Patch Tuesday - September 2026
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday, including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today.
Windows ALPC: zero-day EoP
The eternal game of elevation of privilege whack-a-mole between Microsoft and attackers continues. This month, the battle is centered on the Windows Advanced Local Procedure Call (ALPC) mechanism, a kernel capability that facilitates inter-process communication. Microsoft is aware of exploitation in the wild already. Successful abuse of the flaw underlying CVE-2026-85880 grants an attacker SYSTEM via a buffer overflow that enables an out-of-bounds write, and as we all know by now, this is exactly what would happen during the first five minutes of a technically accurate horror movie about ransomware. We can infer one silver lining here: since neither Server 2025 nor Windows 11 receives patches for CVE-2026-85880, it is likely that Microsoft’s ongoing efforts to level up memory safety by rewriting critical kernel components in Rust are paying off.
Windows Update Stack: zero-day EoP
Attackers disappointed by Microsoft’s move towards memory safety improvements for various critical kernel components need not leave empty-handed today. Microsoft is aware of existing exploitation in the wild for CVE-2026-81963, an elevation of privilege vulnerability in the Windows Update Stack that leads to SYSTEM privileges via improper link resolution. All supported versions of Windows receive a patch, which presumably tightens up controls to prevent the Windows Update Stack from following a malicious link and overwriting a system component with an attacker-controlled imposter. The relatively pedestrian CVSS v3 base score of 7.8 is no reason for less concern, since no serious attacker will bother developing an intricate one-shot RCE when a two-stage attack chain consisting of low-privileged local access coupled with elevation of privilege will achieve the same ultimate goal much more easily.
Living on the Edge: browser advisory uncertainty
For the second month in a row, Microsoft does not appear to have published any desktop browser security advisories between the start of the month and Patch Tuesday. Microsoft Edge is built on top of Google’s open-source Chromium project, and on September 3, 2026, Google Chrome patched CVE-2026-85046, an exploited-in-the-wild zero-day vulnerability in the V8 JavaScript engine relied upon by both Edge and Chrome. So, is Microsoft Edge falling dangerously behind Google Chrome? Well, maybe. In this specific case, the Edge stable channel did receive a patch a day earlier than Chrome on September 2, 2026, and we know this because the Edge release notes mention it. However, almost a week later, Microsoft still hasn’t published a security advisory for CVE-2026-85046, and until that URL returns something better than a 404, that will remain true. In short: if you’re patched, you are protected, but if you rely on advisories to know which vulns exist, you could miss this zero-day vulnerability altogether. Only Microsoft knows why this advisory is missing, but there is no reason to suppose that Microsoft is somehow immune to the pressures that come along with the vast increase in vulnerability volume. A patch without an advisory is perhaps marginally better than an advisory without a patch, but keeping track of exposures without reliable advisory materials is not straightforward. Chrome patched 11 other vulnerabilities at the same time as CVE-2026-85046, but it’s not yet clear if those are patched in Edge. Until Microsoft sets the record straight, the only safe assumption is that these vulnerabilities (e.g. CVE-2026-85045) remain unpatched in Edge.
Microsoft lifecycle update
The next Microsoft product lifecycle changes with broad impact occur on October 14, 2026, when Windows 11 24H2 Home & Pro reach end of servicing, and Windows Server 2022 moves to extended support, with free critical security updates continuing, but no further feature development. At the same time, the final curtain falls for Windows Server 2012 and 2012 R2 with the expiry of the third and final year of cash-for-updates Extended Security Update (ESU) program for these aging workhorses. Office 2021 also moves beyond support, including the Long-Term Servicing Channel, with no ESU available in that case. Also in October, Exchange Server 2016 and 2019 will join the “no ESU” club, after two previous six-month reprieves. Presumably, Microsoft really means it this time.
Summary tables
Apps vulnerabilities
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-80097 | Microsoft Authenticator Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.6 |
| CVE-2026-58611 | Xbox Gaming Services Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
Azure vulnerabilities
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-70352 | Azure AI Language Elevation of Privilege Vulnerability | N/A | No | 10.0 |
| CVE-2026-62895 | Azure Arc SQL Server Extension Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69857 | Azure Cosmos DB Spoofing Vulnerability | Exploitation More Likely | No | 8.5 |
| CVE-2026-77909 | Azure CycleCloud Information Disclosure Vulnerability | Exploitation Less Likely | No | 7.7 |
| CVE-2026-81349 | Azure HDInsight Ambari Elevation of Privilege Vulnerability | N/A | No | 7.2 |
| CVE-2026-83941 | Entra ID Elevation of Privilege Vulnerability | N/A | No | 9.9 |
| CVE-2026-84003 | Microsoft Authentication Library (MSAL) for Node.js Spoofing Vulnerability | Exploitation Less Likely | No | 7.4 |
| CVE-2026-83711 | Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability | N/A | No | 10.0 |
| CVE-2026-83948 | Microsoft Azure CLI Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.0 |
| CVE-2026-62906 | Microsoft Discovery Studio Information Disclosure Vulnerability | N/A | No | 7.4 |
| CVE-2026-62916 | Microsoft Entra ID Elevation of Privilege Vulnerability | N/A | No | 9.1 |
| CVE-2026-69854 | Spring Cloud Azure Elevation of Privilege Vulnerability | Exploitation More Likely | No | 9.0 |
Browser vulnerabilities
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-84323 | Chromium: CVE-2026-84323 Missing authorization in FileSystem | n/a | No | |
| CVE-2026-84324 | Chromium: CVE-2026-84324 Use after free in Proxy | n/a | No | |
| CVE-2026-84325 | Chromium: CVE-2026-84325 Improper input validation in DataTransfer | n/a | No | |
| CVE-2026-84326 | Chromium: CVE-2026-84326 Uninitialized resource in V8 | n/a | No | |
| CVE-2026-84327 | Chromium: CVE-2026-84327 Incorrect authorization in Autofill | n/a | No | |
| CVE-2026-84328 | Chromium: CVE-2026-84328 Missing authorization in FileSystem | n/a | No | |
| CVE-2026-84329 | Chromium: CVE-2026-84329 Confused deputy in CredentialProvider | n/a | No | |
| CVE-2026-84331 | Chromium: CVE-2026-84331 Incorrect authorization in Actor | n/a | No | |
| CVE-2026-84332 | Chromium: CVE-2026-84332 Incorrect authorization in SiteSettings | n/a | No | |
| CVE-2026-84334 | Chromium: CVE-2026-84334 Incorrect authorization in Chromoting | n/a | No | |
| CVE-2026-84335 | Chromium: CVE-2026-84335 Incorrect authorization in TabStrip | n/a | No | |
| CVE-2026-84347 | Chromium: CVE-2026-84347 Use after free in WebRTC | n/a | No | |
| CVE-2026-84348 | Chromium: CVE-2026-84348 Information leak in MediaCapture | n/a | No | |
| CVE-2026-84349 | Chromium: CVE-2026-84349 Use after free in Browser | n/a | No | |
| CVE-2026-84350 | Chromium: CVE-2026-84350 Use after free in TabStrip | n/a | No | |
| CVE-2026-84351 | Chromium: CVE-2026-84351 Buffer overflow in GPU | n/a | No | |
| CVE-2026-84353 | Chromium: CVE-2026-84353 Use after free in Shared Tab Groups | n/a | No | |
| CVE-2026-84354 | Chromium: CVE-2026-84354 Incorrect authorization in FileSystem | n/a | No | |
| CVE-2026-84355 | Chromium: CVE-2026-84355 Incorrect authorization in Navigation | n/a | No | |
| CVE-2026-84356 | Chromium: CVE-2026-84356 UI misrepresentation in FullScreen | n/a | No | |
| CVE-2026-84357 | Chromium: CVE-2026-84357 Improper input validation in Omnibox | n/a | No | |
| CVE-2026-84358 | Chromium: CVE-2026-84358 Improper privilege management in Downloads | n/a | No | |
| CVE-2026-84359 | Chromium: CVE-2026-84359 Information leak in Skia | n/a | No |
Developer Tools vulnerabilities
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-69439 | .NET and Visual Studio Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-69522 | .NET and Visual Studio Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-71328 | .NET and Visual Studio Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-69805 | .NET Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-69806 | .NET Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-58649 | .NET Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2025-70873 | An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file. | n/a | No | 7.5 |
| CVE-2026-57099 | ASP.NET Core Denial of Service Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-69304 | ASP.NET Core Denial of Service Vulnerability | Exploitation Less Likely | No | 5.9 |
| CVE-2026-34182 | CMS AuthEnvelopedData Processing May Accept Forged Messages | n/a | No | 9.1 |
| CVE-2026-81380 | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability | N/A | No | 5.3 |
| CVE-2026-81381 | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-81383 | Visual Studio Code Information Disclosure Vulnerability | Exploitation Less Likely | No | 7.4 |
| CVE-2026-70334 | Visual Studio Code Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-78461 | Visual Studio Code Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 7.4 |
| CVE-2026-78462 | Visual Studio Code Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-81356 | Visual Studio Code Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 8.2 |
| CVE-2026-81357 | Visual Studio Code Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 8.2 |
| CVE-2026-81376 | Visual Studio Code Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 9.6 |
| CVE-2026-81378 | Visual Studio Code Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 8.2 |
| CVE-2026-81379 | Visual Studio Code Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 8.2 |
| CVE-2026-81377 | Visual Studio Code Tampering Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-77906 | Visual Studio Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-77907 | Visual Studio Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
Mariner vulnerabilities
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2025-70873 | An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file. | n/a | No | 7.5 |
Microsoft Dynamics vulnerabilities
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-65772 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-77908 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | N/A | No | 8.8 |
| CVE-2026-77897 | Microsoft Power Automate Desktop Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-65818 | Power Automate Elevation of Privilege Vulnerability | N/A | No | 8.5 |
Microsoft Office vulnerabilities
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-80098 | Copilot Studio Elevation of Privilege Vulnerability | N/A | No | 9.3 |
| CVE-2026-81387 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-81390 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-81391 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-81392 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-81393 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-81394 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-81395 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Unlikely | No | 5.5 |
| CVE-2026-81399 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-81400 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Unlikely | No | 5.5 |
| CVE-2026-81401 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-81958 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Unlikely | No | 5.5 |
| CVE-2026-81386 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81388 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-81389 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-81396 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-81397 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81398 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81947 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81948 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81949 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-81950 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81951 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81953 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81954 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81956 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81957 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81959 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-81960 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-70178 | Microsoft Fabric Elevation of Privilege Vulnerability | N/A | No | 8.5 |
| CVE-2026-69477 | Microsoft Office Access Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.3 |
| CVE-2026-69529 | Microsoft Office Access Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69614 | Microsoft Office Access Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69778 | Microsoft Office Access Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-72974 | Microsoft Office Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-78515 | Microsoft Office Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-85875 | Microsoft Office Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-78518 | Microsoft Office Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-78439 | Microsoft Office Graphics Component Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69626 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-69739 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-80076 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-80078 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-80082 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-80087 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-80089 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-80091 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-78520 | Microsoft Office Outlook Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-80073 | Microsoft Office Outlook Information Disclosure Vulnerability | Exploitation Less Likely | No | |
| CVE-2026-80084 | Microsoft Office Outlook Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-69629 | Microsoft Office Outlook Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-78509 | Microsoft Office Outlook Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-78519 | Microsoft Office Outlook Remote Code Execution Vulnerability | Exploitation Less Likely | No | |
| CVE-2026-78525 | Microsoft Office Outlook Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-72938 | Microsoft Office PowerPoint Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-72956 | Microsoft Office PowerPoint Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-72975 | Microsoft Office PowerPoint Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-72977 | Microsoft Office PowerPoint Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-78513 | Microsoft Office PowerPoint Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-80086 | Microsoft Office PowerPoint Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-69678 | Microsoft Office PowerPoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69767 | Microsoft Office PowerPoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69797 | Microsoft Office PowerPoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-80081 | Microsoft Office PowerPoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | |
| CVE-2026-69742 | Microsoft Office Publisher Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-81385 | Microsoft Office Publisher Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69285 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69442 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69632 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-77898 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-78505 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-78524 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69464 | Microsoft Office SharePoint Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69716 | Microsoft Office SharePoint Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69409 | Microsoft Office SharePoint Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-69636 | Microsoft Office SharePoint Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-69683 | Microsoft Office SharePoint Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-69904 | Microsoft Office SharePoint Information Disclosure Vulnerability | Exploitation Less Likely | No | 3.5 |
| CVE-2026-69268 | Microsoft Office SharePoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69273 | Microsoft Office SharePoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69282 | Microsoft Office SharePoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69465 | Microsoft Office SharePoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69724 | Microsoft Office SharePoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-69804 | Microsoft Office SharePoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-69402 | Microsoft Office SharePoint Spoofing Vulnerability | Exploitation Less Likely | No | 7.3 |
| CVE-2026-69417 | Microsoft Office SharePoint Spoofing Vulnerability | Exploitation Less Likely | No | 7.3 |
| CVE-2026-69615 | Microsoft Office SharePoint Spoofing Vulnerability | Exploitation Unlikely | No | 3.5 |
| CVE-2026-69690 | Microsoft Office SharePoint Spoofing Vulnerability | Exploitation Unlikely | No | 4.6 |
| CVE-2026-64918 | Microsoft Office Spoofing Vulnerability | Exploitation Less Likely | No | 6.5 |
Open Source Software vulnerabilities
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-69805 | .NET Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2025-70873 | An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file. | n/a | No | 7.5 |
| CVE-2026-34182 | CMS AuthEnvelopedData Processing May Accept Forged Messages | n/a | No | 9.1 |
Server Software vulnerabilities
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-69378 | Microsoft Exchange Server Denial of Service Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-69380 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.1 |
| CVE-2026-69641 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 9.1 |
| CVE-2026-69382 | Microsoft Exchange Server Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.9 |
| CVE-2026-55007 | Microsoft Exchange Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.1 |
| CVE-2026-69355 | Microsoft Exchange Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 Reproduced in full under licence from Rapid7 Blog. © Rapid7 Blog. Written by Rapid7. Read at rapid7.com ↗Established Source At a glance
Vulnerabilities referenced
CoverageOne outlet has carried this so far.
Related stories
|