ThreatCluster

Multiple CVEs Disclosed for Microsoft Products

First seen 8 Sep 2026, 21:44 UTC Api.Msrc.Microsoftwww.cve.org 57

Article Content

Browse articles
ThreatCluster

On September 8, 2026, Microsoft published advisories for three critical vulnerabilities affecting its products. CVE-2026-54990 is a heap-based buffer overflow in the Remote Desktop Client, allowing unauthorized code execution via a malicious RDP server. CVE-2026-42914 is an out-of-bounds read in Windows Kerberos, enabling authorized attackers to cause denial of service under specific conditions. CVE-2026-44814 involves an out-of-bounds read in the Windows DWM Core Library, which could lead to local information disclosure. The vulnerabilities were released between June and July 2026, with the latest updates provided on September 8, 2026. Successful exploitation of these vulnerabilities requires user interaction or specific configurations. Microsoft has acknowledged these vulnerabilities and provided guidance for mitigation.

Key Points: • CVE-2026-54990 allows remote code execution via malicious RDP servers. • CVE-2026-42914 can cause denial of service under specific conditions. • CVE-2026-44814 may lead to local information disclosure.

Ask AI about this cluster

Timeline

2026-06-09
CVE-2026-42914 published
An out-of-bounds read vulnerability in Windows Kerberos disclosed, allowing denial of service.
Api.Msrc.Microsoft
2026-06-09
CVE-2026-44814 published
An out-of-bounds read vulnerability in Windows DWM Core Library disclosed, enabling local information disclosure.
Api.Msrc.Microsoft
2026-07-14
CVE-2026-54990 published
Heap-based buffer overflow in Remote Desktop Client disclosed, allowing unauthorized code execution.
Api.Msrc.Microsoft
2026-09-08
Advisories updated
Microsoft updated the advisories for the vulnerabilities, providing additional information and guidance.
Api.Msrc.Microsoft