Common Vulnerabilities and Exposures (CVE)

CVE-2026-78447

Sep 25, 2026 21:38:10 UTC

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-78450

Sep 25, 2026 21:38:09 UTC

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

CVE-2026-78444

Sep 25, 2026 21:38:08 UTC

Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.

CVE-2026-78449

Sep 25, 2026 21:38:08 UTC

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

CVE-2026-78446

Sep 25, 2026 21:38:07 UTC

Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network.

CVE-2026-78445

Sep 25, 2026 21:38:07 UTC

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.

CVE-2026-78441

Sep 25, 2026 21:38:06 UTC

Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network.

CVE-2026-78442

Sep 25, 2026 21:38:06 UTC

Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.

CVE-2026-69562

Sep 25, 2026 21:38:05 UTC

Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network.

CVE-2026-77911

Sep 25, 2026 21:38:05 UTC

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

CVE-2026-77905

Sep 25, 2026 21:38:04 UTC

Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.

CVE-2026-69854

Sep 25, 2026 21:38:04 UTC

Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-77901

Sep 25, 2026 21:38:03 UTC

Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-77488

Sep 25, 2026 21:38:03 UTC

Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.

CVE-2026-77486

Sep 25, 2026 21:38:02 UTC

Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.