CPE
Microsoft September 2026 Patch Tuesday Addresses Two Actively Exploited Zero-Days
1 TTP 2 CVEsMicrosoft's September 2026 update cycle addresses 974 vulnerabilities, including two privilege-escalation zero-days actively exploited in the wild and 20 potentially wormable RCE flaws.
Microsoft Security Updates - September 2026
71 CVEsRoundup of Microsoft security advisories published in September 2026.
August 2026 Microsoft Security Update Analysis
1 TTP 5 CVEsMicrosoft's August 2026 security release addresses 415 vulnerabilities, including a zero-day (CVE-2026-68820) exploited in the wild that enables local privilege escalation in the Windows Ancillary Function Driver for WinSock.
Microsoft Security Updates — August 2026
29 CVEsRoundup of Microsoft security advisories published in August 2026.
Microsoft Addresses Two Actively Exploited Zero-Day Vulnerabilities in July 2026 Patch Tuesday
8 TTPs 4 CVEs 8 IOCsMicrosoft's July 2026 Patch Tuesday addressed 622 vulnerabilities, including two actively exploited zero-day elevation of privilege flaws, CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint, allowing local and remote attackers to gain administrative control.
Microsoft Security Updates — July 2026
5 CVEsRoundup of Microsoft security advisories published in July 2026.
Windows Snipping Tool NTLMv2 Hash Hijack Vulnerability (CVE-2026-33829)
2 rules 1 TTP 1 CVEA local exploit has been published for Windows Snipping Tool (CVE-2026-33829), enabling NTLMv2 Hash Hijacking by forcing authentication to a remote SMB server via a crafted ms-screensketch:edit URI, potentially leading to credential theft and lateral movement.
CVE-2026-32153 Windows Speech Use-After-Free Privilege Escalation
2 rules 1 TTP 1 CVECVE-2026-32153 is a use-after-free vulnerability in Microsoft Windows Speech that allows a locally authorized attacker to elevate privileges.
Windows Server Update Service (WSUS) Privilege Escalation via CVE-2026-26174
2 rules 1 TTPCVE-2026-26174 is a race condition vulnerability in Windows Server Update Service that allows an authorized attacker to elevate privileges locally.