Skip to content
Threat Feed

CPE

Cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*

9 briefs RSS
critical threat

Microsoft September 2026 Patch Tuesday Addresses Two Actively Exploited Zero-Days

Microsoft's September 2026 update cycle addresses 974 vulnerabilities, including two privilege-escalation zero-days actively exploited in the wild and 20 potentially wormable RCE flaws.

exploited Windows +7 vulnerability-management patch-tuesday privilege-escalation
1t 2c
high threat

Microsoft Security Updates - September 2026

Roundup of Microsoft security advisories published in September 2026.

roundup
71c updated
critical threat

August 2026 Microsoft Security Update Analysis

Microsoft's August 2026 security release addresses 415 vulnerabilities, including a zero-day (CVE-2026-68820) exploited in the wild that enables local privilege escalation in the Windows Ancillary Function Driver for WinSock.

exploited Windows +7 vulnerability-management patch-tuesday privilege-escalation
1t 5c updated
high threat

Microsoft Security Updates — August 2026

Roundup of Microsoft security advisories published in August 2026.

roundup
29c updated
critical threat

Microsoft Addresses Two Actively Exploited Zero-Day Vulnerabilities in July 2026 Patch Tuesday

Microsoft's July 2026 Patch Tuesday addressed 622 vulnerabilities, including two actively exploited zero-day elevation of privilege flaws, CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint, allowing local and remote attackers to gain administrative control.

exploited PoC Active Directory Federation Services +23 patch-tuesday zero-day vulnerability microsoft windows sharepoint active-directory-federation-services bitlocker +2
8t 4c 8i updated
high advisory

Microsoft Security Updates — July 2026

Roundup of Microsoft security advisories published in July 2026.

roundup
5c updated
medium advisory

Windows Snipping Tool NTLMv2 Hash Hijack Vulnerability (CVE-2026-33829)

A local exploit has been published for Windows Snipping Tool (CVE-2026-33829), enabling NTLMv2 Hash Hijacking by forcing authentication to a remote SMB server via a crafted ms-screensketch:edit URI, potentially leading to credential theft and lateral movement.

Windows Snipping Tool credential-access ntlmv2 pass-the-hash cve-2026-33829
2r 1t 1c
high advisory

CVE-2026-32153 Windows Speech Use-After-Free Privilege Escalation

CVE-2026-32153 is a use-after-free vulnerability in Microsoft Windows Speech that allows a locally authorized attacker to elevate privileges.

Windows Speech Runtime cve-2026-32153 privilege-escalation windows
2r 1t 1c updated
high advisory

Windows Server Update Service (WSUS) Privilege Escalation via CVE-2026-26174

CVE-2026-26174 is a race condition vulnerability in Windows Server Update Service that allows an authorized attacker to elevate privileges locally.

Windows Server Update Service cve-2026-26174 privilege-escalation windows wsus
2r 1t updated