5d ago
2026-09-08 18:21Z
HIGH

CVE-2026-85880 — Microsoft Windows_10_1607: Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85880in the wild

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. CVSSv3.1 7.8 (HIGH)

CWECWE 122CWECWE 908VNDMicrosoftVNDHeapTYPVulnerabilitySTAitw exploited
7.8
CVSS v3.1
89
Edit Score
5d ago
2026-09-08 18:21Z
HIGH

CVE-2026-85877 — Heap: Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85877

Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:21Z
HIGH

CVE-2026-83998 — Heap: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83998

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:21Z
HIGH

CVE-2026-83997 — Use: after free in Windows Message Queuing allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83997

Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-08 18:21Z
HIGH

CVE-2026-83996 — Heap: Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83996

Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:21Z
HIGH

CVE-2026-83992 — Heap: Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83992

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:21Z
HIGH

CVE-2026-83948 — Improper neutralization of special elements used in a command ('command injection') in Microsoft Azure

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83948

Improper neutralization of special elements used in a command ('command injection') in Microsoft Azure CLI allows an authorized attacker to execute code over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 77TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
728 × 90 / responsive · programmatic ad slot
5d ago
2026-09-08 18:21Z
CRIT

CVE-2026-83941 — Entra: Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83941

Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network. CVSSv3.1 9.9 (CRITICAL)

CWECWE 862VNDEntraTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
5d ago
2026-09-08 18:21Z
HIGH

CVE-2026-83939 — Untrusted: pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83939

Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. CVSSv3.1 8.2 (HIGH)

CWECWE 822VNDUntrustedTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
5d ago
2026-09-08 18:21Z
HIGH

CVE-2026-81963 — Microsoft Windows_11_23h2: Improper link resolution before file access ('link following') in Windows Update Stack allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81963in the wild

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. CVSSv3.1 7.8 (HIGH)

CWECWE 284CWECWE 59VNDMicrosoftTYPVulnerabilitySTAitw exploited
7.8
CVSS v3.1
89
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-81955 — Heap: Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81955

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-81952 — Heap: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81952

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-81822 — The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81822

The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users’ app-native passwords through computational brute-forcing of weak hashes, potentially allowing elevation to a PIMBoards administrator user. CVSSv3.1 8.4 (HIGH)

CWECWE 327TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-81821 — The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81821

The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information. CVSSv3.1 8.4 (HIGH)

CWECWE 321TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-81385 — Deserialization: of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81385

Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-81379 — Not: failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81379

Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. CVSSv3.1 8.2 (HIGH)

CWECWE 636VNDNotTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-81378 — Interpretation: conflict in Visual Studio Code allows an unauthorized attacker to bypass a security

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81378

Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. CVSSv3.1 8.2 (HIGH)

CWECWE 436VNDInterpretationTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
5d ago
2026-09-08 18:20Z
CRIT

CVE-2026-81376 — Incomplete: comparison with missing factors in Visual Studio Code allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81376

Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. CVSSv3.1 9.6 (CRITICAL)

CWECWE 693CWECWE 1023VNDIncompleteTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-81357 — Server: Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81357

Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. CVSSv3.1 8.2 (HIGH)

CWECWE 918TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-81356 — Inconsistent: interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81356

Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. CVSSv3.1 8.2 (HIGH)

CWECWE 444VNDInconsistentTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-81354 — Heap: Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81354

Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally. CVSSv3.1 8.2 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-81352 — Heap: Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81352

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-80097 — Microsoft: Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80097

Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally. CVSSv3.1 8.6 (HIGH)

CWECWE 287VNDMicrosoftTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-80096 — Out: Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80096

Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 125TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-80085 — Heap: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80085

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score