CVE Database
Search and filter vulnerabilities by ID, vendor, product, severity, or description.
Search and filter vulnerabilities by ID, vendor, product, severity, or description.
| CVE ID | Severity | Score | Description | Published | |
|---|---|---|---|---|---|
| CVE-2026-72931 | MEDIUM | 4.7 | Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally. | Sep 8, 2026 | |
| CVE-2026-72926 | HIGH | 7.0 | Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-72923 | HIGH | 7.5 | In Microsoft.OpenApi.YamlReader from 2.0.0-preview.11 until 2.12.0 and from 3.0.0 until 3.10.0, and in Microsoft.OpenApi.Readers prior to 1.6.30, a small YAML OpenAPI document containing nested anchors and aliases can cause uncontrolled resource consumption when parsed through the public YAML reader APIs. YAML is parsed through SharpYaml, which represents aliases as shared nodes in a directed acyclic graph, so the parsed YAML graph stays small, but converting that graph to System.Text.Json.Nodes.JsonNode requires every alias to be materialized as an independent node because a JsonNode cannot be attached to multiple parents. Without a bound on that conversion work, a document with N nested anchors each referenced k times can require k^N materialized JSON nodes, leading to excessive memory allocation and process termination through out-of-memory conditions, a billion laughs style denial of service. The patched versions bound the YAML-to-JSON conversion by node count and nesting depth and report an OpenApiDiagnostic error instead of expanding without limit. This vulnerability is fixed in Microsoft.OpenApi.YamlReader 2.12.0 and 3.10.0, and Microsoft.OpenApi.Readers 1.6.30. | Sep 8, 2026 | |
| CVE-2026-71348 | MEDIUM | 6.8 | Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack. | Sep 8, 2026 | |
| CVE-2026-71341 | MEDIUM | 5.5 | Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-71338 | MEDIUM | 6.4 | Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-71336 | HIGH | 8.8 | Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network. | Sep 8, 2026 | |
| CVE-2026-71330 | HIGH | 7.5 | Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-71329 | MEDIUM | 6.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. | Sep 8, 2026 | |
| CVE-2026-70587 | HIGH | 7.5 | Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-70584 | HIGH | 7.8 | Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-70581 | HIGH | 7.8 | Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-70579 | HIGH | 7.5 | Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-70577 | HIGH | 7.0 | Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-70575 | MEDIUM | 5.3 | Null pointer dereference in Windows Schannel allows an authorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-70574 | HIGH | 7.8 | Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-70568 | HIGH | 7.0 | Heap-based buffer overflow in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-70342 | HIGH | 8.1 | Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network. | Sep 8, 2026 | |
| CVE-2026-70290 | MEDIUM | 5.5 | Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-70283 | HIGH | 7.0 | Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-70145 | MEDIUM | 5.5 | Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-70124 | MEDIUM | 5.9 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-70091 | MEDIUM | 5.9 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-70065 | HIGH | 7.5 | Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-70019 | MEDIUM | 6.5 | Windows hard link in Windows Compressed Folder allows an unauthorized attacker to disclose information over a network. | Sep 8, 2026 |