CVE-2026-68877 Windows Storage Spaces Controller Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
CVE-2026-68887 Windows Message Queuing Queue Manager Denial of Service Vulnerability
Out-of-bounds read in Windows Message Queuing Queue Manager allows an unauthorized attacker to deny service over a network.
CVE-2026-69293 Windows Biometric Service Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69355 Microsoft Exchange Server Remote Code Execution Vulnerability
External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-69356 Microsoft Exchange Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-69361 Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-69375 Microsoft Exchange Server Tampering Vulnerability
Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
CVE-2026-69378 Microsoft Exchange Server Denial of Service Vulnerability
Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.
CVE-2026-69380 Microsoft Exchange Server Elevation of Privilege Vulnerability
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-69382 Microsoft Exchange Server Information Disclosure Vulnerability
Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
CVE-2026-69383 Windows Shell Elevation of Privilege Vulnerability
External control of file name or path in Windows Shell allows an authorized attacker to elevate privileges locally.
CVE-2026-69394 Windows Audio Service Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69443 Windows Device Health Attestation (DHA) Information Disclosure Vulnerability
Out-of-bounds read in Windows Device Health Attestation (DHA) allows an unauthorized attacker to disclose information over a network.
CVE-2026-69469 Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability
Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-69501 Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVE-2026-69518 Windows Remote Desktop Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
CVE-2026-69544 Windows SMB Client Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.
CVE-2026-69548 Windows RNDIS Information Disclosure Vulnerability
Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-69556 Microsoft Office Word Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-69583 Windows Biometric Service Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.


