Common Vulnerabilities and Exposures (CVE)

CVE-2026-69395

Sep 18, 2026 20:44:52 UTC

Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network.

CVE-2026-69392

Sep 18, 2026 20:44:52 UTC

Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

CVE-2026-69910

Sep 18, 2026 20:44:51 UTC

Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.

CVE-2026-69352

Sep 18, 2026 20:44:50 UTC

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69311

Sep 18, 2026 20:44:50 UTC

Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69298

Sep 18, 2026 20:44:49 UTC

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69323

Sep 18, 2026 20:44:48 UTC

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69334

Sep 18, 2026 20:44:48 UTC

Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.

CVE-2026-69291

Sep 18, 2026 20:44:47 UTC

Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.

CVE-2026-69290

Sep 18, 2026 20:44:47 UTC

Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

CVE-2026-69309

Sep 18, 2026 20:44:46 UTC

Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

CVE-2026-69287

Sep 18, 2026 20:44:46 UTC

Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVE-2026-68896

Sep 18, 2026 20:44:45 UTC

Absolute path traversal in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-72967

Sep 18, 2026 20:44:45 UTC

Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.

CVE-2026-72966

Sep 18, 2026 20:44:44 UTC

Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.