Common Vulnerabilities and Exposures (CVE)

CVE-2026-69445

Sep 11, 2026 22:14:23 UTC

Improper limitation of a pathname to a restricted directory ('path traversal') in Windows Compressed Folder allows an authorized attacker to elevate privileges locally.

CVE-2026-69466

Sep 11, 2026 22:14:23 UTC

Time-of-check time-of-use (toctou) race condition in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-69444

Sep 11, 2026 22:14:22 UTC

Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

CVE-2026-69440

Sep 11, 2026 22:14:22 UTC

Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVE-2026-69434

Sep 11, 2026 22:14:21 UTC

Heap-based buffer overflow in Windows URL Moniker allows an unauthorized attacker to execute code over a network.

CVE-2026-69433

Sep 11, 2026 22:14:21 UTC

Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

CVE-2026-69447

Sep 11, 2026 22:14:20 UTC

Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69449

Sep 11, 2026 22:14:20 UTC

Heap-based buffer overflow in Windows BitLocker allows an authorized attacker to execute code locally.

CVE-2026-69430

Sep 11, 2026 22:14:19 UTC

Use after free in Windows Embedded Mode Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69475

Sep 11, 2026 22:14:19 UTC

Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVE-2026-69427

Sep 11, 2026 22:14:18 UTC

Out-of-bounds read in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges over a network.

CVE-2026-69425

Sep 11, 2026 22:14:17 UTC

Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to perform tampering locally.

CVE-2026-69438

Sep 11, 2026 22:14:17 UTC

Incorrect conversion between numeric types in Microsoft JScript allows an unauthorized attacker to execute code over a network.

CVE-2026-69422

Sep 11, 2026 22:14:16 UTC

Use after free in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69428

Sep 11, 2026 22:14:16 UTC

Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.