Skip to content
Microsoft Patch Tuesday for September 2026

Microsoft Patch Tuesday for September 2026

Blog.Talosintelligence Cisco Talos September 8, 2026

Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."

Microsoft notes that 2 of the vulnerabilities disclosed this month have been exploited in the wild:

CVE-2026-81963 affects Windows Update Stack. CVE-2026-81963 is a elevation of privilege vulnerability associated with Improper Link Resolution Before File Access ('Link Following') and Improper Access Control and has a CVSS base score of 7.8.

CVE-2026-85880 affects Windows Advanced Local Procedure Call (ALPC). CVE-2026-85880 is a elevation of privilege vulnerability associated with Heap-based Buffer Overflow and Use of Uninitialized Resource and has a CVSS base score of 7.8.

Out of 113 "critical" vulnerabilities, 82 are remote code execution (RCE) vulnerabilities.

Microsoft considers exploitation of the following vulnerabilities more likely:

CVE-2026-69676 affects Windows Kerberos. CVE-2026-69676 is a remote code execution vulnerability associated with Authentication Bypass by Capture-replay and has a CVSS base score of 8.8.

CVE-2026-69852 affects Windows Routing and Remote Access Service (RRAS). CVE-2026-69852 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 7.5.

CVE-2026-72957 affects Windows Deployment Services. CVE-2026-72957 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 7.8.

CVE-2026-69854 affects Spring Cloud Azure. CVE-2026-69854 is a elevation of privilege vulnerability associated with Improper Authentication and has a CVSS base score of 9.0.

CVE-2026-83501 affects Windows Virtualization-Based Security (VBS). CVE-2026-83501 is a information disclosure vulnerability associated with Out-of-bounds Read and has a CVSS base score of 5.5.

CVE-2026-70585 affects Windows Services for NFS ONCRPC XDR Driver. CVE-2026-70585 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 7.0.

CVE-2026-69730 affects Windows DNS Server. CVE-2026-69730 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 9.8.

CVE-2026-69857 affects Azure Cosmos DB. CVE-2026-69857 is a spoofing vulnerability associated with Authorization Bypass Through User-Controlled Key and has a CVSS base score of 8.5.

Microsoft considers exploitation of the following vulnerabilities less likely:

CVE-2026-69845 and CVE-2026-72979 affect Windows DHCP Server. CVE-2026-69845 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and Improper Input Validation and has a CVSS base score of 9.8. CVE-2026-72979 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 9.8.

CVE-2026-58599 affects HEVC Video Extensions. CVE-2026-58599 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 7.8.

CVE-2026-65772 affects Microsoft Dynamics 365 On-Premises. CVE-2026-65772 is a remote code execution vulnerability associated with Deserialization of Untrusted Data and has a CVSS base score of 8.8.

CVE-2026-66302 affects Skype for Business. CVE-2026-66302 is a remote code execution vulnerability associated with External Control of File Name or Path and has a CVSS base score of 9.8.

CVE-2026-67631 , CVE-2026-65669 , and CVE-2026-67378 affect Microsoft SQL Server. CVE-2026-67631 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8. CVE-2026-65669 is a elevation of privilege vulnerability associated with Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') and has a CVSS base score of 9.6. CVE-2026-67378 is a remote code execution vulnerability associated with Untrusted Pointer Dereference and has a CVSS base score of 8.5.

CVE-2026-69499 , CVE-2026-70296 , CVE-2026-73023 , CVE-2026-77495 , and CVE-2026-73013 affect Windows Imaging Component. CVE-2026-69499 is a remote code execution vulnerability associated with Integer Overflow or Wraparound and has a CVSS base score of 8.8. CVE-2026-70296 is a remote code execution vulnerability associated with Out-of-bounds Write and has a CVSS base score of 9.8. CVE-2026-73023 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8. CVE-2026-77495 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8. CVE-2026-73013 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.

CVE-2026-69501 , CVE-2026-83939 , CVE-2026-69906 , and CVE-2026-69846 affect Windows Secure Kernel Mode. CVE-2026-69501 is a elevation of privilege vulnerability associated with Untrusted Pointer Dereference and has a CVSS base score of 7.0. CVE-2026-83939 is a elevation of privilege vulnerability associated with Untrusted Pointer Dereference and has a CVSS base score of 8.2. CVE-2026-69906 is a elevation of privilege vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.2. CVE-2026-69846 is a elevation of privilege vulnerability associated with Integer Overflow or Wraparound and has a CVSS base score of 8.2.

CVE-2026-69590 and CVE-2026-72959 affect Windows Routing and Remote Access Service (RRAS). CVE-2026-69590 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 9.8. CVE-2026-72959 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.

CVE-2026-69601 affects Microsoft Windows Media Foundation. CVE-2026-69601 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.

CVE-2026-72981 affects IP Helper. CVE-2026-72981 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 8.1.

CVE-2026-73006 affects DirectWrite. CVE-2026-73006 is a remote code execution vulnerability associated with Stack-based Buffer Overflow and has a CVSS base score of 8.8.

CVE-2026-73009 affects Windows Secure Socket Tunneling Protocol (SSTP). CVE-2026-73009 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 9.8.

CVE-2026-73010 and CVE-2026-78444 affect Microsoft Failover Cluster. CVE-2026-73010 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 9.8. CVE-2026-78444 is a remote code execution vulnerability associated with Untrusted Pointer Dereference and has a CVSS base score of 8.1.

CVE-2026-73017 affects Graphics Kernel. CVE-2026-73017 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 7.5.

CVE-2026-77493 affects Windows Graphics Component. CVE-2026-77493 is a remote code execution vulnerability associated with Double Free and has a CVSS base score of 9.8.

CVE-2026-83498 affects Windows Virtualization-Based Security (VBS) Enclave. CVE-2026-83498 is a elevation of privilege vulnerability associated with Untrusted Pointer Dereference and has a CVSS base score of 7.8.

CVE-2026-69530 , CVE-2026-78449 , and CVE-2026-78450 affect Windows Reliable Multicast Transport Driver (RMCAST). CVE-2026-69530 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 8.1. CVE-2026-78449 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 8.1. CVE-2026-78450 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 8.1.

CVE-2026-81948 , CVE-2026-81950 , CVE-2026-81951 , CVE-2026-81959 , and CVE-2026-81953 affect Microsoft Excel. CVE-2026-81948 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 7.8. CVE-2026-81950 is a remote code execution vulnerability associated with Double Free and has a CVSS base score of 7.8. CVE-2026-81951 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 7.8. CVE-2026-81959 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and Integer Overflow or Wraparound and has a CVSS base score of 7.8. CVE-2026-81953 is a remote code execution vulnerability associated with Stack-based Buffer Overflow and has a CVSS base score of 7.8.

CVE-2026-81354 affects Windows Hello. CVE-2026-81354 is a elevation of privilege vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.2.

CVE-2026-78525 , CVE-2026-78520 , CVE-2026-78519 , and CVE-2026-78509 affect Microsoft Office Outlook. CVE-2026-78525 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 8.8. CVE-2026-78520 is a remote code execution vulnerability associated with Out-of-bounds Read and has a CVSS base score of 6.5. CVE-2026-78519 is a remote code execution vulnerability associated with Use of Uninitialized Resource and has a CVSS base score of 8.8. CVE-2026-78509 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 9.8.

CVE-2026-81952 and CVE-2026-78510 affect Microsoft Word. CVE-2026-81952 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8. CVE-2026-78510 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 9.8.

CVE-2026-69595 and CVE-2026-78445 affect Windows Services for NFS ONCRPC XDR Driver. CVE-2026-69595 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 9.8. CVE-2026-78445 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 9.8.

CVE-2026-73018 and CVE-2026-72986 affect Graphic Fonts. CVE-2026-73018 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8. CVE-2026-72986 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and Integer Overflow or Wraparound and has a CVSS base score of 8.8.

CVE-2026-70203 affects Windows Media Player. CVE-2026-70203 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.

CVE-2026-69632 , CVE-2026-77898 , CVE-2026-69285 , and CVE-2026-78505 affect Microsoft Office. CVE-2026-69632 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 8.8. CVE-2026-77898 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 7.5. CVE-2026-69285 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8. CVE-2026-78505 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.

CVE-2026-69813 and CVE-2026-77505 affect Windows DNS Server. CVE-2026-69813 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 8.1. CVE-2026-77505 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 8.1.

CVE-2026-78439 affects Microsoft Office Graphics Component. CVE-2026-78439 is a remote code execution vulnerability associated with Stack-based Buffer Overflow and has a CVSS base score of 8.8.

CVE-2026-81355 affects Virtual Hard Disk (VHD) Miniport Driver. CVE-2026-81355 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 7.5.

CVE-2026-77504 affects Microsoft Office Word. CVE-2026-77504 is a remote code execution vulnerability associated with Double Free and has a CVSS base score of 8.8.

CVE-2026-69649 affects Raw Image Extension. CVE-2026-69649 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.

CVE-2026-69797 , CVE-2026-69767 , and CVE-2026-69678 affect Microsoft Office PowerPoint. CVE-2026-69797 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 8.8. CVE-2026-69767 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 8.8. CVE-2026-69678 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 8.8.

CVE-2026-72983 affects Internet Connection Sharing (ICS). CVE-2026-72983 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 9.8.

CVE-2026-69518 affects Windows Remote Desktop. CVE-2026-69518 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.

CVE-2026-69712 affects Windows Key Distribution Center. CVE-2026-69712 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 8.8.

Microsoft considers exploitation of the following vulnerabilities unlikely:

CVE-2026-69603 , CVE-2026-72961 , and CVE-2026-80083 affect Windows Hyper-V. CVE-2026-69603 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8. CVE-2026-72961 is a elevation of privilege vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.2. CVE-2026-80083 is a remote code execution vulnerability associated with Untrusted Pointer Dereference and has a CVSS base score of 8.8.

CVE-2026-69710 , CVE-2026-69725 , CVE-2026-69740 , CVE-2026-69784 , CVE-2026-69799 , CVE-2026-69820 , CVE-2026-69864 , and CVE-2026-72980 affect Windows Hello. CVE-2026-69710 is a elevation of privilege vulnerability associated with Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') and has a CVSS base score of 7.5. CVE-2026-69725 is a elevation of privilege vulnerability associated with Double Free and has a CVSS base score of 7.8. CVE-2026-69740 is a elevation of privilege vulnerability associated with Use After Free and has a CVSS base score of 8.8. CVE-2026-69784 is a elevation of privilege vulnerability associated with Use After Free and has a CVSS base score of 8.8. CVE-2026-69799 is a elevation of privilege vulnerability associated with Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') and has a CVSS base score of 7.8. CVE-2026-69820 is a elevation of privilege vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.2. CVE-2026-69864 is a elevation of privilege vulnerability associated with Use After Free and has a CVSS base score of 7.8. CVE-2026-72980 is a security feature bypass vulnerability associated with Uncontrolled Path Element and has a CVSS base score of 4.4.

CVE-2026-69769 affects Windows HTTP Print Provider. CVE-2026-69769 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 9.8.

CVE-2026-69829 affects Windows Shell. CVE-2026-69829 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 9.8.

CVE-2026-69860 affects Windows Imaging Component. CVE-2026-69860 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.

CVE-2026-69874 affects Windows ALPC. CVE-2026-69874 is a elevation of privilege vulnerability associated with Untrusted Pointer Dereference and has a CVSS base score of 8.2.

CVE-2026-69890 affects Windows Virtual Trusted Platform Module. CVE-2026-69890 is a elevation of privilege vulnerability associated with Use After Free and has a CVSS base score of 7.5.

CVE-2026-70586 affects Windows Paint. CVE-2026-70586 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.

CVE-2026-72950 affects Windows Routing and Remote Access Service (RRAS). CVE-2026-72950 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.

CVE-2026-72954 affects Windows Deployment Services. CVE-2026-72954 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 7.5.

CVE-2026-72958 affects Windows Credential Guard. CVE-2026-72958 is a elevation of privilege vulnerability associated with Double Free and has a CVSS base score of 8.2.

CVE-2026-72960 affects Windows Media Player. CVE-2026-72960 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.

CVE-2026-72962 affects Windows USB Video Driver. CVE-2026-72962 is a elevation of privilege vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.2.

CVE-2026-72982 affects Windows Netlogon. CVE-2026-72982 is a remote code execution vulnerability associated with Stack-based Buffer Overflow and has a CVSS base score of 9.8.

CVE-2026-72987 affects Windows DNS. CVE-2026-72987 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 8.1.

CVE-2026-81949 affects Microsoft Excel. CVE-2026-81949 is a remote code execution vulnerability associated with Integer Overflow or Wraparound and has a CVSS base score of 7.8.

CVE-2026-81352 affects Web Media Extensions. CVE-2026-81352 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.

CVE-2026-81955 affects Windows Graphics Component. CVE-2026-81955 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.

CVE-2026-69858 and CVE-2026-69827 affect Windows DNS Server. CVE-2026-69858 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 8.1. CVE-2026-69827 is a remote code execution vulnerability associated with Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') and Use After Free and has a CVSS base score of 8.1.

CVE-2026-67643 and CVE-2026-67636 affect Microsoft SQL Server. CVE-2026-67643 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8. CVE-2026-67636 is a remote code execution vulnerability associated with Out-of-bounds Read and has a CVSS base score of 8.5.

CVE-2026-69579 affects Windows Message Queuing. CVE-2026-69579 is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 9.8.

CVE-2026-70351 affects Microsoft WebP Image Extension. CVE-2026-70351 is a remote code execution vulnerability associated with Integer Overflow or Wraparound and Heap-based Buffer Overflow and has a CVSS base score of 8.8.

Other critical vulnerabilities:

CVE-2026-62916 affects Microsoft Entra ID. CVE-2026-62916 is a elevation of privilege vulnerability associated with Authentication Bypass Using an Alternate Path or Channel and has a CVSS base score of 9.1.

CVE-2026-83941 affects Entra ID. CVE-2026-83941 is a elevation of privilege vulnerability associated with Missing Authorization and has a CVSS base score of 9.9.

CVE-2026-65818 affects Power Automate. CVE-2026-65818 is a elevation of privilege vulnerability associated with Server-Side Request Forgery (SSRF) and has a CVSS base score of 8.5.

CVE-2026-80098 affects Copilot Studio. CVE-2026-80098 is a elevation of privilege vulnerability associated with Improper Verification of Cryptographic Signature and has a CVSS base score of 9.3.

CVE-2026-83711 affects Microsoft Azure Active Directory B2C. CVE-2026-83711 is a elevation of privilege vulnerability associated with Authorization Bypass Through User-Controlled Key and has a CVSS base score of 10.0.

CVE-2026-70178 affects Microsoft Fabric. CVE-2026-70178 is a elevation of privilege vulnerability associated with Missing Authorization and has a CVSS base score of 8.5.

CVE-2026-70352 affects Azure AI Language. CVE-2026-70352 is a elevation of privilege vulnerability associated with Missing Authentication for Critical Function and has a CVSS base score of 10.0.

CVE-2026-62906 affects Microsoft Discovery Studio. CVE-2026-62906 is a information disclosure vulnerability associated with Improper Neutralization of Special Elements in Data Query Logic and has a CVSS base score of 7.4.

Talos would also like to highlight the following "important" vulnerabilities as Microsoft has determined that their exploitation is "more likely:"

CVE-2026-68846 : Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-68876 : Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability

CVE-2026-68880 : Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-68884 : Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-69274 : Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-69277 : Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability

CVE-2026-69301 : Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-69305 : Microsoft Windows Component Elevation of Privilege Vulnerability

CVE-2026-69310 : Windows DNS Elevation of Privilege Vulnerability

CVE-2026-69337 : Windows Registry Elevation of Privilege Vulnerability

CVE-2026-69364 : Windows Print Spooler Components Elevation of Privilege Vulnerability

CVE-2026-69385 : Windows TCP/IP Elevation of Privilege Vulnerability

CVE-2026-69391 : Windows Broker Infrastructure Service Elevation of Privilege Vulnerability

CVE-2026-69406 : Windows Kernel Information Disclosure Vulnerability

CVE-2026-69436 : Windows Error Reporting Elevation of Privilege Vulnerability

CVE-2026-69450 : Windows Error Reporting Elevation of Privilege Vulnerability

CVE-2026-69451 : Windows Management Instrumentation Elevation of Privilege Vulnerability

CVE-2026-69459 : Windows Power Dependency Coordinator Elevation of Privilege Vulnerability

CVE-2026-69466 : Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-69473 : Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-69478 : Windows Device Association Service Elevation of Privilege Vulnerability

CVE-2026-69498 : Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-69525 : Remote Desktop Services Remote Code Execution Vulnerability

CVE-2026-69541 : Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability

CVE-2026-69585 : Microsoft Windows Component Elevation of Privilege Vulnerability

CVE-2026-69600 : Microsoft Windows Component Elevation of Privilege Vulnerability

CVE-2026-69605 : Microsoft Install Service Elevation of Privilege Vulnerability

CVE-2026-69623 : Windows HTTP Print Provider Remote Code Execution Vulnerability

CVE-2026-69714 : Windows Device Association Service Elevation of Privilege Vulnerability

CVE-2026-69723 : Windows Kernel Information Disclosure Vulnerability

CVE-2026-69757 : Windows TCP/IP Elevation of Privilege Vulnerability

CVE-2026-69777 : Windows DHCP Client Elevation of Privilege Vulnerability

CVE-2026-69779 : Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-69832 : Win32k Information Disclosure Vulnerability

CVE-2026-69911 : Microsoft Windows Component Elevation of Privilege Vulnerability

CVE-2026-69921 : Windows Print Spooler Components Elevation of Privilege Vulnerability

CVE-2026-70289 : Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-70342 : Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-70562 : Windows Audio Service Elevation of Privilege Vulnerability

CVE-2026-70583 : Windows Core Messaging Elevation of Privilege Vulnerability

CVE-2026-71340 : Windows File History Service Elevation of Privilege Vulnerability

CVE-2026-72936 : Windows SMB Client Remote Code Execution Vulnerability

CVE-2026-77500 : Windows Device Association Service Elevation of Privilege Vulnerability

CVE-2026-78454 : Windows CD-ROM Driver Information Disclosure Vulnerability

CVE-2026-69460 : Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability

CVE-2026-69467 : Microsoft Graphics Component Elevation of Privilege Vulnerability

CVE-2026-80093 : Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2026-72940 : Windows Schannel Remote Code Execution Vulnerability

CVE-2026-71343 : Windows Remote Access Connection Manager Remote Code Execution Vulnerability

CVE-2026-69366 : Windows Kernel Elevation of Privilege Vulnerability

A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its update page .

Snort 2 rule coverage: SIDs 67011-67032 and 67036-67084.

Snort 3 rule coverage: SIDs 301619-301629, 301632-301655, and 67046.

Extracted Entities

CVEs (165)

CVE-2026-58599CVE-2026-62906CVE-2026-62916CVE-2026-65669CVE-2026-65772CVE-2026-65818CVE-2026-66302CVE-2026-67378CVE-2026-67631CVE-2026-67636CVE-2026-67643CVE-2026-68846CVE-2026-68876CVE-2026-68880CVE-2026-68884CVE-2026-69274CVE-2026-69277CVE-2026-69285CVE-2026-69301CVE-2026-69305CVE-2026-69310CVE-2026-69337CVE-2026-69364CVE-2026-69366CVE-2026-69385CVE-2026-69391CVE-2026-69406CVE-2026-69436CVE-2026-69450CVE-2026-69451CVE-2026-69459CVE-2026-69460CVE-2026-69466CVE-2026-69467CVE-2026-69473CVE-2026-69478CVE-2026-69498CVE-2026-69499CVE-2026-69501CVE-2026-69518CVE-2026-69525CVE-2026-69530CVE-2026-69541CVE-2026-69579CVE-2026-69585CVE-2026-69590CVE-2026-69595CVE-2026-69600CVE-2026-69601CVE-2026-69603CVE-2026-69605CVE-2026-69623CVE-2026-69632CVE-2026-69649CVE-2026-69676CVE-2026-69678CVE-2026-69710CVE-2026-69712CVE-2026-69714CVE-2026-69723CVE-2026-69725CVE-2026-69730CVE-2026-69740CVE-2026-69757CVE-2026-69767CVE-2026-69769CVE-2026-69777CVE-2026-69779CVE-2026-69784CVE-2026-69797CVE-2026-69799CVE-2026-69813CVE-2026-69820CVE-2026-69827CVE-2026-69829CVE-2026-69832CVE-2026-69845CVE-2026-69846CVE-2026-69852CVE-2026-69854CVE-2026-69857CVE-2026-69858CVE-2026-69860CVE-2026-69864CVE-2026-69874CVE-2026-69890CVE-2026-69906CVE-2026-69911CVE-2026-69921CVE-2026-70178CVE-2026-70203CVE-2026-70289CVE-2026-70296CVE-2026-70342CVE-2026-70351CVE-2026-70352CVE-2026-70562CVE-2026-70583CVE-2026-70585CVE-2026-70586CVE-2026-71340CVE-2026-71343CVE-2026-72936CVE-2026-72940CVE-2026-72950CVE-2026-72954CVE-2026-72957CVE-2026-72958CVE-2026-72959CVE-2026-72960CVE-2026-72961CVE-2026-72962CVE-2026-72979CVE-2026-72980CVE-2026-72981CVE-2026-72982CVE-2026-72983CVE-2026-72986CVE-2026-72987CVE-2026-73006CVE-2026-73009CVE-2026-73010CVE-2026-73013CVE-2026-73017CVE-2026-73018CVE-2026-73023CVE-2026-77493CVE-2026-77495CVE-2026-77500CVE-2026-77504CVE-2026-77505CVE-2026-77898CVE-2026-78439CVE-2026-78444CVE-2026-78445CVE-2026-78449CVE-2026-78450CVE-2026-78454CVE-2026-78505CVE-2026-78509CVE-2026-78510CVE-2026-78519CVE-2026-78520CVE-2026-78525CVE-2026-80083CVE-2026-80093CVE-2026-80098CVE-2026-81352CVE-2026-81354CVE-2026-81355CVE-2026-81948CVE-2026-81949CVE-2026-81950CVE-2026-81951CVE-2026-81952CVE-2026-81953CVE-2026-81955CVE-2026-81959CVE-2026-81963CVE-2026-83498CVE-2026-83501CVE-2026-83711CVE-2026-83939CVE-2026-83941CVE-2026-85880