Skip to content
Patch Tuesday September 2026

Patch Tuesday September 2026

www.action1.com September 9, 2026

This digest covers the most serious vulnerabilities patched by Microsoft in this month’s Patch Tuesday release.

For even more information, join our Patch Tuesday webinar and visit our Patch Tuesday Watch page .

Microsoft Vulnerabilities

Microsoft’s September 2026 Patch Tuesday is the largest on record, with 995 patches, a volume unlike anything we’ve seen before and just shy of the 1,000 mark. The release includes 119 critical vulnerabilities and two zero-days, both elevation-of-privilege flaws: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows Advanced Local Procedure Call (ALPC).

At this scale, the challenge is not simply getting through the patch list. It is knowing what needs attention first. With hundreds of updates landing at once, IT and security teams need to quickly separate the vulnerabilities that demand immediate action from those that can follow the normal deployment cycle. Below, we break down the September updates and highlight where remediation should start.

Critical - Same Day Deployment CVE-2026-62878Windows DNS Server Remote Code Execution Vulnerability

“A single malicious network packet could turn an exposed Windows DNS service into a remote code execution target without credentials or user interaction.”

CVE-2026-62878 is a remote code execution vulnerability in Windows DNS Server caused by a stack-based buffer overflow. An unauthenticated attacker could send a specially crafted packet to an affected DNS service over the network and potentially execute code on the target system. The attack has low complexity, requires no privileges, and requires no user interaction.

Critical - Same Day Deployment CVE-2026-62817Windows DNS Server Remote Code Execution Vulnerability

“An attacker already on the network could turn a malformed DNS request into remote code execution on a critical infrastructure server.”

CVE-2026-62817 is a remote code execution vulnerability in Windows DNS Server caused by an out-of-bounds write. An unauthenticated attacker on an adjacent network could exploit the flaw by interacting with arbitrary endpoints and potentially execute code on the target system. The attack has low complexity and requires no privileges or user interaction.

Critical - Same Day Deployment CVE-2026-62820Windows DNS Server Remote Code Execution Vulnerability

“This DNS flaw can turn a race condition into remote code execution, giving an unauthenticated attacker a path to compromise a critical network service.”

CVE-2026-62820 is a remote code execution vulnerability in Windows DNS Server caused by improper synchronization during concurrent access to a shared resource. An unauthenticated attacker could send a specially crafted packet to an affected DNS service over the network and potentially execute code on the target system. Successful exploitation requires the attacker to win a race condition, which increases attack complexity.

Critical - Same Day Deployment CVE-2026-62823Windows DHCP Server Remote Code Execution Vulnerability

“A single malicious network packet could give an unauthenticated attacker code execution on a vulnerable DHCP server, with no user action required.”

CVE-2026-62823 is a remote code execution vulnerability in Windows DHCP Server caused by a heap-based buffer overflow. An unauthenticated attacker on an adjacent network could send a specially crafted packet to an affected DHCP service and potentially execute code on the target system. The attack requires no privileges, no authentication, and no user interaction.

Critical - Same Day Deployment CVE-2026-62893Windows Deployment Services TFTP Server Remote Code Execution Vulnerability

“This flaw gives an unauthenticated attacker a direct network path to code execution, with no user interaction and low attack complexity.”

CVE-2026-62893 is a remote code execution vulnerability in Windows Deployment Services caused by a use-after-free condition. An unauthenticated attacker could send a specially crafted packet to an affected TFTP service over the network and potentially execute code on the target system. The attack requires no privileges, no authentication, and no user interaction.

Critical - Same Day Deployment CVE-2026-65789Windows DNS Server Remote Code Execution Vulnerability

“A specially crafted network packet can potentially turn a vulnerable DNS service into a remote code execution path, with no authentication or user interaction required.”

CVE-2026-65789 is a remote code execution vulnerability in Windows DNS caused by a use-after-free condition. An unauthenticated attacker could send a specially crafted packet to an affected DNS service over the network and potentially execute code on the target system. Exploitation requires specific network configurations and timing conditions, making successful exploitation less reliable across all environments.

Critical - Same Day Deployment CVE-2026-58231 – SAP Products

“Critical SAP flaws put core applications at risk of code execution, system compromise, and severe disruption.”

SAP patches address three Critical vulnerabilities across Commerce Cloud, Manufacturing Integration and Intelligence, and NetWeaver and ABAP Platform. CVE-2026-58231 has a CVSS score of 10.0, Critical severity, and can allow an unauthenticated attacker to execute arbitrary code. CVE-2026-44758 has a CVSS score of 9.1, Critical severity, and can allow a highly privileged attacker to execute arbitrary operating-system commands. CVE-2026-34265 has a CVSS score of 9.8, Critical severity, and can allow an unauthenticated attacker to trigger memory corruption, potentially exposing sensitive information or crashing the system.

These vulnerabilities can significantly affect confidentiality, integrity, and availability across critical SAP environments.

High with EoP or RCE – Expedited Deployment CVE-2026-62913Microsoft Exchange Server 2016 CU23

“Multiple Exchange flaws create paths to code execution, privilege escalation, and broader server compromise.”

Microsoft Exchange Server 2016 CU23 is affected by six vulnerabilities spanning remote code execution, privilege escalation, and other security weaknesses. CVE-2026-62913 has a CVSS score of 8.8, High severity. CVE-2026-62911 has a CVSS score of 8.0, High severity. CVE-2026-62910 has a CVSS score of 7.2, High severity. CVE-2026-62912 has a CVSS score of 6.5, Medium severity. CVE-2026-62914 has a CVSS score of 7.3, High severity. CVE-2026-62915 has a CVSS score of 6.5, Medium severity.

The patch addresses the affected Exchange Server components and reduces the risk of server compromise, unauthorized privilege gains, and disruption.

Zero Day – Immediate Deployment CVE-2026-81963 – Windows Update Stack Elevation of Privilege Vulnerability

“This Windows Update Stack flaw is already being exploited, and a low-privilege attacker can turn local access into SYSTEM-level control.”

CVE-2026-81963 is an elevation of privilege vulnerability in the Windows Update Stack caused by improper link resolution before file access and improper access control. A local attacker with low privileges could exploit the weakness to gain SYSTEM privileges. Microsoft reports that exploitation has already been detected.

Zero Day – Immediate Deployment CVE-2026-85880 – Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

“This ALPC flaw is already being exploited, and a successful attack can turn low-privilege code execution into full SYSTEM control.”

A heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC) allows an authorized local attacker to elevate privileges. An attacker who can execute code from a low-privilege AppContainer can exploit the vulnerability to escape the sandbox and obtain SYSTEM privileges without requiring user interaction.

Critical - Same Day Deployment CVE-2026-69678 – Microsoft Office PowerPoint Remote Code Execution Vulnerability

“A malicious PowerPoint presentation could turn opening or previewing a file into remote code execution, putting sensitive data and system integrity at risk.”

CVE-2026-69678 is a critical use-after-free vulnerability in Microsoft Office PowerPoint that can allow an unauthorized attacker to execute code. An attacker can send a specially crafted presentation, with exploitation occurring when a user opens the file or when it is rendered in a preview pane. Successful exploitation can execute code in the user's context and can have a high impact on confidentiality, integrity, and availability.

Critical - Same Day Deployment CVE-2026-69820 – Windows Hello Elevation of Privilege Vulnerability

“A Windows Hello memory flaw could turn existing local access into powerful VTL1 privileges, putting sensitive systems and data at greater risk.”

CVE-2026-69820 is a heap-based buffer overflow vulnerability in Windows Hello that allows an authorized local attacker to elevate privileges. Successful exploitation could give the attacker Virtual Trust Level 1 (VTL1) privileges. No exploitation or public disclosure is reported, and exploit code maturity is listed as unproven.

Critical - Same Day Deployment CVE-2026-81354 – Windows Hello Elevation of Privilege Vulnerability

“A malformed face-data request could turn existing administrative control into access across a critical Windows security boundary.”

CVE-2026-81354 is a critical elevation-of-privilege vulnerability in Windows Hello caused by a heap-based buffer overflow. An attacker with administrative control of the operating system, or control of a face-sensor adapter, could submit malformed face data to the Windows Hello Face secure sensor adapter and potentially gain Virtual Trust Level 1 (VTL1) privileges. No user interaction is required.

Critical - Same Day Deployment CVE-2026-69864 – Windows Hello Elevation of Privilege Vulnerability

“A successful attack could turn limited local access into powerful system privileges, putting sensitive Windows resources at risk.”

CVE-2026-69864 is a critical elevation-of-privilege vulnerability in Windows Hello caused by a use-after-free weakness (CWE-416). An authorized local attacker with low privileges could exploit a race condition to elevate privileges to Virtual Trust Level 1 (VTL1). Exploitation requires high attack complexity but does not require user interaction. The vulnerability is not publicly disclosed and is not currently reported as exploited.

Critical - Same Day Deployment CVE-2026-69784 – Windows Hello Elevation of Privilege Vulnerability

“A successful attack could turn limited local access into powerful VTL1 privileges, putting system confidentiality, integrity, and availability at risk.”

CVE-2026-69784 is a critical elevation-of-privilege vulnerability in Windows Hello caused by a use-after-free weakness. An authorized local attacker with low privileges could exploit the vulnerability and gain Virtual Trust Level 1 (VTL1) privileges. No user interaction is required. The vulnerability is not publicly disclosed and is not known to be exploited.

Critical - Same Day Deployment CVE-2026-66302 – Skype for Business Remote Code Execution Vulnerability

“A single crafted network request could turn an exposed Skype for Business server into a path for full remote code execution.”

CVE-2026-66302 is a critical remote code execution vulnerability in affected Microsoft Skype for Business Server versions. External control of a file name or path allows an unauthenticated attacker to send a specially crafted network request that writes an attacker-controlled file to an arbitrary location on the server. Successful exploitation could allow code execution on the target server without authentication or user interaction.

Critical - Same Day Deployment CVE-2026-72980 – Windows Hello Security Feature Bypass Vulnerability

“A local attacker with high privileges could bypass Windows Hello protections and expose confidential information.”

CVE-2026-72980 is a Windows Hello security feature bypass vulnerability caused by an uncontrolled path element (CWE-427). An authorized local attacker with high privileges could exploit the issue to bypass the Windows Hello security feature. Successful exploitation can result in a high confidentiality impact, although no integrity or availability impact is identified.

Critical - Same Day Deployment CVE-2026-69797 – Microsoft Office PowerPoint Remote Code Execution Vulnerability

“A malicious PowerPoint file could turn a routine document opening or preview into remote code execution, putting sensitive data and systems at risk.”

CVE-2026-69797 is a critical remote code execution vulnerability in Microsoft Office PowerPoint caused by a use-after-free weakness (CWE-416). An unauthorized attacker can send a specially crafted presentation that may trigger the vulnerability when a user opens the file or it is rendered in a preview pane. Successful exploitation could execute code in the user's context and result in significant confidentiality, integrity, and availability impact.

Critical - Same Day Deployment CVE-2026-69710 – Windows Hello Elevation of Privilege Vulnerability

“A successful race-condition attack could turn existing local access into powerful VTL1 privileges, putting the confidentiality, integrity, and availability of the system at risk.”

CVE-2026-69710 is a Critical elevation-of-privilege vulnerability in Windows Hello caused by improper synchronization of a shared resource during concurrent execution. An authorized local attacker who successfully wins a race condition could elevate privileges to Virtual Trust Level 1 (VTL1). Exploitation requires high privileges and high attack complexity but does not require user interaction. The vulnerability is not publicly disclosed and is not known to be exploited.

Critical - Same Day Deployment CVE-2026-80083 – Windows Hyper-V Remote Code Execution Vulnerability

"A malicious application inside a Hyper-V guest could cross the virtualization boundary and put the host system at risk."

CVE-2026-80083 is a critical remote code execution vulnerability in Windows Hyper-V caused by an untrusted pointer dereference. An authorized attacker with low privileges could run a specially crafted application within a Hyper-V guest and cause the Hyper-V host operating system to execute arbitrary code. No user interaction is required. The vulnerability is not publicly disclosed or known to be exploited, and exploitation is assessed as unlikely.

Critical - Same Day Deployment CVE-2026-72961 – Windows Hyper-V Elevation of Privilege Vulnerability

“A compromised Hyper-V administrator could turn crafted virtual TPM data into higher privileges, crossing an important security boundary.”

CVE-2026-72961 is a Critical Windows Hyper-V elevation-of-privilege vulnerability. An authorized attacker with administrative access to an affected Hyper-V host can supply specially crafted virtual TPM state data to a virtual machine. Successful exploitation can cross a security boundary and grant Virtual Trust Level 1 (VTL1) privileges. The vulnerability requires local access and high privileges but does not require user interaction.

Critical - Same Day Deployment CVE-2026-69829 – Windows Shell Remote Code Execution Vulnerability

“A network attacker could turn a Windows Shell memory flaw into remote code execution without needing privileges or user interaction.”

CVE-2026-69829 is a Critical heap-based buffer overflow vulnerability in Windows Shell. An unauthorized attacker can exploit the flaw over a network by calling arbitrary endpoints, potentially gaining remote code execution. Successful exploitation could severely affect the confidentiality, integrity, and availability of an affected Windows system.

Critical - Same Day Deployment CVE-2026-69603 – Windows Hyper-V Remote Code Execution Vulnerability

“A malicious hypercall can turn a memory flaw in Hyper-V into high-impact code execution across a security boundary.”

CVE-2026-69603 is a critical heap-based buffer overflow vulnerability in Windows Hyper-V. An authorized attacker running code inside a virtualized environment can issue a specially crafted hypercall containing a maliciously large or malformed payload size. This can trigger a buffer overflow in the hypervisor during memory operations and allow local code execution. The vulnerability requires low privileges and no user interaction.

Critical - Same Day Deployment CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability

“A single malicious network packet could turn an exposed NFS service into a path for remote code execution.”

CVE-2026-69595 is a critical use-after-free vulnerability (CWE-416) in the Windows Services for NFS ONCRPC XDR Driver. An unauthenticated remote attacker can send a specially crafted packet to an affected service and potentially execute code on the target system. Exploitation requires neither privileges nor user interaction.

Critical - Same Day Deployment CVE-2026-70585 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability

“A successful race-condition attack could turn limited local access into full code execution, putting the confidentiality, integrity, and availability of critical Windows servers at risk.”

CVE-2026-70585 is a critical use-after-free vulnerability in the Windows Services for NFS ONCRPC XDR Driver. An authorized attacker with low privileges could exploit the flaw locally to execute code. Successful exploitation requires winning a race condition, making the attack complexity high, but no user interaction is required.

Critical - Same Day Deployment CVE-2026-78445 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability

“A single specially crafted NFS request could give an unauthenticated attacker a path to remote code execution on a vulnerable server.”

CVE-2026-78445 is a critical use-after-free vulnerability in the Windows Services for NFS ONCRPC XDR Driver. An unauthorized remote attacker can exploit the flaw by sending a specially crafted, unauthenticated call to a Network File System (NFS) service, potentially achieving remote code execution. The vulnerability requires no privileges or user interaction and has low attack complexity.

Critical - Same Day Deployment CVE-2026-69769 – Windows HTTP Print Provider Remote Code Execution Vulnerability

“A network attacker could turn a memory corruption flaw in Windows printing into remote code execution, without needing privileges or user interaction.”

CVE-2026-69769 is a critical heap-based buffer overflow in the Windows HTTP Print Provider. Successful exploitation could allow an unauthorized, in-network attacker to execute code remotely by calling arbitrary endpoints. The vulnerability requires low attack complexity and can affect the confidentiality, integrity, and availability of a compromised system.

Critical - Same Day Deployment CVE-2026-69874 – Windows ALPC Elevation of Privilege Vulnerability

“A successful local attack could turn existing access into highly privileged control, putting sensitive Windows systems and data at risk.”

CVE-2026-69874 is a Critical elevation-of-privilege vulnerability in Windows ALPC caused by an untrusted pointer dereference. An authorized local attacker who successfully exploits the flaw could elevate privileges to Virtual Trust Level 1 (VTL1). Exploitation requires high privileges and no user interaction. The vulnerability is not publicly disclosed or known to be exploited, and exploitation is assessed as unlikely.

Critical - Same Day Deployment CVE-2026-69799 – Windows Hello Elevation of Privilege Vulnerability

“A successful race-condition attack could turn limited local access into powerful VTL1 privileges, putting system confidentiality, integrity, and availability at risk.”

CVE-2026-69799 is a critical elevation-of-privilege vulnerability in Windows Hello caused by improper synchronization when a shared resource is accessed concurrently. An authorized local attacker with low privileges could exploit a race condition to gain Virtual Trust Level 1 (VTL1) privileges. Successful exploitation can have a high impact on confidentiality, integrity, and availability.

Critical - Same Day Deployment CVE-2026-69767 – Microsoft Office PowerPoint Remote Code Execution Vulnerability

“A malicious PowerPoint file could turn a simple file open into remote code execution, putting sensitive information and system integrity at risk.”

CVE-2026-69767 is a critical use-after-free vulnerability in Microsoft Office PowerPoint that could allow an unauthorized attacker to execute code. Exploitation requires a user to open a specially crafted file. The attack has low complexity and requires no attacker privileges, but user interaction is required. The vulnerability can have a high impact on confidentiality, integrity, and availability.

Critical - Same Day Deployment CVE-2026-81950 – Microsoft Excel Remote Code Execution Vulnerability

“A malicious Office file can turn a routine document open into remote code execution, putting sensitive data and system integrity at risk.”

CVE-2026-81950 is a Critical remote code execution vulnerability in Microsoft Excel and affected Microsoft Office products. The vulnerability is caused by a double-free memory condition. An attacker must convince a user to open a malicious Office file, after which code execution may occur locally without the attacker requiring privileges. The Preview Pane is not an attack vector. The vulnerability is not publicly disclosed or known to be exploited.

Critical - Same Day Deployment CVE-2026-81953 – Microsoft Excel Remote Code Execution Vulnerability

“A malicious Office file can turn a routine document opening into code execution with high impact on data and systems.”

CVE-2026-81953 is a Critical remote code execution vulnerability in Microsoft Excel caused by a stack-based buffer overflow. An attacker can send a specially crafted Office file and convince a user to open it, potentially allowing unauthorized code execution. Successful exploitation can have a high impact on confidentiality, integrity, and availability.

Critical - Same Day Deployment CVE-2026-81959 – Microsoft Excel Remote Code Execution Vulnerability

“A malicious Excel file could turn one successful click into code execution with high impact to data and systems.”

CVE-2026-81959 is a Critical remote code execution vulnerability affecting Microsoft Excel and multiple Microsoft Office releases. A heap-based buffer overflow involving integer overflow or wraparound can allow an unauthorized attacker to execute code locally. Exploitation requires a user to open a malicious Office file, but the attacker does not require prior privileges. The Preview Pane is not an attack vector.

Critical - Same Day Deployment CVE-2026-81949 – Microsoft Excel Remote Code Execution Vulnerability

“A malicious Excel file could turn a routine document open into code execution with high impact to data and systems.”

CVE-2026-81949 is a critical remote code execution vulnerability caused by an integer overflow or wraparound in Microsoft Office Excel. An unauthorized attacker can send a specially crafted Office file and convince a user to open it, potentially resulting in code execution. Exploitation requires no privileges but does require user interaction. The Preview Pane is not an attack vector.

Critical - Same Day Deployment CVE-2026-81948 – Microsoft Excel Remote Code Execution Vulnerability

“A malicious Office file could turn a routine document opening into remote code execution, putting sensitive data and system integrity at risk.”

CVE-2026-81948 is a critical Microsoft Excel remote code execution vulnerability caused by a heap-based buffer overflow. An unauthorized attacker can send a specially crafted Office file and convince a user to open it, potentially allowing attacker-controlled code to execute locally. No privileges are required, but successful exploitation requires user interaction.

Critical - Same Day Deployment CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability

“A single malicious network packet could give an unauthenticated attacker the ability to run code on a vulnerable system.”

CVE-2026-73010 is a critical use-after-free vulnerability in Microsoft Windows Failover Cluster. An unauthorized remote attacker can send a specially crafted packet to an affected service and potentially execute code on the target system. Exploitation requires no authentication, privileges, or user interaction.

Critical - Same Day Deployment CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability

“A single crafted network packet could turn a race condition into remote code execution, with no authentication or user action required.”

CVE-2026-78444 is a critical remote code execution vulnerability in Microsoft Windows Failover Cluster. The issue is caused by an untrusted pointer dereference. An unauthenticated attacker could send a specially crafted packet to an affected service over the network and, after successfully winning a race condition, execute code on the target system. The vulnerability is not publicly disclosed and is not known to be exploited.

Critical - Same Day Deployment CVE-2026-69725 – Windows Hello Elevation of Privilege Vulnerability

“A successful attack could turn limited local access into highly privileged control, putting sensitive Windows protections at risk.”

CVE-2026-69725 is a Windows Hello elevation-of-privilege vulnerability caused by a double-free weakness. An authorized local attacker who successfully exploits the vulnerability could elevate privileges to Virtual Trust Level 1 (VTL1). Exploitation requires low privileges and no user interaction. The source information contains conflicting attack-complexity statements: the CVSS metrics specify Low, while the FAQ states High and says successful exploitation requires winning a race condition.

Critical - Same Day Deployment CVE-2026-78510 – Microsoft Office Outlook Remote Code Execution Vulnerability

“A malicious RTF file can turn Outlook content into a path for remote code execution, with no privileges or user interaction required.”

CVE-2026-78510 is a critical heap-based buffer overflow vulnerability in Microsoft Office Outlook that can allow an unauthenticated attacker to execute arbitrary code over a network. An attacker can craft a malicious RTF file that triggers the vulnerability when opened or rendered in the Preview Pane. Successful exploitation can compromise confidentiality, integrity, and availability with code executing in the user's context.

Critical - Same Day Deployment CVE-2026-78520 – Microsoft Office Outlook Information Disclosure Vulnerability

“A malicious Outlook item can expose sensitive memory simply through the Preview Pane, turning routine email handling into a potential data exposure risk.”

CVE-2026-78520 is a Microsoft Office Outlook vulnerability caused by an out-of-bounds read. An unauthorized remote attacker can target the vulnerability over a network, and exploitation requires user interaction. Microsoft confirms that the Outlook Preview Pane is an attack vector. Successful exploitation could allow an attacker to read small portions of heap memory, potentially exposing sensitive information stored in memory.

Critical - Same Day Deployment CVE-2026-78525 – Microsoft Office Outlook Remote Code Execution Vulnerability

“A malicious email can turn an Outlook message or preview into a path for remote code execution.”

CVE-2026-78525 is a Critical remote code execution vulnerability caused by a use-after-free weakness (CWE-416) in Microsoft Office Outlook. An unauthorized attacker can send a specially crafted email, and exploitation may occur when the victim opens the email using an affected Outlook version or when Outlook displays its preview. Successful exploitation could allow the attacker to execute remote code on the victim’s machine.

Critical - Same Day Deployment CVE-2026-77493 – Microsoft Office Outlook Remote Code Execution Vulnerability

“A malicious email can turn the Outlook Reading Pane into a path for remote code execution without a click.”

CVE-2026-77493 is a critical remote code execution vulnerability caused by a double-free memory handling issue in Microsoft Office Outlook. An attacker can send a specially crafted email to a target, and simply viewing that message in the Outlook Reading Pane can trigger the vulnerability. Successful exploitation could allow attacker-controlled code to execute on the recipient's system. The affected Microsoft product is identified as Microsoft Office Outlook; the affected-software table specifically lists supported Windows client and Windows Server versions.

Critical - Same Day Deployment CVE-2026-78519 – Microsoft Office Outlook Remote Code Execution Vulnerability

“A malicious email can turn Outlook into a path for remote code execution, putting affected systems and business data at risk.”

CVE-2026-78519 is a critical remote code execution vulnerability in Microsoft Office Outlook caused by the use of an uninitialized resource. An unauthorized attacker can send a specially crafted email to a victim, and exploitation may occur when the victim opens the email or when an affected Outlook application displays its preview. Successful exploitation could allow the attacker to execute remote code on the victim’s machine.

Critical - Same Day Deployment CVE-2026-77898 – Microsoft Office PowerPoint Remote Code Execution Vulnerability

“A malicious PowerPoint interaction could turn a memory error into remote code execution, putting sensitive data and systems at risk.”

CVE-2026-77898 is a critical heap-based buffer overflow vulnerability in Microsoft Office PowerPoint that can allow an unauthorized attacker to execute code over a network. Exploitation requires no privileges but does require user interaction and has high attack complexity. Successful exploitation could have a high impact on confidentiality, integrity, and availability.

Critical - Same Day Deployment CVE-2026-69632 – Microsoft Office PowerPoint Remote Code Execution Vulnerability

"A malicious PowerPoint file could turn a routine document opening or preview into remote code execution."

A use-after-free vulnerability in Microsoft Office PowerPoint could allow an unauthorized attacker to execute code by sending a specially crafted presentation. Exploitation can occur when a user opens the malicious file or it is rendered in a preview pane. The vulnerability requires no attacker privileges but does require user interaction. It is not publicly disclosed and is not reported as exploited.

Critical - Same Day Deployment CVE-2026-73017 – Graphics Kernel Remote Code Execution Vulnerability

“A successful attack could turn a graphics kernel memory flaw into code execution with serious consequences for confidentiality, integrity, and availability.”

CVE-2026-73017 is a Critical heap-based buffer overflow vulnerability in the Windows Graphics Kernel. An authorized local attacker with high privileges could manipulate system components to trigger the flaw and execute code. Exploitation requires high attack complexity but no user interaction.

Critical - Same Day Deployment CVE-2026-78509 – Microsoft Office Outlook Remote Code Execution Vulnerability

“A specially crafted email could turn simply viewing a message into remote code execution, with no clicks or user action required.”

CVE-2026-78509 is a Critical heap-based buffer overflow vulnerability in Microsoft Office Outlook that could allow an unauthorized remote attacker to execute code on a target system. An attacker can send a specially crafted email, and simply viewing it in the Outlook Reading Pane can trigger the vulnerability without opening the message or clicking anything. The CVSS base score is 9.8, and exploitation requires neither authentication nor user interaction.

Critical - Same Day Deployment CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

“A single malicious network packet could give an unauthenticated attacker the ability to run code on a vulnerable Windows system.”

CVE-2026-73009 is a critical use-after-free vulnerability in Windows Secure Socket Tunneling Protocol (SSTP). An unauthorized remote attacker can send a specially crafted packet to an affected service and potentially execute code on the target system. The attack has low complexity and requires no privileges or user interaction. The vulnerability is not publicly disclosed and is not known to be exploited.

Critical - Same Day Deployment CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

"A specially crafted network packet could turn a memory flaw into remote code execution, with no authentication or user action required."

A use-after-free vulnerability in the Windows Reliable Multicast Transport Driver (RMCAST) could allow an unauthorized remote attacker to execute code on an affected Windows system. Exploitation requires sending a specially crafted packet to an affected service and successfully winning a race condition. The vulnerability is not publicly disclosed and is not known to be exploited.

Critical - Same Day Deployment CVE-2026-83939 – Windows Secure Kernel Mode Elevation of Privilege Vulnerability

"A successful attack can cross a critical Windows security boundary and give an attacker powerful VTL1 privileges."

CVE-2026-83939 is a Critical elevation-of-privilege vulnerability in Windows Secure Kernel Mode caused by an untrusted pointer dereference. An authorized attacker who already has kernel-level access can submit a specially crafted Code Integrity policy to an affected system. Successful exploitation can allow code execution in Virtual Trust Level 1 (VTL1), with high potential impact to confidentiality, integrity, and availability.

Critical - Same Day Deployment CVE-2026-58599 – HEVC Video Extensions Remote Code Execution Vulnerability

“A memory corruption flaw in HEVC video processing can turn user interaction into an opportunity for an attacker to execute code.”

CVE-2026-58599 is a critical remote code execution vulnerability caused by a heap-based buffer overflow in the Microsoft Windows Codecs Library. An unauthorized attacker can execute code locally by exploiting the flaw. Exploitation requires user interaction, but no privileges are required. Successful exploitation can have a high impact on confidentiality, integrity, and availability.

Critical - Same Day Deployment CVE-2026-81352 – Web Media Extensions Remote Code Execution Vulnerability

"A malicious media payload could turn routine content handling into remote code execution, putting sensitive data and system integrity at risk."

CVE-2026-81352 is a critical remote code execution vulnerability caused by a heap-based buffer overflow in the Microsoft Windows Codecs Library and affecting Web Media Extensions. An unauthorized attacker can target the vulnerability over a network. Exploitation requires user interaction but does not require attacker privileges. Successful exploitation could result in high impact to confidentiality, integrity, and availability.

Critical - Same Day Deployment CVE-2026-69601 – Microsoft Windows Media Foundation Remote Code Execution Vulnerability

“A malicious file can turn one user action into remote code execution, putting the confidentiality, integrity, and availability of affected Windows systems at risk.”

CVE-2026-69601 is a critical remote code execution vulnerability caused by a heap-based buffer overflow in Microsoft Windows Media Foundation. An unauthorized attacker can target the vulnerability over a network, but successful exploitation requires a user to open a specially crafted file. No privileges are required. Successful exploitation could allow attacker-controlled code to execute on an affected Windows system.

Critical - Same Day Deployment CVE-2026-70203 – Windows Media Player Remote Code Execution Vulnerability

“A malicious media file can turn a routine file-open action into remote code execution, putting the confidentiality, integrity, and availability of the affected system at risk.”

CVE-2026-70203 is a critical heap-based buffer overflow vulnerability in Windows Media Player. An unauthorized attacker can attempt exploitation by convincing a user to open a specially crafted media file. Processing that file can cause memory corruption and potentially allow attacker-controlled code to execute on the affected system. The vulnerability is not publicly disclosed and is not reported as exploited.

Critical - Same Day Deployment CVE-2026-72960 – Windows Media Player Remote Code Execution Vulnerability

“A specially crafted file can turn a single user action into remote code execution, putting system confidentiality, integrity, and availability at risk.”

CVE-2026-72960 is a Critical remote code execution vulnerability caused by a heap-based buffer overflow in Windows Media Player. An unauthorized attacker can exploit the issue over a network by convincing a user to open a specially crafted file. Successful exploitation can allow attacker-controlled code to execute on the affected system. No privileges are required, but user interaction is required.

Critical - Same Day Deployment CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability

“A single malicious network packet could turn a memory flaw into remote code execution, with no authentication or user action required.”

CVE-2026-69579 is a critical use-after-free vulnerability in Windows Message Queuing. An unauthorized, unauthenticated attacker can send a specially crafted packet to an affected service over the network and potentially execute code on the target system. The vulnerability requires low attack complexity, no privileges, and no user interaction. It is not publicly disclosed and is not known to be exploited.

Critical - Same Day Deployment CVE-2026-67636 – Microsoft SQL Server Remote Code Execution Vulnerability

“A specially crafted database request could turn authorized SQL Server access into remote code execution, putting sensitive data and critical services at risk.”

CVE-2026-67636 is a critical remote code execution vulnerability in Microsoft SQL Server caused by an out-of-bounds read. An authenticated attacker with low privileges could connect to an affected SQL Server over the network and submit a specially crafted query or request that triggers a memory corruption condition. Successful exploitation could allow code execution on the server and result in high confidentiality, integrity, and availability impact. Exploitation requires specific conditions because attack complexity is high, and no user interaction is required.

Critical - Same Day Deployment CVE-2026-70351 – Microsoft WebP Image Extension Remote Code Execution Vulnerability

“A malicious WebP file could turn a simple file-open action into remote code execution, putting systems and data at serious risk.”

An integer overflow or wraparound in the Microsoft WebP Image Extension can lead to a heap-based buffer overflow and remote code execution. An unauthorized attacker can target the vulnerability over a network, but exploitation requires a user to open a specially crafted file. No privileges are required. Successful exploitation can have a high impact on confidentiality, integrity, and availability.

Critical - Same Day Deployment CVE-2026-70586 – Windows Paint Remote Code Execution Vulnerability

“A malicious file opened in Paint could turn a simple user action into remote code execution with high impact to confidentiality, integrity, and availability.”

CVE-2026-70586 is a critical remote code execution vulnerability caused by a heap-based buffer overflow in Windows Paint. An unauthorized attacker can trigger the vulnerability by convincing a user to open a specially crafted file. The attack requires no privileges but does require user interaction. Successful exploitation can execute code and has a high potential impact on confidentiality, integrity, and availability.

Critical - Same Day Deployment CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

“A specially crafted network packet could turn a memory flaw into remote code execution, with no authentication or user action required.”

A critical use-after-free vulnerability in the Windows Reliable Multicast Transport Driver (RMCAST) could allow an unauthenticated attacker to execute code remotely. Exploitation requires winning a race condition, which increases attack complexity, but a successful attack could have a high impact on confidentiality, integrity, and availability.

Critical - Same Day Deployment CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

“A specially crafted network packet could turn a memory flaw into remote code execution, with no credentials or user action required.”

CVE-2026-78449 is a critical use-after-free vulnerability in the Windows Reliable Multicast Transport Driver (RMCAST). An unauthenticated attacker could send a specially crafted packet to an affected service over the network and potentially execute code on the target system. Exploitation is considered less likely because attack complexity is high and successful exploitation depends on multiple environmental and system factors.

Critical - Same Day Deployment CVE-2026-65669 – Microsoft SQL Server Elevation of Privilege Vulnerability

“A crafted SQL Copilot instruction could turn read-only access into the ability to reach or change sensitive database data.”

CVE-2026-65669 is an elevation-of-privilege vulnerability involving improper neutralization of special elements in output used by a downstream component. An unauthorized attacker could convince a user to submit specially crafted instructions to SQL Copilot in SQL Server Management Studio. Successful exploitation could bypass intended read-only restrictions and access or modify database data with the connected user's permissions.

Critical - Same Day Deployment CVE-2026-67631 – Microsoft SQL Server Remote Code Execution Vulnerability

“A single malicious database request from an authenticated attacker could corrupt SQL Server memory and turn database access into remote code execution.”

CVE-2026-67631 is a critical heap-based buffer overflow vulnerability in Microsoft SQL Server. An authenticated attacker with low privileges can connect to an affected SQL Server over the network and submit a specially crafted query or request that triggers memory corruption, potentially allowing code execution on the server. No user interaction is required.

Critical - Same Day Deployment CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability

“A single malicious network packet could turn this Netlogon flaw into remote code execution, without authentication or user interaction.”

CVE-2026-72982 is a critical stack-based buffer overflow vulnerability in Windows Netlogon. An unauthenticated attacker can send a specially crafted packet to an affected service over the network and potentially execute code on the target system. The vulnerability requires no privileges or user interaction and can result in high impact to confidentiality, integrity, and availability.

Critical - Same Day Deployment CVE-2026-77505 – Windows DNS Server Remote Code Execution Vulnerability

“A malicious DNS query could turn a timing flaw into SYSTEM-level code execution on a vulnerable DNS server.”

CVE-2026-77505 is a critical use-after-free vulnerability in Windows DNS Server. An unauthenticated attacker with network access could send specially timed DNS queries to a DNS server configured with a server-level DNS plug-in and attempt to trigger a race condition. Successful exploitation could result in remote code execution with SYSTEM privileges. The vulnerability is not publicly disclosed and is not currently reported as exploited.

Critical - Same Day Deployment CVE-2026-69854 – Spring Cloud Azure Elevation of Privilege Vulnerability

"A stolen path to authentication can turn an untrusted tenant into a doorway to protected business data and operations."

Spring Cloud Azure contains an improper authentication vulnerability that could allow an unauthenticated attacker to elevate privileges over a network. In an affected multi-tenant application, an attacker could use an identity token issued by a tenant they control to obtain an authenticated session. Successful exploitation could expose protected data and allow actions normally restricted to authenticated users. The affected Microsoft product is Spring Cloud Azure.

Critical - Same Day Deployment CVE-2026-67643 – Microsoft SQL Server Remote Code Execution Vulnerability

“A specially crafted SQL request can turn authenticated database access into remote code execution, putting sensitive data and critical server operations at risk.”

CVE-2026-67643 is a Critical heap-based buffer overflow vulnerability affecting Microsoft SQL Server 2022 and SQL Server 2025. An authenticated attacker with low privileges can connect to an affected SQL Server and submit a specially crafted query or request that triggers memory corruption and allows code execution on the server. The vulnerability can be attacked over the network with low complexity and requires no user interaction.

Critical - Same Day Deployment CVE-2026-67378 – Microsoft SQL Server Remote Code Execution Vulnerability

“A specially crafted request could turn authorized SQL Server access into remote code execution, putting sensitive data and critical systems at risk.”

CVE-2026-67378 is a critical remote code execution vulnerability caused by an untrusted pointer dereference in Microsoft SQL Server. An authenticated attacker with low privileges could connect to an affected SQL Server and submit a specially crafted query or request that triggers memory corruption and allows code execution. Successful exploitation requires specific conditions because attack complexity is high, but no user interaction is required.

Critical - Same Day Deployment CVE-2026-69712 – Windows Key Distribution Center Remote Code Execution Vulnerability

“A low-privileged attacker could turn a specially crafted network request into code execution on a vulnerable Windows Server.”

CVE-2026-69712 is a critical use-after-free vulnerability in the Windows Key Distribution Center (KDC). An authenticated attacker with low-level access to an affected server could send a specially crafted request over the network and execute code on that server. Successful exploitation could have a high impact on confidentiality, integrity, and availability, and no user interaction is required.

Critical - Same Day Deployment CVE-2026-69518 – Windows Remote Desktop Remote Code Execution Vulnerability

“A malicious participant in a Remote Desktop sharing session could turn crafted clipboard data into code execution on the host.”

CVE-2026-69518 is a critical heap-based buffer overflow vulnerability in Windows Remote Desktop. An unauthorized attacker could join a Remote Desktop sharing session and send specially crafted clipboard data to the sharing host. Successful exploitation could execute code on the host system, potentially affecting the confidentiality, integrity, and availability of the system. The attack requires no privileges, but user interaction is required to initiate or participate in the sharing session.

Critical - Same Day Deployment CVE-2026-69501 – Windows Secure Kernel Mode Elevation of Privilege Vulnerability

“A local attacker who triggers this flaw under the right memory conditions could turn limited access into full SYSTEM control.”

CVE-2026-69501 is an elevation-of-privilege vulnerability caused by an untrusted pointer dereference in Windows Secure Kernel Mode. An authorized local attacker with low privileges could exploit the issue to gain SYSTEM privileges. Exploitation is considered less likely because successful exploitation requires high attack complexity and sustained low-memory conditions on the target.

Critical - Same Day Deployment CVE-2026-69846 – Windows Secure Kernel Mode Elevation of Privilege Vulnerability

“An attacker who already controls the Windows kernel could use this flaw to break into the more protected VTL1 environment, putting sensitive system operations at risk.”

CVE-2026-69846 is a critical elevation-of-privilege vulnerability in Windows Secure Kernel Mode caused by an integer overflow or wraparound. An authorized attacker who already has kernel-level access could submit a specially crafted Code Integrity policy and potentially execute code with Virtual Trust Level 1 (VTL1) privileges. The vulnerability is not publicly disclosed and is not known to be exploited.

Critical - Same Day Deployment CVE-2026-69906 – Windows Secure Kernel Mode Elevation of Privilege Vulnerability

“A successful attack can turn existing privileged access into kernel-level code execution, putting the confidentiality, integrity, and availability of the system at risk.”

CVE-2026-69906 is a critical elevation-of-privilege vulnerability caused by a heap-based buffer overflow in Windows Secure Kernel Mode. An authorized local attacker who successfully exploits the flaw could execute code in the Windows kernel. The vulnerability requires high privileges but does not require user interaction.

Critical - Same Day Deployment CVE-2026-73013 – Windows Imaging Component Remote Code Execution Vulnerability

“A malicious file can turn a simple user action into remote code execution, putting sensitive data and system integrity at risk.”

A heap-based buffer overflow in the Windows Imaging Component could allow an unauthorized attacker to execute code on an affected Windows system. Exploitation occurs over a network but requires a user to open a specially crafted file. No privil...

Extracted Entities

Attack Types (1)

CVEs (81)