6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-67638 — Heap: Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67638

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-67636 — Out: Out-of-bounds read in SQL Server allows an authorized attacker to execute code over a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67636

Out-of-bounds read in SQL Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.5 (HIGH)

CWECWE 125TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-67631 — Heap: Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67631

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-67388 — Heap: Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67388

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-67385 — Use: after free in SQL Server allows an authorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67385

Use after free in SQL Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-67384 — Integer: overflow or wraparound in SQL Server allows an authorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67384

Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122CWECWE 190TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-67381 — Heap: Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67381

Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-67380 — Heap: Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67380

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-67379 — Stack: Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67379

Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.5 (HIGH)

CWECWE 121VNDStackTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-67378 — Untrusted: pointer dereference in SQL Server allows an authorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67378

Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.5 (HIGH)

CWECWE 822VNDUntrustedTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-67373 — Heap: Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67373

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-67370 — Improper neutralization of special elements used in an sql command ('sql injection') in SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67370

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-67368 — Improper link resolution before file access ('link following') in SQL Server allows an authorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67368

Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 59TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-66820 — Improper neutralization of special elements used in an sql command ('sql injection') in SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66820

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-66819 — Improper neutralization of special elements used in an sql command ('sql injection') in SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66819

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-66818 — SQL: Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66818

Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-66814 — Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66814

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 1220TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-65772 — Deserialization: of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65772

Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:18Z
CRIT

CVE-2026-65669 — Improper neutralization of special elements in output used by a downstream component ('injection') in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65669

Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 9.6 (CRITICAL)

CWECWE 74TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
6d ago
2026-09-08 18:18Z
HIGH

CVE-2026-62895 — Permissive: cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62895

Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 89CWECWE 942CWECWE 1390VNDPermissiveTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:17Z
HIGH

CVE-2026-62744 — Heap: Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62744

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:17Z
HIGH

CVE-2026-62706 — Out: Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62706

Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 125CWECWE 121TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
6d ago
2026-09-08 18:17Z
HIGH

CVE-2026-55007 — Double: free in Microsoft Exchange Server allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55007

Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 415VNDDoubleTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
6d ago
2026-09-08 18:17Z
HIGH

CVE-2026-47297 — Deserialization: of untrusted data in SQL Server allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47297

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
6d ago
2026-09-08 17:30Z
HIGH

Token Analysis and Tracking System (TATS)

SpecterOps·specterops.io

SpecterOps released TATS (Token Analysis and Tracking System), an open-source tool for collecting, decoding, analyzing, and visualizing OAuth token exchanges across Microsoft Entra, AWS, Okta, and AD environments. The tool supports live session tracking via Chrome DevTools Protocol, mitmproxy, and Burp imports, with a web GUI for token inventory, exchange visualization, and enrichment via entrascopes. The author demonstrated two practical findings: audience claim mismatches allowing tokens to be presented to unintended resources, and a Conditional Access Policy gap where pre-MFA tokens can be brokered to nested applications lacking explicit MFA requirements.

TACTA0005TACTA0006SRFIdentitySRFWebSRFCloudSWTatsVNDMicrosoftTYPTool
78
Edit Score