6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-69380 — Microsoft: Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69380

Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDMicrosoftTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-69371 — Heap: Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69371

Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-69365 — Out: Out-of-bounds read in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69365

Out-of-bounds read in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 125TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-69360 — Heap: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69360

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
CRIT

CVE-2026-69356 — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69356

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. CVSSv3.1 9.3 (CRITICAL)

CWECWE 79TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-69355 — External: control of file name or path in Microsoft Exchange Server allows an authorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69355

External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 73TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-69346 — Heap: Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69346

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
728 × 90 / responsive · programmatic ad slot
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-69334 — Heap: Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69334

Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 125CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-69332 — Out: Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69332

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 125TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-69325 — Heap: Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69325

Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-69322 — Double: free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69322

Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 415VNDDoubleTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-69301 — Stack: Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69301

Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 121VNDStackTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-69291 — Heap: Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69291

Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-69285 — Heap: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69285

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-69282 — Microsoft: Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69282

Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 284VNDMicrosoftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
CRIT

CVE-2026-69276 — Integer: underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69276

Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122CWECWE 191TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-69273 — Microsoft: Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69273

Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 284VNDMicrosoftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-69271 — Heap: Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69271

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-69268 — Microsoft: Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69268

Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 284VNDMicrosoftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-69266 — Integer: overflow or wraparound in Windows DHCP Server allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69266

Integer overflow or wraparound in Windows DHCP Server allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 190TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-68894 — Heap: Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68894

Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-68880 — Heap: Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68880

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 122CWECWE 197VNDHeapTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-68878 — Stack: Stack-based buffer overflow in Windows Fast FAT Driver allows an authorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68878

Stack-based buffer overflow in Windows Fast FAT Driver allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 121VNDStackTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-68876 — Heap: Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68876

Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
6d ago
2026-09-08 18:18Z
CRIT

CVE-2026-68839 — Heap: Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68839

Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 20CWECWE 122VNDHeapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score