64907">CVE-2026-64907</a>, <a href="#cve-2026-64915">CVE-2026-64915</a>, <a href="#cve-2026-64917">CVE-2026-64917</a>, <a href="#cve-2026-66806">CVE-2026-66806</a>, <a href="#cve-2026-66810">CVE-2026-66810</a>.</p>
<h2 id="cve-2026-64907">CVE-2026-64907</h2>
<p>CVE-2026-64907 describes a stack-based buffer overflow vulnerability in Microsoft Office Word that enables an unauthorized attacker to achieve remote code execution on the host system. The vulnerability is triggered when the application processes specially crafted content, allowing for arbitrary code execution.</p>
<p>Affected products:</p>
<ul>
<li>Office Word</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64907">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64907</a></p>
<p>Related in this roundup: <a href="#cve-2026-63518">CVE-2026-63518</a>, <a href="#cve-2026-70311">CVE-2026-70311</a>, <a href="#cve-2026-70319">CVE-2026-70319</a>, <a href="#cve-2026-63528">CVE-2026-63528</a>, <a href="#cve-2026-63527">CVE-2026-63527</a>, <a href="#cve-2026-63531">CVE-2026-63531</a>, <a href="#cve-2026-64905">CVE-2026-64905</a>, <a href="#cve-2026-64915">CVE-2026-64915</a>, <a href="#cve-2026-64917">CVE-2026-64917</a>, <a href="#cve-2026-66806">CVE-2026-66806</a>, <a href="#cve-2026-66810">CVE-2026-66810</a>.</p>
<h2 id="cve-2026-64906">CVE-2026-64906</h2>
<p>CVE-2026-64906 is a heap-based buffer overflow vulnerability in Microsoft Access that allows an unauthorized attacker to achieve remote code execution. The vulnerability is triggered by processing malicious input within the application, enabling local code execution.</p>
<p>Affected products:</p>
<ul>
<li>Access</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64906">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64906</a></p>
<p>Related in this roundup: <a href="#cve-2026-64912">CVE-2026-64912</a>, <a href="#cve-2026-64914">CVE-2026-64914</a>, <a href="#cve-2026-64920">CVE-2026-64920</a>, <a href="#cve-2026-64919">CVE-2026-64919</a>.</p>
<h2 id="cve-2026-64909">CVE-2026-64909</h2>
<p>CVE-2026-64909 describes an integer underflow vulnerability in Microsoft Office that enables an attacker to achieve remote code execution. The vulnerability stems from improper handling of integer wraparound, allowing for malicious code execution on the targeted system.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64909">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64909</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-64910">CVE-2026-64910</h2>
<p>CVE-2026-64910 is a remote code execution vulnerability in Microsoft Office caused by an untrusted pointer dereference. An attacker could exploit this flaw to execute arbitrary code locally on a victim's machine, typically requiring the user to interact with a malicious file.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64910">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64910</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-64912">CVE-2026-64912</h2>
<p>A stack-based buffer overflow vulnerability in Microsoft Access allows an unauthorized attacker to achieve remote code execution. Successful exploitation requires the application to process a specially crafted file, potentially leading to arbitrary code execution within the context of the current user.</p>
<p>Affected products:</p>
<ul>
<li>Access</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64912">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64912</a></p>
<p>Related in this roundup: <a href="#cve-2026-64906">CVE-2026-64906</a>, <a href="#cve-2026-64914">CVE-2026-64914</a>, <a href="#cve-2026-64920">CVE-2026-64920</a>, <a href="#cve-2026-64919">CVE-2026-64919</a>.</p>
<h2 id="cve-2026-64911">CVE-2026-64911</h2>
<p>CVE-2026-64911 is a remote code execution vulnerability in Microsoft Office caused by an integer overflow or wraparound condition, allowing an attacker to execute arbitrary code locally.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64911">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64911</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-64908">CVE-2026-64908</h2>
<p>CVE-2026-64908 describes a heap-based buffer overflow vulnerability in Microsoft Office Access. An unauthorized attacker can leverage this flaw to achieve remote code execution on the local machine by enticing a user to open a specially crafted file.</p>
<p>Affected products:</p>
<ul>
<li>Office Access</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64908">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64908</a></p>
<h2 id="cve-2026-64914">CVE-2026-64914</h2>
<p>CVE-2026-64914 is a heap-based buffer overflow vulnerability in Microsoft Access that allows an unauthorized attacker to execute arbitrary code locally.</p>
<p>Affected products:</p>
<ul>
<li>Access</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64914">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64914</a></p>
<p>Related in this roundup: <a href="#cve-2026-64906">CVE-2026-64906</a>, <a href="#cve-2026-64912">CVE-2026-64912</a>, <a href="#cve-2026-64920">CVE-2026-64920</a>, <a href="#cve-2026-64919">CVE-2026-64919</a>.</p>
<h2 id="cve-2026-64915">CVE-2026-64915</h2>
<p>CVE-2026-64915 is a heap-based buffer overflow vulnerability in Microsoft Office Word that enables an unauthorized attacker to execute arbitrary code on the host system. Successful exploitation typically requires a user to open a malicious document, leading to remote code execution within the context of the application.</p>
<p>Affected products:</p>
<ul>
<li>Office Word</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64915">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64915</a></p>
<p>Related in this roundup: <a href="#cve-2026-63518">CVE-2026-63518</a>, <a href="#cve-2026-70311">CVE-2026-70311</a>, <a href="#cve-2026-70319">CVE-2026-70319</a>, <a href="#cve-2026-63528">CVE-2026-63528</a>, <a href="#cve-2026-63527">CVE-2026-63527</a>, <a href="#cve-2026-63531">CVE-2026-63531</a>, <a href="#cve-2026-64905">CVE-2026-64905</a>, <a href="#cve-2026-64907">CVE-2026-64907</a>, <a href="#cve-2026-64917">CVE-2026-64917</a>, <a href="#cve-2026-66806">CVE-2026-66806</a>, <a href="#cve-2026-66810">CVE-2026-66810</a>.</p>
<h2 id="cve-2026-64916">CVE-2026-64916</h2>
<p>CVE-2026-64916 describes a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server that allows an authenticated attacker to perform spoofing attacks over the network. The vulnerability arises due to improper input neutralization during the generation of web pages.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64916">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64916</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-64920">CVE-2026-64920</h2>
<p>CVE-2026-64920 is a heap-based buffer overflow vulnerability in Microsoft Access that can be exploited by an unauthorized local attacker to achieve remote code execution on a target system.</p>
<p>Affected products:</p>
<ul>
<li>Access</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64920">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64920</a></p>
<p>Related in this roundup: <a href="#cve-2026-64906">CVE-2026-64906</a>, <a href="#cve-2026-64912">CVE-2026-64912</a>, <a href="#cve-2026-64914">CVE-2026-64914</a>, <a href="#cve-2026-64919">CVE-2026-64919</a>.</p>
<h2 id="cve-2026-64917">CVE-2026-64917</h2>
<p>CVE-2026-64917 is an out-of-bounds read vulnerability in Microsoft Office Word that enables an unauthorized local attacker to perform information disclosure by reading sensitive data from memory.</p>
<p>Affected products:</p>
<ul>
<li>Office Word</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64917">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64917</a></p>
<p>Related in this roundup: <a href="#cve-2026-63518">CVE-2026-63518</a>, <a href="#cve-2026-70311">CVE-2026-70311</a>, <a href="#cve-2026-70319">CVE-2026-70319</a>, <a href="#cve-2026-63528">CVE-2026-63528</a>, <a href="#cve-2026-63527">CVE-2026-63527</a>, <a href="#cve-2026-63531">CVE-2026-63531</a>, <a href="#cve-2026-64905">CVE-2026-64905</a>, <a href="#cve-2026-64907">CVE-2026-64907</a>, <a href="#cve-2026-64915">CVE-2026-64915</a>, <a href="#cve-2026-66806">CVE-2026-66806</a>, <a href="#cve-2026-66810">CVE-2026-66810</a>.</p>
<h2 id="cve-2026-64919">CVE-2026-64919</h2>
<p>CVE-2026-64919 is a stack-based buffer overflow vulnerability in Microsoft Office Access that can be exploited by an unauthorized attacker to achieve local remote code execution.</p>
<p>Affected products:</p>
<ul>
<li>Access</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64919">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64919</a></p>
<p>Related in this roundup: <a href="#cve-2026-64906">CVE-2026-64906</a>, <a href="#cve-2026-64912">CVE-2026-64912</a>, <a href="#cve-2026-64914">CVE-2026-64914</a>, <a href="#cve-2026-64920">CVE-2026-64920</a>.</p>
<h2 id="cve-2026-64921">CVE-2026-64921</h2>
<p>CVE-2026-64921 is a privilege escalation vulnerability in Microsoft SharePoint Server caused by missing authentication for a critical function. An authenticated attacker can exploit this flaw over the network to elevate their privileges within the application environment.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64921">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64921</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-62882">CVE-2026-62882</h2>
<p>CVE-2026-62882 is a spoofing vulnerability in Microsoft Outlook caused by insufficiently protected credentials, which can be exploited by an unauthorized attacker over a network to impersonate legitimate sources.</p>
<p>Affected products:</p>
<ul>
<li>Outlook</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62882">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62882</a></p>
<p>Related in this roundup: <a href="#cve-2026-70329">CVE-2026-70329</a>.</p>
<h2 id="cve-2026-65673">CVE-2026-65673</h2>
<p>CVE-2026-65673 is a privilege escalation vulnerability affecting Microsoft Entra Connect. This flaw allows a local, authenticated attacker to escalate their privileges within the context of the affected service.</p>
<p>Affected products:</p>
<ul>
<li>Entra Connect</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65673">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65673</a></p>
<h2 id="cve-2026-65681">CVE-2026-65681</h2>
<p>A denial of service vulnerability exists in the Windows iSCSI Target Service, which may allow a remote, unauthenticated attacker to disrupt service availability by sending specially crafted network requests to the target service.</p>
<p>Affected products:</p>
<ul>
<li>Windows iSCSI Target Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65681">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65681</a></p>
<p>Related in this roundup: <a href="#cve-2026-65679">CVE-2026-65679</a>, <a href="#cve-2026-65791">CVE-2026-65791</a>, <a href="#cve-2026-65796">CVE-2026-65796</a>.</p>
<h2 id="cve-2026-65679">CVE-2026-65679</h2>
<p>CVE-2026-65679 is a heap-based buffer overflow vulnerability in the Windows iSCSI Target Service. An unauthorized remote attacker can exploit this flaw to achieve remote code execution by sending specifically crafted network packets to the service.</p>
<p>Affected products:</p>
<ul>
<li>Windows iSCSI Target Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65679">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65679</a></p>
<p>Related in this roundup: <a href="#cve-2026-65681">CVE-2026-65681</a>, <a href="#cve-2026-65791">CVE-2026-65791</a>, <a href="#cve-2026-65796">CVE-2026-65796</a>.</p>
<h2 id="cve-2026-65773">CVE-2026-65773</h2>
<p>An improper access control vulnerability exists in the Windows Kernel that allows a local, authenticated attacker to escalate privileges on the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Kernel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65773">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65773</a></p>
<p>Related in this roundup: <a href="#cve-2026-54113">CVE-2026-54113</a>, <a href="#cve-2026-61930">CVE-2026-61930</a>, <a href="#cve-2026-62737">CVE-2026-62737</a>, <a href="#cve-2026-62708">CVE-2026-62708</a>, <a href="#cve-2026-62749">CVE-2026-62749</a>.</p>
<h2 id="cve-2026-65774">CVE-2026-65774</h2>
<p>A heap-based buffer overflow vulnerability in Windows Installer permits a locally authenticated attacker to gain elevated privileges on the target system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Installer</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65774">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65774</a></p>
<p>Related in this roundup: <a href="#cve-2026-59127">CVE-2026-59127</a>, <a href="#cve-2026-61925">CVE-2026-61925</a>, <a href="#cve-2026-70344">CVE-2026-70344</a>, <a href="#cve-2026-70345">CVE-2026-70345</a>, <a href="#cve-2026-70346">CVE-2026-70346</a>, <a href="#cve-2026-70347">CVE-2026-70347</a>, <a href="#cve-2026-61938">CVE-2026-61938</a>, <a href="#cve-2026-62768">CVE-2026-62768</a>.</p>
<h2 id="cve-2026-65775">CVE-2026-65775</h2>
<p>A use-after-free vulnerability exists in the Windows Win32k component that allows an authenticated local attacker to achieve privilege escalation by triggering the flaw.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65775">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65775</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-65776">CVE-2026-65776</h2>
<p>A use-after-free vulnerability in the Windows Win32k kernel component allows a locally authenticated attacker to elevate their privileges. Successful exploitation requires an attacker to already have local access to the system.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65776">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65776</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-65779">CVE-2026-65779</h2>
<p>A use-after-free vulnerability in Windows Autopilot allows an authorized, local attacker to escalate their privileges. Successful exploitation could grant the attacker higher-level access to the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Autopilot</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65779">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65779</a></p>
<p>Related in this roundup: <a href="#cve-2026-65783">CVE-2026-65783</a>, <a href="#cve-2026-65780">CVE-2026-65780</a>, <a href="#cve-2026-65778">CVE-2026-65778</a>, <a href="#cve-2026-65782">CVE-2026-65782</a>, <a href="#cve-2026-65781">CVE-2026-65781</a>.</p>
<h2 id="cve-2026-65780">CVE-2026-65780</h2>
<p>A double free vulnerability in Windows Autopilot allows an attacker with local authorization to elevate their privileges on the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Autopilot</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65780">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65780</a></p>
<p>Related in this roundup: <a href="#cve-2026-65783">CVE-2026-65783</a>, <a href="#cve-2026-65779">CVE-2026-65779</a>, <a href="#cve-2026-65778">CVE-2026-65778</a>, <a href="#cve-2026-65782">CVE-2026-65782</a>, <a href="#cve-2026-65781">CVE-2026-65781</a>.</p>
<h2 id="cve-2026-65778">CVE-2026-65778</h2>
<p>CVE-2026-65778 is a privilege escalation vulnerability in Windows Autopilot caused by a use-after-free flaw. An authenticated local attacker can leverage this vulnerability to elevate their privileges on an affected Windows system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Autopilot</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65778">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65778</a></p>
<p>Related in this roundup: <a href="#cve-2026-65783">CVE-2026-65783</a>, <a href="#cve-2026-65779">CVE-2026-65779</a>, <a href="#cve-2026-65780">CVE-2026-65780</a>, <a href="#cve-2026-65782">CVE-2026-65782</a>, <a href="#cve-2026-65781">CVE-2026-65781</a>.</p>
<h2 id="cve-2026-65782">CVE-2026-65782</h2>
<p>CVE-2026-65782 is a privilege escalation vulnerability in Windows Autopilot caused by a use-after-free condition. An authorized local attacker can exploit this flaw to execute code with elevated privileges on the affected Windows system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Autopilot</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65782">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65782</a></p>
<p>Related in this roundup: <a href="#cve-2026-65783">CVE-2026-65783</a>, <a href="#cve-2026-65779">CVE-2026-65779</a>, <a href="#cve-2026-65780">CVE-2026-65780</a>, <a href="#cve-2026-65778">CVE-2026-65778</a>, <a href="#cve-2026-65781">CVE-2026-65781</a>.</p>
<h2 id="cve-2026-65781">CVE-2026-65781</h2>
<p>A use-after-free vulnerability in Windows Autopilot allows a locally authenticated attacker to elevate their privileges on the host system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Autopilot</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65781">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65781</a></p>
<p>Related in this roundup: <a href="#cve-2026-65783">CVE-2026-65783</a>, <a href="#cve-2026-65779">CVE-2026-65779</a>, <a href="#cve-2026-65780">CVE-2026-65780</a>, <a href="#cve-2026-65778">CVE-2026-65778</a>, <a href="#cve-2026-65782">CVE-2026-65782</a>.</p>
<h2 id="cve-2026-65790">CVE-2026-65790</h2>
<p>CVE-2026-65790 is a heap-based buffer overflow vulnerability in the Windows Message Queuing component. An authorized local attacker can exploit this flaw to elevate their privileges on the target system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Message Queuing</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65790">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65790</a></p>
<p>Related in this roundup: <a href="#cve-2026-62719">CVE-2026-62719</a>, <a href="#cve-2026-62717">CVE-2026-62717</a>.</p>
<h2 id="cve-2026-65791">CVE-2026-65791</h2>
<p>A heap-based buffer overflow vulnerability in the Windows iSCSI Target Service allows an unauthenticated remote attacker to execute arbitrary code on the target system. The vulnerability exists within the service's request handling, potentially leading to remote code execution.</p>
<p>Affected products:</p>
<ul>
<li>Windows iSCSI Target Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65791">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65791</a></p>
<p>Related in this roundup: <a href="#cve-2026-65681">CVE-2026-65681</a>, <a href="#cve-2026-65679">CVE-2026-65679</a>, <a href="#cve-2026-65796">CVE-2026-65796</a>.</p>
<h2 id="cve-2026-65795">CVE-2026-65795</h2>
<p>An elevation of privilege vulnerability exists in the Windows DNS component that allows an authorized local attacker to escalate their privileges. Successful exploitation requires the attacker to already have a foothold on the system.</p>
<p>Affected products:</p>
<ul>
<li>Windows DNS</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65795">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65795</a></p>
<p>Related in this roundup: <a href="#cve-2026-70304">CVE-2026-70304</a>, <a href="#cve-2026-70330">CVE-2026-70330</a>, <a href="#cve-2026-62769">CVE-2026-62769</a>, <a href="#cve-2026-62778">CVE-2026-62778</a>, <a href="#cve-2026-62881">CVE-2026-62881</a>, <a href="#cve-2026-62883">CVE-2026-62883</a>, <a href="#cve-2026-65797">CVE-2026-65797</a>, <a href="#cve-2026-65799">CVE-2026-65799</a>, <a href="#cve-2026-65798">CVE-2026-65798</a>.</p>
<h2 id="cve-2026-65794">CVE-2026-65794</h2>
<p>A buffer over-read vulnerability in the Windows SMB Client allows an unauthorized remote attacker to disclose sensitive information over the network by exploiting the client's handling of specific SMB traffic patterns.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65794">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65794</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-56179">CVE-2026-56179</a>.</p>
<h2 id="cve-2026-65797">CVE-2026-65797</h2>
<p>CVE-2026-65797 is a local privilege escalation vulnerability in the Windows DNS component caused by a numeric truncation error. An authorized attacker can exploit this flaw to elevate their privileges on an affected system.</p>
<p>Affected products:</p>
<ul>
<li>Windows DNS</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65797">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65797</a></p>
<p>Related in this roundup: <a href="#cve-2026-70304">CVE-2026-70304</a>, <a href="#cve-2026-70330">CVE-2026-70330</a>, <a href="#cve-2026-62769">CVE-2026-62769</a>, <a href="#cve-2026-62778">CVE-2026-62778</a>, <a href="#cve-2026-62881">CVE-2026-62881</a>, <a href="#cve-2026-62883">CVE-2026-62883</a>, <a href="#cve-2026-65795">CVE-2026-65795</a>, <a href="#cve-2026-65799">CVE-2026-65799</a>, <a href="#cve-2026-65798">CVE-2026-65798</a>.</p>
<h2 id="cve-2026-65799">CVE-2026-65799</h2>
<p>CVE-2026-65799 is a local privilege escalation vulnerability in Windows DNS stemming from an integer overflow or wraparound condition, allowing an authenticated attacker to gain higher privileges on the target system.</p>
<p>Affected products:</p>
<ul>
<li>Windows DNS</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65799">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65799</a></p>
<p>Related in this roundup: <a href="#cve-2026-70304">CVE-2026-70304</a>, <a href="#cve-2026-70330">CVE-2026-70330</a>, <a href="#cve-2026-62769">CVE-2026-62769</a>, <a href="#cve-2026-62778">CVE-2026-62778</a>, <a href="#cve-2026-62881">CVE-2026-62881</a>, <a href="#cve-2026-62883">CVE-2026-62883</a>, <a href="#cve-2026-65795">CVE-2026-65795</a>, <a href="#cve-2026-65797">CVE-2026-65797</a>, <a href="#cve-2026-65798">CVE-2026-65798</a>.</p>
<h2 id="cve-2026-65798">CVE-2026-65798</h2>
<p>CVE-2026-65798 is a local privilege escalation vulnerability in the Windows DNS component caused by a numeric truncation error. An authorized attacker can exploit this flaw to elevate their privileges on the host system.</p>
<p>Affected products:</p>
<ul>
<li>Windows DNS</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65798">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65798</a></p>
<p>Related in this roundup: <a href="#cve-2026-70304">CVE-2026-70304</a>, <a href="#cve-2026-70330">CVE-2026-70330</a>, <a href="#cve-2026-62769">CVE-2026-62769</a>, <a href="#cve-2026-62778">CVE-2026-62778</a>, <a href="#cve-2026-62881">CVE-2026-62881</a>, <a href="#cve-2026-62883">CVE-2026-62883</a>, <a href="#cve-2026-65795">CVE-2026-65795</a>, <a href="#cve-2026-65797">CVE-2026-65797</a>, <a href="#cve-2026-65799">CVE-2026-65799</a>.</p>
<h2 id="cve-2026-65796">CVE-2026-65796</h2>
<p>A heap-based buffer overflow vulnerability in the Windows iSCSI Target Service allows a remote, unauthorized attacker to trigger a denial of service condition on affected systems.</p>
<p>Affected products:</p>
<ul>
<li>Windows iSCSI Target Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65796">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65796</a></p>
<p>Related in this roundup: <a href="#cve-2026-65681">CVE-2026-65681</a>, <a href="#cve-2026-65679">CVE-2026-65679</a>, <a href="#cve-2026-65791">CVE-2026-65791</a>.</p>
<h2 id="cve-2026-66802">CVE-2026-66802</h2>
<p>The Microsoft Azure Attestation and Device Health Attestation services are vulnerable to a race condition (concurrent execution with improper synchronization) that enables an unauthenticated attacker to achieve remote code execution over a network.</p>
<p>Affected products:</p>
<ul>
<li>Azure Attestation</li>
<li>Device Health Attestation Service</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66802">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66802</a></p>
<p>Related in this roundup: <a href="#cve-2026-71331">CVE-2026-71331</a>.</p>
<h2 id="cve-2026-66805">CVE-2026-66805</h2>
<p>CVE-2026-66805 is a remote code execution vulnerability in Microsoft SharePoint Server caused by improper deserialization of untrusted data. An authorized attacker can exploit this flaw to execute arbitrary code over the network.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66805">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66805</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-66806">CVE-2026-66806</h2>
<p>CVE-2026-66806 is an off-by-one vulnerability in Microsoft Office Word that enables an unauthorized attacker to perform local information disclosure. The vulnerability resides within the application's memory handling logic.</p>
<p>Affected products:</p>
<ul>
<li>Office Word</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66806">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66806</a></p>
<p>Related in this roundup: <a href="#cve-2026-63518">CVE-2026-63518</a>, <a href="#cve-2026-70311">CVE-2026-70311</a>, <a href="#cve-2026-70319">CVE-2026-70319</a>, <a href="#cve-2026-63528">CVE-2026-63528</a>, <a href="#cve-2026-63527">CVE-2026-63527</a>, <a href="#cve-2026-63531">CVE-2026-63531</a>, <a href="#cve-2026-64905">CVE-2026-64905</a>, <a href="#cve-2026-64907">CVE-2026-64907</a>, <a href="#cve-2026-64915">CVE-2026-64915</a>, <a href="#cve-2026-64917">CVE-2026-64917</a>, <a href="#cve-2026-66810">CVE-2026-66810</a>.</p>
<h2 id="cve-2026-66807">CVE-2026-66807</h2>
<p>A stack-based buffer overflow vulnerability exists in the Microsoft Office Graphics Component that allows an unauthorized attacker to achieve remote code execution on the local machine through the processing of malformed files.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66807">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66807</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-66808">CVE-2026-66808</h2>
<p>CVE-2026-66808 is a remote code execution vulnerability in Microsoft SharePoint Server caused by improper deserialization of untrusted data. An authorized attacker can leverage this flaw to execute arbitrary code over the network, posing a significant risk to the integrity and availability of the SharePoint environment.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66808">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66808</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-66810">CVE-2026-66810</h2>
<p>CVE-2026-66810 is an information disclosure vulnerability in Microsoft Office Word caused by a heap-based buffer overflow. An attacker can exploit this flaw to read sensitive data locally.</p>
<p>Affected products:</p>
<ul>
<li>Office Word</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66810">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66810</a></p>
<p>Related in this roundup: <a href="#cve-2026-63518">CVE-2026-63518</a>, <a href="#cve-2026-70311">CVE-2026-70311</a>, <a href="#cve-2026-70319">CVE-2026-70319</a>, <a href="#cve-2026-63528">CVE-2026-63528</a>, <a href="#cve-2026-63527">CVE-2026-63527</a>, <a href="#cve-2026-63531">CVE-2026-63531</a>, <a href="#cve-2026-64905">CVE-2026-64905</a>, <a href="#cve-2026-64907">CVE-2026-64907</a>, <a href="#cve-2026-64915">CVE-2026-64915</a>, <a href="#cve-2026-64917">CVE-2026-64917</a>, <a href="#cve-2026-66806">CVE-2026-66806</a>.</p>
<h2 id="cve-2026-66809">CVE-2026-66809</h2>
<p>An out-of-bounds read vulnerability exists in the Microsoft Office Graphics Component that could allow a local attacker to disclose sensitive information from the application's memory space.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66809">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66809</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-70130">CVE-2026-70130</a>.</p>
<h2 id="cve-2026-68797">CVE-2026-68797</h2>
<p>CVE-2026-68797 describes an out-of-bounds read vulnerability in Microsoft Excel that allows a local unauthorized attacker to disclose sensitive information. The vulnerability occurs due to improper memory handling within the application, and detection efforts should focus on anomalous file access patterns or unexpected memory read operations involving Excel processes.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68797">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68797</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68798">CVE-2026-68798</h2>
<p>A heap-based buffer overflow vulnerability in Microsoft Excel allows an attacker to achieve remote code execution. Successful exploitation requires the user to open a specially crafted malicious file, which can lead to the execution of arbitrary code with the privileges of the current user.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68798">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68798</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68799">CVE-2026-68799</h2>
<p>Microsoft Excel is vulnerable to an information disclosure flaw due to the use of an uninitialized resource. An attacker can exploit this vulnerability locally to gain unauthorized access to sensitive information.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68799">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68799</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68801">CVE-2026-68801</h2>
<p>CVE-2026-68801 describes a heap-based buffer overflow vulnerability in Microsoft Excel that can be exploited by an unauthorized attacker to achieve remote code execution. Detection efforts should focus on monitoring for anomalous file handling behaviors or malicious macro/script execution originating from Excel processes.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68801">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68801</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68803">CVE-2026-68803</h2>
<p>CVE-2026-68803 is a type confusion vulnerability in Microsoft Excel that allows an attacker to achieve remote code execution. The vulnerability is triggered when a user opens a specially crafted file, leading to memory corruption that can be leveraged to execute arbitrary code with the privileges of the current user.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68803">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68803</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68804">CVE-2026-68804</h2>
<p>CVE-2026-68804 is a remote code execution vulnerability in Microsoft Excel caused by a numeric truncation error. An attacker can exploit this flaw to execute arbitrary code on a victim's system, typically requiring user interaction by opening a maliciously crafted file.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68804">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68804</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68805">CVE-2026-68805</h2>
<p>CVE-2026-68805 describes a heap-based buffer overflow vulnerability in Microsoft Excel that can be exploited by an unauthorized attacker to achieve remote code execution. Detection efforts should focus on monitoring for anomalous child processes spawned by Excel and identifying attempts to parse malformed spreadsheet files.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68805">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68805</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68812">CVE-2026-68812</h2>
<p>CVE-2026-68812 is a heap-based buffer overflow vulnerability in Microsoft Excel that enables a remote, unauthorized attacker to execute arbitrary code locally on the victim's machine, typically through the user opening a malicious file.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68812">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68812</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68814">CVE-2026-68814</h2>
<p>CVE-2026-68814 is an out-of-bounds read vulnerability in Microsoft Excel that can be leveraged by an unauthorized attacker to achieve remote code execution on the target system.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68814">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68814</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68817">CVE-2026-68817</a>.</p>
<h2 id="cve-2026-68817">CVE-2026-68817</h2>
<p>CVE-2026-68817 is a stack-based buffer overflow vulnerability in Microsoft Excel that allows an unauthorized attacker to achieve remote code execution on the target system when a user opens a specially crafted file.</p>
<p>Affected products:</p>
<ul>
<li>Excel</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68817">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68817</a></p>
<p>Related in this roundup: <a href="#cve-2026-65807">CVE-2026-65807</a>, <a href="#cve-2026-68793">CVE-2026-68793</a>, <a href="#cve-2026-68794">CVE-2026-68794</a>, <a href="#cve-2026-68795">CVE-2026-68795</a>, <a href="#cve-2026-68796">CVE-2026-68796</a>, <a href="#cve-2026-68800">CVE-2026-68800</a>, <a href="#cve-2026-68802">CVE-2026-68802</a>, <a href="#cve-2026-68807">CVE-2026-68807</a>, <a href="#cve-2026-68806">CVE-2026-68806</a>, <a href="#cve-2026-68808">CVE-2026-68808</a>, <a href="#cve-2026-68810">CVE-2026-68810</a>, <a href="#cve-2026-68811">CVE-2026-68811</a>, <a href="#cve-2026-68813">CVE-2026-68813</a>, <a href="#cve-2026-68815">CVE-2026-68815</a>, <a href="#cve-2026-68816">CVE-2026-68816</a>, <a href="#cve-2026-70318">CVE-2026-70318</a>, <a href="#cve-2026-70327">CVE-2026-70327</a>, <a href="#cve-2026-70328">CVE-2026-70328</a>, <a href="#cve-2026-68797">CVE-2026-68797</a>, <a href="#cve-2026-68798">CVE-2026-68798</a>, <a href="#cve-2026-68799">CVE-2026-68799</a>, <a href="#cve-2026-68801">CVE-2026-68801</a>, <a href="#cve-2026-68803">CVE-2026-68803</a>, <a href="#cve-2026-68804">CVE-2026-68804</a>, <a href="#cve-2026-68805">CVE-2026-68805</a>, <a href="#cve-2026-68812">CVE-2026-68812</a>, <a href="#cve-2026-68814">CVE-2026-68814</a>.</p>
<h2 id="cve-2026-56179">CVE-2026-56179</h2>
<p>CVE-2026-56179 describes an origin validation error in the Windows Network Address Translation (NAT) driver. This vulnerability allows an unauthorized attacker positioned on an adjacent network to perform spoofing attacks, potentially leading to unauthorized data interception or manipulation.</p>
<p>Affected products:</p>
<ul>
<li>Windows</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56179">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56179</a></p>
<p>Related in this roundup: <a href="#cve-2026-68480">CVE-2026-68480</a>, <a href="#cve-2026-64564">CVE-2026-64564</a>, <a href="#cve-2026-54876">CVE-2026-54876</a>, <a href="#cve-2026-68388">CVE-2026-68388</a>, <a href="#cve-2026-68189">CVE-2026-68189</a>, <a href="#cve-2026-68312">CVE-2026-68312</a>, <a href="#cve-2026-68176">CVE-2026-68176</a>, <a href="#cve-2026-68118">CVE-2026-68118</a>, <a href="#cve-2026-68175">CVE-2026-68175</a>, <a href="#cve-2026-68328">CVE-2026-68328</a>, <a href="#cve-2026-68406">CVE-2026-68406</a>, <a href="#cve-2026-68317">CVE-2026-68317</a>, <a href="#cve-2026-68354">CVE-2026-68354</a>, <a href="#cve-2026-68326">CVE-2026-68326</a>, <a href="#cve-2026-68151">CVE-2026-68151</a>, <a href="#cve-2026-68343">CVE-2026-68343</a>, <a href="#cve-2026-68184">CVE-2026-68184</a>, <a href="#cve-2026-68322">CVE-2026-68322</a>, <a href="#cve-2026-68214">CVE-2026-68214</a>, <a href="#cve-2026-68188">CVE-2026-68188</a>, <a href="#cve-2026-68132">CVE-2026-68132</a>, <a href="#cve-2026-68304">CVE-2026-68304</a>, <a href="#cve-2026-68348">CVE-2026-68348</a>, <a href="#cve-2026-68195">CVE-2026-68195</a>, <a href="#cve-2026-68419">CVE-2026-68419</a>, <a href="#cve-2026-68171">CVE-2026-68171</a>, <a href="#cve-2025-37938">CVE-2025-37938</a>, <a href="#cve-2026-68207">CVE-2026-68207</a>, <a href="#cve-2026-50472">CVE-2026-50472</a>, <a href="#cve-2026-59132">CVE-2026-59132</a>, <a href="#cve-2026-61927">CVE-2026-61927</a>, <a href="#cve-2026-61937">CVE-2026-61937</a>, <a href="#cve-2026-61933">CVE-2026-61933</a>, <a href="#cve-2026-61934">CVE-2026-61934</a>, <a href="#cve-2026-61936">CVE-2026-61936</a>, <a href="#cve-2026-62702">CVE-2026-62702</a>, <a href="#cve-2026-62712">CVE-2026-62712</a>, <a href="#cve-2026-62746">CVE-2026-62746</a>, <a href="#cve-2026-62735">CVE-2026-62735</a>, <a href="#cve-2026-62739">CVE-2026-62739</a>, <a href="#cve-2026-62754">CVE-2026-62754</a>, <a href="#cve-2026-62766">CVE-2026-62766</a>, <a href="#cve-2026-62773">CVE-2026-62773</a>, <a href="#cve-2026-62774">CVE-2026-62774</a>, <a href="#cve-2026-62779">CVE-2026-62779</a>, <a href="#cve-2026-62792">CVE-2026-62792</a>, <a href="#cve-2026-62798">CVE-2026-62798</a>, <a href="#cve-2026-62795">CVE-2026-62795</a>, <a href="#cve-2026-62796">CVE-2026-62796</a>, <a href="#cve-2026-62876">CVE-2026-62876</a>, <a href="#cve-2026-62877">CVE-2026-62877</a>, <a href="#cve-2026-65662">CVE-2026-65662</a>, <a href="#cve-2026-65672">CVE-2026-65672</a>, <a href="#cve-2026-65678">CVE-2026-65678</a>, <a href="#cve-2026-65784">CVE-2026-65784</a>, <a href="#cve-2026-70307">CVE-2026-70307</a>, <a href="#cve-2026-42976">CVE-2026-42976</a>, <a href="#cve-2026-6726">CVE-2026-6726</a>, <a href="#cve-2026-61358">CVE-2026-61358</a>, <a href="#cve-2026-61360">CVE-2026-61360</a>, <a href="#cve-2026-61926">CVE-2026-61926</a>, <a href="#cve-2026-61929">CVE-2026-61929</a>, <a href="#cve-2026-62698">CVE-2026-62698</a>, <a href="#cve-2026-62700">CVE-2026-62700</a>, <a href="#cve-2026-62711">CVE-2026-62711</a>, <a href="#cve-2026-62721">CVE-2026-62721</a>, <a href="#cve-2026-62733">CVE-2026-62733</a>, <a href="#cve-2026-62743">CVE-2026-62743</a>, <a href="#cve-2026-62730">CVE-2026-62730</a>, <a href="#cve-2026-62757">CVE-2026-62757</a>, <a href="#cve-2026-62741">CVE-2026-62741</a>, <a href="#cve-2026-62770">CVE-2026-62770</a>, <a href="#cve-2026-62780">CVE-2026-62780</a>, <a href="#cve-2026-62781">CVE-2026-62781</a>, <a href="#cve-2026-62786">CVE-2026-62786</a>, <a href="#cve-2026-62788">CVE-2026-62788</a>, <a href="#cve-2026-62793">CVE-2026-62793</a>, <a href="#cve-2026-62811">CVE-2026-62811</a>, <a href="#cve-2026-62880">CVE-2026-62880</a>, <a href="#cve-2026-62885">CVE-2026-62885</a>, <a href="#cve-2026-62887">CVE-2026-62887</a>, <a href="#cve-2026-62888">CVE-2026-62888</a>, <a href="#cve-2026-65775">CVE-2026-65775</a>, <a href="#cve-2026-65776">CVE-2026-65776</a>, <a href="#cve-2026-65794">CVE-2026-65794</a>.</p>
<h2 id="cve-2026-70130">CVE-2026-70130</h2>
<p>CVE-2026-70130 describes a heap-based buffer overflow vulnerability in Microsoft Office that enables an unauthorized attacker to achieve remote code execution. Detection efforts should focus on monitoring for anomalous process behavior or crashes occurring during the parsing of malformed Office documents.</p>
<p>Affected products:</p>
<ul>
<li>Office</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70130">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70130</a></p>
<p>Related in this roundup: <a href="#cve-2026-63513">CVE-2026-63513</a>, <a href="#cve-2026-63515">CVE-2026-63515</a>, <a href="#cve-2026-63517">CVE-2026-63517</a>, <a href="#cve-2026-63521">CVE-2026-63521</a>, <a href="#cve-2026-63519">CVE-2026-63519</a>, <a href="#cve-2026-65657">CVE-2026-65657</a>, <a href="#cve-2026-65656">CVE-2026-65656</a>, <a href="#cve-2026-65661">CVE-2026-65661</a>, <a href="#cve-2026-65664">CVE-2026-65664</a>, <a href="#cve-2026-68792">CVE-2026-68792</a>, <a href="#cve-2026-70310">CVE-2026-70310</a>, <a href="#cve-2026-70315">CVE-2026-70315</a>, <a href="#cve-2026-70314">CVE-2026-70314</a>, <a href="#cve-2026-70317">CVE-2026-70317</a>, <a href="#cve-2026-70323">CVE-2026-70323</a>, <a href="#cve-2026-62842">CVE-2026-62842</a>, <a href="#cve-2026-63524">CVE-2026-63524</a>, <a href="#cve-2026-63525">CVE-2026-63525</a>, <a href="#cve-2026-63526">CVE-2026-63526</a>, <a href="#cve-2026-63529">CVE-2026-63529</a>, <a href="#cve-2026-63530">CVE-2026-63530</a>, <a href="#cve-2026-63532">CVE-2026-63532</a>, <a href="#cve-2026-63533">CVE-2026-63533</a>, <a href="#cve-2026-64898">CVE-2026-64898</a>, <a href="#cve-2026-64899">CVE-2026-64899</a>, <a href="#cve-2026-64903">CVE-2026-64903</a>, <a href="#cve-2026-64904">CVE-2026-64904</a>, <a href="#cve-2026-64909">CVE-2026-64909</a>, <a href="#cve-2026-64910">CVE-2026-64910</a>, <a href="#cve-2026-64911">CVE-2026-64911</a>, <a href="#cve-2026-66807">CVE-2026-66807</a>, <a href="#cve-2026-66809">CVE-2026-66809</a>.</p>
<h2 id="cve-2026-70306">CVE-2026-70306</h2>
<p>CVE-2026-70306 is a cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint that allows an unauthorized remote attacker to conduct spoofing attacks by improperly neutralizing user-supplied input during web page generation.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70306">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70306</a></p>
<p>Related in this roundup: <a href="#cve-2026-57105">CVE-2026-57105</a>, <a href="#cve-2026-70321">CVE-2026-70321</a>, <a href="#cve-2026-70324">CVE-2026-70324</a>.</p>
<h2 id="cve-2026-70326">CVE-2026-70326</h2>
<p>CVE-2026-70326 describes an elevation of privilege vulnerability in Microsoft SharePoint Server arising from a server-side request forgery (SSRF) flaw. An authenticated attacker can exploit this over the network to gain elevated privileges, highlighting the need to restrict network access to SharePoint management interfaces.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70326">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70326</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-70337">CVE-2026-70337</h2>
<p>CVE-2026-70337 describes a relative path traversal vulnerability within Microsoft PowerShell Core. This flaw allows a remote, unauthorized attacker to achieve remote code execution (RCE) by leveraging the traversal vulnerability over a network.</p>
<p>Affected products:</p>
<ul>
<li>PowerShell Core</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70337">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70337</a></p>
<p>Related in this roundup: <a href="#cve-2026-58612">CVE-2026-58612</a>.</p>
<h2 id="cve-2026-70354">CVE-2026-70354</h2>
<p>An out-of-bounds write vulnerability in .NET Core allows a local unauthorized attacker to execute arbitrary code. The vulnerability exists due to improper bounds checking, which could lead to memory corruption.</p>
<p>Affected products:</p>
<ul>
<li>.NET Core</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70354">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70354</a></p>
<h2 id="cve-2026-71331">CVE-2026-71331</h2>
<p>CVE-2026-71331 is a critical vulnerability identified in Microsoft's Azure Attestation and Device Health Attestation services. The flaw stems from an integer overflow or wraparound condition, which enables an unauthenticated remote attacker to execute arbitrary code within the context of the service. Security teams should prioritize patching or applying vendor-provided mitigations to these cloud-based attestation services to prevent potential remote compromise.</p>
<p>Affected products:</p>
<ul>
<li>Azure Attestation</li>
<li>Device Health Attestation</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71331">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71331</a></p>
<p>Related in this roundup: <a href="#cve-2026-66802">CVE-2026-66802</a>.</p>
<h2 id="cve-2026-62738">CVE-2026-62738</h2>
<p>CVE-2026-62738 describes an out-of-bounds read vulnerability within the Windows Management Instrumentation (WMI) component. An authorized, local attacker can leverage this flaw to disclose sensitive information from the system.</p>
<p>Affected products:</p>
<ul>
<li>Windows Management Instrumentation</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62738">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62738</a></p>
<h2 id="cve-2026-62898">CVE-2026-62898</h2>
<p>CVE-2026-62898 describes a use-after-free vulnerability in Microsoft QUIC that can be leveraged by a remote, unauthorized attacker to perform information disclosure over a network connection.</p>
<p>Affected products:</p>
<ul>
<li>Microsoft QUIC</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62898">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62898</a></p>
<p>Related in this roundup: <a href="#cve-2026-62815">CVE-2026-62815</a>.</p>
<h2 id="cve-2026-65767">CVE-2026-65767</h2>
<p>CVE-2026-65767 is a cross-site scripting (XSS) vulnerability in Microsoft Teams for Android that allows an attacker to perform spoofing attacks over a network by failing to properly neutralize input during web page generation.</p>
<p>Affected products:</p>
<ul>
<li>Teams</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65767">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65767</a></p>
<p>Related in this roundup: <a href="#cve-2026-65768">CVE-2026-65768</a>.</p>
<h2 id="cve-2026-58639">CVE-2026-58639</h2>
<p>CVE-2026-58639 describes a Server-Side Request Forgery (SSRF) vulnerability in Microsoft SharePoint Server that enables an authorized attacker to conduct spoofing attacks over a network.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58639">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58639</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-62839">CVE-2026-62839</h2>
<p>CVE-2026-62839 is a spoofing vulnerability in Microsoft SharePoint Server caused by insufficiently protected credentials. An attacker with existing authorized network access can exploit this flaw to perform spoofing attacks, potentially leading to unauthorized manipulation or impersonation of content within the SharePoint environment.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62839">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62839</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62917">CVE-2026-62917</a>.</p>
<h2 id="cve-2026-62917">CVE-2026-62917</h2>
<p>CVE-2026-62917 is a spoofing vulnerability in Microsoft SharePoint Server caused by improper input validation. An authorized attacker on the network can leverage this flaw to perform spoofing attacks against the affected server.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Server</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62917">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62917</a></p>
<p>Related in this roundup: <a href="#cve-2026-62829">CVE-2026-62829</a>, <a href="#cve-2026-62827">CVE-2026-62827</a>, <a href="#cve-2026-62837">CVE-2026-62837</a>, <a href="#cve-2026-63514">CVE-2026-63514</a>, <a href="#cve-2026-63512">CVE-2026-63512</a>, <a href="#cve-2026-63516">CVE-2026-63516</a>, <a href="#cve-2026-63520">CVE-2026-63520</a>, <a href="#cve-2026-64922">CVE-2026-64922</a>, <a href="#cve-2026-65658">CVE-2026-65658</a>, <a href="#cve-2026-65663">CVE-2026-65663</a>, <a href="#cve-2026-65660">CVE-2026-65660</a>, <a href="#cve-2026-65665">CVE-2026-65665</a>, <a href="#cve-2026-70355">CVE-2026-70355</a>, <a href="#cve-2026-64897">CVE-2026-64897</a>, <a href="#cve-2026-64900">CVE-2026-64900</a>, <a href="#cve-2026-64902">CVE-2026-64902</a>, <a href="#cve-2026-64901">CVE-2026-64901</a>, <a href="#cve-2026-64916">CVE-2026-64916</a>, <a href="#cve-2026-64921">CVE-2026-64921</a>, <a href="#cve-2026-66805">CVE-2026-66805</a>, <a href="#cve-2026-66808">CVE-2026-66808</a>, <a href="#cve-2026-70326">CVE-2026-70326</a>, <a href="#cve-2026-58639">CVE-2026-58639</a>, <a href="#cve-2026-62839">CVE-2026-62839</a>.</p>
<h2 id="cve-2026-65680">CVE-2026-65680</h2>
<p>CVE-2026-65680 describes an elevation of privilege vulnerability in Microsoft OneDrive for macOS caused by improper link resolution before file access. An attacker with local access can exploit this vulnerability to gain elevated privileges on the affected system.</p>
<p>Affected products:</p>
<ul>
<li>OneDrive</li>
</ul>
<p>Source: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65680">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65680</a></p>
<h2 id="cve-2026-50516">CVE-2026-50516</h2>
<p>CVE-2026-50516 describes a critical vulnerability in Microsoft Azure Kubernetes Service (AKS) where a missing authentication for a critical function allows an unauthenticated, remote attacker to escalate privileges over the network. This vulnerability carries a CVSS base score of 9.4, indicating a high risk of unauthorized access and system compromise.</p>
<p>Affected products:</p>
<ul>
<li>Azure Kubernetes Service</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50516">https://nvd.nist.gov/vuln/detail/CVE-2026-50516</a></p>
<h2 id="cve-2026-62869">CVE-2026-62869</h2>
<p>CVE-2026-62869 is a vulnerability in Microsoft Entra ID involving insufficient verification of data authenticity. This flaw allows an authorized attacker to perform spoofing over a network, potentially leading to unauthorized data manipulation or unauthorized access within the identity management environment.</p>
<p>Affected products:</p>
<ul>
<li>Microsoft Entra</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62869">https://nvd.nist.gov/vuln/detail/CVE-2026-62869</a></p>
<h2 id="cve-2026-62872">CVE-2026-62872</h2>
<p>An incorrect authorization vulnerability in the Microsoft .NET Framework allows an authenticated attacker to perform a privilege escalation attack over the network. The vulnerability, tracked as CVE-2026-62872, is categorized as an improper authorization issue and can be exploited by an attacker with low privileges, impacting the confidentiality, integrity, and availability of the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Microsoft .NET Framework</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62872">https://nvd.nist.gov/vuln/detail/CVE-2026-62872</a></p>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>roundup</category></item></channel></rss>