ThreatCluster

Multiple CVEs Disclosed on September 8, 2026, Affecting Microsoft Products

First seen 8 Sep 2026, 19:20 UTC Api.Msrc.Microsoftcwe.mitre.orgwww.cve.org 74

Article Content

Browse articles
ThreatCluster

On September 8, 2026, multiple CVEs were disclosed affecting various Microsoft products, including SharePoint and Office. Key vulnerabilities include improper access controls, buffer overflows, and command injections, which could allow unauthorized code execution and information disclosure. CVE-2026-85880, noted for active exploitation, was added to CISA's KEV list on the same day. Other vulnerabilities, such as CVE-2026-69428 and CVE-2026-69621, also pose significant risks due to their potential for exploitation. Organizations using affected versions of Microsoft products are urged to apply patches immediately to mitigate risks. The vulnerabilities impact a range of systems, including SharePoint Server and Microsoft Office, and could lead to severe consequences if exploited.

Key Points: • Multiple CVEs disclosed on September 8, 2026, affecting Microsoft products. • CVE-2026-85880 is actively exploited and added to CISA's KEV list. • Organizations are urged to apply patches immediately to mitigate risks.

Ask AI about this cluster

Timeline

2026-09-08
CVE-2026-85880 added to CISA KEV list
CISA confirmed active exploitation of CVE-2026-85880, prompting immediate action.
Api.Msrc.Microsoft
2026-09-08
Multiple CVEs published
Microsoft disclosed several vulnerabilities, including CVE-2026-69428 and CVE-2026-69621, affecting various products.
Api.Msrc.Microsoft
2026-09-08
Patches recommended
Organizations using affected Microsoft products are advised to apply patches immediately to prevent exploitation.
Api.Msrc.Microsoft
2026-09-08
CVE-2026-83999 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-69758 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-81355 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-69564 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-69377 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-72939 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-69395 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE