Skip to content
ThreatCluster

Multiple CVEs Disclosed for Microsoft Products with Privilege Escalation Risks

First seen 15 Sep 2026, 21:04 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 16, 2026 at 20:55 UTC
  • Multiple CVEs disclosed affecting Microsoft products, with risks of privilege escalation.
  • Attack vectors include malicious Office files and specific protocol settings.
  • Microsoft advises immediate application of security updates to mitigate vulnerabilities.

On September 15, 2026, Microsoft disclosed several vulnerabilities affecting its products, including CVE-2026-55121, CVE-2026-62753, CVE-2026-62721, CVE-2026-49805, CVE-2026-61923, CVE-2026-50683, and CVE-2026-50688. These vulnerabilities include out-of-bounds reads, heap-based buffer overflows, and improper access controls, allowing attackers to elevate privileges to SYSTEM level. The vulnerabilities affect various Microsoft products, including Windows and Microsoft Office. Attack vectors include malicious Office files and specific protocol settings. The vulnerabilities have varying levels of attack complexity, with some requiring user interaction. Microsoft recommends applying security updates as soon as possible to mitigate risks. The CVEs have been assigned CVSS scores indicating potential impacts on confidentiality, integrity, and availability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-08-11
CVE-2026-62721 published
Insufficient access control in User-Mode Power Service allows privilege elevation.
Api.Msrc.Microsoft
2026-09-14
CVE-2026-85921 published
Double free vulnerability in Windows Secure Kernel Mode allows privilege elevation.
Api.Msrc.Microsoft
2026-09-15
Multiple CVEs disclosed
Microsoft disclosed several vulnerabilities including CVE-2026-55121, CVE-2026-62753, and others.
Api.Msrc.Microsoft

More articles in this cluster (16)

Following this threat?

Track CVE-2026-62721 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed