| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-73028 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-73026 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-73025 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-73024 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-73023 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-73022 | Hig | 0.46 | 7.0 | 0.00 | Sep 8, 2026 | Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-73021 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-73020 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-73019 | Med | 0.28 | 4.3 | 0.01 | Sep 8, 2026 | Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-73018 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-73017 | Hig | 0.49 | 7.5 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally. | ||
| CVE-2026-73016 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-73015 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-73014 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-73013 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-73012 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-73011 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-73010 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-73009 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-73008 | Med | 0.36 | 5.5 | 0.00 | Sep 8, 2026 | Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally. | ||
| CVE-2026-73007 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-73006 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-73005 | Hig | 0.46 | 7.0 | 0.00 | Sep 8, 2026 | Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-73004 | Med | 0.36 | 5.5 | 0.00 | Sep 8, 2026 | Missing authentication for critical function in Windows Autopilot allows an authorized attacker to perform tampering locally. | ||
| CVE-2026-73003 | Hig | 0.46 | 7.0 | 0.00 | Sep 8, 2026 | Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-73002 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-73001 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-73000 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-72999 | Med | 0.44 | 6.8 | 0.00 | Sep 8, 2026 | Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack. | ||
| CVE-2026-72997 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-72996 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-72995 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-72994 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-72993 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-72992 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-72991 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-72990 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-72989 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2026 | Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-72988 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-72987 | Hig | 0.53 | 8.1 | 0.01 | Sep 8, 2026 | Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-72986 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-72985 | Med | 0.44 | 6.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack. | ||
| CVE-2026-72983 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-72982 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-72981 | Hig | 0.53 | 8.1 | 0.01 | Sep 8, 2026 | Use after free in IP Helper allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-72980 | Med | 0.29 | 4.4 | 0.00 | Sep 8, 2026 | Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-72979 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-72978 | Med | 0.38 | 5.9 | 0.01 | Sep 8, 2026 | Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-72977 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-72976 | Med | 0.33 | 5.0 | 0.00 | Sep 8, 2026 | Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally. |
- risk 0.57cvss 8.8epss 0.01
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.64cvss 9.8epss 0.01
Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.28cvss 4.3epss 0.01
Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.00
Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.64cvss 9.8epss 0.01
Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
- risk 0.36cvss 5.5epss 0.00
Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.57cvss 8.8epss 0.01
Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
- risk 0.36cvss 5.5epss 0.00
Missing authentication for critical function in Windows Autopilot allows an authorized attacker to perform tampering locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.8epss 0.00
Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.49cvss 7.5epss 0.01
Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.53cvss 8.1epss 0.01
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.
- risk 0.44cvss 6.8epss 0.00
Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack.
- risk 0.64cvss 9.8epss 0.01
Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in IP Helper allows an unauthorized attacker to execute code over a network.
- risk 0.29cvss 4.4epss 0.00
Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.
- risk 0.64cvss 9.8epss 0.01
Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
- risk 0.38cvss 5.9epss 0.01
Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
- risk 0.33cvss 5.0epss 0.00
Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally.