<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom"
   version="2.0" xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title><![CDATA[ Rapid7 Cybersecurity Blog ]]></title>
    <description><![CDATA[Rapid7 transforms data into insight, empowering security professionals to progress and protect their organizations.]]></description>
    <link>https://www.rapid7.com/blog/</link>
    <image>
      <url>https://blog.rapid7.com/favicon.png</url>
      <title>Rapid7 Cybersecurity Blog</title>
      <link>https://www.rapid7.com/blog/</link>
    </image>
    <lastBuildDate>Sun, 27 Sep 2026 17:18:24 GMT</lastBuildDate>
    <atom:link href="https://www.rapid7.com/rss.xml" rel="self" type="application/rss+xml" />
    <ttl>60</ttl>
    <item>
      <title><![CDATA[Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?]]></title>
      <description><![CDATA[]]></description>
      <link>https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-belgian-waffles-chocolates-and-modules-frites</link>
      <guid isPermaLink="false">blt0e07d4de87ef7cf7</guid>
      <category><![CDATA[Metasploit]]></category>
      <category><![CDATA[Metasploit Weekly Wrapup]]></category><dc:creator><![CDATA[The Metasploit Team]]></dc:creator>
      <pubDate>Fri, 25 Sep 2026 14:38:05 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt0475760a2990dfd7/6849ab41a770d7563190a3ea/metasploit-fence.png" medium="image" />
    </item>
    <item>
      <title><![CDATA[When Business Email Compromise Starts Rewriting Reality]]></title>
      <description><![CDATA[<p><span style='color:rgb(29, 28, 29);font-size: undefined;'>Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultimately exploit that access to divert funds or exfiltrate sensitive assets.</span></p><p style="direction: ltr;"><span style='color:rgb(29, 28, 29);font-size: undefined;'>This dynamic is central to our analysis as we kick off a series around Rapid7's collaborative research with Zimbra; upcoming installments will explore technical details and broader findings based within the Zimbra Collaboration Suite. Our investigation disrupted the traditional BEC model in unexpected ways. We uncovered over 50 vulnerabilities, and found that several allow attackers not just to observe environments, but to actively rewrite them by impersonating senders without credentials, controlling inbox visibility, and altering shared documents and calendars.</span></p><h2><span style='color:rgb(29, 28, 29);font-size: undefined;'>Business Email Compromise in action: Digital abuse of trust</span></h2><p style="direction: ltr;"><span style='color:rgb(29, 28, 29);font-size: undefined;'>None of this is theoretical for Zimbra. But don’t take my word for it, just ask </span><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a" target="_blank"><span style='font-size: undefined;'>Russia</span></a><span style='color:rgb(29, 28, 29);font-size: undefined;'>. CISA keeps putting Zimbra bugs into the</span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank"><span style='font-size: undefined;'> Known Exploited Vulnerabilities catalog</span></a><span style='color:rgb(29, 28, 29);font-size: undefined;'>, and the last three years make the point on their own:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-45519" target="_blank"><span style='font-size: undefined;'>CVE-2024-45519</span></a><span style='color:rgb(29, 28, 29);font-size: undefined;'>, command injection in the postjournal service, unauthenticated command execution. Proofpoint saw attackers stuffing base64 payloads into CC fields on September 28, 2024. CISA added it to KEV on October 3.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-27915" target="_blank"><span style='font-size: undefined;'>CVE-2025-27915</span></a><span style='color:rgb(29, 28, 29);font-size: undefined;'>, stored XSS in the Classic Web Client, triggered by a crafted .ICS attachment. It is used as a zero-day against Brazilian military targets to steal mail and quietly set forwarding filters. It went into KEV in October, 2025.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><a href="https://www.cisa.gov/news-events/alerts/2026/08/21/cisa-adds-one-known-exploited-vulnerability-catalog" target="_blank"><span style='font-size: undefined;'>CVE-2026-73570</span></a><span style='color:rgb(29, 28, 29);font-size: undefined;'>, unauthenticated command injection through SNMP notification handling. CISA added it on August 21 of this year and gave federal agencies three days. Shadowserver has been counting somewhere north of 260 compromised instances while hunting for exploitation artifacts.</span></p></li></ul><p style="direction: ltr;"><span style='color:rgb(29, 28, 29);font-size: undefined;'>Go back further and the pattern holds. Rapid7 tracked</span><a href="https://www.rapid7.com/blog/post/2022/08/17/active-exploitation-of-multiple-vulnerabilities-in-zimbra-collaboration-suite/" target="_blank"><span style='font-size: undefined;'> widespread exploitation</span></a><span style='color:rgb(29, 28, 29);font-size: undefined;'> of CVE-2022-27925 and CVE-2022-37042 in 2022, a path traversal chained with an authentication bypass that let attackers drop a JSP shell on a Zimbra server without credentials. Google's Threat Analysis Group later documented</span><a href="https://blog.google/threat-analysis-group/zimbra-0-day-used-to-target-international-government-organizations/" target="_blank"><span style='font-size: undefined;'> four separate threat groups</span></a><span style='color:rgb(29, 28, 29);font-size: undefined;'> working the same zero-day known as CVE-2023-37580. Each of these groups went after email, credentials, and authentication tokens. Attackers figured out a long time ago that the system sitting in the middle of everyone's communication is worth the effort. So when you find a set of bugs that let you write to that system instead of only reading from it, data theft stops being the interesting part.</span></p><p style="direction: ltr;"><span style='color:rgb(29, 28, 29);font-size: undefined;'>Send an email as your CFO without ever touching their password, and you have the front half of a very convincing BEC. Keep control of the mailbox afterward and you have the back half, too. Here, the attacker has a strategic choice. They can delete the sent message to hide their tracks, effectively wiping the trail of the fraud OR they can choose to leave the message in the Sent Items folder. By doing so, they ensure the CFO sees 'evidence' of the email they supposedly sent, creating a gaslighting scenario where the victim is left questioning their own actions. Whether the attacker cleans up or leaves the trail, they are shaping the organization’s perception of reality. In the ensuing investigation, where Finance sees a sent request and the CFO sees no such activity, the organization is trapped in a conflict of evidence. At that point, BEC looks less like traditional fraud and more like a psychological operation.</span></p><p style="direction: ltr;"><span style='color:rgb(29, 28, 29);font-size: undefined;'>Documents make it worse, as Zimbra is not just a mail server. The collaboration side holds the files employees actually use to make decisions. An attacker who can plant a fake HR memo or financial summary in an executive's enterprise drive, and make it look like it came from a peer they trust, is starting from a much better position than someone attaching a PDF to a cold email.</span></p><p style="direction: ltr;"><span style='color:rgb(29, 28, 29);font-size: undefined;'>Say a document shows up from HR about a confidential restructuring, and a few days later an email from a trusted executive references it. Neither piece has to carry the whole deception, as each one props up the other.</span></p><h2><span style='color:rgb(29, 28, 29);font-size: undefined;'>Calendar warfare and manufactured enterprise reality</span></h2><p><span style='color:rgb(29, 28, 29);font-size: undefined;'>Then there is the thing I have started calling ‘</span><span style='color:rgb(29, 28, 29);font-size: undefined;'><em>calendar warfare</em></span><span style='color:rgb(29, 28, 29);font-size: undefined;'>.’ Meetings can be modified or deleted without generating the notification trail users expect to see. RSVP status can also be flipped. Maybe a key executive is changed from Accepted to Declined and leadership might reschedule, or move ahead without them, or read the whole thing as a deliberate opt-out.</span></p><p style="direction: ltr;"><span style='color:rgb(29, 28, 29);font-size: undefined;'>It works in the other direction too. An "Emergency Board Meeting" lands on an executive's calendar with a believable organizer, a popup reminder, and a malicious Zoom link. When the reminder fires, the victim is not sizing up a suspicious email that arrived thirty seconds ago. They are joining a meeting that has been sitting in their calendar for two days. And the calendar is not some exotic attack surface nobody has thought of. If we look back at CVE-2025-27915, the delivery vehicle was a calendar invite.</span></p><p style="direction: ltr;"><span style='color:rgb(29, 28, 29);font-size: undefined;'>Stack all of it together now – a financial document appears, a trusted executive emails about it, then a mandatory meeting shows up to discuss it. And the attacker still has the ability to clean up some of what gets left behind. Every artifact the victim checks lives inside a system they have no reason to question, and all of them tell the same fabricated story.</span></p><p style="direction: ltr;"><span style='color:rgb(29, 28, 29);font-size: undefined;'>I keep coming back to the phrase '</span><span style='color:rgb(29, 28, 29);font-size: undefined;'><em>manufactured enterprise reality</em></span><span style='color:rgb(29, 28, 29);font-size: undefined;'>'. I have touched on the idea in </span><a href="https://www.themondaybrief.com/" target="_blank"><span style='font-size: undefined;'>The Monday Brief,</span></a><span style='color:rgb(29, 28, 29);font-size: undefined;'> that attackers get to borrow whatever trust an organization has already extended to its own tooling. Zimbra makes it concrete. The platform supplies the credibility, so the attacker does not have to build any.</span></p><p style="direction: ltr;"><span style='color:rgb(29, 28, 29);font-size: undefined;'>Collaboration suites quietly became systems of record. Email is the record of who said what. Calendars are the record of who agreed to be where. Classic BEC abuses the trust between two people. The scenario we’ve discussed here abuses the machinery those people use to decide who to trust in the first place. Once employees are making real business decisions off fabricated context, stealing data is the least of your problems.</span></p>]]></description>
      <link>https://www.rapid7.com/blog/post/ve-business-email-compromise-rewriting-reality-zimbra-cve</link>
      <guid isPermaLink="false">blt4f83a601f42f0e29</guid>
      <category><![CDATA[Phishing]]></category>
      <category><![CDATA[Vulnerability Disclosure]]></category><dc:creator><![CDATA[Douglas McKee, Director, Vulnerability Intelligence]]></dc:creator>
      <pubDate>Thu, 24 Sep 2026 13:00:00 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blted8cb9466d79dc4d/6852c596a274324cfbb23d9d/PSN-gov-showcase-hero-image.png" medium="image" />
    </item>
    <item>
      <title><![CDATA[How dynamic application security testing validates risk at runtime]]></title>
      <description><![CDATA[<p style="direction: ltr;"><span style='font-size: undefined;'>Security teams already have long queues of potential application vulnerabilities. The useful question is what happens next: can they see how a weakness behaves in a running application, reproduce the attack, and give developers enough evidence to fix it?</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Dynamic application security testing (DAST) helps answer those questions by testing applications as an attacker encounters them. The </span><span style='font-size: undefined;'><em>IDC MarketScape: Worldwide Dynamic Application Security Testing 2026 Vendor Assessment</em></span><span style='font-size: undefined;'> (Doc #US54119126, September 2026). The IDC MarketScape evaluated 16 vendors and named Rapid7 a Leader.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>We believe the result reflects the strength of Rapid7’s DAST capabilities, but the IDC MarketScape also offers a useful view of where the category is heading. DAST has developed beyond traditional web scanning into a source of runtime evidence that can help organizations validate risk across the application layer.</span></p><h2 style="direction: ltr;">From possible weakness to validated application risk</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Code analysis and dependency scanning help teams identify weaknesses before an application is deployed. DAST provides a different view by interacting with the assembled application while it is running. It can show what happens when a particular request reaches the application, how the application responds, and whether a suspected weakness can be reproduced.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>This is especially valuable for APIs and AI-backed applications, where risk may emerge through interactions among models, prompts, data, tools, and permissions. Some of these behaviors cannot be fully understood from source code or a dependency manifest. They become visible when the application is exercised under runtime conditions.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>DAST therefore has a direct role in continuous threat exposure management (CTEM). Discovery gives teams a view of their assets and possible weaknesses, but that view alone does not tell them where to focus. Validation helps narrow the field by showing which exposures can be reached or exploited and providing evidence that teams can use to take action.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>For Rapid7, DAST is exposure management applied to the application layer. Web applications, APIs, and AI-backed endpoints are all part of the attack surface, so they need to be discovered, tested, prioritized, and managed alongside infrastructure, cloud, and other exposures.</span></p><h2 style="direction: ltr;">Why we believe Rapid7 was named a Leader by IDC</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Rapid7’s DAST solution is delivered as part of the Exposure Command portfolio. Its scan engine maps an application, executes attacks against the discovered paths, and validates confirmed findings. Security teams can map a broad area of an application while limiting active attacks to an appropriate set of paths, giving them control over how testing is performed.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Findings are checked against Rapid7 telemetry to help determine which issues warrant closer attention. When a finding needs action, browser-based replay reproduces the original request, the attack request, and the triggering response. Developers receive evidence they can work with, rather than a finding they must first spend time proving.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Authenticated scanning can be difficult to maintain across a changing application portfolio, and a broken login sequence can leave important areas untested. Rapid7’s solution can identify the affected step and support a targeted update without requiring the entire sequence to be recorded again.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The connection with Surface Command adds another useful layer. Newly discovered external assets can be surfaced for application testing, helping teams close the gap between finding an application and understanding the risk it presents</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>DAST plays a core role within Exposure Command: providing the application-layer validation teams need to prioritize risk and move from findings to remediation.</span></p><p style="direction: ltr;"><a href="https://www.rapid7.com/products/command/exposure-management/"><span style='font-size: undefined;'>Learn more about Rapid7 Exposure Command.</span></a></p>]]></description>
      <link>https://www.rapid7.com/blog/post/em-dynamic-application-security-testing-dast-validates-risk-at-runtime-idc-marketscape</link>
      <guid isPermaLink="false">bltc26267e5dc844b04</guid>
      <category><![CDATA[Exposure Command]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Wed, 23 Sep 2026 13:49:39 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt6de5ce916fee1306/67e1ab62a352dfa88a696f5f/IDC-report.jpg" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On September 22, 2026, F5 published a security </span><a href="https://my.f5.com/manage/s/article/K000162605"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> for </span><a href="https://nvd.nist.gov/vuln/detail/cve-2026-94127"><span style='font-size: undefined;'>CVE-2026-94127</span></a><span style='font-size: undefined;'>, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted traffic.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>BIG-IP APM provides identity-aware access control for applications and other corporate resources and can integrate with authentication technologies including OAuth, OpenID Connect, and SAML. CVE-2026-94127 is not exposed in a default configuration: exploitation requires a BIG-IP virtual server with both an APM access policy and an OAuth profile configured. Because affected BIG-IP systems may process traffic at an organization's network edge, organizations using this configuration should prioritize remediation.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The vulnerability affects the data plane and does not expose the BIG-IP control plane. BIG-IP systems operating in Appliance mode are also affected.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>F5 lists the following affected release trains and corresponding fixed hotfixes:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>BIG-IP 21.1.0: versions prior to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>BIG-IP 17.5.0: versions prior to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>BIG-IP 17.1.0: versions prior to Hotfix-BIGIP-17.1.3.5.0.41.14-ENG</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>As of September 22, 2026, CVE-2026-94127 has been added to the </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search=CVE-2026-94127&amp;field_date_added_wrapper=all&amp;field_cve=&amp;sort_by=field_date_added&amp;items_per_page=20&amp;url="><span style='font-size: undefined;'>CISA KEV</span></a><span style='font-size: undefined;'> while a publicly available proof of concept was not confirmed.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations running affected F5 BIG-IP deployments should apply the appropriate F5 hotfix as soon as operationally feasible, particularly where a vulnerable APM and OAuth configuration is reachable from untrusted networks.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>F5 lists the following remediation versions:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>BIG-IP 21.1.0: update to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG or later.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>BIG-IP 17.5.0: update to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG or later.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>BIG-IP 17.1.0: update to Hotfix-BIGIP-17.1.3.5.0.41.14-ENG or later.</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Administrators should first determine whether a BIG-IP APM access policy and an OAuth profile are configured together on a virtual server, since this configuration is required for exposure.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>For organizations that cannot immediately apply the applicable update, F5 provides an iRule workaround through F5 Support. Customers should open a support case with F5 to obtain the vendor-provided workaround and follow F5's implementation guidance.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;">Exposure Command, Vulnerability Management, and Nexpose</h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, Vulnerability Management, Nexpose customers can assess exposure to CVE-2026-94127 using vulnerability checks expected to be available in today’s (September 23) content release.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>September 22, 2026: Initial publication.</span></p></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-94127-critical-unauthenticated-rce-in-f5-big-ip-apm</link>
      <guid isPermaLink="false">blt2aea79a3a1361bda</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Labs]]></category>
      <category><![CDATA[Vulnerability Management]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Wed, 23 Sep 2026 08:43:39 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On September 14, 2026, Cisco published a security </span><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> for </span><a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-76461/"><span style='font-size: undefined;'>CVE-2026-76461</span></a><span style='font-size: undefined;'>, a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of </span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"><span style='font-size: undefined;'>9.8</span></a><span style='font-size: undefined;'> and could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Cisco Secure Email Gateway, formerly known as IronPort Email Security Appliance, is an enterprise email security product that inspects inbound and outbound email for threats including phishing, malware, spam, and business email compromise. Because affected gateways process externally delivered email as part of their normal operation, exploitation does not require access to an administrative interface or authentication. An attacker can reportedly trigger the vulnerability by sending a specially crafted email through a vulnerable gateway.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-76461 was </span><a href="https://www.cisa.gov/news-events/alerts/2026/09/14/cisa-adds-one-known-exploited-vulnerability-catalog"><span style='font-size: undefined;'>added</span></a><span style='font-size: undefined;'> to CISA's Known Exploited Vulnerabilities (</span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search=CVE-2026-76461&amp;field_date_added_wrapper=all&amp;field_cve=&amp;sort_by=field_date_added&amp;items_per_page=20&amp;url="><span style='font-size: undefined;'>KEV</span></a><span style='font-size: undefined;'>) catalog on the same day as the vendor disclosed the vulnerability, indicating that CVE-2026-76461 was exploited as a zero-day prior to disclosure. Cisco noted that their PSIRT became aware of active exploitation in September 2026. At the time of publication, there is no public proof-of-concept exploit code available, and no attribution for the current threat actor activity.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations running Cisco Secure Email Gateway should prioritize upgrading to a vendor-supplied fixed version on an emergency basis, outside of normal patching cycles.</span></p><table><colgroup data-width='500'><col style="width:71.57190635451505%"/><col style="width:28.428093645484946%"/></colgroup><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Affected Version</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Fixed Version</strong></span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>15.5 and earlier</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>15.5.5-014</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>16.0</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>16.0.4-302</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>16.5</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>16.5.0-780</span></p></td></tr></tbody></table><p style="direction: ltr;"><span style='font-size: undefined;'>Given the reported active exploitation and the ability to achieve unauthenticated root-level command execution through malicious email processing, organizations should prioritize patching rather than relying solely on network controls or monitoring. Cisco also strongly recommends that customers migrate to the latest product version, 16.5.0-780.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>For the latest remediation guidance, see the vendor </span><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Indicators of compromise</h2><p style="direction: ltr;"><span style='font-size: undefined;'>The following indicators of compromise for CVE-2026-76461 were reported within the Cisco security </span><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'>.</span></p><blockquote><span style='font-size: undefined;'>To confirm any attempted exploitation of this vulnerability, review the mail_logs and look for suspicious SQL statements. If the device is part of a cluster, review the logs of each cluster device. The following is a non-exhaustive example of how a malicious SQL statement could be detected in the logs:</span></blockquote><blockquote><span style='font-size: undefined;'>cisco-esa&gt; grep -i "COPY.*TO PROGRAM" [IronPort Text Mail Logs Log name - Default: mail_logs]</span></blockquote><blockquote><span style='font-size: undefined;'>The presence of any entry in the output may indicate malicious activity.</span></blockquote><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;">Exposure Command, InsightVM, and Nexpose</h3><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-76461 with a vulnerability check expected to be available in the September 16 content release.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>September 15, 2026:</strong></span><span style='font-size: undefined;'> Initial publication.</span></p></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild</link>
      <guid isPermaLink="false">blteb427d6325634414</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Labs]]></category>
      <category><![CDATA[Vulnerability Management]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Tue, 15 Sep 2026 12:22:50 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Rapid7 Named Among Notable Vendors in Forrester MDR Landscape: Why the Future is Exposure-informed, Preemptive MDR]]></title>
      <description><![CDATA[<p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>The managed detection and response (MDR) market has reached a turning point. We’ve gone beyond the baseline of 24/7 monitoring focusing on the speed of detection and moved to a world with a convergence of exposure management and response to deliver measurable, outcome-based defenses of a larger, AI-driven attack surface.</span></p><p><span style='font-size: undefined;'>For anyone evaluating MDR right now, the Managed Detection and Response Services Landscape, Q3 2026 report by Forrester is a useful map that lays out where the market is heading. This is a market that has moved beyond "do you cover my telemetry?" to “Can a provider connect and prove that its activity is tied to real reduction in risk?”. </span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Rapid7 was named among the notable providers in this Forrester MDR Landscape. Being included matters to us, but the more interesting story is in what Forrester says about the market itself.</span></p><h2><span style='font-size: undefined;'>Detection and exposure are becoming one service</span></h2><p style="direction: ltr;"><span style='font-size: undefined;'>One of the report's clearest signals is directional: Forrester writes that "MDR services will converge with exposure and posture improvement.”</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>That convergence is the whole basis of </span><a href="/services/managed-detection-and-response-mdr/" target="_self"><span style='font-size: undefined;'>Rapid7 MDR</span></a><span style='font-size: undefined;'> and our Command Platform strategy. Most MDR services react after an attacker has already broken in. Rapid7 designed its service to anticipate where attackers are likely to succeed and disrupt them earlier. We combine exposure context, detection, and response into a single operational loop, where vulnerability findings and asset risk scoring flow directly into alerts and investigations. This means analysts can cut noise and focus response on the exposures most likely to cause business impact. It's what we mean by </span><a href="/services/managed-detection-and-response-mdr/enterprise/" target="_self"><span style='font-size: undefined;'>exposure-informed, Preemptive MDR</span></a><span style='font-size: undefined;'>: The same context that tells you where you're weak is the context that sharpens how you detect and respond.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>For buyers, the practical implication is that old procurement habits are changing. Buyers used to invest in detection from one vendor, exposure management from another, and then hope the two solutions would seamlessly talk to each other. That approach is now turning into a liability.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The market will reward providers that connect these additions to measurable risk reduction rather than bolting on loosely joined SKUs. That's a bar customers should hold every provider to, including Rapid7.</span></p><h2><span style='font-size: undefined;'>"Make providers prove the investigation, rather than narrate the dashboard"</span></h2><p style="direction: ltr;"><span style='font-size: undefined;'>The second theme is about accountability. In its guidance on working with providers, Forrester is blunt: Buyers should "make providers prove the investigation, rather than narrate the dashboard." A slick activity feed is not evidence that anyone reached the right conclusion. Buyers should ask to see the reasoning behind a disposition, the actions taken, and the controls that keep automation from making unsafe decisions.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>This is a healthy pressure on the whole market, and it's a test we welcome. Rapid7 MDR is delivered on Rapid7's own SIEM, which gives customers a direct window into our SOC, including validated threats, the response actions taken, where AI accelerated the work, and where a human analyst stepped in and why. Every action is logged, explainable, and auditable. As agentic AI takes on more of the investigation workload, that transparency becomes the difference between a service you trust and a black box you </span><span style='font-size: undefined;'><em>hope</em></span><span style='font-size: undefined;'> is working. Our approach is deliberately human-led and AI-enhanced: AI scales triage and investigation across large volumes of telemetry, while analysts stay responsible for validation and response decisions.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Accountability also shows up in commercial terms. Rapid7 MDR includes unlimited incident response, so the team stays engaged until an incident is fully remediated rather than stopping when a clock runs out, and gives a concrete answer to the "who owns the outcome?" question.</span></p><h2><span style='font-size: undefined;'>What to do with the report</span></h2><p style="direction: ltr;"><span style='font-size: undefined;'>If you're evaluating MDR, and have access to Forrester, the report is a strong prompt to rewrite your evaluation criteria. A few questions worth taking into any provider conversation:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Ask</strong></span><span style='font-size: undefined;'> how exposure context actually enters investigations. Is it a legitimate input to detection and prioritization, or a separate dashboard? </span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Ask</strong></span><span style='font-size: undefined;'> to see a real, redacted case file rather than a metrics summary. Then probe how the provider handles uncertainty and model failure. </span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Clarify</strong></span><span style='font-size: undefined;'> the place where accountability sits when a response action carries risk, and get a clear answer on how far the provider remains engaged during an incident. </span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>These are the same standards we hold ourselves to, and they map to how we've built our MDR service. If you want to go deeper, our </span><a href="/lp/mdr-buyers-guide/" target="_self"><span style='font-size: undefined;'>MDR Buyer's Guide </span></a><span style='font-size: undefined;'>walks through what to look for in a partner, and you can compare Rapid7 MDR against other providers or talk to our SOC team directly.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The MDR market is one in which detection, exposure, and response stop being separate purchases and start being one accountable outcome. That's the service we set out to build, and now is a good moment for every security leader to ask whether their current provider is heading the same way.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><em>Source: Forrester, The Managed Detection And Response Services Landscape, Q3 2026, Jeff Pollard with Joseph Blankenship, Emily Doherty, and Michael Belden, September 1, 2026. Forrester does not endorse any company, product, brand, or service included in its research publications and does not advise any person to select the products or services of any company or brand based on the ratings included in such publications. Information is based on the best available resources. Opinions reflect judgment at the time and are subject to change. This report is part of a broader collection of Forrester resources, including interactive models, frameworks, tools, data, and access to analyst guidance. For more information, read about Forrester’s objectivity </em></span><a href="https://www.forrester.com/about-us/objectivity/" target="_blank"><span style='font-size: undefined;'><em>here </em></span></a><span style='font-size: undefined;'><em>.</em></span></p>]]></description>
      <link>https://www.rapid7.com/blog/post/dr-forrester-mdr-landscape-notable-vendor-preemptive</link>
      <guid isPermaLink="false">blt579edca6b0f1ed2f</guid>
      <category><![CDATA[Managed Detection and Response (MDR)]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Mon, 14 Sep 2026 14:51:07 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltebc2810157aecfaf/68af2715c53b04810df94abb/blog-hero-generic-pixel.jpg" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild]]></title>
      <description><![CDATA[<p></p><h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On September 10, 2026, GitLab </span><a href="https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/"><span style='font-size: undefined;'>published a critical patch release</span></a><span style='font-size: undefined;'> for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-85706"><span style='font-size: undefined;'>CVE-2026-85706</span></a><span style='font-size: undefined;'>, a critical path traversal vulnerability (</span><a href="https://cwe.mitre.org/data/definitions/22.html"><span style='font-size: undefined;'>CWE-22</span></a><span style='font-size: undefined;'>) in the repository commits API with a CVSSv3.1 score of </span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"><span style='font-size: undefined;'>10.0</span></a><span style='font-size: undefined;'>. According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>On September 11, 2026, CVE-2026-85706 was </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85706"><span style='font-size: undefined;'>added</span></a><span style='font-size: undefined;'> to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. CISA set a remediation due date of September 14, 2026, for affected Federal Civilian Executive Branch agencies and marked the vulnerability as subject to </span><a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk"><span style='font-size: undefined;'>forensic triage requirements</span></a><span style='font-size: undefined;'> under Binding Operational Directive 26-04.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations running affected self-managed GitLab instances should remediate CVE-2026-85706 on an emergency basis, outside of normal patch cycles.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>A vendor-supplied update is available to remediate CVE-2026-85706. Organizations running affected self-managed GitLab CE or EE instances should upgrade to a fixed version immediately.</span></p><p></p><table><thead><tr><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Affected GitLab CE/EE versions</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Fixed version</strong></span></p></th></tr></thead><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>All versions from </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>18.7</span></span><span style='font-size: undefined;'> before </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>19.1.8</span></span></p></td><td><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>19.1.8</span></span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>All versions from </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>19.2</span></span><span style='font-size: undefined;'> before </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>19.2.6</span></span></p></td><td><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>19.2.6</span></span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>All versions from </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>19.3</span></span><span style='font-size: undefined;'> before </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>19.3.2</span></span></p></td><td><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>19.3.2</span></span></p></td></tr></tbody></table><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>GitLab.com is already running a patched version, and GitLab Dedicated customers do not need to take action. Per GitLab, all self-managed deployment types are affected, including Omnibus, source code, and Helm chart deployments.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The updates include database migrations. Single-node installations will experience downtime while the migrations run; multi-node deployments can use GitLab's zero-downtime upgrade procedure. Of the fixed releases, only </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>19.3.2</span></span><span style='font-size: undefined;'> includes post-deployment migrations.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The patch release also addresses 17 other vulnerabilities. These include </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-87719"><span style='font-size: undefined;'>CVE-2026-87719</span></a><span style='font-size: undefined;'>, a critical insecure deserialization vulnerability (</span><a href="https://cwe.mitre.org/data/definitions/502.html"><span style='font-size: undefined;'>CWE-502</span></a><span style='font-size: undefined;'>) in GitLab EE with a CVSSv3.1 score of </span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"><span style='font-size: undefined;'>9.9</span></a><span style='font-size: undefined;'>. GitLab states that, under certain conditions, an authenticated user with Duo Chat access could obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument. At the time of publication, only CVE-2026-85706 is known to be exploited in the wild.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Given the confirmed exploitation, Rapid7 strongly recommends looking for signs of compromise even after the update has been applied. Organizations subject to CISA's BOD 26-04 should also follow the forensic triage requirements associated with the KEV entry.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>For the latest mitigation guidance, please refer to the vendor's </span><a href="https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/"><span style='font-size: undefined;'>security advisory</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-85706 with a vulnerability check available in the September 15 content release.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>September 14, 2026</strong></span><span style='font-size: undefined;'>: Initial publication.</span></p></li></ul><p></p>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-85706-critical-gitlab-path-traversal-exploited-in-the-wild</link>
      <guid isPermaLink="false">blt07b849d3d19553d6</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Emerging Threats]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Mon, 14 Sep 2026 10:02:57 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Metasploit Wrap Up: This One Goes to Sixteen!]]></title>
      <description><![CDATA[<p style="direction: ltr;"><span style='font-size: undefined;'></span><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt4e6f4307f0e3573e/6aa3da1d04494b06f60a1033/metasploit-dials.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="metasploit-dials.png" asset-alt="metasploit-dials.png" inline="true" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt4e6f4307f0e3573e/6aa3da1d04494b06f60a1033/metasploit-dials.png" data-sys-asset-uid="blt4e6f4307f0e3573e" data-sys-asset-filename="metasploit-dials.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="metasploit-dials.png" sys-style-type="display"/></p><h2>This One Goes to Sixteen!</h2><p>Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers!</p><h2>New module content (16)</h2><h3>Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read</h3><p>Authors: Bourbon Offensive Security Services and Jean-Marie Bourbon</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21739">#21739</a> contributed by <a href="https://github.com/kmkz">kmkz</a></p><p>Path: scanner/http/elasticsearch_tika_xfa_xxe</p><p>CVE reference: <a href="https://www.rapid7.com/db/vulnerabilities/cve-2025-66516/">CVE-2025-66516</a></p><p>Description: Adds an auxiliary scanner module for CVE-2025-54988/CVE-2025-66516. The module validates an XML External Entity (XXE) vulnerability in Apache Tika's XFA parser exposed through the Elasticsearch attachment ingest processor.</p><h3>SPIP Unauthenticated Blind SQLi via Date Field Escaping Bypass</h3><p>Authors: Benoit Hua, Franck Chevalier, Julien Voisin, and ka3n1x</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21791">#21791</a> contributed by <a href="https://github.com/jvoisin">jvoisin</a></p><p>Path: scanner/http/spip_annee_sqli</p><p>Description: Adds modules/auxiliary/scanner/http/spip_annee_sqli.rb which exploits a blind SQL injection in SPIP's date column escaping logic.</p><h3>Metasploit Payload Handler Detection (TCP/UDP/HTTP/HTTPS)</h3><p>Author: h00die</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21551">#21551</a> contributed by <a href="https://github.com/h00die">h00die</a></p><p>Path: scanner/msf/handler_detect</p><p>Description: Adds a scanner module to enumerate ports on a host and determine if they're a Metasploit Reverse Handler or not, and if they are, what kind of shell they were going to land.</p><h3>ESC8 Relay: SMB to HTTP(S) via Kerberos</h3><p>Author: Pushpender Rathore</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21709">#21709</a> contributed by <a href="https://github.com/Pushpenderrathore">Pushpenderrathore</a></p><p>Path: server/relay/esc8_kerberos</p><p>CVE reference: <a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-20929/">CVE-2026-20929</a></p><p>Description: This introduces native Kerberos authentication relay capabilities to the framework's relay stack. It includes a new auxiliary module (esc8_kerberos) that exploits CVE-2026-20929 by targeting AD CS Web Enrollment (ESC8). The module captures an SMB2 AP-REQ from a coerced client and seamlessly replays the authentication to the target certificate server over HTTP. This chain ultimately allows an attacker to issue a certificate for the coerced victim and obtain a valid Kerberos TGT without requiring their credentials.</p><h3>Linux x64 Sandbox Environment Gate</h3><p>Author: Massimo Bertocchi</p><p>Type: Evasion</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21642">#21642</a> contributed by <a href="https://github.com/litemars">litemars</a></p><p>Path: linux/x64/sandbox_gate</p><p>Description: Adds a Linux x64 sandbox‑evasion module that performs lightweight runtime environment checks and aborts execution when a likely sandbox or VM is detected.</p><h3>Cisco Secure Firewall Management Center Authentication Bypass RCE</h3><p>Authors: Arian Eidizadeh, Brandon Sakai, and Cale Black</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21796">#21796</a> contributed by <a href="https://github.com/CyberAuth">CyberAuth</a></p><p>Path: linux/http/cisco_fmc_auth_bypass_rce</p><p>CVE reference: <a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-20079/">CVE-2026-20079</a></p><p>Description: Adds a native Metasploit exploit module for CVE-2026-20079, an unauthenticated authentication bypass in Cisco Secure Firewall Management Center (FMC).</p><h3>SonicWall SMA1000 WorkPlace SSRF to Root Remote Code Execution</h3><p>Authors: Adam Babis, William Perry, and sfewer-r7</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21883">#21883</a> contributed by <a href="https://github.com/sfewer-r7">sfewer-r7</a></p><p>Path: linux/http/sonicwall_sma1000_couchdb_rce</p><p>CVE reference: <a href="https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild/">CVE-2026-83549</a></p><p>Description: This adds an exploit module for the recent SonicWall SMA1000 zero-day exploit chain that was disclosed in the first week of September as being exploited in-the-wild. CVE-2026-83548 is an SSRF used to bypass auth. SMA1000-9427 is an RCE with low privileges via CouchDB read/write primitives. CVE-2026-83549 is a command injection in cmsSnmpTrap.sh for RCE with root privs. The patched version 12.5.0-02952 has been verified to successfully remediate this exploit chain.</p><h3>JetBrains TeamCity Agent Polling Unauthenticated Remote Code Execution</h3><p>Authors: Antoni Tremblay and sfewer-r7</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21775">#21775</a> contributed by <a href="https://github.com/sfewer-r7">sfewer-r7</a></p><p>Path: multi/http/jetbrains_teamcity_rce_cve_2026_63077</p><p>CVE reference: <a href="https://www.rapid7.com/blog/post/ra-unauthenticated-rce-in-jetbrains-teamcity-cve-2026-63077/">CVE-2026-63077</a></p><p>Description: This introduces a new unauthenticated Remote Code Execution (RCE) exploit module for JetBrains TeamCity, targeting the vulnerability tracked as CVE-2026-63077. The module exploits an unsafe XStream deserialization flaw within the agent polling protocol to deliver and execute a one-shot JSP payload on the server. The module supports both Windows and Linux targets and features built-in cleanup logic to automatically unregister and remove the fake build agent created during the exploitation process.</p><h3>Langflow AI authenticated RCE</h3><p>Author: Richard Howe</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21837">#21837</a> contributed by <a href="https://github.com/rmhowe425">rmhowe425</a></p><p>Path: multi/http/langflow_auth_rce_cve_2026_19295</p><p>CVE reference: <a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-19295/">CVE-2026-19295</a></p><p>Description: Adds a new module targeting CVE-2026-19295, an authenticated remote code execution vulnerability impacting Langflow versions 1.10.0 and below.</p><h3>MCPJam Inspector Connect API Command Execution</h3><p>Authors: Louay-075 and earthenvessel</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21655">#21655</a> contributed by <a href="https://github.com/earthenvessel">earthenvessel</a></p><p>Path: multi/http/mcpjam_inspector_rce</p><p>CVE reference: <a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-23744/">CVE-2026-23744</a></p><p>Description: This adds a new exploit module for CVE-2026-23744, an unauthenticated command execution vulnerability in MCPJam Inspector. The module targets the /api/mcp/connect endpoint. Vulnerable versions accept a JSON serverConfig object containing a command and args array, then use those values to start an MCP server. When MCPJam Inspector is exposed on a routable interface, an unauthenticated remote attacker can abuse this behavior to execute operating system commands as the user running MCPJam Inspector.</p><h3>PaperCut NG/MF Unauthenticated RCE (CVE-2026-81578 + CVE-2026-82078)</h3><p>Author: sfewer-r7</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21842">#21842</a> contributed by <a href="https://github.com/sfewer-r7">sfewer-r7</a></p><p>Path: multi/http/papercut_ng_external_user_lookup_rce</p><p>CVE reference: <a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-82078/">CVE-2026-82078</a></p><p>Description: Adds an exploit module for the recent PaperCut MF and PaperCut NG exploit chain (CVE-2026-81578 + CVE-2026-82078) that was reported last week as a zero-day being actively exploited in the wild.</p><h3>SimpleHelp OIDC Authentication Bypass Remote Code Execution</h3><p>Authors: Blackpoint Cyber, Horizon3.ai, Zach Hanley, and jheysel-r7</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21825">#21825</a> contributed by <a href="https://github.com/jheysel-r7">jheysel-r7</a></p><p>Path: multi/http/simplehelp_oidc_auth_bypass_rce</p><p>CVE reference: <a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-48558/">CVE-2026-48558</a></p><p>Description: Adds an exploit module for CVE-2026-48558, an OIDC authentication bypass affecting SimpleHelp 5.5.0 through 5.5.15.</p><h3>SPIP Autosave Session Unauthenticated RCE</h3><p>Author: Julien Voisin</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21859">#21859</a> contributed by <a href="https://github.com/jvoisin">jvoisin</a></p><p>Path: multi/http/spip_autosave_rce</p><p>Description: Adds a module targeting an unauthenticated remote code execution vulnerability in SPIP &lt;= 4.4.21 via the forum autosave session handler. The action=session endpoint lets any visitor store arbitrary PHP code in a session variable, which is then executed by the template engine when the article page is rendered. No CVE has yet been issued.</p><h3>Next.js Unauthenticated RCE on Windows Servers</h3><p>Authors: Avishek Sarkar, Bogyeom Lee, and Maksim Rogov</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21834">#21834</a> contributed by <a href="https://github.com/vognik">vognik</a></p><p>Path: windows/http/nextjs_unauth_rce_cve_2026_75604</p><p>CVE reference: <a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-75604/">CVE-2026-75604</a></p><p>Description: Adds a module targeting CVE-2026-75604, a Remote Code Execution (RCE) vulnerability in Next.js applications hosted on Windows servers. Specifically crafted requests can execute arbitrary code on the target server running Next.js versions from 13.4.0 up to 15.5.24, and 16.0.0 up to 16.3.3.</p><h3>Boot Verification Program Persistence</h3><p>Author: Emanuele Cervelli</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21550">#21550</a> contributed by <a href="https://github.com/M4nu02">M4nu02</a></p><p>Path: windows/persistence/boot_verification_program</p><p>Description: Adds a Windows persistence module leveraging the registry key BootVerificationProgram.</p><h3>Windows Time Provider Persistence</h3><p>Author: Emanuele Cervelli</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21522">#21522</a> contributed by <a href="https://github.com/M4nu02">M4nu02</a></p><p>Path: windows/persistence/time_provider</p><p>Description: Adds a new persistence module that registers a custom Time Provider DLL under the W32Time service registry key.</p><h2>Bugs fixed (4)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21719">#21719</a> from <a href="https://github.com/Pushpenderrathore">Pushpenderrathore</a> - Fixes a race condition in the module Metadata cache.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21838">#21838</a> from <a href="https://github.com/jheysel-r7">jheysel-r7</a> - Fixes payload choosing behaviour when swapping targets to auto-select the most fitting payload which can now also include Java payloads.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21853">#21853</a> from <a href="https://github.com/Pushpenderrathore">Pushpenderrathore</a> - Three fixes to the core Rex::Proto::DNS forward/cache path that surface once the DNS server is used as a selective poisoner in front of a real upstream resolver</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21861">#21861</a> from <a href="https://github.com/prithvee07">prithvee07</a> - Fixes a recent regression in the vsftpd_234_backdoor module where by updating the module to support ARCH_CMD payloads we inadvertently dropped support for cmd/unix/interact payloads. Both payloads are now supported.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:2026-08-27T12%3A02%3A38%2B01%3A00..2026-09-09T21%3A03%3A01Z" target="_blank">Pull Requests 6.5.3…6.5.4</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.5.3%E2%80%A66.5.4">Full diff 6.5.3…6.5.4</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro.</a></p>]]></description>
      <link>https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-goes-to-sixteen</link>
      <guid isPermaLink="false">bltfbb6cf78885e22ee</guid>
      <category><![CDATA[Metasploit Weekly Wrapup]]></category>
      <category><![CDATA[Metasploit]]></category><dc:creator><![CDATA[Brendan Watters]]></dc:creator>
      <pubDate>Fri, 11 Sep 2026 13:35:11 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt0d50271a40a5f14f/6849ab419621d9f3824d5017/metasploit-sky.png" medium="image" />
    </item>
    <item>
      <title><![CDATA[The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment]]></title>
      <description><![CDATA[<h2 target="_blank" style="text-align: left;">Introduction</h2><p target="_blank" style="text-align: left;"><span style='font-size: undefined;'>The surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web channels, and various smaller niche marketplaces. Security teams today face evolving challenges, requiring them to continuously refine monitoring channels, adjust operational strategies, and foster cross-functional internal collaboration to capture actionable intelligence.</span></p><p target="_blank" style="text-align: left;"><span style='font-size: undefined;'>With fraud damages anticipated to approach </span><a href="https://verafin.com/nasdaq-verafin-global-financial-crime-report/" target="_blank"><span style='font-size: undefined;'>hundreds of billions of USD</span></a><span style='font-size: undefined;'>, security teams must navigate numerous non-compliant channels while ingesting and processing diverse data formats—such as documents, imagery, video, and unformatted text—linked to organizational assets. The recent introduction of a new </span><a href="https://ctid.mitre.org/fraud#/" target="_blank"><span style='font-size: undefined;'>Fraud framework</span></a><span style='font-size: undefined;'> by the MITRE organization underscores the critical need to combat fraud and highlights the significant danger these threat actors pose to all organizations. The MITRE organization has been taking a positive step towards standardizing the fight against fraud, while helping organizations target the relevant directions to look at. </span></p><p target="_blank" style="text-align: left;"><span style='font-size: undefined;'>These marketplaces supply a range of services in need for the novice fraudster, encompassing server infrastructure, targeted lists, and even support for money laundering facilitated through compromised accounts across various platforms. As larger, well-known marketplaces have been dismantled, smaller, specialized shops are experiencing heightened activity from buyers seeking to engage in fraudulent endeavors.</span></p><p target="_blank" style="text-align: left;"><span style='font-size: undefined;'>This blog post undertakes an exploration of these marketplaces and their operational modalities, illuminating the contemporary fraud economy and underscoring the enduring critical nature of robust detection and prevention initiatives.</span></p><h2 target="_blank" style="text-align: left;">Fraud-as-a-Service (FaaS)</h2><p target="_blank" style="text-align: left;"><span style='font-size: undefined;'>Fraud is broadly defined as an intentional, dishonest act or misrepresentation of material facts, calculated to deceive others in order to secure an unfair or unlawful gain. Consequently, the Fraud-as-a-Service (FaaS) model encompasses various vendors and digital storefronts that facilitate such activities by providing new tools, instructional guides, and ancillary services for fraudsters.</span></p><p target="_blank" style="text-align: left;"><span style='font-size: undefined;'>Online shops and marketplaces, such as Xleet, Blackpass, Infodig and Styx, provide a venue for contemporary fraudsters to acquire the necessary resources for whichever scheme they intend to execute. Users are able to purchase active accounts for online platforms, including major financial institutions, online dating services, and even AI platforms. In addition different offerings may include stolen PII, synthetic identity generator, and ready to use online infrastructure.</span></p><p target="_blank" style="text-align: left;"><span style='font-size: undefined;'>To satisfy shifting market demands, threat actors—alongside malware developers and marketplace administrators—continuously refine their products to optimize future monetization. Novice fraudsters often begin their journey by seeking instructional manuals on various forums or platforms like Styx. Once a strategy is established, they leverage diverse online shops and marketplaces to acquire the necessary infrastructure and credentials. These same venues frequently provide stolen personal or business data, which criminals then exploit during the monetization phase. A common tactic involves business email compromise (BEC) schemes designed to manipulate customers into transferring funds directly to accounts controlled by the fraudster.</span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7815801c15fe2600/6aa4053e8e00eb1dba5c8a16/infostealer-ad.png" alt="infostealer-ad.png" caption="Figure 1 - Ad for Infostealer with special detection for financial accounts" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="infostealer-ad.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7815801c15fe2600/6aa4053e8e00eb1dba5c8a16/infostealer-ad.png" data-sys-asset-uid="blt7815801c15fe2600" data-sys-asset-filename="infostealer-ad.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 1 - Ad for Infostealer with special detection for financial accounts" data-sys-asset-alt="infostealer-ad.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 1 - Ad for Infostealer with special detection for financial accounts</figcaption></div></figure><p>⠀</p><p style="direction: ltr;text-align: left;"><span style='font-size: undefined;'>As companies attempt to protect themselves from being taken advantage of by these fraudsters, they could gather troves of important intelligence about how the malicious actors think, and more importantly gain operational information about breaking fraud networks and protecting their ecosystems. Companies may utilize the available or purchased information into operational decisions, reducing the number of incidents, or at least hinder the fraudster’s attempts. </span></p><h2 style="direction: ltr;text-align: left;">MITRE Fraud Fighting Framework (F3)</h2><p style="direction: ltr;text-align: left;"><span style='font-size: undefined;'>Introduced in early 2026, the MITRE Fraud Fighting Framework (MITRE F3) is designed to help organizations recognize adversarial TTPs, and could help security teams prioritize relevant sources for monitoring through prioritization of attack vectors or vulnerabilities. Due to the large amount of available sources, such a framework could indeed help organizations create the best strategy.</span></p><p style="direction: ltr;text-align: left;"><span style='font-size: undefined;'>While the framework's structure mirrors traditional MITRE matrices, MITRE F3 expands into domains bridging cybersecurity and financial crime, specifically addressing the monetization stage. Although it introduces a novel perspective on fraud analysis, it does not sufficiently address the necessity of enhanced collaboration between an organization's internal departments.</span></p><p style="direction: ltr;text-align: left;"><span style='font-size: undefined;'>To obtain meaningful environmental insights, security, fraud, and financial crime teams must maintain constant surveillance of marketplaces and similar forums. Monitoring marketplaces for asset mentions is critical for early detection of threats and new trends targeting new victims.</span></p><h2 style="direction: ltr;text-align: left;">Key marketplaces and trends</h2><p style="direction: ltr;text-align: left;"><span style='font-size: undefined;'>Like other cybercrime-focused shops and forums, our monitored marketplaces also handle external threats targeting their clientele; some even use mirror sites. Similarly to other underground marketplaces, the key players must navigate themselves in an ever changing shattered environment where new marketplaces operate along alternative shopping methods through Telegram and P2P options.</span></p><p style="direction: ltr;text-align: left;"><span style='font-size: undefined;'>When examining the MITRE framework, we can immediately see many techniques in common–mostly account takeover (ATO) techniques. Nevertheless, as seen in the different stocks and sellers, the offerings changed with time according to market demands.</span></p><p style="direction: ltr;text-align: left;"><span style='font-size: undefined;'>There are some notable differences between Styx and the rest of the reported marketplaces, however. Styx operates by offering sellers more space for promoting their own personal shops, available mostly through Telegram.</span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt53a3b4ea087932c5/6aa4065e361ab348cb39858b/Styx-Marketplace-Seller-Page.png" alt="Styx-Marketplace-Seller-Page.png" caption="Figure 2 - Styx marketplace seller page" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Styx-Marketplace-Seller-Page.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt53a3b4ea087932c5/6aa4065e361ab348cb39858b/Styx-Marketplace-Seller-Page.png" data-sys-asset-uid="blt53a3b4ea087932c5" data-sys-asset-filename="Styx-Marketplace-Seller-Page.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 2 - Styx marketplace seller page" data-sys-asset-alt="Styx-Marketplace-Seller-Page.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 2 - Styx marketplace seller page</figcaption></div></figure><p style="text-align: center;direction: ltr;">⠀</p><p style="text-align: left;direction: ltr;"><span style='font-size: undefined;'>Styx also aims to cultivate a specialized community through their "freemium" model, where premium, high-value content is reserved for users willing to pay significant fees.</span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt6f2654e123ad6a10/6aa406a37c24e5f6e3d4b234/Styx-Marketplace-Private-Section.png" alt="Styx-Marketplace-Private-Section.png" caption="Figure 3 - Styx Marketplace Private Section" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Styx-Marketplace-Private-Section.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt6f2654e123ad6a10/6aa406a37c24e5f6e3d4b234/Styx-Marketplace-Private-Section.png" data-sys-asset-uid="blt6f2654e123ad6a10" data-sys-asset-filename="Styx-Marketplace-Private-Section.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 3 - Styx Marketplace Private Section" data-sys-asset-alt="Styx-Marketplace-Private-Section.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 3 - Styx Marketplace Private Section</figcaption></div></figure><p style="text-align: center;direction: ltr;">⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>While some of the free manuals have been posted through different cybercrime forums before, they show not only a real attempt by the Styx admins to generate additional income, but also sell ad space for different sellers working outside of the marketplace. These monetization techniques indicate the admins are probably well aware they have many competitors, as they attempt to provide a different shopping experience for their users.</span></p><h2 style="direction: ltr;">Resource development: Infrastructure</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Infrastructure for cybercrime operations has been sold for a long time, offering adversaries illegal access to active domains, cpanels, and more.</span></p><p style="direction: ltr;">One of the leading marketplaces for such items is Xleet, first observed in 2022, which has quickly become a source for large collections of stolen credentials spanning multiple platforms. Distinguishing itself from other monitored marketplaces, Xleet is transparent about its offerings, frequently including evidence like screenshots or even email proof sent to the compromised account's email address.</p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltd87ac10fd1463db9/6aa407dadcc13f72d64f6c58/mailers-infrastructure-for-sale.png" alt="mailers-infrastructure-for-sale.png" caption="Figure 4 - Mailer infrastructure available for sale" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="mailers-infrastructure-for-sale.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltd87ac10fd1463db9/6aa407dadcc13f72d64f6c58/mailers-infrastructure-for-sale.png" data-sys-asset-uid="bltd87ac10fd1463db9" data-sys-asset-filename="mailers-infrastructure-for-sale.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 4 - Mailer infrastructure available for sale" data-sys-asset-alt="mailers-infrastructure-for-sale.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 4 - Mailer infrastructure available for sale</figcaption></div></figure><p style="text-align: center;direction: ltr;">⠀</p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt3ddc1eab27d18a2a/6aa4082fb15ff94d6ccc4a41/SMPT-infrastructure-for-sale.png" alt="SMPT-infrastructure-for-sale.png" caption="Figure 5 - SMTP infrastructure available for sale" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="SMPT-infrastructure-for-sale.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt3ddc1eab27d18a2a/6aa4082fb15ff94d6ccc4a41/SMPT-infrastructure-for-sale.png" data-sys-asset-uid="blt3ddc1eab27d18a2a" data-sys-asset-filename="SMPT-infrastructure-for-sale.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 5 - SMTP infrastructure available for sale" data-sys-asset-alt="SMPT-infrastructure-for-sale.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 5 - SMTP infrastructure available for sale</figcaption></div></figure><p>⠀</p><p style="direction: ltr;text-align: left;"><span style='font-size: undefined;'>Access to SMTP servers could help fraudsters reach larger audiences and evade different email protection and filtering services, thus improving success rate for different schemes. Xleet also offers alleged access to protected networks through Cpanel, web shells, SSH, and RDP connections, as well as VoIP access through their accounts:</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt0b086442c9c5924d/6aa408715ef72d641dc937ae/voip-for-sale-xleet.png" alt="voip-for-sale-xleet.png" caption="Figure 6 - VoIP access available for sale through Xleet" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="voip-for-sale-xleet.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt0b086442c9c5924d/6aa408715ef72d641dc937ae/voip-for-sale-xleet.png" data-sys-asset-uid="blt0b086442c9c5924d" data-sys-asset-filename="voip-for-sale-xleet.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 6 - VoIP access available for sale through Xleet" data-sys-asset-alt="voip-for-sale-xleet.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 6 - VoIP access available for sale through Xleet</figcaption></div></figure><p style="text-align: center;direction: ltr;">⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>BlackPass is another marketplace offering RDP credentials, as well as proxy services used by malicious actors for veiling their location or, as mentioned above, bypassing different restrictions on their IP addresses.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Blackpass, initially named 'Paysell,' emerged as one of the first known online marketplaces dedicated to selling compromised accounts. Estimates suggest this platform has facilitated the sale of hundreds of millions of accounts. Legal documents indicate the marketplace is controlled by Russian cybercriminals, a detail consistent with its product focus: items exclusively targeting Western countries, particularly the US.</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltbdd972ace3def2ec/6aa408c304494bcc6f0a110d/designated-infrastucture-blackpass.png" alt="designated-infrastucture-blackpass.png" caption="Figure 7 - Designated infrastructure for sale on Blackpass" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="designated-infrastucture-blackpass.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltbdd972ace3def2ec/6aa408c304494bcc6f0a110d/designated-infrastucture-blackpass.png" data-sys-asset-uid="bltbdd972ace3def2ec" data-sys-asset-filename="designated-infrastucture-blackpass.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 7 - Designated infrastructure for sale on Blackpass" data-sys-asset-alt="designated-infrastucture-blackpass.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 7 - Designated infrastructure for sale on Blackpass</figcaption></div></figure><p style="text-align: center;direction: ltr;">⠀</p><p style="direction: ltr;text-align: left;"><span style='font-size: undefined;'>All of these vulnerable environments could be part of a bigger scheme run by fraudsters, leading to other techniques being executed like a new vendor set up.</span></p><p style="direction: ltr;text-align: left;">Another marketplace, Infodig, would offer different phone infrastructure in the past as mentioned in one of their opening posts on a cybercrime forum. Foreign or stolen numbers could be used for receiving or intercepting OTP messages, forging IT calls to employees, or self registering new accounts for other services.</p><p style="direction: ltr;text-align: left;"><span style='font-size: undefined;'>Infodig has recently revamped some services offered, including the phone infrastructure, having been removed completely around the end of 2025 during an update the marketplace went through.</span></p><p style="text-align: justify;direction: ltr;"><span style='font-size: undefined;'><strong> </strong></span></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt4ff68b15bd55e22d/6aa40b8a2a8ab63cb24267ed/designated-infrastructure-for-sale-infodig.png" alt="designated-infrastructure-for-sale-infodig.png" caption="Figure 8 - Designated infrastructure for sale on Infodig" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="designated-infrastructure-for-sale-infodig.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt4ff68b15bd55e22d/6aa40b8a2a8ab63cb24267ed/designated-infrastructure-for-sale-infodig.png" data-sys-asset-uid="blt4ff68b15bd55e22d" data-sys-asset-filename="designated-infrastructure-for-sale-infodig.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 8 - Designated infrastructure for sale on Infodig" data-sys-asset-alt="designated-infrastructure-for-sale-infodig.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 8 - Designated infrastructure for sale on Infodig</figcaption></div></figure><p style="text-align: center;direction: ltr;">⠀</p><p style="text-align: left;direction: ltr;"><span style='font-size: undefined;'>Styx also offers many options for fraudsters looking for ready to use infrastructure including eSIMs, VoIP services, and compromised VPN accounts. Localized SIM cards could be used by fraudsters for many reasons such as account creation but more importantly as a way to strengthen claims when confronting modern anti-fraud solutions, thus improving scam success rates.</span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt80fcc1f5e3c12551/6aa409ab58ee9d584558e4d1/Styx-VoIP-eSIMs.png" height="855" alt="Styx-VoIP-eSIMs.png" caption="Figure 9 - Styx VoIP and eSIM section" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Styx-VoIP-eSIMs.png" width="1363" style="width: 1363px; height: 855px" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt80fcc1f5e3c12551/6aa409ab58ee9d584558e4d1/Styx-VoIP-eSIMs.png" data-sys-asset-uid="blt80fcc1f5e3c12551" data-sys-asset-filename="Styx-VoIP-eSIMs.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 9 - Styx VoIP and eSIM section" data-sys-asset-alt="Styx-VoIP-eSIMs.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 9 - Styx VoIP and eSIM section</figcaption></div></figure><p style="text-align: center;direction: ltr;">⠀</p><p style="text-align: left;">The same marketplaces offer additional stolen, forged, and even active company documents for sale including incorporation forms, US tax forms, and other various products connected to shelf companies and stolen PII. These documents allow threat actors to generate troves of mule accounts, shelf corporations, and even combine them into money laundering networks.</p><h2>Acquiring access</h2><p style="text-align: left;"><span style='font-size: undefined;'>Stolen, self-registered (self-reg), or user-sold accounts are high-demand assets in underground markets. By acquiring pre-existing accounts that have already circumvented anti-fraud protections, threat actors can rapidly deploy them for various criminal operations.</span></p><p style="text-align: left;"><span style='font-size: undefined;'>These platforms provide access to a wide range of services, from financial institutions and streaming providers to dating sites and AI-driven website builders. Novice fraudsters often utilize these resources to secure quick profits or to stockpile accounts for future resale.</span></p><p style="text-align: left;"><span style='font-size: undefined;'>For example, Blackpass features an extensive account inventory that includes regional banks, neo-banks, and major corporations. Pricing within these markets is fluid; however, self-reg accounts typically represent the most expensive tier due to the significant labor required for their initial setup.</span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta523a6cb6b16b452/6aa40a04e96fa6dd19785323/self-reg-for-sale.png" height="716" alt="self-reg-for-sale.png" caption="Figure 10 - Self-reg item available for sale" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="self-reg-for-sale.png" width="1559" style="width: 1559px; height: 716px" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta523a6cb6b16b452/6aa40a04e96fa6dd19785323/self-reg-for-sale.png" data-sys-asset-uid="blta523a6cb6b16b452" data-sys-asset-filename="self-reg-for-sale.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 10 - Self-reg item available for sale" data-sys-asset-alt="self-reg-for-sale.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 10 - Self-reg item available for sale</figcaption></div></figure><p style="text-align: center;direction: ltr;">⠀</p><p style="text-align: left;direction: ltr;"><span style='font-size: undefined;'>Xleet provides an extensive accounts division that covers a broad spectrum of common targets, including gaming, streaming, and dating service profiles. These specific credentials serve as high-value assets for executing various "pig butchering" fraud operations. Furthermore, a notable emerging trend within this marketplace is the significant surge in available credentials for AI platforms, especially those focused on accelerated website creation.</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt9b237468b020054e/6aa40a3fa4ecdf1201ca7759/streaming-accounts-for-sale.png" alt="streaming-accounts-for-sale.png" caption="Figure 11 - Streaming accounts for sale, including proof" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="streaming-accounts-for-sale.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt9b237468b020054e/6aa40a3fa4ecdf1201ca7759/streaming-accounts-for-sale.png" data-sys-asset-uid="blt9b237468b020054e" data-sys-asset-filename="streaming-accounts-for-sale.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 11 - Streaming accounts for sale, including proof" data-sys-asset-alt="streaming-accounts-for-sale.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 11 - Streaming accounts for sale, including proof</figcaption></div></figure><p style="text-align: center;direction: ltr;"><span style='font-size: undefined;'><em></em></span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The newer type of marketplace, active since 2023, features an unorthodox design and much higher prices for their products. Styx holds the usual stock including stolen or self-reg accounts for a large variety of services, including financial institutions, social media accounts, streaming services, and casinos or other gambling sites.</span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc5476a9ae4a3f7b3/6aa40b0b5ceda95d76dadd2c/image3.png" alt="styx-marketplace.png" caption="Figure 12 - Styx marketplace" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="styx-marketplace.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc5476a9ae4a3f7b3/6aa40b0b5ceda95d76dadd2c/image3.png" data-sys-asset-uid="bltc5476a9ae4a3f7b3" data-sys-asset-filename="image3.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 12 - Styx marketplace" data-sys-asset-alt="styx-marketplace.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 12 - Styx marketplace</figcaption></div></figure><p style="text-align: left;">⠀</p><p style="text-align: left;"><span style='font-size: undefined;'>The inventory at Infodig is categorized into several distinct sections, featuring stealer logs alongside stolen Financial Information and Personal Identifiable Information (PII), such as Social Security numbers. Their accounts division has recently been going through some technical or supply issues and there are no current accounts available. However the marketplace has revamped their target list section into a new ULP (URL:LOGIN:PASS), offering a new targeted option for large scale ATO operations.</span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltce0f913f467212ce/6aa40ba35ef72d3e15c937d2/new-ulp-section-infodig.png" alt="new-ulp-section-infodig.png" caption="Figure 13 - New ULP section for Infodig" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="new-ulp-section-infodig.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltce0f913f467212ce/6aa40ba35ef72d3e15c937d2/new-ulp-section-infodig.png" data-sys-asset-uid="bltce0f913f467212ce" data-sys-asset-filename="new-ulp-section-infodig.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 13 - New ULP section for Infodig" data-sys-asset-alt="new-ulp-section-infodig.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 13 - New ULP section for Infodig</figcaption></div></figure><h2>Monetization</h2><p style="text-align: left;"><span style='font-size: undefined;'>Styx has gained notoriety for its support of various "cashout" operations, which are prominently featured in numerous service advertisements throughout the platform.</span></p><p style="text-align: left;"><span style='font-size: undefined;'>By functioning as a hybrid of a marketplace and a forum, Styx provides a unique platform where merchants can offer specialized cashout services that exploit financial institutions across different payment rails. These merchants utilize various business accounts to assist fraudsters in laundering illicit funds through established methods, including payroll schemes, ACH transfers, and refund scams targeting multiple banks and geographic regions.</span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blte8ed539761539485/6aa40bcfa4ecdf2950ca776d/styx-cashout-ad.png" alt="styx-cashout-ad.png" caption="Figure 14 - Styx marketplace cashout ad" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="styx-cashout-ad.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blte8ed539761539485/6aa40bcfa4ecdf2950ca776d/styx-cashout-ad.png" data-sys-asset-uid="blte8ed539761539485" data-sys-asset-filename="styx-cashout-ad.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 14 - Styx marketplace cashout ad" data-sys-asset-alt="styx-cashout-ad.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 14 - Styx marketplace cashout ad</figcaption></div></figure><p style="text-align: left;">⠀</p><p style="text-align: left;"><span style='font-size: undefined;'>Beyond explicit solicitations for these services, marketplaces provide a variety of other products that are frequently exploited for money laundering. The exploitation of online gambling platforms remains a prevalent tactic for fraudsters, particularly as new regulations across the US lead to more states and companies entering the market. By acquiring stolen or synthetic PII, malicious actors can establish new gambling accounts to facilitate the laundering of illicit funds through techniques like chip dumping and minimal gameplay.</span></p><h2>Conclusion</h2><p style="text-align: left;"><span style='font-size: undefined;'>The fraud economy is changing at a fast pace with new techniques and players entering the field every day. By examining the different marketplaces portrayed in this blog post, we can see that they all react and appeal to different market needs. </span></p><p style="text-align: left;"><span style='font-size: undefined;'>The change seen through available items across shops are a clear indication of this, as marketplaces pivot towards a larger crowd–one lacking the deep technical knowledge of the earlier fraudsters and carders. The different marketplaces allow every new fraudster to purchase their entire infrastructure for the fraud kill chain, from target lists, servers, and even support for laundering illegal income. Other online services include rapid AI creation of phishing threats, or other forms of abuse of legitimate service through stolen credentials. Marketplaces are not solely made for direct use and other threat actors view them as a major supplier for their shops as well, due to their fixed prices for items with prices which could easily be inflated through their personal shops as seen below:</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt424c7bdf9568eace/6aa40c69f548684cd4812c6f/image10.png" alt="steaming-account-fraud-shop.png" caption="Figure 15 - Specialized shop for streaming accounts" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="steaming-account-fraud-shop.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt424c7bdf9568eace/6aa40c69f548684cd4812c6f/image10.png" data-sys-asset-uid="blt424c7bdf9568eace" data-sys-asset-filename="image10.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 15 - Specialized shop for streaming accounts" data-sys-asset-alt="steaming-account-fraud-shop.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 15 - Specialized shop for streaming accounts</figcaption></div></figure><p>⠀</p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1a9fee7443eb58bc/6aa40c8ca824f6548300e52e/image8.png" alt="telegram-fraud-account-shop.png" caption="Figure 16 - Specializing account shop on Telegram" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="telegram-fraud-account-shop.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1a9fee7443eb58bc/6aa40c8ca824f6548300e52e/image8.png" data-sys-asset-uid="blt1a9fee7443eb58bc" data-sys-asset-filename="image8.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 16 - Specializing account shop on Telegram" data-sys-asset-alt="telegram-fraud-account-shop.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 16 - Specializing account shop on Telegram</figcaption></div></figure><p style="text-align: left;">⠀</p><p style="text-align: left;"><span style='font-size: undefined;'>As fraud communities and groups become increasingly fragmented, the industry continues to splinter into smaller shops. These new, smaller marketplaces often require an invitation or administrator approval to join, a tactic designed to impede investigations and extend the lifespan of their fraudulent products. This shift to smaller shops also benefits merchants, allowing them to keep 100% of their profits instead of sharing them with marketplace administrators. Targeted companies should continue to monitor the marketplaces as they continue to function as an important link in the fraud supply chain. Threat actors are very aware and understand a major part of every business is the profit, therefore financial crime services and associated accounts are continuing to evolve.  </span></p><p style="text-align: left;"><span style='font-size: undefined;'>Nevertheless, underground marketplaces will continue to operate as an important part of the cybercrime economic system. Smaller merchants may use these larger stores as suppliers for their smaller shops, as second income or even double or triple their income by selling the same stock in multiple locations. However companies should not only be aware of these underground ‘malls’, and regularly monitor them for any suspicious findings, but take a more proactive approach. The evolving nature of fraud demands a stronger reaction from organizations as well as cooperation from security, financial crime, and compliance teams for proactive measures against these threats.</span></p><p style="text-align: left;"><span style='font-size: undefined;'>Targeted companies, especially financial institutions or gambling providers, should actively investigate stolen accounts and gather vital intelligence for protecting themselves in the future, making it more difficult for threat actors to abuse their payment rails, brands, and customers. </span></p><h2>What organizations should do</h2><p style="text-align: left;"><span style='font-size: undefined;'>To safeguard both their infrastructure and clients, security teams must move beyond monitoring disparate data streams and actively align with internal fraud and financial crime units to cultivate actionable intelligence. Because illicit merchants rely on marketing their offerings, security analysts should actively communicate with threat actors, purchase account samples, as well as analyze images or videos to map threat actor networks, verify operational legitimacy, and finally deploy targeted security countermeasures. Threat actors are threatening organizations with more than just data exfiltration, with compliance or financial crime requirements, companies become more vulnerable to newer forms of threats, not commonly associated with security teams, but initiating through cybercrime sources.</span></p><p style="text-align: left;"><span style='font-size: undefined;'>By proactively identifying leaked assets, correlating them to their own environments, and responding quickly through credential resets, and fraud monitoring, organizations can significantly reduce both financial losses and downstream risks such as ATO, and money laundering.</span></p>]]></description>
      <link>https://www.rapid7.com/blog/post/tr-fraud-ecosystem-fragmenting-marketplaces</link>
      <guid isPermaLink="false">bltdf5694eabdad65a8</guid>
      <category><![CDATA[Threat Intel]]></category><dc:creator><![CDATA[Gal Givon]]></dc:creator>
      <pubDate>Fri, 11 Sep 2026 13:33:33 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt83e3180716d766f0/69b180eb669f1ce1a02fe1aa/Purple-teaming-in-2026-hero.jpg" medium="image" />
    </item>
    <item>
      <title><![CDATA[Credentialed Pre-Port Discovery: Don't Probe the Host, Ask it]]></title>
      <description><![CDATA[<p style="direction: ltr;"><span style='font-size: undefined;'>If your scan engine already holds credentials for a host, it can ask that host which ports are open instead of probing for them.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Every scan begins with the same question: which ports on this host are open? Everything after it, from identifying services to checking for vulnerabilities to evaluating policy, depends on the answer being right. The traditional answer comes from the outside: the scan engine sends traffic to a range of ports and infers each port's state from how the host responds. That approach is the industry standard, and it works well when a clear network path exists between the engine and the host. Hardened hosts can stay silent rather than replying, which forces the engine to wait out timeouts. Rate limiting and intrusion prevention can throttle a burst of probes, and genuinely open ports go missing when they do. Large port ranges take time to cover thoroughly, and that time comes out of your scan window.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>There is a more direct route on any host where the scan engine already holds valid credentials: ask the host itself. This is credentialed discovery, so a credential that matches the host is the precondition for everything that follows. The engine connects to the port that credential uses, authenticates with a credential you already manage, and the host's operating system returns an authoritative list of the ports it is listening on. That list covers both TCP and UDP ports. There is no probing, no inference, and nothing to wait out.</span></p><h2 style="direction: ltr;">Three things to know before enabling pre-port discovery</h2><ol><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Pre-port discovery can report ports that a firewall or other network control stops your scan engine from reaching, and on those hosts you get fewer results and a longer scan.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>SSH and the Scan Assistant are tried on their standard ports, TCP 22 and TCP 21047, unless you set a different port on the credential's restriction.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Credential coverage decides which hosts benefit, and a host with no matching credential falls back to a network port scan.</span></p></li></ol><p style="direction: ltr;"><span style='font-size: undefined;'>Each of these is covered in full in the </span><a href="https://docs.rapid7.com/insightvm/enable-credentialed-pre-port-discovery/#before-you-begin"><span style='font-size: undefined;'>configuration and troubleshooting documentation</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Why probing from the outside can hit a wall</h2><p style="direction: ltr;"><span style='font-size: undefined;'>A network port scan works by inference. The engine sends traffic to each port in a configured range and reads the host's response, or its silence, as evidence about that port's state. Inference is the whole method, and its accuracy depends on the path between the engine and the host behaving predictably.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Several common conditions break that assumption. A hardened host that drops unsolicited traffic instead of refusing it gives the engine nothing to work with, so the engine waits for a timeout and then records an ambiguous result. Rate limiting and intrusion prevention are built to react to exactly the traffic pattern a port scan produces, and a throttled probe looks the same to the engine as a closed port. Wide port ranges make both problems worse, because every additional port is another probe, another possible timeout, and more scan time.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The outcome is a picture that can be partial on one scan and different on the next, on the hosts where an accurate picture matters most.</span></p><h2 style="direction: ltr;">If you already have credentials, ask the host</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Credentialed pre-port discovery replaces that inference with a question, and it is available from version 8.58. The engine connects to the port a credential uses, authenticates, and reads the list of listening ports from the host. For any host where that succeeds, the engine skips the network port scan and moves straight to examining the ports the host reported. That is what pre-port discovery means: discovering ports before, and in place of, the network port scan.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>There is nothing new to deploy, because pre-port discovery reuses the credentials you already configure for authenticated scanning. You do not have to choose a method: when more than one credential fits a host, the engine prefers the Scan Assistant, then SSH, then a direct Windows connection, and it uses the first one that authenticates.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>A host with no matching credential, or one where authentication does not succeed, falls back to a network port scan automatically, and that fallback is not reported as an error.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The option is a per-template checkbox under Asset Discovery, and it is off by default. Everything after port discovery is unchanged: fingerprinting, vulnerability checks, and policy evaluation run as they do today. The </span><a href="https://docs.rapid7.com/insightvm/enable-credentialed-pre-port-discovery/#enable-pre-port-discovery"><span style='font-size: undefined;'>configuration guide</span></a><span style='font-size: undefined;'> has the console and REST API steps.</span></p><h2 style="direction: ltr;">Pre-port discovery's trade-off, stated plainly</h2><p style="direction: ltr;"><span style='font-size: undefined;'>A host reports what it is listening on, and it has no way of knowing what sits between it and your scan engine. A network port scan never ran into that, because it only ever reported a port it could actually reach. Pre-port discovery trades that outside-in view for the host's authoritative inside-out view, and the trade has a cost worth understanding first.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>After discovery, the engine still connects to each reported port to identify the service on it. A port the engine cannot reach has to time out before the engine moves on. Three things follow on that host: no service is identified on the unreachable port, the scan takes longer, and the engine can read repeated connection failures as a sign that the host has stopped responding. In that case it stops examining the host early and reports a finding saying the host scan was terminated because of excessive connection errors.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The finding describes the engine's experience of the host, not the health of the host. The port is genuinely open, and the host answered every question pre-port discovery asked it. The </span><a href="https://docs.rapid7.com/insightvm/enable-credentialed-pre-port-discovery/#troubleshooting" target="_blank"><span style='font-size: undefined;'>troubleshooting documentation</span></a><span style='font-size: undefined;'> covers what can block the path and </span><a href="https://docs.rapid7.com/insightvm/enable-credentialed-pre-port-discovery/#before-you-begin" target="_blank"><span style='font-size: undefined;'>how to test reachability</span></a><span style='font-size: undefined;'> from the engine.</span></p><h2 style="direction: ltr;">Who should turn on pre-port discovery?</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Pre-port discovery is a good fit where the scan engine has broad network reachability to the hosts it scans, and where you already use SSH, Scan Assistant, or Windows credentials for authenticated scanning. It pays off most on hardened or rate-limited hosts and on large port ranges, which are the cases where a network port scan has been slow or inconsistent. A responsive host on a fast network may show little difference.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Approach it with more care where the engine is deliberately segmented from the hosts it scans and allowed through on only specific ports, or where the firewall rules between the engine and those hosts are restrictive or not fully known. In those environments, confirm reachability first, or keep using the network port scan.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Because this is a per-template setting, both approaches can coexist: a pre-port discovery template for the estate your engine can reach broadly, and a standard template for the hosts that segmentation deliberately keeps at a distance.</span></p><h2 style="direction: ltr;">Try it on one template</h2><p style="direction: ltr;"><span style='font-size: undefined;'>One template at a time is the easiest way to judge the difference. Enable pre-port discovery on a single template, scan a representative group of hosts with it, and compare the results against what those same hosts returned before. If the port lists and the scan times look the way you expect, widen it from there. The configuration and troubleshooting guide has the details.</span></p><h2 style="direction: ltr;">Further reading</h2><p style="direction: ltr;"><a href="https://docs.rapid7.com/insightvm/enable-credentialed-pre-port-discovery/" target="_blank"><span style='font-size: undefined;'>Credentialed pre-port discovery</span></a><span style='font-size: undefined;'>: How to enable it in the console and over the REST API, how it picks a credential and a port, what your template's port settings still control, and what to check when a host does not behave the way you expect.</span></p>]]></description>
      <link>https://www.rapid7.com/blog/post/pt-credentialed-pre-port-discovery-asking-host</link>
      <guid isPermaLink="false">blt9a682ab8a23b8820</guid>
      <category><![CDATA[Vulnerability Management]]></category><dc:creator><![CDATA[Conor McCormick]]></dc:creator>
      <pubDate>Wed, 09 Sep 2026 15:16:34 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt09a532eac4a02570/6852c5968e72c44b89691ca4/PSN-gov-showcase-hero-image-2.png" medium="image" />
    </item>
    <item>
      <title><![CDATA[Patch Tuesday - September 2026]]></title>
      <description><![CDATA[<p style="direction: ltr;"><span style='font-size: undefined;'>Microsoft is publishing 974 own-product vulnerabilities on </span><a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Sep"><span style='font-size: undefined;'>September 2026 Patch Tuesday</span></a><span style='font-size: undefined;'>, including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Windows ALPC: zero-day EoP</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>The eternal game of elevation of privilege whack-a-mole between Microsoft and attackers continues. This month, the battle is centered on the Windows Advanced Local Procedure Call (ALPC) mechanism, a kernel capability that facilitates inter-process communication. Microsoft is aware of exploitation in the wild already. Successful abuse of the flaw underlying </span><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-85880"><span style='font-size: undefined;'>CVE-2026-85880</span></a><span style='font-size: undefined;'> grants an attacker SYSTEM via a buffer overflow that enables an out-of-bounds write, and as we all know by now, this is exactly what would happen during the first five minutes of a technically accurate horror movie about ransomware. We can infer one silver lining here: since neither Server 2025 nor Windows 11 receives patches for CVE-2026-85880, it is likely that Microsoft’s ongoing efforts to level up memory safety by rewriting critical kernel components in Rust are paying off.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Windows Update Stack: zero-day EoP</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Attackers disappointed by Microsoft’s move towards memory safety improvements for various critical kernel components need not leave empty-handed today. Microsoft is aware of existing exploitation in the wild for </span><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963"><span style='font-size: undefined;'>CVE-2026-81963</span></a><span style='font-size: undefined;'>, an elevation of privilege vulnerability in the Windows Update Stack that leads to SYSTEM privileges via improper link resolution. All supported versions of Windows receive a patch, which presumably tightens up controls to prevent the Windows Update Stack from following a malicious link and overwriting a system component with an attacker-controlled imposter. The relatively pedestrian CVSS v3 base score of 7.8 is no reason for less concern, since no serious attacker will bother developing an intricate one-shot RCE when a two-stage attack chain consisting of low-privileged local access coupled with elevation of privilege will achieve the same ultimate goal much more easily.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Living on the Edge: browser advisory uncertainty</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>For the second month in a row, Microsoft does not appear to have published any desktop browser security advisories between the start of the month and Patch Tuesday. Microsoft Edge is built on top of Google’s open-source Chromium project, and on September 3, 2026, Google Chrome patched CVE-2026-85046, an exploited-in-the-wild zero-day vulnerability in the V8 JavaScript engine relied upon by both Edge and Chrome. So, is Microsoft Edge falling dangerously behind Google Chrome? Well, maybe. In this specific case, the Edge stable channel did receive a patch a day earlier than Chrome on September 2, 2026, and we know this because </span><a href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#september-2-2026"><span style='font-size: undefined;'>the Edge release notes mention it</span></a><span style='font-size: undefined;'>. However, almost a week later, Microsoft still hasn’t published a </span><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-85046"><span style='font-size: undefined;'>security advisory for CVE-2026-85046</span></a><span style='font-size: undefined;'>, and until that URL returns something better than a 404, that will remain true. In short: if you’re patched, you are protected, but if you rely on advisories to know which vulns exist, you could miss this zero-day vulnerability altogether. Only Microsoft knows why this advisory is missing, but there is no reason to suppose that Microsoft is somehow immune to the pressures that come along with the vast increase in vulnerability volume. A patch without an advisory is perhaps marginally better than an advisory without a patch, but keeping track of exposures without reliable advisory materials is not straightforward. Chrome patched 11 other vulnerabilities at the same time as CVE-2026-85046, but it’s not yet clear if those are patched in Edge. Until Microsoft sets the record straight, the only safe assumption is that these vulnerabilities (e.g. </span><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-85045"><span style='font-size: undefined;'>CVE-2026-85045</span></a><span style='font-size: undefined;'>) remain unpatched in Edge.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Microsoft lifecycle update</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>The next Microsoft product lifecycle changes with broad impact occur on October 14, 2026, when </span><a href="https://learn.microsoft.com/en-us/lifecycle/products/windows-11-home-and-pro"><span style='font-size: undefined;'>Windows 11 24H2 Home & Pro</span></a><span style='font-size: undefined;'> reach end of servicing, and </span><a href="https://learn.microsoft.com/en-us/lifecycle/products/windows-server-2022"><span style='font-size: undefined;'>Windows Server 2022</span></a><span style='font-size: undefined;'> moves to extended support, with free critical security updates continuing, but no further feature development. At the same time, the final curtain falls for </span><a href="https://learn.microsoft.com/en-us/lifecycle/products/windows-server-2012"><span style='font-size: undefined;'>Windows Server 2012</span></a><span style='font-size: undefined;'> and </span><a href="https://learn.microsoft.com/en-us/lifecycle/products/windows-server-2012-r2"><span style='font-size: undefined;'>2012 R2</span></a><span style='font-size: undefined;'> with the expiry of the third and final year of cash-for-updates Extended Security Update (ESU) program for these aging workhorses. </span><a href="https://learn.microsoft.com/en-us/lifecycle/products/office-2021"><span style='font-size: undefined;'>Office 2021</span></a><span style='font-size: undefined;'> also moves beyond support, including the </span><a href="https://learn.microsoft.com/en-us/lifecycle/products/office-ltsc-2021"><span style='font-size: undefined;'>Long-Term Servicing Channel</span></a><span style='font-size: undefined;'>, with no ESU available in that case. Also in October, Exchange Server 2016 and 2019 will join the “no ESU” club, after two previous six-month reprieves. Presumably, Microsoft really means it this time.</span></p><h2>Summary charts</h2><figure style="margin: 0"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta406d0d7c948904c/6aa0912b075f9772233e406f/2026-09-vuln_count_component.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="2026-09-vuln_count_component.png" asset-alt="2026-09-vuln_count_component.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta406d0d7c948904c/6aa0912b075f9772233e406f/2026-09-vuln_count_component.png" data-sys-asset-uid="blta406d0d7c948904c" data-sys-asset-filename="2026-09-vuln_count_component.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="2026-09-vuln_count_component.png" sys-style-type="display"/></figure><figure style="margin: 0"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt015997cad759a6ee/6aa0912b346a4b7caf408ec5/2026-09-vuln_count_impact-component-heatmap.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="2026-09-vuln_count_impact-component-heatmap.png" asset-alt="2026-09-vuln_count_impact-component-heatmap.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt015997cad759a6ee/6aa0912b346a4b7caf408ec5/2026-09-vuln_count_impact-component-heatmap.png" data-sys-asset-uid="blt015997cad759a6ee" data-sys-asset-filename="2026-09-vuln_count_impact-component-heatmap.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="2026-09-vuln_count_impact-component-heatmap.png" sys-style-type="display"/></figure><figure style="margin: 0"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1328a6d59dc671f0/6aa0912b2707c51ef032b655/2026-09-vuln_count_impact.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="2026-09-vuln_count_impact.png" asset-alt="2026-09-vuln_count_impact.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1328a6d59dc671f0/6aa0912b2707c51ef032b655/2026-09-vuln_count_impact.png" data-sys-asset-uid="blt1328a6d59dc671f0" data-sys-asset-filename="2026-09-vuln_count_impact.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="2026-09-vuln_count_impact.png" sys-style-type="display"/></figure><p></p><h2>Summary tables</h2><p></p><h3>Apps vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80097">CVE-2026-80097</a></td><td><p>Microsoft Authenticator Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-58611">CVE-2026-58611</a></td><td><p>Xbox Gaming Services Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr></tbody></table><h3>Azure vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70352">CVE-2026-70352</a></td><td><p>Azure AI Language Elevation of Privilege Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>10.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62895">CVE-2026-62895</a></td><td><p>Azure Arc SQL Server Extension Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69857">CVE-2026-69857</a></td><td><p>Azure Cosmos DB Spoofing Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77909">CVE-2026-77909</a></td><td><p>Azure CycleCloud Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81349">CVE-2026-81349</a></td><td><p>Azure HDInsight Ambari Elevation of Privilege Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>7.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83941">CVE-2026-83941</a></td><td><p>Entra ID Elevation of Privilege Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>9.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84003">CVE-2026-84003</a></td><td><p>Microsoft Authentication Library (MSAL) for Node.js Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83711">CVE-2026-83711</a></td><td><p>Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>10.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83948">CVE-2026-83948</a></td><td><p>Microsoft Azure CLI Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62906">CVE-2026-62906</a></td><td><p>Microsoft Discovery Studio Information Disclosure Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>7.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62916">CVE-2026-62916</a></td><td><p>Microsoft Entra ID Elevation of Privilege Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>9.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69854">CVE-2026-69854</a></td><td><p>Spring Cloud Azure Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>9.0</p></td></tr></tbody></table><h3>Browser vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84323">CVE-2026-84323</a></td><td><p>Chromium: CVE-2026-84323 Missing authorization in FileSystem</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84324">CVE-2026-84324</a></td><td><p>Chromium: CVE-2026-84324 Use after free in Proxy</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84325">CVE-2026-84325</a></td><td><p>Chromium: CVE-2026-84325 Improper input validation in DataTransfer</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84326">CVE-2026-84326</a></td><td><p>Chromium: CVE-2026-84326 Uninitialized resource in V8</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84327">CVE-2026-84327</a></td><td><p>Chromium: CVE-2026-84327 Incorrect authorization in Autofill</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84328">CVE-2026-84328</a></td><td><p>Chromium: CVE-2026-84328 Missing authorization in FileSystem</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84329">CVE-2026-84329</a></td><td><p>Chromium: CVE-2026-84329 Confused deputy in CredentialProvider</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84331">CVE-2026-84331</a></td><td><p>Chromium: CVE-2026-84331 Incorrect authorization in Actor</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84332">CVE-2026-84332</a></td><td><p>Chromium: CVE-2026-84332 Incorrect authorization in SiteSettings</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84334">CVE-2026-84334</a></td><td><p>Chromium: CVE-2026-84334 Incorrect authorization in Chromoting</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84335">CVE-2026-84335</a></td><td><p>Chromium: CVE-2026-84335 Incorrect authorization in TabStrip</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84347">CVE-2026-84347</a></td><td><p>Chromium: CVE-2026-84347 Use after free in WebRTC</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84348">CVE-2026-84348</a></td><td><p>Chromium: CVE-2026-84348 Information leak in MediaCapture</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84349">CVE-2026-84349</a></td><td><p>Chromium: CVE-2026-84349 Use after free in Browser</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84350">CVE-2026-84350</a></td><td><p>Chromium: CVE-2026-84350 Use after free in TabStrip</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84351">CVE-2026-84351</a></td><td><p>Chromium: CVE-2026-84351 Buffer overflow in GPU</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84353">CVE-2026-84353</a></td><td><p>Chromium: CVE-2026-84353 Use after free in Shared Tab Groups</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84354">CVE-2026-84354</a></td><td><p>Chromium: CVE-2026-84354 Incorrect authorization in FileSystem</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84355">CVE-2026-84355</a></td><td><p>Chromium: CVE-2026-84355 Incorrect authorization in Navigation</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84356">CVE-2026-84356</a></td><td><p>Chromium: CVE-2026-84356 UI misrepresentation in FullScreen</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84357">CVE-2026-84357</a></td><td><p>Chromium: CVE-2026-84357 Improper input validation in Omnibox</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84358">CVE-2026-84358</a></td><td><p>Chromium: CVE-2026-84358 Improper privilege management in Downloads</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84359">CVE-2026-84359</a></td><td><p>Chromium: CVE-2026-84359 Information leak in Skia</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p></p></td></tr></tbody></table><h3>Developer Tools vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69439">CVE-2026-69439</a></td><td><p>.NET and Visual Studio Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69522">CVE-2026-69522</a></td><td><p>.NET and Visual Studio Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71328">CVE-2026-71328</a></td><td><p>.NET and Visual Studio Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69805">CVE-2026-69805</a></td><td><p>.NET Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69806">CVE-2026-69806</a></td><td><p>.NET Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-58649">CVE-2026-58649</a></td><td><p>.NET Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-70873">CVE-2025-70873</a></td><td><p>An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-57099">CVE-2026-57099</a></td><td><p>ASP.NET Core Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69304">CVE-2026-69304</a></td><td><p>ASP.NET Core Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34182">CVE-2026-34182</a></td><td><p>CMS AuthEnvelopedData Processing May Accept Forged Messages</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>9.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81380">CVE-2026-81380</a></td><td><p>GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>5.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81381">CVE-2026-81381</a></td><td><p>GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81383">CVE-2026-81383</a></td><td><p>Visual Studio Code Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70334">CVE-2026-70334</a></td><td><p>Visual Studio Code Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78461">CVE-2026-78461</a></td><td><p>Visual Studio Code Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78462">CVE-2026-78462</a></td><td><p>Visual Studio Code Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81356">CVE-2026-81356</a></td><td><p>Visual Studio Code Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81357">CVE-2026-81357</a></td><td><p>Visual Studio Code Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81376">CVE-2026-81376</a></td><td><p>Visual Studio Code Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81378">CVE-2026-81378</a></td><td><p>Visual Studio Code Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81379">CVE-2026-81379</a></td><td><p>Visual Studio Code Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81377">CVE-2026-81377</a></td><td><p>Visual Studio Code Tampering Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77906">CVE-2026-77906</a></td><td><p>Visual Studio Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77907">CVE-2026-77907</a></td><td><p>Visual Studio Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr></tbody></table><p></p><p></p><h3>ESU vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62810">CVE-2026-62810</a></td><td><p>Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69821">CVE-2026-69821</a></td><td><p>Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69395">CVE-2026-69395</a></td><td><p>Active Directory Certificate Services (AD CS) Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69624">CVE-2026-69624</a></td><td><p>Active Directory Certificate Services (AD CS) Tampering Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69359">CVE-2026-69359</a></td><td><p>Active Directory Domain Services Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72978">CVE-2026-72978</a></td><td><p>Active Directory Federation Services (AD FS) Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69329">CVE-2026-69329</a></td><td><p>BranchCache Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69516">CVE-2026-69516</a></td><td><p>Connected Devices Platform Service (Cdpsvc) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68824">CVE-2026-68824</a></td><td><p>Connected User Experiences and Telemetry Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68847">CVE-2026-68847</a></td><td><p>Connected User Experiences and Telemetry Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69470">CVE-2026-69470</a></td><td><p>Connected User Experiences and Telemetry Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69625">CVE-2026-69625</a></td><td><p>Connected User Experiences and Telemetry Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73014">CVE-2026-73014</a></td><td><p>Data Sharing Service Client Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73006">CVE-2026-73006</a></td><td><p>DirectWrite Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73016">CVE-2026-73016</a></td><td><p>DirectWrite Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69576">CVE-2026-69576</a></td><td><p>Graphic Fonts Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72986">CVE-2026-72986</a></td><td><p>Graphic Fonts Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73018">CVE-2026-73018</a></td><td><p>Graphic Fonts Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73017">CVE-2026-73017</a></td><td><p>Graphics Kernel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69731">CVE-2026-69731</a></td><td><p>HID Class Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72983">CVE-2026-72983</a></td><td><p>Internet Connection Sharing (ICS) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68895">CVE-2026-68895</a></td><td><p>Internet Storage Name Service Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72981">CVE-2026-72981</a></td><td><p>IP Helper Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69275">CVE-2026-69275</a></td><td><p>Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69900">CVE-2026-69900</a></td><td><p>Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68852">CVE-2026-68852</a></td><td><p>Microsoft Account Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69299">CVE-2026-69299</a></td><td><p>Microsoft COM for Windows Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69294">CVE-2026-69294</a></td><td><p>Microsoft COM for Windows Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69491">CVE-2026-69491</a></td><td><p>Microsoft DirectMusic Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69378">CVE-2026-69378</a></td><td><p>Microsoft Exchange Server Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69380">CVE-2026-69380</a></td><td><p>Microsoft Exchange Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69641">CVE-2026-69641</a></td><td><p>Microsoft Exchange Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69382">CVE-2026-69382</a></td><td><p>Microsoft Exchange Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-55007">CVE-2026-55007</a></td><td><p>Microsoft Exchange Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69355">CVE-2026-69355</a></td><td><p>Microsoft Exchange Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69356">CVE-2026-69356</a></td><td><p>Microsoft Exchange Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69361">CVE-2026-69361</a></td><td><p>Microsoft Exchange Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69375">CVE-2026-69375</a></td><td><p>Microsoft Exchange Server Tampering Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69467">CVE-2026-69467</a></td><td><p>Microsoft Graphics Component Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84000">CVE-2026-84000</a></td><td><p>Microsoft Graphics Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69605">CVE-2026-69605</a></td><td><p>Microsoft Install Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69325">CVE-2026-69325</a></td><td><p>Microsoft JScript Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69438">CVE-2026-69438</a></td><td><p>Microsoft JScript Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69277">CVE-2026-69277</a></td><td><p>Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69365">CVE-2026-69365</a></td><td><p>Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68843">CVE-2026-68843</a></td><td><p>Microsoft Office Word Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69360">CVE-2026-69360</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77504">CVE-2026-77504</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69397">CVE-2026-69397</a></td><td><p>Microsoft OpenSSH for Windows Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62801">CVE-2026-62801</a></td><td><p>Microsoft PowerShell Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68885">CVE-2026-68885</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68888">CVE-2026-68888</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68889">CVE-2026-68889</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68890">CVE-2026-68890</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68892">CVE-2026-68892</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68897">CVE-2026-68897</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69269">CVE-2026-69269</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69271">CVE-2026-69271</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69272">CVE-2026-69272</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69313">CVE-2026-69313</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69336">CVE-2026-69336</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68881">CVE-2026-68881</a></td><td><p>Microsoft Standard XPS Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68891">CVE-2026-68891</a></td><td><p>Microsoft Standard XPS Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69308">CVE-2026-69308</a></td><td><p>Microsoft Standard XPS Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69345">CVE-2026-69345</a></td><td><p>Microsoft Standard XPS Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69367">CVE-2026-69367</a></td><td><p>Microsoft Standard XPS Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69376">CVE-2026-69376</a></td><td><p>Microsoft Standard XPS Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69824">CVE-2026-69824</a></td><td><p>Microsoft Standard XPS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69276">CVE-2026-69276</a></td><td><p>Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69420">CVE-2026-69420</a></td><td><p>Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69427">CVE-2026-69427</a></td><td><p>Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72933">CVE-2026-72933</a></td><td><p>Microsoft WDAC OLE DB provider for SQL Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62706">CVE-2026-62706</a></td><td><p>Microsoft Windows Media Foundation Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69386">CVE-2026-69386</a></td><td><p>Microsoft Windows Media Foundation Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69408">CVE-2026-69408</a></td><td><p>Microsoft Windows Media Foundation Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69511">CVE-2026-69511</a></td><td><p>Microsoft Windows Media Foundation Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69601">CVE-2026-69601</a></td><td><p>Microsoft Windows Media Foundation Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69586">CVE-2026-69586</a></td><td><p>Microsoft Windows PDF Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78451">CVE-2026-78451</a></td><td><p>Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78452">CVE-2026-78452</a></td><td><p>Microsoft Windows SCSI Class System File Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78453">CVE-2026-78453</a></td><td><p>Microsoft Windows SCSI Class System File Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69305">CVE-2026-69305</a></td><td><p>Microsoft Windows Search Component Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69585">CVE-2026-69585</a></td><td><p>Microsoft Windows Search Component Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69600">CVE-2026-69600</a></td><td><p>Microsoft Windows Search Component Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69608">CVE-2026-69608</a></td><td><p>Microsoft Windows Search Component Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69911">CVE-2026-69911</a></td><td><p>Microsoft Windows Search Component Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70145">CVE-2026-70145</a></td><td><p>Microsoft Windows Search Component Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69453">CVE-2026-69453</a></td><td><p>Microsoft Windows Search Component Tampering Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69554">CVE-2026-69554</a></td><td><p>Microsoft Windows Search Component Tampering Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69444">CVE-2026-69444</a></td><td><p>Microsoft Windows Speech Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69456">CVE-2026-69456</a></td><td><p>Microsoft Windows Speech Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69531">CVE-2026-69531</a></td><td><p>Microsoft Windows Speech Tampering Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69807">CVE-2026-69807</a></td><td><p>PowerShell Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr></tbody></table><p></p><p></p><table><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69303"><br/>CVE-2026-69303</a></td><td><p>Push Message Routing Service Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68828">CVE-2026-68828</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69358">CVE-2026-69358</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69485">CVE-2026-69485</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83998">CVE-2026-83998</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69292">CVE-2026-69292</a></td><td><p>Remote Desktop Gateway Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69338">CVE-2026-69338</a></td><td><p>Remote Desktop Gateway Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68893">CVE-2026-68893</a></td><td><p>Remote Desktop Licensing Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69514">CVE-2026-69514</a></td><td><p>Remote Desktop Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69525">CVE-2026-69525</a></td><td><p>Remote Desktop Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69539">CVE-2026-69539</a></td><td><p>Remote Desktop Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69509">CVE-2026-69509</a></td><td><p>Role: Windows Fax Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69621">CVE-2026-69621</a></td><td><p>Role: Windows Fax Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72944">CVE-2026-72944</a></td><td><p>Role: Windows Fax Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69819">CVE-2026-69819</a></td><td><p>RPC Runtime Library Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69568">CVE-2026-69568</a></td><td><p>Storage Spaces Controller Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69431">CVE-2026-69431</a></td><td><p>Telnet Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69384">CVE-2026-69384</a></td><td><p>Virtual Hard Disk (VHD) Miniport Driver Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69541">CVE-2026-69541</a></td><td><p>Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69549">CVE-2026-69549</a></td><td><p>Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69611">CVE-2026-69611</a></td><td><p>Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69681">CVE-2026-69681</a></td><td><p>Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70574">CVE-2026-70574</a></td><td><p>Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81355">CVE-2026-81355</a></td><td><p>Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69407">CVE-2026-69407</a></td><td><p>Volume Manager Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69418">CVE-2026-69418</a></td><td><p>Volume Manager Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69432">CVE-2026-69432</a></td><td><p>Volume Manager Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72985">CVE-2026-72985</a></td><td><p>Volume Shadow Copy Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69609">CVE-2026-69609</a></td><td><p>Win32k Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69808">CVE-2026-69808</a></td><td><p>Win32k Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69832">CVE-2026-69832</a></td><td><p>Win32k Information Disclosure Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>5.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69853">CVE-2026-69853</a></td><td><p>Win32k Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70290">CVE-2026-70290</a></td><td><p>Win32k Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69654">CVE-2026-69654</a></td><td><p>Windows Accounts Control Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69816">CVE-2026-69816</a></td><td><p>Windows Accounts Control Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62762">CVE-2026-62762</a></td><td><p>Windows Active Directory Domain Services Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62813">CVE-2026-62813</a></td><td><p>Windows Active Directory Domain Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69524">CVE-2026-69524</a></td><td><p>Windows Active Directory Domain Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69546">CVE-2026-69546</a></td><td><p>Windows Active Directory Domain Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-85880">CVE-2026-85880</a></td><td><p>Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Detected</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70565">CVE-2026-70565</a></td><td><p>Windows AF_UNIX Socket Provider Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69834">CVE-2026-69834</a></td><td><p>Windows ALPC Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69874">CVE-2026-69874</a></td><td><p>Windows ALPC Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50349">CVE-2026-50349</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70342">CVE-2026-70342</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69311">CVE-2026-69311</a></td><td><p>Windows Audio Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69394">CVE-2026-69394</a></td><td><p>Windows Audio Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69540">CVE-2026-69540</a></td><td><p>Windows Audio Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69604">CVE-2026-69604</a></td><td><p>Windows Audio Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69692">CVE-2026-69692</a></td><td><p>Windows Audio Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69801">CVE-2026-69801</a></td><td><p>Windows Audio Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70562">CVE-2026-70562</a></td><td><p>Windows Audio Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73005">CVE-2026-73005</a></td><td><p>Windows Authentication Methods Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73004">CVE-2026-73004</a></td><td><p>Windows Autopilot Tampering Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69293">CVE-2026-69293</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69298">CVE-2026-69298</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69323">CVE-2026-69323</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr></tbody></table><p></p><p></p><table><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69352"><br/>CVE-2026-69352</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69476">CVE-2026-69476</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69489">CVE-2026-69489</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69580">CVE-2026-69580</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69583">CVE-2026-69583</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69589">CVE-2026-69589</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69593">CVE-2026-69593</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69727">CVE-2026-69727</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69738">CVE-2026-69738</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69773">CVE-2026-69773</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69787">CVE-2026-69787</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69826">CVE-2026-69826</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70572">CVE-2026-70572</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70573">CVE-2026-70573</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70581">CVE-2026-70581</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72941">CVE-2026-72941</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72988">CVE-2026-72988</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72990">CVE-2026-72990</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72991">CVE-2026-72991</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72992">CVE-2026-72992</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72993">CVE-2026-72993</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72994">CVE-2026-72994</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72995">CVE-2026-72995</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72996">CVE-2026-72996</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72997">CVE-2026-72997</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73000">CVE-2026-73000</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73001">CVE-2026-73001</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73002">CVE-2026-73002</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73007">CVE-2026-73007</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73011">CVE-2026-73011</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73015">CVE-2026-73015</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73020">CVE-2026-73020</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73021">CVE-2026-73021</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73026">CVE-2026-73026</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77489">CVE-2026-77489</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78447">CVE-2026-78447</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78448">CVE-2026-78448</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83954">CVE-2026-83954</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83955">CVE-2026-83955</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83967">CVE-2026-83967</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83968">CVE-2026-83968</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83969">CVE-2026-83969</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83970">CVE-2026-83970</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83971">CVE-2026-83971</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83972">CVE-2026-83972</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83973">CVE-2026-83973</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83974">CVE-2026-83974</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83975">CVE-2026-83975</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83976">CVE-2026-83976</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83977">CVE-2026-83977</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83978">CVE-2026-83978</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83979">CVE-2026-83979</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83980">CVE-2026-83980</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83981">CVE-2026-83981</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83982">CVE-2026-83982</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83983">CVE-2026-83983</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83985">CVE-2026-83985</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83986">CVE-2026-83986</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83987">CVE-2026-83987</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83988">CVE-2026-83988</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73008">CVE-2026-73008</a></td><td><p>Windows Biometric Service Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69458">CVE-2026-69458</a></td><td><p>Windows BitLocker Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69449">CVE-2026-69449</a></td><td><p>Windows BitLocker Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69817">CVE-2026-69817</a></td><td><p>Windows Bluetooth Port Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68849">CVE-2026-68849</a></td><td><p>Windows Bluetooth Port Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69388">CVE-2026-69388</a></td><td><p>Windows Bluetooth Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69398">CVE-2026-69398</a></td><td><p>Windows Bluetooth Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69448">CVE-2026-69448</a></td><td><p>Windows Bluetooth Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69889">CVE-2026-69889</a></td><td><p>Windows Bluetooth Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77892">CVE-2026-77892</a></td><td><p>Windows Boot Manager Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69735">CVE-2026-69735</a></td><td><p>Windows Broadcast DVR User Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69391">CVE-2026-69391</a></td><td><p>Windows Broker Infrastructure Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr></tbody></table><p></p><p></p><table><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69283"><br/>CVE-2026-69283</a></td><td><p>Windows CD-ROM Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69561">CVE-2026-69561</a></td><td><p>Windows CD-ROM Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78454">CVE-2026-78454</a></td><td><p>Windows CD-ROM Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78508">CVE-2026-78508</a></td><td><p>Windows CD-ROM Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69279">CVE-2026-69279</a></td><td><p>Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80093">CVE-2026-80093</a></td><td><p>Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83991">CVE-2026-83991</a></td><td><p>Windows Cloud Files Mini Filter Driver Tampering Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69445">CVE-2026-69445</a></td><td><p>Windows Compressed Folder Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69496">CVE-2026-69496</a></td><td><p>Windows Compressed Folder Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69267">CVE-2026-69267</a></td><td><p>Windows Connected User Experiences and Telemetry Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70583">CVE-2026-70583</a></td><td><p>Windows Core Messaging Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70584">CVE-2026-70584</a></td><td><p>Windows Core Messaging Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70578">CVE-2026-70578</a></td><td><p>Windows Credential Guard Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69790">CVE-2026-69790</a></td><td><p>Windows Credential Providers Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69284">CVE-2026-69284</a></td><td><p>Windows DCOM Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70568">CVE-2026-70568</a></td><td><p>Windows Defender Firewall Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68831">CVE-2026-68831</a></td><td><p>Windows Defender Firewall Service Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69607">CVE-2026-69607</a></td><td><p>Windows Deployment Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72943">CVE-2026-72943</a></td><td><p>Windows Deployment Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72954">CVE-2026-72954</a></td><td><p>Windows Deployment Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72957">CVE-2026-72957</a></td><td><p>Windows Deployment Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69314">CVE-2026-69314</a></td><td><p>Windows Device Association Broker Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69693">CVE-2026-69693</a></td><td><p>Windows Device Association Broker Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69296">CVE-2026-69296</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69478">CVE-2026-69478</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69488">CVE-2026-69488</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69574">CVE-2026-69574</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69581">CVE-2026-69581</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69711">CVE-2026-69711</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69714">CVE-2026-69714</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69791">CVE-2026-69791</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69866">CVE-2026-69866</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77500">CVE-2026-77500</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83940">CVE-2026-83940</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69472">CVE-2026-69472</a></td><td><p>Windows Devices Human Interface Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69342">CVE-2026-69342</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69405">CVE-2026-69405</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69416">CVE-2026-69416</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69497">CVE-2026-69497</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69637">CVE-2026-69637</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69679">CVE-2026-69679</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70065">CVE-2026-70065</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77494">CVE-2026-77494</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77498">CVE-2026-77498</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77499">CVE-2026-77499</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77501">CVE-2026-77501</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77502">CVE-2026-77502</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77886">CVE-2026-77886</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77888">CVE-2026-77888</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77889">CVE-2026-77889</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77890">CVE-2026-77890</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77893">CVE-2026-77893</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77895">CVE-2026-77895</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69415">CVE-2026-69415</a></td><td><p>Windows DHCP Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69297">CVE-2026-69297</a></td><td><p>Windows DHCP Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69803">CVE-2026-69803</a></td><td><p>Windows DHCP Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69929">CVE-2026-69929</a></td><td><p>Windows DHCP Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69930">CVE-2026-69930</a></td><td><p>Windows DHCP Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70124">CVE-2026-70124</a></td><td><p>Windows DHCP Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69266">CVE-2026-69266</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69412">CVE-2026-69412</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69510">CVE-2026-69510</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69547">CVE-2026-69547</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69620">CVE-2026-69620</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69845">CVE-2026-69845</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69847">CVE-2026-69847</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69876">CVE-2026-69876</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69878">CVE-2026-69878</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72979">CVE-2026-72979</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77887">CVE-2026-77887</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77891">CVE-2026-77891</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69715">CVE-2026-69715</a></td><td><p>Windows Direct Show Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr></tbody></table><p></p><p></p><table><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78446"><br/>CVE-2026-78446</a></td><td><p>Windows Distributed File System (DFS) Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69424">CVE-2026-69424</a></td><td><p>Windows Distributed File System (DFS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69631">CVE-2026-69631</a></td><td><p>Windows DNS Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70091">CVE-2026-70091</a></td><td><p>Windows DNS Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69310">CVE-2026-69310</a></td><td><p>Windows DNS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72948">CVE-2026-72948</a></td><td><p>Windows DNS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69369">CVE-2026-69369</a></td><td><p>Windows DNS Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69672">CVE-2026-69672</a></td><td><p>Windows DNS Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72987">CVE-2026-72987</a></td><td><p>Windows DNS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78523">CVE-2026-78523</a></td><td><p>Windows DNS Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69551">CVE-2026-69551</a></td><td><p>Windows DNS Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69730">CVE-2026-69730</a></td><td><p>Windows DNS Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69782">CVE-2026-69782</a></td><td><p>Windows DNS Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69813">CVE-2026-69813</a></td><td><p>Windows DNS Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69827">CVE-2026-69827</a></td><td><p>Windows DNS Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69989">CVE-2026-69989</a></td><td><p>Windows DNS Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77505">CVE-2026-77505</a></td><td><p>Windows DNS Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69680">CVE-2026-69680</a></td><td><p>Windows DNS Spoofing Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69430">CVE-2026-69430</a></td><td><p>Windows Embedded Mode Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69688">CVE-2026-69688</a></td><td><p>Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69841">CVE-2026-69841</a></td><td><p>Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69794">CVE-2026-69794</a></td><td><p>Windows Encrypting File System (EFS) Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69481">CVE-2026-69481</a></td><td><p>Windows Enterprise App Management Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69907">CVE-2026-69907</a></td><td><p>Windows Enterprise App Management Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68894">CVE-2026-68894</a></td><td><p>Windows Error Reporting Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69362">CVE-2026-69362</a></td><td><p>Windows Error Reporting Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69433">CVE-2026-69433</a></td><td><p>Windows Error Reporting Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69436">CVE-2026-69436</a></td><td><p>Windows Error Reporting Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69450">CVE-2026-69450</a></td><td><p>Windows Error Reporting Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69462">CVE-2026-69462</a></td><td><p>Windows Error Reporting Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69513">CVE-2026-69513</a></td><td><p>Windows Error Reporting Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69612">CVE-2026-69612</a></td><td><p>Windows Error Reporting Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83996">CVE-2026-83996</a></td><td><p>Windows Error Reporting Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69684">CVE-2026-69684</a></td><td><p>Windows Error Reporting Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69482">CVE-2026-69482</a></td><td><p>Windows Error Reporting Tampering Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69493">CVE-2026-69493</a></td><td><p>Windows Event Logging Service Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69494">CVE-2026-69494</a></td><td><p>Windows Event Logging Service Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69495">CVE-2026-69495</a></td><td><p>Windows Event Logging Service Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69619">CVE-2026-69619</a></td><td><p>Windows exFAT File System Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71338">CVE-2026-71338</a></td><td><p>Windows Failover Cluster Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68878">CVE-2026-68878</a></td><td><p>Windows Fast FAT Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69347">CVE-2026-69347</a></td><td><p>Windows Fast FAT Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68837">CVE-2026-68837</a></td><td><p>Windows File History Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71340">CVE-2026-71340</a></td><td><p>Windows File History Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72947">CVE-2026-72947</a></td><td><p>Windows File History Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77491">CVE-2026-77491</a></td><td><p>Windows GDI Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68827">CVE-2026-68827</a></td><td><p>Windows GDI+ Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69288">CVE-2026-69288</a></td><td><p>Windows GDI+ Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77493">CVE-2026-77493</a></td><td><p>Windows Graphics Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81955">CVE-2026-81955</a></td><td><p>Windows Graphics Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69717">CVE-2026-69717</a></td><td><p>Windows Group Policy Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69710">CVE-2026-69710</a></td><td><p>Windows Hello Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69725">CVE-2026-69725</a></td><td><p>Windows Hello Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69784">CVE-2026-69784</a></td><td><p>Windows Hello Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69799">CVE-2026-69799</a></td><td><p>Windows Hello Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69820">CVE-2026-69820</a></td><td><p>Windows Hello Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69864">CVE-2026-69864</a></td><td><p>Windows Hello Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81354">CVE-2026-81354</a></td><td><p>Windows Hello Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72980">CVE-2026-72980</a></td><td><p>Windows Hello Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69682">CVE-2026-69682</a></td><td><p>Windows Host Guardian Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69623">CVE-2026-69623</a></td><td><p>Windows HTTP Print Provider Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69769">CVE-2026-69769</a></td><td><p>Windows HTTP Print Provider Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69553">CVE-2026-69553</a></td><td><p>Windows Hyper-V Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72961">CVE-2026-72961</a></td><td><p>Windows Hyper-V Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69603">CVE-2026-69603</a></td><td><p>Windows Hyper-V Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69910">CVE-2026-69910</a></td><td><p>Windows Hyper-V Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69341">CVE-2026-69341</a></td><td><p>Windows Image Acquisition Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69500">CVE-2026-69500</a></td><td><p>Windows Image Acquisition Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69613">CVE-2026-69613</a></td><td><p>Windows Image Acquisition Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69483">CVE-2026-69483</a></td><td><p>Windows Image Acquisition Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69318">CVE-2026-69318</a></td><td><p>Windows Imaging Component Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69499">CVE-2026-69499</a></td><td><p>Windows Imaging Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69860">CVE-2026-69860</a></td><td><p>Windows Imaging Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70296">CVE-2026-70296</a></td><td><p>Windows Imaging Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73013">CVE-2026-73013</a></td><td><p>Windows Imaging Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73023">CVE-2026-73023</a></td><td><p>Windows Imaging Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77495">CVE-2026-77495</a></td><td><p>Windows Imaging Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83992">CVE-2026-83992</a></td><td><p>Windows Imaging Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62694">CVE-2026-62694</a></td><td><p>Windows Installer Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69441">CVE-2026-69441</a></td><td><p>Windows Installer Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71339">CVE-2026-71339</a></td><td><p>Windows Installer Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77894">CVE-2026-77894</a></td><td><p>Windows Installer Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72926">CVE-2026-72926</a></td><td><p>Windows Internet Connection Sharing (ICS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72964">CVE-2026-72964</a></td><td><p>Windows Internet Connection Sharing (ICS) Tampering Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69881">CVE-2026-69881</a></td><td><p>Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69429">CVE-2026-69429</a></td><td><p>Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69694">CVE-2026-69694</a></td><td><p>Windows IP Address Management (IPAM) Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68898">CVE-2026-68898</a></td><td><p>Windows iSCSI Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69598">CVE-2026-69598</a></td><td><p>Windows iSCSI Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69628">CVE-2026-69628</a></td><td><p>Windows iSCSI Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73025">CVE-2026-73025</a></td><td><p>Windows iSCSI Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr></tbody></table><p></p><p></p><table><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69839"><br/>CVE-2026-69839</a></td><td><p>Windows iSCSI Target Service Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69760">CVE-2026-69760</a></td><td><p>Windows Kerberos Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69685">CVE-2026-69685</a></td><td><p>Windows Kerberos Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69822">CVE-2026-69822</a></td><td><p>Windows Kerberos Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69676">CVE-2026-69676</a></td><td><p>Windows Kerberos Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68846">CVE-2026-68846</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68884">CVE-2026-68884</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69366">CVE-2026-69366</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69466">CVE-2026-69466</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69473">CVE-2026-69473</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69578">CVE-2026-69578</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83942">CVE-2026-83942</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-85360">CVE-2026-85360</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69406">CVE-2026-69406</a></td><td><p>Windows Kernel Information Disclosure Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69723">CVE-2026-69723</a></td><td><p>Windows Kernel Information Disclosure Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69669">CVE-2026-69669</a></td><td><p>Windows Kernel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69421">CVE-2026-69421</a></td><td><p>Windows Kernel-Mode Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84001">CVE-2026-84001</a></td><td><p>Windows Key Distribution Center Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69712">CVE-2026-69712</a></td><td><p>Windows Key Distribution Center Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69428">CVE-2026-69428</a></td><td><p>Windows LDAP - Lightweight Directory Access Protocol Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69281">CVE-2026-69281</a></td><td><p>Windows License Manager Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69315">CVE-2026-69315</a></td><td><p>Windows License Manager Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69732">CVE-2026-69732</a></td><td><p>Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69451">CVE-2026-69451</a></td><td><p>Windows Management Instrumentation Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70582">CVE-2026-70582</a></td><td><p>Windows Management Instrumentation Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77905">CVE-2026-77905</a></td><td><p>Windows Management Instrumentation Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69349">CVE-2026-69349</a></td><td><p>Windows Management Instrumentation Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73012">CVE-2026-73012</a></td><td><p>Windows Management Services Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69891">CVE-2026-69891</a></td><td><p>Windows Media Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70203">CVE-2026-70203</a></td><td><p>Windows Media Player Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72960">CVE-2026-72960</a></td><td><p>Windows Media Player Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69645">CVE-2026-69645</a></td><td><p>Windows Message Queuing Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68887">CVE-2026-68887</a></td><td><p>Windows Message Queuing Queue Manager Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72932">CVE-2026-72932</a></td><td><p>Windows Message Queuing Queue Manager Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69579">CVE-2026-69579</a></td><td><p>Windows Message Queuing Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83997">CVE-2026-83997</a></td><td><p>Windows Message Queuing Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70579">CVE-2026-70579</a></td><td><p>Windows Mobile Broadband Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69377">CVE-2026-69377</a></td><td><p>Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69460">CVE-2026-69460</a></td><td><p>Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70577">CVE-2026-70577</a></td><td><p>Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73003">CVE-2026-73003</a></td><td><p>Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73022">CVE-2026-73022</a></td><td><p>Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69674">CVE-2026-69674</a></td><td><p>Windows Modern Device Management (MDM) Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72963">CVE-2026-72963</a></td><td><p>Windows Modern Execution Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69357">CVE-2026-69357</a></td><td><p>Windows NDIS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69396">CVE-2026-69396</a></td><td><p>Windows NDIS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72982">CVE-2026-72982</a></td><td><p>Windows Netlogon Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62759">CVE-2026-62759</a></td><td><p>Windows Netlogon Spoofing Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72967">CVE-2026-72967</a></td><td><p>Windows Network Connection Broker Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68886">CVE-2026-68886</a></td><td><p>Windows Network Connection Broker Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69372">CVE-2026-69372</a></td><td><p>Windows Network File System Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69772">CVE-2026-69772</a></td><td><p>Windows Network File System Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71334">CVE-2026-71334</a></td><td><p>Windows NFS Portmapper Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69648">CVE-2026-69648</a></td><td><p>Windows Notification Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68832">CVE-2026-68832</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68834">CVE-2026-68834</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68838">CVE-2026-68838</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68841">CVE-2026-68841</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69265">CVE-2026-69265</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69312">CVE-2026-69312</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69332">CVE-2026-69332</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69340">CVE-2026-69340</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69505">CVE-2026-69505</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69532">CVE-2026-69532</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69567">CVE-2026-69567</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69875">CVE-2026-69875</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72935">CVE-2026-72935</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77503">CVE-2026-77503</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83995">CVE-2026-83995</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68851">CVE-2026-68851</a></td><td><p>Windows NTFS Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69504">CVE-2026-69504</a></td><td><p>Windows NTFS Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69591">CVE-2026-69591</a></td><td><p>Windows NTFS Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68833">CVE-2026-68833</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68875">CVE-2026-68875</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69461">CVE-2026-69461</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69463">CVE-2026-69463</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69479">CVE-2026-69479</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69566">CVE-2026-69566</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69638">CVE-2026-69638</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69709">CVE-2026-69709</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71329">CVE-2026-71329</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69564">CVE-2026-69564</a></td><td><p>Windows Online Certificate Status Protocol (OCSP) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69350">CVE-2026-69350</a></td><td><p>Windows Overlay Filter Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69368">CVE-2026-69368</a></td><td><p>Windows Overlay Filter Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69371">CVE-2026-69371</a></td><td><p>Windows Overlay Filter Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69373">CVE-2026-69373</a></td><td><p>Windows Overlay Filter Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69316">CVE-2026-69316</a></td><td><p>Windows Overlay Filter Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69343">CVE-2026-69343</a></td><td><p>Windows Overlay Filter Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69474">CVE-2026-69474</a></td><td><p>Windows Overlay Filter Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70586">CVE-2026-70586</a></td><td><p>Windows Paint Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr></tbody></table><p></p><p></p><table><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69480"><br/>CVE-2026-69480</a></td><td><p>Windows Partition Management Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69492">CVE-2026-69492</a></td><td><p>Windows Partition Management Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71341">CVE-2026-71341</a></td><td><p>Windows Partition Management Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69324">CVE-2026-69324</a></td><td><p>Windows Performance Monitor Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69459">CVE-2026-69459</a></td><td><p>Windows Power Dependency Coordinator Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69321">CVE-2026-69321</a></td><td><p>Windows Power Dependency Coordinator Tampering Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69569">CVE-2026-69569</a></td><td><p>Windows Print Spooler Components Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68835">CVE-2026-68835</a></td><td><p>Windows Print Spooler Components Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68848">CVE-2026-68848</a></td><td><p>Windows Print Spooler Components Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69309">CVE-2026-69309</a></td><td><p>Windows Print Spooler Components Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69346">CVE-2026-69346</a></td><td><p>Windows Print Spooler Components Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69364">CVE-2026-69364</a></td><td><p>Windows Print Spooler Components Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69838">CVE-2026-69838</a></td><td><p>Windows Print Spooler Components Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69921">CVE-2026-69921</a></td><td><p>Windows Print Spooler Components Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70564">CVE-2026-70564</a></td><td><p>Windows Print Spooler Components Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69344">CVE-2026-69344</a></td><td><p>Windows Print Spooler Components Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69552">CVE-2026-69552</a></td><td><p>Windows Print Spooler Components Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69602">CVE-2026-69602</a></td><td><p>Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68845">CVE-2026-68845</a></td><td><p>Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68876">CVE-2026-68876</a></td><td><p>Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69534">CVE-2026-69534</a></td><td><p>Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69563">CVE-2026-69563</a></td><td><p>Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68874">CVE-2026-68874</a></td><td><p>Windows Program Compatibility Assistant Service Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62697">CVE-2026-62697</a></td><td><p>Windows Push Notifications Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69280">CVE-2026-69280</a></td><td><p>Windows Push Notifications Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69337">CVE-2026-69337</a></td><td><p>Windows Registry Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78449">CVE-2026-78449</a></td><td><p>Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69331">CVE-2026-69331</a></td><td><p>Windows Remote Access Connection Manager Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69455">CVE-2026-69455</a></td><td><p>Windows Remote Access Connection Manager Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71333">CVE-2026-71333</a></td><td><p>Windows Remote Access Connection Manager Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71342">CVE-2026-71342</a></td><td><p>Windows Remote Access Connection Manager Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71343">CVE-2026-71343</a></td><td><p>Windows Remote Access Connection Manager Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71352">CVE-2026-71352</a></td><td><p>Windows Remote Access Connection Manager Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72966">CVE-2026-72966</a></td><td><p>Windows Remote Access Connection Manager Tampering Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77896">CVE-2026-77896</a></td><td><p>Windows Remote Desktop Client Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69317">CVE-2026-69317</a></td><td><p>Windows Remote Desktop Client Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69627">CVE-2026-69627</a></td><td><p>Windows Remote Desktop Licensing Service Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70587">CVE-2026-70587</a></td><td><p>Windows Remote Desktop Protocol Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69518">CVE-2026-69518</a></td><td><p>Windows Remote Desktop Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69287">CVE-2026-69287</a></td><td><p>Windows Remote Desktop Services Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69475">CVE-2026-69475</a></td><td><p>Windows Remote Desktop Services Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80096">CVE-2026-80096</a></td><td><p>Windows Remote Desktop Services Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69616">CVE-2026-69616</a></td><td><p>Windows Remote Desktop Services Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69548">CVE-2026-69548</a></td><td><p>Windows RNDIS Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69768">CVE-2026-69768</a></td><td><p>Windows RNDIS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72939">CVE-2026-72939</a></td><td><p>Windows Routing and Remote Access Service (RRAS) Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71351">CVE-2026-71351</a></td><td><p>Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71353">CVE-2026-71353</a></td><td><p>Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69590">CVE-2026-69590</a></td><td><p>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69852">CVE-2026-69852</a></td><td><p>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70570">CVE-2026-70570</a></td><td><p>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72950">CVE-2026-72950</a></td><td><p>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72959">CVE-2026-72959</a></td><td><p>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69713">CVE-2026-69713</a></td><td><p>Windows Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69501">CVE-2026-69501</a></td><td><p>Windows Secure Kernel Mode Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69846">CVE-2026-69846</a></td><td><p>Windows Secure Kernel Mode Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69906">CVE-2026-69906</a></td><td><p>Windows Secure Kernel Mode Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72931">CVE-2026-72931</a></td><td><p>Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71332">CVE-2026-71332</a></td><td><p>Windows Secure Socket Tunneling Protocol (SSTP) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72930">CVE-2026-72930</a></td><td><p>Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73009">CVE-2026-73009</a></td><td><p>Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77899">CVE-2026-77899</a></td><td><p>Windows Security Center Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-56177">CVE-2026-56177</a></td><td><p>Windows Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83989">CVE-2026-83989</a></td><td><p>Windows Services for NFS ONCRPC XDR Driver Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73024">CVE-2026-73024</a></td><td><p>Windows Services for NFS ONCRPC XDR Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71330">CVE-2026-71330</a></td><td><p>Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69595">CVE-2026-69595</a></td><td><p>Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70585">CVE-2026-70585</a></td><td><p>Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78445">CVE-2026-78445</a></td><td><p>Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69289">CVE-2026-69289</a></td><td><p>Windows Setup Files Cleanup Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69829">CVE-2026-69829</a></td><td><p>Windows Shell Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70563">CVE-2026-70563</a></td><td><p>Windows Shell Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69785">CVE-2026-69785</a></td><td><p>Windows Smart Card Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69572">CVE-2026-69572</a></td><td><p>Windows SMB Client Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69618">CVE-2026-69618</a></td><td><p>Windows SMB Client Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69374">CVE-2026-69374</a></td><td><p>Windows SMB Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69403">CVE-2026-69403</a></td><td><p>Windows SMB Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69512">CVE-2026-69512</a></td><td><p>Windows Spaceport.sys Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69535">CVE-2026-69535</a></td><td><p>Windows Spaceport.sys Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69643">CVE-2026-69643</a></td><td><p>Windows Spaceport.sys Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69691">CVE-2026-69691</a></td><td><p>Windows Spaceport.sys Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69390">CVE-2026-69390</a></td><td><p>Windows Spaceport.sys Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69393">CVE-2026-69393</a></td><td><p>Windows Spaceport.sys Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69741">CVE-2026-69741</a></td><td><p>Windows Spaceport.sys Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69770">CVE-2026-69770</a></td><td><p>Windows Spaceport.sys Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69895">CVE-2026-69895</a></td><td><p>Windows Spaceport.sys Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72942">CVE-2026-72942</a></td><td><p>Windows Spaceport.sys Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69538">CVE-2026-69538</a></td><td><p>Windows Spaceport.sys Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71345">CVE-2026-71345</a></td><td><p>Windows Spaceport.sys Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71348">CVE-2026-71348</a></td><td><p>Windows Spaceport.sys Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71349">CVE-2026-71349</a></td><td><p>Windows Spaceport.sys Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71350">CVE-2026-71350</a></td><td><p>Windows Spaceport.sys Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72952">CVE-2026-72952</a></td><td><p>Windows Spaceport.sys Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69328">CVE-2026-69328</a></td><td><p>Windows Storage Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78516">CVE-2026-78516</a></td><td><p>Windows Storage Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69389">CVE-2026-69389</a></td><td><p>Windows Storage Management Provider Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71337">CVE-2026-71337</a></td><td><p>Windows Storage Management Provider Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69381">CVE-2026-69381</a></td><td><p>Windows Storage Port Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72937">CVE-2026-72937</a></td><td><p>Windows Storage Port Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77492">CVE-2026-77492</a></td><td><p>Windows Storage Port Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69290">CVE-2026-69290</a></td><td><p>Windows Storage Spaces Controller Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69575">CVE-2026-69575</a></td><td><p>Windows Storage Spaces Controller Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68844">CVE-2026-68844</a></td><td><p>Windows Storage Spaces Controller Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68877">CVE-2026-68877</a></td><td><p>Windows Storage Spaces Controller Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72945">CVE-2026-72945</a></td><td><p>Windows Task Scheduler Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69385">CVE-2026-69385</a></td><td><p>Windows TCP/IP Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69404">CVE-2026-69404</a></td><td><p>Windows TCP/IP Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69757">CVE-2026-69757</a></td><td><p>Windows TCP/IP Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69761">CVE-2026-69761</a></td><td><p>Windows TCP/IP Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69793">CVE-2026-69793</a></td><td><p>Windows TCP/IP Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69353">CVE-2026-69353</a></td><td><p>Windows Text Shaping Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69786">CVE-2026-69786</a></td><td><p>Windows Text Shaping Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69573">CVE-2026-69573</a></td><td><p>Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69592">CVE-2026-69592</a></td><td><p>Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69758">CVE-2026-69758</a></td><td><p>Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68830">CVE-2026-68830</a></td><td><p>Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69351">CVE-2026-69351</a></td><td><p>Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69434">CVE-2026-69434</a></td><td><p>Windows URL Moniker Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73019">CVE-2026-73019</a></td><td><p>Windows URL Moniker Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69270">CVE-2026-69270</a></td><td><p>Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69307">CVE-2026-69307</a></td><td><p>Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69413">CVE-2026-69413</a></td><td><p>Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr></tbody></table><p></p><p></p><table><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69469"><br/>CVE-2026-69469</a></td><td><p>Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69571">CVE-2026-69571</a></td><td><p>Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69687">CVE-2026-69687</a></td><td><p>Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69707">CVE-2026-69707</a></td><td><p>Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69859">CVE-2026-69859</a></td><td><p>Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69286">CVE-2026-69286</a></td><td><p>Windows USB Audio Class Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68840">CVE-2026-68840</a></td><td><p>Windows USB Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69295">CVE-2026-69295</a></td><td><p>Windows USB Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69503">CVE-2026-69503</a></td><td><p>Windows USB Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72953">CVE-2026-72953</a></td><td><p>Windows USB Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69457">CVE-2026-69457</a></td><td><p>Windows USB Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72999">CVE-2026-72999</a></td><td><p>Windows USB Hub Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69490">CVE-2026-69490</a></td><td><p>Windows USB Mass Storage Class Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69527">CVE-2026-69527</a></td><td><p>Windows USB Mass Storage Class Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68839">CVE-2026-68839</a></td><td><p>Windows USB Mass Storage Class Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69319">CVE-2026-69319</a></td><td><p>Windows USB Video Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69423">CVE-2026-69423</a></td><td><p>Windows USB Video Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69584">CVE-2026-69584</a></td><td><p>Windows USB Video Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72962">CVE-2026-72962</a></td><td><p>Windows USB Video Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-56172">CVE-2026-56172</a></td><td><p>Windows VHD miniport driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69890">CVE-2026-69890</a></td><td><p>Windows Virtual Trusted Platform Module Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69426">CVE-2026-69426</a></td><td><p>Windows VOLSNAP.SYS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69468">CVE-2026-69468</a></td><td><p>Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69582">CVE-2026-69582</a></td><td><p>Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77904">CVE-2026-77904</a></td><td><p>Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69291">CVE-2026-69291</a></td><td><p>Windows Volume Manager Extension Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69334">CVE-2026-69334</a></td><td><p>Windows Volume Manager Extension Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69708">CVE-2026-69708</a></td><td><p>Windows Web Platform Storage Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72965">CVE-2026-72965</a></td><td><p>Windows WebClient Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68880">CVE-2026-68880</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69274">CVE-2026-69274</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69301">CVE-2026-69301</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69335">CVE-2026-69335</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69410">CVE-2026-69410</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69498">CVE-2026-69498</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69610">CVE-2026-69610</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69630">CVE-2026-69630</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69652">CVE-2026-69652</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69689">CVE-2026-69689</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69706">CVE-2026-69706</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69762">CVE-2026-69762</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69779">CVE-2026-69779</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69844">CVE-2026-69844</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70283">CVE-2026-70283</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70289">CVE-2026-70289</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69792">CVE-2026-69792</a></td><td><p>Windows Win32K Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69517">CVE-2026-69517</a></td><td><p>Windows Wireless Networking Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69862">CVE-2026-69862</a></td><td><p>Windows Wireless Wide Area Network Service Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69560">CVE-2026-69560</a></td><td><p>Windows Work Folder Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71336">CVE-2026-71336</a></td><td><p>Windows Work Folder Service Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80075">CVE-2026-80075</a></td><td><p>Windows Work Folders Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72927">CVE-2026-72927</a></td><td><p>Winsock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78455">CVE-2026-78455</a></td><td><p>Xbox Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.3</p></td></tr></tbody></table><p></p><p></p><h3>Mariner vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-70873">CVE-2025-70873</a></td><td><p>An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.5</p></td></tr></tbody></table><h3>Microsoft Dynamics vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-65772">CVE-2026-65772</a></td><td><p>Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77908">CVE-2026-77908</a></td><td><p>Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77897">CVE-2026-77897</a></td><td><p>Microsoft Power Automate Desktop Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-65818">CVE-2026-65818</a></td><td><p>Power Automate Elevation of Privilege Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>8.5</p></td></tr></tbody></table><h3>Microsoft Office vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80098">CVE-2026-80098</a></td><td><p>Copilot Studio Elevation of Privilege Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>9.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81387">CVE-2026-81387</a></td><td><p>Microsoft Excel Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81390">CVE-2026-81390</a></td><td><p>Microsoft Excel Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81391">CVE-2026-81391</a></td><td><p>Microsoft Excel Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81392">CVE-2026-81392</a></td><td><p>Microsoft Excel Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81393">CVE-2026-81393</a></td><td><p>Microsoft Excel Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81394">CVE-2026-81394</a></td><td><p>Microsoft Excel Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81395">CVE-2026-81395</a></td><td><p>Microsoft Excel Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81399">CVE-2026-81399</a></td><td><p>Microsoft Excel Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81400">CVE-2026-81400</a></td><td><p>Microsoft Excel Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81401">CVE-2026-81401</a></td><td><p>Microsoft Excel Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81958">CVE-2026-81958</a></td><td><p>Microsoft Excel Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81386">CVE-2026-81386</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81388">CVE-2026-81388</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81389">CVE-2026-81389</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81396">CVE-2026-81396</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81397">CVE-2026-81397</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81398">CVE-2026-81398</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81947">CVE-2026-81947</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81948">CVE-2026-81948</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81949">CVE-2026-81949</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81950">CVE-2026-81950</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81951">CVE-2026-81951</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81953">CVE-2026-81953</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81954">CVE-2026-81954</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81956">CVE-2026-81956</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81957">CVE-2026-81957</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81959">CVE-2026-81959</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81960">CVE-2026-81960</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70178">CVE-2026-70178</a></td><td><p>Microsoft Fabric Elevation of Privilege Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>8.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69477">CVE-2026-69477</a></td><td><p>Microsoft Office Access Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69529">CVE-2026-69529</a></td><td><p>Microsoft Office Access Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69614">CVE-2026-69614</a></td><td><p>Microsoft Office Access Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69778">CVE-2026-69778</a></td><td><p>Microsoft Office Access Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72974">CVE-2026-72974</a></td><td><p>Microsoft Office Excel Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78515">CVE-2026-78515</a></td><td><p>Microsoft Office Excel Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-85875">CVE-2026-85875</a></td><td><p>Microsoft Office Excel Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78518">CVE-2026-78518</a></td><td><p>Microsoft Office Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78439">CVE-2026-78439</a></td><td><p>Microsoft Office Graphics Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69626">CVE-2026-69626</a></td><td><p>Microsoft Office Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69739">CVE-2026-69739</a></td><td><p>Microsoft Office Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80076">CVE-2026-80076</a></td><td><p>Microsoft Office Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80078">CVE-2026-80078</a></td><td><p>Microsoft Office Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80082">CVE-2026-80082</a></td><td><p>Microsoft Office Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80087">CVE-2026-80087</a></td><td><p>Microsoft Office Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80089">CVE-2026-80089</a></td><td><p>Microsoft Office Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80091">CVE-2026-80091</a></td><td><p>Microsoft Office Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78520">CVE-2026-78520</a></td><td><p>Microsoft Office Outlook Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80073">CVE-2026-80073</a></td><td><p>Microsoft Office Outlook Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80084">CVE-2026-80084</a></td><td><p>Microsoft Office Outlook Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69629">CVE-2026-69629</a></td><td><p>Microsoft Office Outlook Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78509">CVE-2026-78509</a></td><td><p>Microsoft Office Outlook Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78519">CVE-2026-78519</a></td><td><p>Microsoft Office Outlook Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78525">CVE-2026-78525</a></td><td><p>Microsoft Office Outlook Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72938">CVE-2026-72938</a></td><td><p>Microsoft Office PowerPoint Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72956">CVE-2026-72956</a></td><td><p>Microsoft Office PowerPoint Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72975">CVE-2026-72975</a></td><td><p>Microsoft Office PowerPoint Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72977">CVE-2026-72977</a></td><td><p>Microsoft Office PowerPoint Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78513">CVE-2026-78513</a></td><td><p>Microsoft Office PowerPoint Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80086">CVE-2026-80086</a></td><td><p>Microsoft Office PowerPoint Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69678">CVE-2026-69678</a></td><td><p>Microsoft Office PowerPoint Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69767">CVE-2026-69767</a></td><td><p>Microsoft Office PowerPoint Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69797">CVE-2026-69797</a></td><td><p>Microsoft Office PowerPoint Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80081">CVE-2026-80081</a></td><td><p>Microsoft Office PowerPoint Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69742">CVE-2026-69742</a></td><td><p>Microsoft Office Publisher Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81385">CVE-2026-81385</a></td><td><p>Microsoft Office Publisher Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69285">CVE-2026-69285</a></td><td><p>Microsoft Office Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69442">CVE-2026-69442</a></td><td><p>Microsoft Office Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69632">CVE-2026-69632</a></td><td><p>Microsoft Office Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77898">CVE-2026-77898</a></td><td><p>Microsoft Office Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78505">CVE-2026-78505</a></td><td><p>Microsoft Office Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78524">CVE-2026-78524</a></td><td><p>Microsoft Office Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69464">CVE-2026-69464</a></td><td><p>Microsoft Office SharePoint Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69716">CVE-2026-69716</a></td><td><p>Microsoft Office SharePoint Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69409">CVE-2026-69409</a></td><td><p>Microsoft Office SharePoint Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69636">CVE-2026-69636</a></td><td><p>Microsoft Office SharePoint Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69683">CVE-2026-69683</a></td><td><p>Microsoft Office SharePoint Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69904">CVE-2026-69904</a></td><td><p>Microsoft Office SharePoint Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>3.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69268">CVE-2026-69268</a></td><td><p>Microsoft Office SharePoint Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69273">CVE-2026-69273</a></td><td><p>Microsoft Office SharePoint Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69282">CVE-2026-69282</a></td><td><p>Microsoft Office SharePoint Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69465">CVE-2026-69465</a></td><td><p>Microsoft Office SharePoint Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69724">CVE-2026-69724</a></td><td><p>Microsoft Office SharePoint Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69804">CVE-2026-69804</a></td><td><p>Microsoft Office SharePoint Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69402">CVE-2026-69402</a></td><td><p>Microsoft Office SharePoint Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69417">CVE-2026-69417</a></td><td><p>Microsoft Office SharePoint Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69615">CVE-2026-69615</a></td><td><p>Microsoft Office SharePoint Spoofing Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>3.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69690">CVE-2026-69690</a></td><td><p>Microsoft Office SharePoint Spoofing Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-64918">CVE-2026-64918</a></td><td><p>Microsoft Office Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr></tbody></table><p></p><p></p><table><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69719"><br/>CVE-2026-69719</a></td><td><p>Microsoft Office Word Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69734">CVE-2026-69734</a></td><td><p>Microsoft Office Word Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72976">CVE-2026-72976</a></td><td><p>Microsoft Office Word Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77911">CVE-2026-77911</a></td><td><p>Microsoft Office Word Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78502">CVE-2026-78502</a></td><td><p>Microsoft Office Word Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78503">CVE-2026-78503</a></td><td><p>Microsoft Office Word Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78506">CVE-2026-78506</a></td><td><p>Microsoft Office Word Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78522">CVE-2026-78522</a></td><td><p>Microsoft Office Word Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80079">CVE-2026-80079</a></td><td><p>Microsoft Office Word Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p></p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80088">CVE-2026-80088</a></td><td><p>Microsoft Office Word Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80090">CVE-2026-80090</a></td><td><p>Microsoft Office Word Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83949">CVE-2026-83949</a></td><td><p>Microsoft Office Word Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83951">CVE-2026-83951</a></td><td><p>Microsoft Office Word Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69556">CVE-2026-69556</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69671">CVE-2026-69671</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69686">CVE-2026-69686</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69722">CVE-2026-69722</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69759">CVE-2026-69759</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69764">CVE-2026-69764</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72972">CVE-2026-72972</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72973">CVE-2026-72973</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77901">CVE-2026-77901</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78504">CVE-2026-78504</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78507">CVE-2026-78507</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78511">CVE-2026-78511</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78512">CVE-2026-78512</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78514">CVE-2026-78514</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78517">CVE-2026-78517</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78521">CVE-2026-78521</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78526">CVE-2026-78526</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80080">CVE-2026-80080</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80085">CVE-2026-80085</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-65812">CVE-2026-65812</a></td><td><p>Microsoft Teams for Android Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69559">CVE-2026-69559</a></td><td><p>Microsoft Teams for Android Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62804">CVE-2026-62804</a></td><td><p>Microsoft Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78510">CVE-2026-78510</a></td><td><p>Microsoft Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81952">CVE-2026-81952</a></td><td><p>Microsoft Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-66303">CVE-2026-66303</a></td><td><p>Skype for Business and Lync Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-66307">CVE-2026-66307</a></td><td><p>Skype for Business and Lync Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-66308">CVE-2026-66308</a></td><td><p>Skype for Business and Lync Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-66304">CVE-2026-66304</a></td><td><p>Skype for Business Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-66306">CVE-2026-66306</a></td><td><p>Skype for Business Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-66302">CVE-2026-66302</a></td><td><p>Skype for Business Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-63523">CVE-2026-63523</a></td><td><p>Skype for Business Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-66305">CVE-2026-66305</a></td><td><p>Skype for Business Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69642">CVE-2026-69642</a></td><td><p>Skype for Business Spoofing Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69646">CVE-2026-69646</a></td><td><p>Skype for Business Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81955">CVE-2026-81955</a></td><td><p>Windows Graphics Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr></tbody></table><p></p><p></p><h3>Open Source Software vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69805">CVE-2026-69805</a></td><td><p>.NET Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-70873">CVE-2025-70873</a></td><td><p>An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34182">CVE-2026-34182</a></td><td><p>CMS AuthEnvelopedData Processing May Accept Forged Messages</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>9.1</p></td></tr></tbody></table><h3>Server Software vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69378">CVE-2026-69378</a></td><td><p>Microsoft Exchange Server Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69380">CVE-2026-69380</a></td><td><p>Microsoft Exchange Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69641">CVE-2026-69641</a></td><td><p>Microsoft Exchange Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69382">CVE-2026-69382</a></td><td><p>Microsoft Exchange Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-55007">CVE-2026-55007</a></td><td><p>Microsoft Exchange Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69355">CVE-2026-69355</a></td><td><p>Microsoft Exchange Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69356">CVE-2026-69356</a></td><td><p>Microsoft Exchange Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69361">CVE-2026-69361</a></td><td><p>Microsoft Exchange Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69375">CVE-2026-69375</a></td><td><p>Microsoft Exchange Server Tampering Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr></tbody></table><h3>SQL Server vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67376">CVE-2026-67376</a></td><td><p>Microsoft SQL Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67633">CVE-2026-67633</a></td><td><p>Microsoft SQL Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67641">CVE-2026-67641</a></td><td><p>Microsoft SQL Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-66814">CVE-2026-66814</a></td><td><p>Microsoft SQL Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-66818">CVE-2026-66818</a></td><td><p>Microsoft SQL Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-66819">CVE-2026-66819</a></td><td><p>Microsoft SQL Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67368">CVE-2026-67368</a></td><td><p>Microsoft SQL Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67370">CVE-2026-67370</a></td><td><p>Microsoft SQL Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67381">CVE-2026-67381</a></td><td><p>Microsoft SQL Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67369">CVE-2026-67369</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67383">CVE-2026-67383</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67386">CVE-2026-67386</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67389">CVE-2026-67389</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67390">CVE-2026-67390</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67393">CVE-2026-67393</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67624">CVE-2026-67624</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67629">CVE-2026-67629</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67630">CVE-2026-67630</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67645">CVE-2026-67645</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67648">CVE-2026-67648</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68776">CVE-2026-68776</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68777">CVE-2026-68777</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68778">CVE-2026-68778</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68779">CVE-2026-68779</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68780">CVE-2026-68780</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68781">CVE-2026-68781</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68784">CVE-2026-68784</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69562">CVE-2026-69562</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73029">CVE-2026-73029</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77488">CVE-2026-77488</a></td><td><p>Microsoft SQL Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47297">CVE-2026-47297</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67373">CVE-2026-67373</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67378">CVE-2026-67378</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67379">CVE-2026-67379</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67380">CVE-2026-67380</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67384">CVE-2026-67384</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67385">CVE-2026-67385</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67388">CVE-2026-67388</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67631">CVE-2026-67631</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67636">CVE-2026-67636</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67638">CVE-2026-67638</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67639">CVE-2026-67639</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67642">CVE-2026-67642</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-67643">CVE-2026-67643</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68775">CVE-2026-68775</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68785">CVE-2026-68785</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68786">CVE-2026-68786</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68787">CVE-2026-68787</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77481">CVE-2026-77481</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77482">CVE-2026-77482</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77484">CVE-2026-77484</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77486">CVE-2026-77486</a></td><td><p>Microsoft SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-66816">CVE-2026-66816</a></td><td><p>Microsoft SQL Server Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-66820">CVE-2026-66820</a></td><td><p>SQL Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73028">CVE-2026-73028</a></td><td><p>SQL Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77480">CVE-2026-77480</a></td><td><p>SQL Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77483">CVE-2026-77483</a></td><td><p>SQL Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77485">CVE-2026-77485</a></td><td><p>SQL Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77487">CVE-2026-77487</a></td><td><p>SQL Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78456">CVE-2026-78456</a></td><td><p>SQL Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78441">CVE-2026-78441</a></td><td><p>Windows OLE DB Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78442">CVE-2026-78442</a></td><td><p>Windows OLE DB Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr></tbody></table><p></p><p></p><h3>Windows vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62810">CVE-2026-62810</a></td><td><p>Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69821">CVE-2026-69821</a></td><td><p>Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69395">CVE-2026-69395</a></td><td><p>Active Directory Certificate Services (AD CS) Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69624">CVE-2026-69624</a></td><td><p>Active Directory Certificate Services (AD CS) Tampering Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69359">CVE-2026-69359</a></td><td><p>Active Directory Domain Services Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72978">CVE-2026-72978</a></td><td><p>Active Directory Federation Services (AD FS) Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69401">CVE-2026-69401</a></td><td><p>Audio Video Control Transport Protocol Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69329">CVE-2026-69329</a></td><td><p>BranchCache Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69516">CVE-2026-69516</a></td><td><p>Connected Devices Platform Service (Cdpsvc) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68824">CVE-2026-68824</a></td><td><p>Connected User Experiences and Telemetry Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68847">CVE-2026-68847</a></td><td><p>Connected User Experiences and Telemetry Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69470">CVE-2026-69470</a></td><td><p>Connected User Experiences and Telemetry Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69625">CVE-2026-69625</a></td><td><p>Connected User Experiences and Telemetry Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73014">CVE-2026-73014</a></td><td><p>Data Sharing Service Client Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73006">CVE-2026-73006</a></td><td><p>DirectWrite Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73016">CVE-2026-73016</a></td><td><p>DirectWrite Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69576">CVE-2026-69576</a></td><td><p>Graphic Fonts Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72986">CVE-2026-72986</a></td><td><p>Graphic Fonts Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73018">CVE-2026-73018</a></td><td><p>Graphic Fonts Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73017">CVE-2026-73017</a></td><td><p>Graphics Kernel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81353">CVE-2026-81353</a></td><td><p>HEIF Image Extensions Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-58600">CVE-2026-58600</a></td><td><p>HEVC Video Extensions Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-58599">CVE-2026-58599</a></td><td><p>HEVC Video Extensions Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69731">CVE-2026-69731</a></td><td><p>HID Class Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72983">CVE-2026-72983</a></td><td><p>Internet Connection Sharing (ICS) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68895">CVE-2026-68895</a></td><td><p>Internet Storage Name Service Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72981">CVE-2026-72981</a></td><td><p>IP Helper Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69275">CVE-2026-69275</a></td><td><p>Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69900">CVE-2026-69900</a></td><td><p>Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68850">CVE-2026-68850</a></td><td><p>Microsoft Account Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68852">CVE-2026-68852</a></td><td><p>Microsoft Account Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69299">CVE-2026-69299</a></td><td><p>Microsoft COM for Windows Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69294">CVE-2026-69294</a></td><td><p>Microsoft COM for Windows Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69491">CVE-2026-69491</a></td><td><p>Microsoft DirectMusic Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73010">CVE-2026-73010</a></td><td><p>Microsoft Failover Cluster Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78444">CVE-2026-78444</a></td><td><p>Microsoft Failover Cluster Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69467">CVE-2026-69467</a></td><td><p>Microsoft Graphics Component Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83990">CVE-2026-83990</a></td><td><p>Microsoft Graphics Component Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84000">CVE-2026-84000</a></td><td><p>Microsoft Graphics Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69605">CVE-2026-69605</a></td><td><p>Microsoft Install Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69325">CVE-2026-69325</a></td><td><p>Microsoft JScript Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69438">CVE-2026-69438</a></td><td><p>Microsoft JScript Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69277">CVE-2026-69277</a></td><td><p>Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69365">CVE-2026-69365</a></td><td><p>Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69594">CVE-2026-69594</a></td><td><p>Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68843">CVE-2026-68843</a></td><td><p>Microsoft Office Word Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69360">CVE-2026-69360</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77504">CVE-2026-77504</a></td><td><p>Microsoft Office Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69397">CVE-2026-69397</a></td><td><p>Microsoft OpenSSH for Windows Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62801">CVE-2026-62801</a></td><td><p>Microsoft PowerShell Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-57098">CVE-2026-57098</a></td><td><p>Microsoft Remote Desktop App for Windows Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-65669">CVE-2026-65669</a></td><td><p>Microsoft SQL Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68885">CVE-2026-68885</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68888">CVE-2026-68888</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68889">CVE-2026-68889</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68890">CVE-2026-68890</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68892">CVE-2026-68892</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68897">CVE-2026-68897</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69269">CVE-2026-69269</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69271">CVE-2026-69271</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69272">CVE-2026-69272</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69313">CVE-2026-69313</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69336">CVE-2026-69336</a></td><td><p>Microsoft Standard XPS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68881">CVE-2026-68881</a></td><td><p>Microsoft Standard XPS Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68891">CVE-2026-68891</a></td><td><p>Microsoft Standard XPS Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69308">CVE-2026-69308</a></td><td><p>Microsoft Standard XPS Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69345">CVE-2026-69345</a></td><td><p>Microsoft Standard XPS Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69367">CVE-2026-69367</a></td><td><p>Microsoft Standard XPS Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69376">CVE-2026-69376</a></td><td><p>Microsoft Standard XPS Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69824">CVE-2026-69824</a></td><td><p>Microsoft Standard XPS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72946">CVE-2026-72946</a></td><td><p>Microsoft Storage Port Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-56198">CVE-2026-56198</a></td><td><p>Microsoft Trace Data Helper Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69276">CVE-2026-69276</a></td><td><p>Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69420">CVE-2026-69420</a></td><td><p>Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69427">CVE-2026-69427</a></td><td><p>Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72933">CVE-2026-72933</a></td><td><p>Microsoft WDAC OLE DB provider for SQL Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70351">CVE-2026-70351</a></td><td><p>Microsoft WebP Image Extension Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62706">CVE-2026-62706</a></td><td><p>Microsoft Windows Media Foundation Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62744">CVE-2026-62744</a></td><td><p>Microsoft Windows Media Foundation Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69386">CVE-2026-69386</a></td><td><p>Microsoft Windows Media Foundation Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69408">CVE-2026-69408</a></td><td><p>Microsoft Windows Media Foundation Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69511">CVE-2026-69511</a></td><td><p>Microsoft Windows Media Foundation Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69601">CVE-2026-69601</a></td><td><p>Microsoft Windows Media Foundation Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69586">CVE-2026-69586</a></td><td><p>Microsoft Windows PDF Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78451">CVE-2026-78451</a></td><td><p>Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78452">CVE-2026-78452</a></td><td><p>Microsoft Windows SCSI Class System File Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78453">CVE-2026-78453</a></td><td><p>Microsoft Windows SCSI Class System File Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68896">CVE-2026-68896</a></td><td><p>Microsoft Windows Search Component Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69305">CVE-2026-69305</a></td><td><p>Microsoft Windows Search Component Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69322">CVE-2026-69322</a></td><td><p>Microsoft Windows Search Component Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69585">CVE-2026-69585</a></td><td><p>Microsoft Windows Search Component Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69600">CVE-2026-69600</a></td><td><p>Microsoft Windows Search Component Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69608">CVE-2026-69608</a></td><td><p>Microsoft Windows Search Component Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69911">CVE-2026-69911</a></td><td><p>Microsoft Windows Search Component Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69507">CVE-2026-69507</a></td><td><p>Microsoft Windows Search Component Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70145">CVE-2026-70145</a></td><td><p>Microsoft Windows Search Component Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69453">CVE-2026-69453</a></td><td><p>Microsoft Windows Search Component Tampering Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69554">CVE-2026-69554</a></td><td><p>Microsoft Windows Search Component Tampering Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69444">CVE-2026-69444</a></td><td><p>Microsoft Windows Speech Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69456">CVE-2026-69456</a></td><td><p>Microsoft Windows Speech Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69531">CVE-2026-69531</a></td><td><p>Microsoft Windows Speech Tampering Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69807">CVE-2026-69807</a></td><td><p>PowerShell Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69303">CVE-2026-69303</a></td><td><p>Push Message Routing Service Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69649">CVE-2026-69649</a></td><td><p>Raw Image Extension Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr></tbody></table><p></p><p></p><p></p><table><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68828"><br/>CVE-2026-68828</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69358">CVE-2026-69358</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69485">CVE-2026-69485</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78463">CVE-2026-78463</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80074">CVE-2026-80074</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80077">CVE-2026-80077</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83998">CVE-2026-83998</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69292">CVE-2026-69292</a></td><td><p>Remote Desktop Gateway Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69338">CVE-2026-69338</a></td><td><p>Remote Desktop Gateway Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68893">CVE-2026-68893</a></td><td><p>Remote Desktop Licensing Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69514">CVE-2026-69514</a></td><td><p>Remote Desktop Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69525">CVE-2026-69525</a></td><td><p>Remote Desktop Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69536">CVE-2026-69536</a></td><td><p>Remote Desktop Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69539">CVE-2026-69539</a></td><td><p>Remote Desktop Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69599">CVE-2026-69599</a></td><td><p>Remote Desktop Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69509">CVE-2026-69509</a></td><td><p>Role: Windows Fax Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69621">CVE-2026-69621</a></td><td><p>Role: Windows Fax Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72944">CVE-2026-72944</a></td><td><p>Role: Windows Fax Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69819">CVE-2026-69819</a></td><td><p>RPC Runtime Library Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69568">CVE-2026-69568</a></td><td><p>Storage Spaces Controller Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69431">CVE-2026-69431</a></td><td><p>Telnet Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69384">CVE-2026-69384</a></td><td><p>Virtual Hard Disk (VHD) Miniport Driver Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69541">CVE-2026-69541</a></td><td><p>Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69549">CVE-2026-69549</a></td><td><p>Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69611">CVE-2026-69611</a></td><td><p>Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69681">CVE-2026-69681</a></td><td><p>Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70574">CVE-2026-70574</a></td><td><p>Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81355">CVE-2026-81355</a></td><td><p>Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69407">CVE-2026-69407</a></td><td><p>Volume Manager Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69418">CVE-2026-69418</a></td><td><p>Volume Manager Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69432">CVE-2026-69432</a></td><td><p>Volume Manager Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72985">CVE-2026-72985</a></td><td><p>Volume Shadow Copy Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81352">CVE-2026-81352</a></td><td><p>Web Media Extensions Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69609">CVE-2026-69609</a></td><td><p>Win32k Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69808">CVE-2026-69808</a></td><td><p>Win32k Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69832">CVE-2026-69832</a></td><td><p>Win32k Information Disclosure Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>5.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69853">CVE-2026-69853</a></td><td><p>Win32k Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70290">CVE-2026-70290</a></td><td><p>Win32k Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69654">CVE-2026-69654</a></td><td><p>Windows Accounts Control Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69816">CVE-2026-69816</a></td><td><p>Windows Accounts Control Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62762">CVE-2026-62762</a></td><td><p>Windows Active Directory Domain Services Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69809">CVE-2026-69809</a></td><td><p>Windows Active Directory Domain Services Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62813">CVE-2026-62813</a></td><td><p>Windows Active Directory Domain Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69524">CVE-2026-69524</a></td><td><p>Windows Active Directory Domain Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69546">CVE-2026-69546</a></td><td><p>Windows Active Directory Domain Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-85880">CVE-2026-85880</a></td><td><p>Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Detected</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70565">CVE-2026-70565</a></td><td><p>Windows AF_UNIX Socket Provider Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69834">CVE-2026-69834</a></td><td><p>Windows ALPC Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69874">CVE-2026-69874</a></td><td><p>Windows ALPC Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50349">CVE-2026-50349</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70342">CVE-2026-70342</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69311">CVE-2026-69311</a></td><td><p>Windows Audio Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69394">CVE-2026-69394</a></td><td><p>Windows Audio Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69447">CVE-2026-69447</a></td><td><p>Windows Audio Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69540">CVE-2026-69540</a></td><td><p>Windows Audio Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69604">CVE-2026-69604</a></td><td><p>Windows Audio Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69692">CVE-2026-69692</a></td><td><p>Windows Audio Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69801">CVE-2026-69801</a></td><td><p>Windows Audio Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70562">CVE-2026-70562</a></td><td><p>Windows Audio Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73005">CVE-2026-73005</a></td><td><p>Windows Authentication Methods Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73004">CVE-2026-73004</a></td><td><p>Windows Autopilot Tampering Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68825">CVE-2026-68825</a></td><td><p>Windows Bind Filter Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69293">CVE-2026-69293</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69298">CVE-2026-69298</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69323">CVE-2026-69323</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69352">CVE-2026-69352</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69476">CVE-2026-69476</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69489">CVE-2026-69489</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69580">CVE-2026-69580</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69583">CVE-2026-69583</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69589">CVE-2026-69589</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69593">CVE-2026-69593</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69727">CVE-2026-69727</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69738">CVE-2026-69738</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69773">CVE-2026-69773</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69787">CVE-2026-69787</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69826">CVE-2026-69826</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70572">CVE-2026-70572</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70573">CVE-2026-70573</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70581">CVE-2026-70581</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72941">CVE-2026-72941</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72988">CVE-2026-72988</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72990">CVE-2026-72990</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72991">CVE-2026-72991</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72992">CVE-2026-72992</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72993">CVE-2026-72993</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72994">CVE-2026-72994</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72995">CVE-2026-72995</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72996">CVE-2026-72996</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72997">CVE-2026-72997</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73000">CVE-2026-73000</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73001">CVE-2026-73001</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73002">CVE-2026-73002</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73007">CVE-2026-73007</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73011">CVE-2026-73011</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73015">CVE-2026-73015</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73020">CVE-2026-73020</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73021">CVE-2026-73021</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73026">CVE-2026-73026</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77489">CVE-2026-77489</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78447">CVE-2026-78447</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78448">CVE-2026-78448</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83954">CVE-2026-83954</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83955">CVE-2026-83955</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83967">CVE-2026-83967</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83968">CVE-2026-83968</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83969">CVE-2026-83969</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83970">CVE-2026-83970</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83971">CVE-2026-83971</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83972">CVE-2026-83972</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83973">CVE-2026-83973</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83974">CVE-2026-83974</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83975">CVE-2026-83975</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83976">CVE-2026-83976</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83977">CVE-2026-83977</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83978">CVE-2026-83978</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83979">CVE-2026-83979</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83980">CVE-2026-83980</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83981">CVE-2026-83981</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83982">CVE-2026-83982</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83983">CVE-2026-83983</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83985">CVE-2026-83985</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83986">CVE-2026-83986</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83987">CVE-2026-83987</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83988">CVE-2026-83988</a></td><td><p>Windows Biometric Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73008">CVE-2026-73008</a></td><td><p>Windows Biometric Service Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69458">CVE-2026-69458</a></td><td><p>Windows BitLocker Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69449">CVE-2026-69449</a></td><td><p>Windows BitLocker Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69817">CVE-2026-69817</a></td><td><p>Windows Bluetooth Port Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68849">CVE-2026-68849</a></td><td><p>Windows Bluetooth Port Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69388">CVE-2026-69388</a></td><td><p>Windows Bluetooth Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69398">CVE-2026-69398</a></td><td><p>Windows Bluetooth Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69448">CVE-2026-69448</a></td><td><p>Windows Bluetooth Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69889">CVE-2026-69889</a></td><td><p>Windows Bluetooth Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77892">CVE-2026-77892</a></td><td><p>Windows Boot Manager Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69735">CVE-2026-69735</a></td><td><p>Windows Broadcast DVR User Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69391">CVE-2026-69391</a></td><td><p>Windows Broker Infrastructure Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69542">CVE-2026-69542</a></td><td><p>Windows Camera Frame Server Monitor Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69283">CVE-2026-69283</a></td><td><p>Windows CD-ROM Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69561">CVE-2026-69561</a></td><td><p>Windows CD-ROM Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78454">CVE-2026-78454</a></td><td><p>Windows CD-ROM Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78508">CVE-2026-78508</a></td><td><p>Windows CD-ROM Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69279">CVE-2026-69279</a></td><td><p>Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80093">CVE-2026-80093</a></td><td><p>Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83991">CVE-2026-83991</a></td><td><p>Windows Cloud Files Mini Filter Driver Tampering Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69445">CVE-2026-69445</a></td><td><p>Windows Compressed Folder Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70019">CVE-2026-70019</a></td><td><p>Windows Compressed Folder Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69496">CVE-2026-69496</a></td><td><p>Windows Compressed Folder Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr></tbody></table><p></p><p></p><p></p><table><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69267"><br/>CVE-2026-69267</a></td><td><p>Windows Connected User Experiences and Telemetry Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69771">CVE-2026-69771</a></td><td><p>Windows Container Manager Service Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70583">CVE-2026-70583</a></td><td><p>Windows Core Messaging Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70584">CVE-2026-70584</a></td><td><p>Windows Core Messaging Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70578">CVE-2026-70578</a></td><td><p>Windows Credential Guard Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72958">CVE-2026-72958</a></td><td><p>Windows Credential Guard Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69790">CVE-2026-69790</a></td><td><p>Windows Credential Providers Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69814">CVE-2026-69814</a></td><td><p>Windows Credential Providers Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69729">CVE-2026-69729</a></td><td><p>Windows Credential Providers Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69284">CVE-2026-69284</a></td><td><p>Windows DCOM Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70568">CVE-2026-70568</a></td><td><p>Windows Defender Firewall Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68831">CVE-2026-68831</a></td><td><p>Windows Defender Firewall Service Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69607">CVE-2026-69607</a></td><td><p>Windows Deployment Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72943">CVE-2026-72943</a></td><td><p>Windows Deployment Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72954">CVE-2026-72954</a></td><td><p>Windows Deployment Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72957">CVE-2026-72957</a></td><td><p>Windows Deployment Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69314">CVE-2026-69314</a></td><td><p>Windows Device Association Broker Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69693">CVE-2026-69693</a></td><td><p>Windows Device Association Broker Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69296">CVE-2026-69296</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69478">CVE-2026-69478</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69488">CVE-2026-69488</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69574">CVE-2026-69574</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69581">CVE-2026-69581</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69711">CVE-2026-69711</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69714">CVE-2026-69714</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69791">CVE-2026-69791</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69866">CVE-2026-69866</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77500">CVE-2026-77500</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83940">CVE-2026-83940</a></td><td><p>Windows Device Association Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69443">CVE-2026-69443</a></td><td><p>Windows Device Health Attestation (DHA) Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69472">CVE-2026-69472</a></td><td><p>Windows Devices Human Interface Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69781">CVE-2026-69781</a></td><td><p>Windows DHCP Client Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69777">CVE-2026-69777</a></td><td><p>Windows DHCP Client Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69342">CVE-2026-69342</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69405">CVE-2026-69405</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69416">CVE-2026-69416</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69497">CVE-2026-69497</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69637">CVE-2026-69637</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69679">CVE-2026-69679</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70065">CVE-2026-70065</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77494">CVE-2026-77494</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77498">CVE-2026-77498</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77499">CVE-2026-77499</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77501">CVE-2026-77501</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77502">CVE-2026-77502</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77886">CVE-2026-77886</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77888">CVE-2026-77888</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77889">CVE-2026-77889</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77890">CVE-2026-77890</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77893">CVE-2026-77893</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77895">CVE-2026-77895</a></td><td><p>Windows DHCP Server Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69415">CVE-2026-69415</a></td><td><p>Windows DHCP Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69297">CVE-2026-69297</a></td><td><p>Windows DHCP Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69803">CVE-2026-69803</a></td><td><p>Windows DHCP Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69929">CVE-2026-69929</a></td><td><p>Windows DHCP Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69930">CVE-2026-69930</a></td><td><p>Windows DHCP Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70124">CVE-2026-70124</a></td><td><p>Windows DHCP Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69266">CVE-2026-69266</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69412">CVE-2026-69412</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69510">CVE-2026-69510</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69547">CVE-2026-69547</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69620">CVE-2026-69620</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69845">CVE-2026-69845</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69847">CVE-2026-69847</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69876">CVE-2026-69876</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69878">CVE-2026-69878</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72979">CVE-2026-72979</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77887">CVE-2026-77887</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77891">CVE-2026-77891</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69715">CVE-2026-69715</a></td><td><p>Windows Direct Show Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70567">CVE-2026-70567</a></td><td><p>Windows Display Enhancement Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78446">CVE-2026-78446</a></td><td><p>Windows Distributed File System (DFS) Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69424">CVE-2026-69424</a></td><td><p>Windows Distributed File System (DFS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69631">CVE-2026-69631</a></td><td><p>Windows DNS Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70091">CVE-2026-70091</a></td><td><p>Windows DNS Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69310">CVE-2026-69310</a></td><td><p>Windows DNS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72948">CVE-2026-72948</a></td><td><p>Windows DNS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69369">CVE-2026-69369</a></td><td><p>Windows DNS Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69672">CVE-2026-69672</a></td><td><p>Windows DNS Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72987">CVE-2026-72987</a></td><td><p>Windows DNS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78523">CVE-2026-78523</a></td><td><p>Windows DNS Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69551">CVE-2026-69551</a></td><td><p>Windows DNS Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69730">CVE-2026-69730</a></td><td><p>Windows DNS Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69782">CVE-2026-69782</a></td><td><p>Windows DNS Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69813">CVE-2026-69813</a></td><td><p>Windows DNS Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69827">CVE-2026-69827</a></td><td><p>Windows DNS Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69858">CVE-2026-69858</a></td><td><p>Windows DNS Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69989">CVE-2026-69989</a></td><td><p>Windows DNS Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72928">CVE-2026-72928</a></td><td><p>Windows DNS Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77505">CVE-2026-77505</a></td><td><p>Windows DNS Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69680">CVE-2026-69680</a></td><td><p>Windows DNS Spoofing Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69775">CVE-2026-69775</a></td><td><p>Windows DWM Core Library Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69430">CVE-2026-69430</a></td><td><p>Windows Embedded Mode Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69688">CVE-2026-69688</a></td><td><p>Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69841">CVE-2026-69841</a></td><td><p>Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69794">CVE-2026-69794</a></td><td><p>Windows Encrypting File System (EFS) Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69481">CVE-2026-69481</a></td><td><p>Windows Enterprise App Management Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69907">CVE-2026-69907</a></td><td><p>Windows Enterprise App Management Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68894">CVE-2026-68894</a></td><td><p>Windows Error Reporting Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69362">CVE-2026-69362</a></td><td><p>Windows Error Reporting Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69433">CVE-2026-69433</a></td><td><p>Windows Error Reporting Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69436">CVE-2026-69436</a></td><td><p>Windows Error Reporting Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69450">CVE-2026-69450</a></td><td><p>Windows Error Reporting Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69462">CVE-2026-69462</a></td><td><p>Windows Error Reporting Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69513">CVE-2026-69513</a></td><td><p>Windows Error Reporting Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69612">CVE-2026-69612</a></td><td><p>Windows Error Reporting Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69896">CVE-2026-69896</a></td><td><p>Windows Error Reporting Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83996">CVE-2026-83996</a></td><td><p>Windows Error Reporting Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69684">CVE-2026-69684</a></td><td><p>Windows Error Reporting Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69482">CVE-2026-69482</a></td><td><p>Windows Error Reporting Tampering Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69493">CVE-2026-69493</a></td><td><p>Windows Event Logging Service Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69494">CVE-2026-69494</a></td><td><p>Windows Event Logging Service Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69495">CVE-2026-69495</a></td><td><p>Windows Event Logging Service Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69619">CVE-2026-69619</a></td><td><p>Windows exFAT File System Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71338">CVE-2026-71338</a></td><td><p>Windows Failover Cluster Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72989">CVE-2026-72989</a></td><td><p>Windows Failover Cluster Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68878">CVE-2026-68878</a></td><td><p>Windows Fast FAT Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69347">CVE-2026-69347</a></td><td><p>Windows Fast FAT Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68837">CVE-2026-68837</a></td><td><p>Windows File History Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71340">CVE-2026-71340</a></td><td><p>Windows File History Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72947">CVE-2026-72947</a></td><td><p>Windows File History Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77491">CVE-2026-77491</a></td><td><p>Windows GDI Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68827">CVE-2026-68827</a></td><td><p>Windows GDI+ Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69288">CVE-2026-69288</a></td><td><p>Windows GDI+ Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77493">CVE-2026-77493</a></td><td><p>Windows Graphics Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81955">CVE-2026-81955</a></td><td><p>Windows Graphics Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69717">CVE-2026-69717</a></td><td><p>Windows Group Policy Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69710">CVE-2026-69710</a></td><td><p>Windows Hello Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69725">CVE-2026-69725</a></td><td><p>Windows Hello Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69740">CVE-2026-69740</a></td><td><p>Windows Hello Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69784">CVE-2026-69784</a></td><td><p>Windows Hello Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69799">CVE-2026-69799</a></td><td><p>Windows Hello Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69820">CVE-2026-69820</a></td><td><p>Windows Hello Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69864">CVE-2026-69864</a></td><td><p>Windows Hello Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81354">CVE-2026-81354</a></td><td><p>Windows Hello Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72980">CVE-2026-72980</a></td><td><p>Windows Hello Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69682">CVE-2026-69682</a></td><td><p>Windows Host Guardian Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69623">CVE-2026-69623</a></td><td><p>Windows HTTP Print Provider Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69769">CVE-2026-69769</a></td><td><p>Windows HTTP Print Provider Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69597">CVE-2026-69597</a></td><td><p>Windows HTTP.sys Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69553">CVE-2026-69553</a></td><td><p>Windows Hyper-V Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72961">CVE-2026-72961</a></td><td><p>Windows Hyper-V Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69603">CVE-2026-69603</a></td><td><p>Windows Hyper-V Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69910">CVE-2026-69910</a></td><td><p>Windows Hyper-V Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80083">CVE-2026-80083</a></td><td><p>Windows Hyper-V Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69341">CVE-2026-69341</a></td><td><p>Windows Image Acquisition Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69500">CVE-2026-69500</a></td><td><p>Windows Image Acquisition Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69613">CVE-2026-69613</a></td><td><p>Windows Image Acquisition Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69483">CVE-2026-69483</a></td><td><p>Windows Image Acquisition Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69318">CVE-2026-69318</a></td><td><p>Windows Imaging Component Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69499">CVE-2026-69499</a></td><td><p>Windows Imaging Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69860">CVE-2026-69860</a></td><td><p>Windows Imaging Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70296">CVE-2026-70296</a></td><td><p>Windows Imaging Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73013">CVE-2026-73013</a></td><td><p>Windows Imaging Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73023">CVE-2026-73023</a></td><td><p>Windows Imaging Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77495">CVE-2026-77495</a></td><td><p>Windows Imaging Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83992">CVE-2026-83992</a></td><td><p>Windows Imaging Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62694">CVE-2026-62694</a></td><td><p>Windows Installer Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69441">CVE-2026-69441</a></td><td><p>Windows Installer Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71339">CVE-2026-71339</a></td><td><p>Windows Installer Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72929">CVE-2026-72929</a></td><td><p>Windows Installer Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77894">CVE-2026-77894</a></td><td><p>Windows Installer Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72926">CVE-2026-72926</a></td><td><p>Windows Internet Connection Sharing (ICS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72964">CVE-2026-72964</a></td><td><p>Windows Internet Connection Sharing (ICS) Tampering Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69587">CVE-2026-69587</a></td><td><p>Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69881">CVE-2026-69881</a></td><td><p>Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69429">CVE-2026-69429</a></td><td><p>Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69694">CVE-2026-69694</a></td><td><p>Windows IP Address Management (IPAM) Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68898">CVE-2026-68898</a></td><td><p>Windows iSCSI Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69598">CVE-2026-69598</a></td><td><p>Windows iSCSI Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69628">CVE-2026-69628</a></td><td><p>Windows iSCSI Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73025">CVE-2026-73025</a></td><td><p>Windows iSCSI Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr></tbody></table><p></p><p></p><p></p><table><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69839"><br/>CVE-2026-69839</a></td><td><p>Windows iSCSI Target Service Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69744">CVE-2026-69744</a></td><td><p>Windows Kerberos Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69760">CVE-2026-69760</a></td><td><p>Windows Kerberos Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69685">CVE-2026-69685</a></td><td><p>Windows Kerberos Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69822">CVE-2026-69822</a></td><td><p>Windows Kerberos Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69676">CVE-2026-69676</a></td><td><p>Windows Kerberos Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68846">CVE-2026-68846</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68884">CVE-2026-68884</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69366">CVE-2026-69366</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69466">CVE-2026-69466</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69473">CVE-2026-69473</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69578">CVE-2026-69578</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83942">CVE-2026-83942</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-85360">CVE-2026-85360</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69406">CVE-2026-69406</a></td><td><p>Windows Kernel Information Disclosure Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69723">CVE-2026-69723</a></td><td><p>Windows Kernel Information Disclosure Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69669">CVE-2026-69669</a></td><td><p>Windows Kernel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69421">CVE-2026-69421</a></td><td><p>Windows Kernel-Mode Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-84001">CVE-2026-84001</a></td><td><p>Windows Key Distribution Center Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69712">CVE-2026-69712</a></td><td><p>Windows Key Distribution Center Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69428">CVE-2026-69428</a></td><td><p>Windows LDAP - Lightweight Directory Access Protocol Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69281">CVE-2026-69281</a></td><td><p>Windows License Manager Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69315">CVE-2026-69315</a></td><td><p>Windows License Manager Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69732">CVE-2026-69732</a></td><td><p>Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69451">CVE-2026-69451</a></td><td><p>Windows Management Instrumentation Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70582">CVE-2026-70582</a></td><td><p>Windows Management Instrumentation Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77905">CVE-2026-77905</a></td><td><p>Windows Management Instrumentation Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69349">CVE-2026-69349</a></td><td><p>Windows Management Instrumentation Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73012">CVE-2026-73012</a></td><td><p>Windows Management Services Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69891">CVE-2026-69891</a></td><td><p>Windows Media Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70203">CVE-2026-70203</a></td><td><p>Windows Media Player Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72960">CVE-2026-72960</a></td><td><p>Windows Media Player Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69645">CVE-2026-69645</a></td><td><p>Windows Message Queuing Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68887">CVE-2026-68887</a></td><td><p>Windows Message Queuing Queue Manager Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72932">CVE-2026-72932</a></td><td><p>Windows Message Queuing Queue Manager Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69579">CVE-2026-69579</a></td><td><p>Windows Message Queuing Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83997">CVE-2026-83997</a></td><td><p>Windows Message Queuing Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69440">CVE-2026-69440</a></td><td><p>Windows MIDI Service Module Elevation of Privileges Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69508">CVE-2026-69508</a></td><td><p>Windows MIDI Service Module Elevation of Privileges Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69720">CVE-2026-69720</a></td><td><p>Windows MIDI Service Module Elevation of Privileges Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78464">CVE-2026-78464</a></td><td><p>Windows MIDI Service Module Elevation of Privileges Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68842">CVE-2026-68842</a></td><td><p>Windows MIDI Service Module Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69339">CVE-2026-69339</a></td><td><p>Windows MIDI Service Module Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70579">CVE-2026-70579</a></td><td><p>Windows Mobile Broadband Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69377">CVE-2026-69377</a></td><td><p>Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69460">CVE-2026-69460</a></td><td><p>Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70577">CVE-2026-70577</a></td><td><p>Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73003">CVE-2026-73003</a></td><td><p>Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73022">CVE-2026-73022</a></td><td><p>Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69674">CVE-2026-69674</a></td><td><p>Windows Modern Device Management (MDM) Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72963">CVE-2026-72963</a></td><td><p>Windows Modern Execution Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69357">CVE-2026-69357</a></td><td><p>Windows NDIS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69396">CVE-2026-69396</a></td><td><p>Windows NDIS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72982">CVE-2026-72982</a></td><td><p>Windows Netlogon Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62759">CVE-2026-62759</a></td><td><p>Windows Netlogon Spoofing Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72967">CVE-2026-72967</a></td><td><p>Windows Network Connection Broker Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68886">CVE-2026-68886</a></td><td><p>Windows Network Connection Broker Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69372">CVE-2026-69372</a></td><td><p>Windows Network File System Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69772">CVE-2026-69772</a></td><td><p>Windows Network File System Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71334">CVE-2026-71334</a></td><td><p>Windows NFS Portmapper Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69648">CVE-2026-69648</a></td><td><p>Windows Notification Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68832">CVE-2026-68832</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68834">CVE-2026-68834</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68838">CVE-2026-68838</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68841">CVE-2026-68841</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69265">CVE-2026-69265</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69312">CVE-2026-69312</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69332">CVE-2026-69332</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69340">CVE-2026-69340</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69379">CVE-2026-69379</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69505">CVE-2026-69505</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69532">CVE-2026-69532</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69567">CVE-2026-69567</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69875">CVE-2026-69875</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72935">CVE-2026-72935</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77503">CVE-2026-77503</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83995">CVE-2026-83995</a></td><td><p>Windows NTFS Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68851">CVE-2026-68851</a></td><td><p>Windows NTFS Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69504">CVE-2026-69504</a></td><td><p>Windows NTFS Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69591">CVE-2026-69591</a></td><td><p>Windows NTFS Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68833">CVE-2026-68833</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68875">CVE-2026-68875</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69461">CVE-2026-69461</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69463">CVE-2026-69463</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69479">CVE-2026-69479</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69566">CVE-2026-69566</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69638">CVE-2026-69638</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69709">CVE-2026-69709</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71329">CVE-2026-71329</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69425">CVE-2026-69425</a></td><td><p>Windows NTFS Tampering Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69564">CVE-2026-69564</a></td><td><p>Windows Online Certificate Status Protocol (OCSP) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69350">CVE-2026-69350</a></td><td><p>Windows Overlay Filter Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69368">CVE-2026-69368</a></td><td><p>Windows Overlay Filter Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69371">CVE-2026-69371</a></td><td><p>Windows Overlay Filter Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69373">CVE-2026-69373</a></td><td><p>Windows Overlay Filter Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69316">CVE-2026-69316</a></td><td><p>Windows Overlay Filter Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69343">CVE-2026-69343</a></td><td><p>Windows Overlay Filter Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69474">CVE-2026-69474</a></td><td><p>Windows Overlay Filter Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70586">CVE-2026-70586</a></td><td><p>Windows Paint Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69480">CVE-2026-69480</a></td><td><p>Windows Partition Management Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69492">CVE-2026-69492</a></td><td><p>Windows Partition Management Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71341">CVE-2026-71341</a></td><td><p>Windows Partition Management Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69324">CVE-2026-69324</a></td><td><p>Windows Performance Monitor Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69459">CVE-2026-69459</a></td><td><p>Windows Power Dependency Coordinator Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69321">CVE-2026-69321</a></td><td><p>Windows Power Dependency Coordinator Tampering Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69569">CVE-2026-69569</a></td><td><p>Windows Print Spooler Components Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68835">CVE-2026-68835</a></td><td><p>Windows Print Spooler Components Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68848">CVE-2026-68848</a></td><td><p>Windows Print Spooler Components Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69309">CVE-2026-69309</a></td><td><p>Windows Print Spooler Components Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69346">CVE-2026-69346</a></td><td><p>Windows Print Spooler Components Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69364">CVE-2026-69364</a></td><td><p>Windows Print Spooler Components Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69838">CVE-2026-69838</a></td><td><p>Windows Print Spooler Components Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69921">CVE-2026-69921</a></td><td><p>Windows Print Spooler Components Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70564">CVE-2026-70564</a></td><td><p>Windows Print Spooler Components Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69344">CVE-2026-69344</a></td><td><p>Windows Print Spooler Components Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69552">CVE-2026-69552</a></td><td><p>Windows Print Spooler Components Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-85877">CVE-2026-85877</a></td><td><p>Windows Print Spooler Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69602">CVE-2026-69602</a></td><td><p>Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68845">CVE-2026-68845</a></td><td><p>Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68876">CVE-2026-68876</a></td><td><p>Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69534">CVE-2026-69534</a></td><td><p>Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69563">CVE-2026-69563</a></td><td><p>Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68873">CVE-2026-68873</a></td><td><p>Windows Program Compatibility Assistant Service Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68874">CVE-2026-68874</a></td><td><p>Windows Program Compatibility Assistant Service Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62697">CVE-2026-62697</a></td><td><p>Windows Push Notifications Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69280">CVE-2026-69280</a></td><td><p>Windows Push Notifications Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69300">CVE-2026-69300</a></td><td><p>Windows Push Notifications Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69337">CVE-2026-69337</a></td><td><p>Windows Registry Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69530">CVE-2026-69530</a></td><td><p>Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78449">CVE-2026-78449</a></td><td><p>Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78450">CVE-2026-78450</a></td><td><p>Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69331">CVE-2026-69331</a></td><td><p>Windows Remote Access Connection Manager Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69455">CVE-2026-69455</a></td><td><p>Windows Remote Access Connection Manager Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71333">CVE-2026-71333</a></td><td><p>Windows Remote Access Connection Manager Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71342">CVE-2026-71342</a></td><td><p>Windows Remote Access Connection Manager Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71343">CVE-2026-71343</a></td><td><p>Windows Remote Access Connection Manager Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71352">CVE-2026-71352</a></td><td><p>Windows Remote Access Connection Manager Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72966">CVE-2026-72966</a></td><td><p>Windows Remote Access Connection Manager Tampering Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77896">CVE-2026-77896</a></td><td><p>Windows Remote Desktop Client Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69317">CVE-2026-69317</a></td><td><p>Windows Remote Desktop Client Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69627">CVE-2026-69627</a></td><td><p>Windows Remote Desktop Licensing Service Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70587">CVE-2026-70587</a></td><td><p>Windows Remote Desktop Protocol Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69518">CVE-2026-69518</a></td><td><p>Windows Remote Desktop Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69287">CVE-2026-69287</a></td><td><p>Windows Remote Desktop Services Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69475">CVE-2026-69475</a></td><td><p>Windows Remote Desktop Services Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80096">CVE-2026-80096</a></td><td><p>Windows Remote Desktop Services Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69616">CVE-2026-69616</a></td><td><p>Windows Remote Desktop Services Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83999">CVE-2026-83999</a></td><td><p>Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69617">CVE-2026-69617</a></td><td><p>Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83952">CVE-2026-83952</a></td><td><p>Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69548">CVE-2026-69548</a></td><td><p>Windows RNDIS Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69768">CVE-2026-69768</a></td><td><p>Windows RNDIS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72939">CVE-2026-72939</a></td><td><p>Windows Routing and Remote Access Service (RRAS) Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71351">CVE-2026-71351</a></td><td><p>Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71353">CVE-2026-71353</a></td><td><p>Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69590">CVE-2026-69590</a></td><td><p>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69852">CVE-2026-69852</a></td><td><p>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70570">CVE-2026-70570</a></td><td><p>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72950">CVE-2026-72950</a></td><td><p>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72959">CVE-2026-72959</a></td><td><p>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70575">CVE-2026-70575</a></td><td><p>Windows Schannel Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72940">CVE-2026-72940</a></td><td><p>Windows Schannel Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69713">CVE-2026-69713</a></td><td><p>Windows Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69501">CVE-2026-69501</a></td><td><p>Windows Secure Kernel Mode Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69846">CVE-2026-69846</a></td><td><p>Windows Secure Kernel Mode Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69906">CVE-2026-69906</a></td><td><p>Windows Secure Kernel Mode Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83939">CVE-2026-83939</a></td><td><p>Windows Secure Kernel Mode Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72931">CVE-2026-72931</a></td><td><p>Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71332">CVE-2026-71332</a></td><td><p>Windows Secure Socket Tunneling Protocol (SSTP) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72930">CVE-2026-72930</a></td><td><p>Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73009">CVE-2026-73009</a></td><td><p>Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr></tbody></table><p></p><p></p><p></p><table><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77899"><br/>CVE-2026-77899</a></td><td><p>Windows Security Center Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78457">CVE-2026-78457</a></td><td><p>Windows Security Health Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-56177">CVE-2026-56177</a></td><td><p>Windows Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83989">CVE-2026-83989</a></td><td><p>Windows Services for NFS ONCRPC XDR Driver Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73024">CVE-2026-73024</a></td><td><p>Windows Services for NFS ONCRPC XDR Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71330">CVE-2026-71330</a></td><td><p>Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69595">CVE-2026-69595</a></td><td><p>Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70585">CVE-2026-70585</a></td><td><p>Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78445">CVE-2026-78445</a></td><td><p>Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69289">CVE-2026-69289</a></td><td><p>Windows Setup Files Cleanup Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69383">CVE-2026-69383</a></td><td><p>Windows Shell Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69392">CVE-2026-69392</a></td><td><p>Windows Shell Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69528">CVE-2026-69528</a></td><td><p>Windows Shell Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69606">CVE-2026-69606</a></td><td><p>Windows Shell Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69829">CVE-2026-69829</a></td><td><p>Windows Shell Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70563">CVE-2026-70563</a></td><td><p>Windows Shell Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69785">CVE-2026-69785</a></td><td><p>Windows Smart Card Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69544">CVE-2026-69544</a></td><td><p>Windows SMB Client Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69572">CVE-2026-69572</a></td><td><p>Windows SMB Client Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69618">CVE-2026-69618</a></td><td><p>Windows SMB Client Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72936">CVE-2026-72936</a></td><td><p>Windows SMB Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69374">CVE-2026-69374</a></td><td><p>Windows SMB Server Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69403">CVE-2026-69403</a></td><td><p>Windows SMB Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72949">CVE-2026-72949</a></td><td><p>Windows SMB Server Network Transport Driver (srvnet.sys) Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69512">CVE-2026-69512</a></td><td><p>Windows Spaceport.sys Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69535">CVE-2026-69535</a></td><td><p>Windows Spaceport.sys Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69643">CVE-2026-69643</a></td><td><p>Windows Spaceport.sys Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69691">CVE-2026-69691</a></td><td><p>Windows Spaceport.sys Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70569">CVE-2026-70569</a></td><td><p>Windows Spaceport.sys Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69390">CVE-2026-69390</a></td><td><p>Windows Spaceport.sys Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69393">CVE-2026-69393</a></td><td><p>Windows Spaceport.sys Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69741">CVE-2026-69741</a></td><td><p>Windows Spaceport.sys Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69770">CVE-2026-69770</a></td><td><p>Windows Spaceport.sys Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69895">CVE-2026-69895</a></td><td><p>Windows Spaceport.sys Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72942">CVE-2026-72942</a></td><td><p>Windows Spaceport.sys Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69538">CVE-2026-69538</a></td><td><p>Windows Spaceport.sys Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71345">CVE-2026-71345</a></td><td><p>Windows Spaceport.sys Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71348">CVE-2026-71348</a></td><td><p>Windows Spaceport.sys Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71349">CVE-2026-71349</a></td><td><p>Windows Spaceport.sys Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71350">CVE-2026-71350</a></td><td><p>Windows Spaceport.sys Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72952">CVE-2026-72952</a></td><td><p>Windows Spaceport.sys Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69328">CVE-2026-69328</a></td><td><p>Windows Storage Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78516">CVE-2026-78516</a></td><td><p>Windows Storage Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69389">CVE-2026-69389</a></td><td><p>Windows Storage Management Provider Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71337">CVE-2026-71337</a></td><td><p>Windows Storage Management Provider Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69381">CVE-2026-69381</a></td><td><p>Windows Storage Port Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72937">CVE-2026-72937</a></td><td><p>Windows Storage Port Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77492">CVE-2026-77492</a></td><td><p>Windows Storage Port Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69290">CVE-2026-69290</a></td><td><p>Windows Storage Spaces Controller Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69575">CVE-2026-69575</a></td><td><p>Windows Storage Spaces Controller Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68844">CVE-2026-68844</a></td><td><p>Windows Storage Spaces Controller Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68877">CVE-2026-68877</a></td><td><p>Windows Storage Spaces Controller Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72945">CVE-2026-72945</a></td><td><p>Windows Task Scheduler Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69588">CVE-2026-69588</a></td><td><p>Windows TCP/IP Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69385">CVE-2026-69385</a></td><td><p>Windows TCP/IP Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69404">CVE-2026-69404</a></td><td><p>Windows TCP/IP Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69757">CVE-2026-69757</a></td><td><p>Windows TCP/IP Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69761">CVE-2026-69761</a></td><td><p>Windows TCP/IP Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69793">CVE-2026-69793</a></td><td><p>Windows TCP/IP Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69353">CVE-2026-69353</a></td><td><p>Windows Text Shaping Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69786">CVE-2026-69786</a></td><td><p>Windows Text Shaping Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69573">CVE-2026-69573</a></td><td><p>Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69592">CVE-2026-69592</a></td><td><p>Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69758">CVE-2026-69758</a></td><td><p>Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68830">CVE-2026-68830</a></td><td><p>Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69351">CVE-2026-69351</a></td><td><p>Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81963">CVE-2026-81963</a></td><td><p>Windows Update Stack Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Detected</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69434">CVE-2026-69434</a></td><td><p>Windows URL Moniker Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73019">CVE-2026-73019</a></td><td><p>Windows URL Moniker Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69270">CVE-2026-69270</a></td><td><p>Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69307">CVE-2026-69307</a></td><td><p>Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69413">CVE-2026-69413</a></td><td><p>Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69469">CVE-2026-69469</a></td><td><p>Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69571">CVE-2026-69571</a></td><td><p>Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69687">CVE-2026-69687</a></td><td><p>Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69707">CVE-2026-69707</a></td><td><p>Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69859">CVE-2026-69859</a></td><td><p>Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69286">CVE-2026-69286</a></td><td><p>Windows USB Audio Class Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68840">CVE-2026-68840</a></td><td><p>Windows USB Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69295">CVE-2026-69295</a></td><td><p>Windows USB Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69503">CVE-2026-69503</a></td><td><p>Windows USB Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72953">CVE-2026-72953</a></td><td><p>Windows USB Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69457">CVE-2026-69457</a></td><td><p>Windows USB Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72999">CVE-2026-72999</a></td><td><p>Windows USB Hub Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69490">CVE-2026-69490</a></td><td><p>Windows USB Mass Storage Class Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69527">CVE-2026-69527</a></td><td><p>Windows USB Mass Storage Class Driver Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68839">CVE-2026-68839</a></td><td><p>Windows USB Mass Storage Class Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69319">CVE-2026-69319</a></td><td><p>Windows USB Video Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69422">CVE-2026-69422</a></td><td><p>Windows USB Video Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69423">CVE-2026-69423</a></td><td><p>Windows USB Video Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69584">CVE-2026-69584</a></td><td><p>Windows USB Video Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72962">CVE-2026-72962</a></td><td><p>Windows USB Video Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-56172">CVE-2026-56172</a></td><td><p>Windows VHD miniport driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69890">CVE-2026-69890</a></td><td><p>Windows Virtual Trusted Platform Module Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83498">CVE-2026-83498</a></td><td><p>Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83501">CVE-2026-83501</a></td><td><p>Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69426">CVE-2026-69426</a></td><td><p>Windows VOLSNAP.SYS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69468">CVE-2026-69468</a></td><td><p>Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69582">CVE-2026-69582</a></td><td><p>Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77904">CVE-2026-77904</a></td><td><p>Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69291">CVE-2026-69291</a></td><td><p>Windows Volume Manager Extension Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69334">CVE-2026-69334</a></td><td><p>Windows Volume Manager Extension Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69708">CVE-2026-69708</a></td><td><p>Windows Web Platform Storage Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72965">CVE-2026-72965</a></td><td><p>Windows WebClient Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68880">CVE-2026-68880</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69274">CVE-2026-69274</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69301">CVE-2026-69301</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69333">CVE-2026-69333</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69335">CVE-2026-69335</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69348">CVE-2026-69348</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr></tbody></table><p></p><p></p><p></p><table><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69410"><br/>CVE-2026-69410</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69498">CVE-2026-69498</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69610">CVE-2026-69610</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69630">CVE-2026-69630</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69652">CVE-2026-69652</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69689">CVE-2026-69689</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69706">CVE-2026-69706</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69762">CVE-2026-69762</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69779">CVE-2026-69779</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69818">CVE-2026-69818</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69844">CVE-2026-69844</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70283">CVE-2026-70283</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70289">CVE-2026-70289</a></td><td><p>Windows Win32k Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69792">CVE-2026-69792</a></td><td><p>Windows Win32K Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69517">CVE-2026-69517</a></td><td><p>Windows Wireless Networking Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69862">CVE-2026-69862</a></td><td><p>Windows Wireless Wide Area Network Service Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69560">CVE-2026-69560</a></td><td><p>Windows Work Folder Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-71336">CVE-2026-71336</a></td><td><p>Windows Work Folder Service Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80075">CVE-2026-80075</a></td><td><p>Windows Work Folders Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72927">CVE-2026-72927</a></td><td><p>Winsock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78455">CVE-2026-78455</a></td><td><p>Xbox Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.3</p></td></tr></tbody></table><h2>Uncategorized Vulnerabilities</h2><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-19931">CVE-2026-19931</a></td><td><p>Negotiate ambient user conn reuse</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-82208">CVE-2026-82208</a></td><td><p>wolfSSL CA-cache hit overrides callback</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-13608">CVE-2026-13608</a></td><td><p>OpenLDAP SASL authentication bypass</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>3.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-18924">CVE-2026-18924</a></td><td><p>HTTP/2 server push UAF</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.9</p></td></tr></tbody></table><h2>Zero-Day Vulnerabilities: Known Exploited</h2><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-85880">CVE-2026-85880</a></td><td><p>Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Detected</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81963">CVE-2026-81963</a></td><td><p>Windows Update Stack Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Detected</p></td><td><p>No</p></td><td><p>7.8</p></td></tr></tbody></table><h2>Critical RCEs and EoPs</h2><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70352">CVE-2026-70352</a></td><td><p>Azure AI Language Elevation of Privilege Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>10.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-80098">CVE-2026-80098</a></td><td><p>Copilot Studio Elevation of Privilege Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>9.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83941">CVE-2026-83941</a></td><td><p>Entra ID Elevation of Privilege Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>9.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72983">CVE-2026-72983</a></td><td><p>Internet Connection Sharing (ICS) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83711">CVE-2026-83711</a></td><td><p>Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>10.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69491">CVE-2026-69491</a></td><td><p>Microsoft DirectMusic Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-62916">CVE-2026-62916</a></td><td><p>Microsoft Entra ID Elevation of Privilege Vulnerability</p></td><td><p>N/A</p></td><td><p>No</p></td><td><p>9.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69641">CVE-2026-69641</a></td><td><p>Microsoft Exchange Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73010">CVE-2026-73010</a></td><td><p>Microsoft Failover Cluster Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78509">CVE-2026-78509</a></td><td><p>Microsoft Office Outlook Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-65669">CVE-2026-65669</a></td><td><p>Microsoft SQL Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69824">CVE-2026-69824</a></td><td><p>Microsoft Standard XPS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69276">CVE-2026-69276</a></td><td><p>Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69408">CVE-2026-69408</a></td><td><p>Microsoft Windows Media Foundation Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69586">CVE-2026-69586</a></td><td><p>Microsoft Windows PDF Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78510">CVE-2026-78510</a></td><td><p>Microsoft Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69525">CVE-2026-69525</a></td><td><p>Remote Desktop Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69819">CVE-2026-69819</a></td><td><p>RPC Runtime Library Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-66302">CVE-2026-66302</a></td><td><p>Skype for Business Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69854">CVE-2026-69854</a></td><td><p>Spring Cloud Azure Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>9.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69431">CVE-2026-69431</a></td><td><p>Telnet Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69496">CVE-2026-69496</a></td><td><p>Windows Compressed Folder Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69845">CVE-2026-69845</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72979">CVE-2026-72979</a></td><td><p>Windows DHCP Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69715">CVE-2026-69715</a></td><td><p>Windows Direct Show Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69730">CVE-2026-69730</a></td><td><p>Windows DNS Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69493">CVE-2026-69493</a></td><td><p>Windows Event Logging Service Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77493">CVE-2026-77493</a></td><td><p>Windows Graphics Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69769">CVE-2026-69769</a></td><td><p>Windows HTTP Print Provider Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69910">CVE-2026-69910</a></td><td><p>Windows Hyper-V Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-70296">CVE-2026-70296</a></td><td><p>Windows Imaging Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69669">CVE-2026-69669</a></td><td><p>Windows Kernel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69579">CVE-2026-69579</a></td><td><p>Windows Message Queuing Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-72982">CVE-2026-72982</a></td><td><p>Windows Netlogon Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69463">CVE-2026-69463</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69768">CVE-2026-69768</a></td><td><p>Windows RNDIS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69590">CVE-2026-69590</a></td><td><p>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-73009">CVE-2026-73009</a></td><td><p>Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69595">CVE-2026-69595</a></td><td><p>Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-78445">CVE-2026-78445</a></td><td><p>Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69829">CVE-2026-69829</a></td><td><p>Windows Shell Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68839">CVE-2026-68839</a></td><td><p>Windows USB Mass Storage Class Driver Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr></tbody></table><p></p>]]></description>
      <link>https://www.rapid7.com/blog/post/em-patch-tuesday-september-2026</link>
      <guid isPermaLink="false">blt35e5b568817ebe1d</guid>
      <category><![CDATA[Patch Tuesday]]></category>
      <category><![CDATA[Vulnerability Management]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Tue, 08 Sep 2026 21:44:04 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt9952397815d84355/6849acff3860836b5c360685/patch-tuesday-repeated.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>While conducting research into a </span><a href="https://www.rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild/"><span style='font-size: undefined;'>recent</span></a><span style='font-size: undefined;'> N-able N-central authentication bypass vulnerability (</span><a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-18577/"><span style='font-size: undefined;'>CVE-2026-18577</span></a><span style='font-size: undefined;'>), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server.</span></p><p></p><table><colgroup data-width='999.9999999999999'><col style="width:21.153846153846157%"/><col style="width:49.358974358974365%"/><col style="width:13.141025641025642%"/><col style="width:16.346153846153847%"/></colgroup><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE ID</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Description</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CWE</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVSSv4</strong></span></p></td></tr><tr><td><p style="direction: ltr;"><a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-86206/"><span style='font-size: undefined;'>CVE-2026-86206</span></a></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Semicolon/Forwarded access-control bypass</span></p></td><td><p style="direction: ltr;"><a href="https://cwe.mitre.org/data/definitions/791.html"><span style='font-size: undefined;'>CWE-791</span></a></p></td><td><p style="direction: ltr;"><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"><span style='font-size: undefined;'>6.9 (Medium)</span></a></p></td></tr><tr><td><p style="direction: ltr;"><a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-86207/"><span style='font-size: undefined;'>CVE-2026-86207</span></a></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>UserTwoFactorLogin authentication bypass</span></p></td><td><p style="direction: ltr;"><a href="https://cwe.mitre.org/data/definitions/305.html"><span style='font-size: undefined;'>CWE-305</span></a></p></td><td><p style="direction: ltr;"><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"><span style='font-size: undefined;'>7.7 (High)</span></a></p></td></tr></tbody></table><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Both CVE-2026-86206 and CVE-2026-86207 have been patched by the vendor via N-central 2026.3 Hotfix 3.</span></p><h2 style="direction: ltr;">Product description</h2><p style="direction: ltr;"><span style='font-size: undefined;'>N-able </span><a href="https://www.n-able.com/products/n-central-rmm"><span style='font-size: undefined;'>N-central</span></a><span style='font-size: undefined;'> is an enterprise-grade Remote Monitoring and Management (RMM) platform designed for Managed Service Providers (MSPs) and IT departments to monitor, manage, and secure complex, large-scale networks from a centralized dashboard.</span></p><h2 style="direction: ltr;">Credit</h2><p style="direction: ltr;"><span style='font-size: undefined;'>These vulnerabilities were discovered by Stephen Fewer, Senior Principal Security Researcher at </span><a href="https://www.rapid7.com/"><span style='font-size: undefined;'>Rapid7</span></a><span style='font-size: undefined;'>, and are being disclosed in accordance with </span><a href="https://www.rapid7.com/security/disclosure/"><span style='font-size: undefined;'>Rapid7's vulnerability disclosure policy</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Technical analysis</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>CVE-2026-86206</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>N-central exposes its management interface (TCP 8443 by default) through </span><a href="https://www.envoyproxy.io/"><span style='font-size: undefined;'>Envoy</span></a><span style='font-size: undefined;'>, an edge proxy. Envoy passes accepted requests to </span><a href="https://jetty.org/"><span style='font-size: undefined;'>Jetty</span></a><span style='font-size: undefined;'>, the Java web server that hosts N-central's application. The application gives requests from the loopback address (i.e. </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>127.0.0.1</span><span style='font-size: undefined;'>) more access than requests from a remote system. This design depends on Envoy, Jetty, and the N-central access filter all agreeing on which application path the client requested and whether the client is really local. The following request can make them disagree about both of these things:</span></p><pre language="html">POST /dms;/services/ServerUI HTTP/1.1
Forwarded: for="127.0.0.\1"
Content-Type: text/xml; charset=utf-8
SOAPAction: ""</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The semicolon in the URI and backslash in the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>Forwarded</span><span style='font-size: undefined;'> value introduce a discrepancy when processing the request that leads to an access control bypass. Looking at Figure 1 below, we can see an overview of how these two values are processed during an incoming malicious request.</span></p><p></p><figure style="margin: 0"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltb77f2bcd8276aa5d/6a9fe92172fa392afc9981d8/nable_cvd_blog.png" alt="nable_cvd_blog.png" height="524" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="nable_cvd_blog.png" width="1187" max-width="1187" max-height="524" style="max-width: 1187px; width: 1187px; max-height: 524px; height: 524px; text-align: center" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltb77f2bcd8276aa5d/6a9fe92172fa392afc9981d8/nable_cvd_blog.png" data-sys-asset-uid="bltb77f2bcd8276aa5d" data-sys-asset-filename="nable_cvd_blog.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="nable_cvd_blog.png" data-sys-asset-position="none" sys-style-type="display"/></figure><p style="text-align: center;"><span style='font-size: undefined;'><em>Figure 1: Processing a malicious request.</em></span></p><h4 style="direction: ltr;"><span style='color:rgb(102, 102, 102);'>The semicolon gets the request past Envoy</span></h4><p style="direction: ltr;"><span style='font-size: undefined;'>The Envoy proxy rules come from the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>n-central-proxy-4.5.6-5</span><span style='font-size: undefined;'> package. In </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>/etc/opt/envoy/lds_intermediate.yaml</span><span style='font-size: undefined;'>, shown below (and edited for brevity), the management listener returns HTTP 403 for paths beginning with </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>/dms/services</span><span style='font-size: undefined;'> or </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>/internal/dms</span><span style='font-size: undefined;'>. A final catch-all rule sends other paths to the DMS application.</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="html">  # /etc/opt/envoy/lds_intermediate.yaml:953
  - match:
      prefix: /internal/dms
    # response-header boilerplate omitted
    direct_response:
      status: 403
      body:
        inline_string: Forbidden. No API access on the UI port.
  # ...
  - match:
      prefix: /dms/services
    # response-header boilerplate omitted
    direct_response:
      status: 403
      body:
        inline_string: Forbidden. No API access on the UI port.
 # ...
 # /etc/opt/envoy/lds_intermediate.yaml:1301
 # A final catch-all rule...
  - match:
      prefix: /
    route:
      cluster: dms
      timeout:
        seconds: 300</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Envoy compares those prefixes with the path it received. The path </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>/dms;/services/ServerUI</span><span style='font-size: undefined;'> does not begin with </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>/dms/services</span><span style='font-size: undefined;'>, because the next character after </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>/dms</span><span style='font-size: undefined;'> is a semicolon. It therefore reaches the catch-all route, passing the request from Envoy to Jetty.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Jetty interprets the path differently. The shipped </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>jetty-http-9.4.56.v20240826.jar</span><span style='font-size: undefined;'> contains </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>org.eclipse.jetty.http.HttpURI</span><span style='font-size: undefined;'>, and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>org.eclipse.jetty.util.URIUtil</span><span style='font-size: undefined;'>. Together, these classes treat text beginning with a semicolon as a path parameter and remove it when producing the decoded path used for servlet dispatch. As a result, Jetty turns </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>/dms;/services/ServerUI</span><span style='font-size: undefined;'> into </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>/dms/services/ServerUI</span><span style='font-size: undefined;'>. That decoded path then matches the Axis SOAP servlet mapping in </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>/opt/nable/webapps/ROOT/WEB-INF/web.xml</span><span style='font-size: undefined;'>. </span></p><p></p><pre language="xml">&lt;!-- /opt/nable/webapps/ROOT/WEB-INF/web.xml --&gt;
&lt;!-- ...snip... --&gt;

   &lt;servlet&gt;
        &lt;servlet-name&gt;DMSServlet&lt;/servlet-name&gt;
        &lt;servlet-class&gt;org.apache.axis.transport.http.AxisServlet&lt;/servlet-class&gt;
    &lt;/servlet&gt;
    &lt;servlet-mapping&gt;
        &lt;servlet-name&gt;DMSServlet&lt;/servlet-name&gt;
        &lt;url-pattern&gt;/dms/services/*&lt;/url-pattern&gt;
        &lt;url-pattern&gt;/internal/dms/services/*&lt;/url-pattern&gt;
    &lt;/servlet-mapping&gt;

    &lt;servlet&gt;
        &lt;display-name&gt;CXF Servlet&lt;/display-name&gt;
        &lt;servlet-name&gt;CXFServlet&lt;/servlet-name&gt;
        &lt;servlet-class&gt;org.apache.cxf.transport.servlet.CXFServlet&lt;/servlet-class&gt;
        &lt;load-on-startup&gt;2&lt;/load-on-startup&gt;
    &lt;/servlet&gt;
    &lt;servlet-mapping&gt;
        &lt;servlet-name&gt;CXFServlet&lt;/servlet-name&gt;
        &lt;url-pattern&gt;/dms2/services2/*&lt;/url-pattern&gt;
        &lt;url-pattern&gt;/internal/dms/services2/*&lt;/url-pattern&gt;
    &lt;/servlet-mapping&gt;</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Similarly, the same technique can be used to target the SOAP service via </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>/internal;/dms/services2/ServerUI2</span><span style='font-size: undefined;'>. Jetty decodes it to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>/internal/dms/services2/ServerUI2</span><span style='font-size: undefined;'>, which matches the CXF SOAP servlet mapping. A single semicolon is sufficient to create the routing disagreement.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Reaching these servlet mappings puts the request at the protected SOAP interfaces that an exploit can leverage to establish an application session and later manage privileged objects, but the semicolon trick alone does not authorize the request. Without the crafted </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>Forwarded</span><span style='font-size: undefined;'> header, Jetty retains the client's real remote address and N-central's </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>ServletPathFilter</span><span style='font-size: undefined;'> denies access. Conversely, the header trick alone cannot help a request to the ordinary </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>/dms/services/ServerUI</span><span style='font-size: undefined;'> or </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>/internal/dms/services2/ServerUI2</span><span style='font-size: undefined;'> path: Envoy returns HTTP 403 without forwarding that request to Jetty. </span></p><p style="direction: ltr;"><span style='font-size: undefined;'>As such, an exploit needs both discrepancies; the semicolon to pass Envoy's path check and the header to pass N-central's local-request check.</span></p><h4 style="direction: ltr;"><span style='color:rgb(102, 102, 102);'>The header makes the remote client look local</span></h4><p style="direction: ltr;"><span style='font-size: undefined;'>The </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>Forwarded</span><span style='font-size: undefined;'> header tells an application about the original client behind a proxy. In a malicious request, the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>for</span><span style='font-size: undefined;'> value is quoted and contains a quoted-pair (</span><span style='color:rgb(24, 128, 56);font-size: undefined;'>\1</span><span style='font-size: undefined;'>):</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="html">Forwarded: for="127.0.0.\1"</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Under the HTTP quoted-string grammar, the backslash escapes the following character. Jetty's </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>ForwardedRequestCustomizer</span><span style='font-size: undefined;'>, from </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>jetty-server-9.4.56.v20240826.jar</span><span style='font-size: undefined;'>, applies that rule. It removes the backslash, reads the value as </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>127.0.0.1</span><span style='font-size: undefined;'>, and exposes that value to N-central as the request's remote address.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>N-central then parses the original header a second time. Its parser is in </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>com.nable.util.LocalHostUtils</span><span style='font-size: undefined;'>, from </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>/opt/nable/webapps/ROOT/WEB-INF/lib/dmsservice-11.0.1-SNAPSHOT.jar</span><span style='font-size: undefined;'>. This parser removes the surrounding quotes but does not remove the backslash. It therefore checks </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>127.0.0.\1</span><span style='font-size: undefined;'>.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>That string is not a valid IP address. </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>LocalHostUtils.xffCheck()</span><span style='font-size: undefined;'> rejects an invalid value found in </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>X-Forwarded-For</span><span style='font-size: undefined;'>, but its </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>Forwarded</span><span style='font-size: undefined;'> branch rejects only values that it successfully recognizes as loopback. The below (abridged) decompilation shows the relevant branch:</span></p><p></p><pre language="java">// dmsservice-11.0.1-SNAPSHOT.jar
// com.nable.util.LocalHostUtils.xffCheck()

List&lt;String&gt; forwardedAddresses =
    LocalHostUtils.getForAddressesFromForwardedHeaders(httpRequest);

for (String addr : forwardedAddresses) {
    if (!LocalHostUtils.isLoopbackAddress(addr.trim())) continue; // &lt;--- [1]
    // log the rejected loopback address
    return false; // &lt;--- [2]
}
return true; // &lt;--- [3]</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>When given the header value </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>127.0.0.\1</span><span style='font-size: undefined;'>, the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>isLoopbackAddress()</span><span style='font-size: undefined;'> call (at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>[1]</span><span style='font-size: undefined;'>) returns </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>false</span><span style='font-size: undefined;'> (at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>[2]</span><span style='font-size: undefined;'>) because the value is invalid. The loop therefore continues and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>xffCheck()</span><span style='font-size: undefined;'> returns </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>true</span><span style='font-size: undefined;'> (at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>[3]</span><span style='font-size: undefined;'>). In other words, an invalid </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>Forwarded</span><span style='font-size: undefined;'> header value causes </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>xffCheck</span><span style='font-size: undefined;'> to fail open. The final decision occurs in </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>com.nable.server.ServletPathFilter</span><span style='font-size: undefined;'>, shown below.</span></p><p></p><pre language="java">// dmsservice-11.0.1-SNAPSHOT.jar
// com.nable.server.ServletPathFilter.isAllowedRequest()

boolean isAllowedRequest(HttpServletRequest httpRequest) {
    if (!LocalHostUtils.xffCheck(httpRequest)) { // &lt;--- [4]
        return false;
    }
    if (LocalHostUtils.isLocalhost(httpRequest)) { // &lt;--- [5]
        return true; // &lt;--- [6]
    }
    String path = this.removeTrailingSlashes(httpRequest.getRequestURI());
    return this.pathFilterService != null
        && this.pathFilterService.isPathAllowed(path);
}</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The first check asks whether a forwarding header is trying to claim a loopback address (at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>[4]</span><span style='font-size: undefined;'>). N-central's parser sees the invalid value </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>127.0.0.\1</span><span style='font-size: undefined;'>, does not recognize it as loopback, and allows it. The second check asks whether Jetty's remote address is local (at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>[5]</span><span style='font-size: undefined;'>). Jetty has already converted the same header value to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>127.0.0.1</span><span style='font-size: undefined;'>, so this check succeeds. The filter returns </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>true</span><span style='font-size: undefined;'> (at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>[6]</span><span style='font-size: undefined;'>) before consulting the normal remote-path allowlist.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>CVE-2026-86207</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>By leveraging CVE-2026-86206 to reach the protected URI </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>/dms/services/ServerUI</span><span style='font-size: undefined;'>, a </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>SessionID</span><span style='font-size: undefined;'> returned by the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>Session.Hello</span><span style='font-size: undefined;'> SOAP operation (See the </span><a href="https://horizon3.ai/attack-research/attack-blogs/n-able-n-central-from-n-days-to-0-days/"><span style='font-size: undefined;'>prior work</span></a><span style='font-size: undefined;'> by Horizon3 on leveraging the legacy SOAP API) can be generated. However, this </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>SessionID</span><span style='font-size: undefined;'> is only a pre-login session. It proves that the request reached the local-only SOAP API via the access control bypass, but it does not yet identify an authenticated user. A separate authentication bypass vulnerability, in how legacy two-factor authentication operates, allows a pre-login session to become an authenticated session.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The method </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>com.nable.server.ui.UserTwoFactorLogin</span><span style='font-size: undefined;'>, from </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>dmsservice-11.0.1-SNAPSHOT.jar</span><span style='font-size: undefined;'> (shown below), binds a requested user ID (e.g. the builtin N-able Administrator account’s well known ID </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>1</span><span style='font-size: undefined;'>) to the session (at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>[1]</span><span style='font-size: undefined;'>) </span><span style='font-size: undefined;'><em>before</em></span><span style='font-size: undefined;'> it attempts legacy two-factor authentication (at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>[2]</span><span style='font-size: undefined;'>) . A normal authentication rejection removes that binding (at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>[4]</span><span style='font-size: undefined;'>), but if an exception occurs, this binding is left in place (at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>[3]</span><span style='font-size: undefined;'>).</span></p><p></p><pre language="java">// dmsservice-11.0.1-SNAPSHOT.jar
// com.nable.server.ui.UserTwoFactorLogin

   public final String twoFactorLogin(int sessionID, int userID, String password) throws RemoteException {
        String response = null;
        try {
            this.updateSession(sessionID, userID); // &lt;--- [1]
            T_User user = this.getUser(userID);
            response = this.authenticate(user, password); // &lt;--- [2]
            Trace.info((Object)this, (String)("2FA authentication response for user '" + user.getUsername() + "': " + response));
            if (response != null && "ACCESS_OK".equals(response)) {
                String audit = "TWO FACTOR LOGIN SUCCESSFUL: UserID [" + userID + "] successfully logged in.";
                this.addSessionAuditEntry(sessionID, audit);
            } else {
                String audit = "TWO FACTOR LOGIN FAILED: UserID [" + userID + "] attempted to login with invalid PIN.";
                this.addSessionAuditEntry(sessionID, audit);
                this.makeSessionInvalid(sessionID); // &lt;--- [4]
            }
        }
        catch (RemoteException re) {
            throw re; // &lt;--- [3]
        }
        catch (Exception ex) {
            throw DMSError.getFault((String)CommonError.GENERIC_ERROR.getCodeAsString(), (String)ex.toString(), (Throwable)ex); // &lt;--- [3]
        }
        return response;
    }</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>N-central supports two distinct second-factor systems: legacy, profile-based authentication using an external AuthAnvil or RSA SecurID server, and native time-based one-time password (TOTP) “Two-Step Verification” using an authenticator application. Despite overlapping 2FA/MFA terminology in N-able’s documentation, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>com.nable.server.ui.UserTwoFactorLogin</span><span style='font-size: undefined;'> implements the former profile-based mechanism; it does not enforce the user’s native TOTP setting.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>In a default installation, legacy two-factor processing raises an exception for several builtin identities used by N-central, as each of these identities lack a single legacy AuthAnvil or RSA 2FA profile association required by UserTwoFactorLogin. Specifically the following built-in identities can be leveraged via their known ID numbers.</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>User ID </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>1</span><span style='font-size: undefined;'> (N-able Administrator)</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>User ID </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>50</span><span style='font-size: undefined;'> (Product Administrator)</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>User ID </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>51</span><span style='font-size: undefined;'> (N-able Support)</span></p></li></ul><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>By creating a new pre-login session for any one of the above IDs, a SOAP call to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>User.TwoFactorLogin</span><span style='font-size: undefined;'> with a dummy password will achieve the authentication bypass, converting the pre-login session to a privileged SOAP session for that user. By using additional calls to the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>ServerUI2</span><span style='font-size: undefined;'> SOAP endpoint, a new attacker-controlled System user account can be created.</span></p><h2 style="direction: ltr;">Remediation</h2><p style="direction: ltr;"><span style='font-size: undefined;'>The vendor-supplied release of N-central 2026.3 Hotfix 3 (version </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>2026.3.1.13</span><span style='font-size: undefined;'>) remediates both CVE-2026-86206 and CVE-2026-86207. All versions of N-central prior to 2026.3.1.13 are vulnerable. Customers running affected on-premise N-central environments are urged to apply the latest update on an urgent basis, outside of normal patching cycles.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Customers using hosted N-central environments do not need to take action as the vendor has applied the needed updates.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>For the latest remediation guidance, please see the vendor </span><a href="https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF3_Release_Notes.htm"><span style='font-size: undefined;'>release notes</span></a><span style='font-size: undefined;'> and the vendor </span><a href="https://www.n-able.com/blog/n-central-security-hotfix-september-5-2026"><span style='font-size: undefined;'>disclosure blog</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM and Nexpose customers will be able to assess their exposure to both CVE-2026-86206 and CVE-2026-86207, with authenticated vulnerability checks expected to be available in the September 8 content release. </span></p><h2 style="direction: ltr;">Disclosure timeline</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>August 27, 2026:</strong></span><span style='font-size: undefined;'> Rapid7 makes initial outreach to N-able who respond the same day.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>August 28, 2026:</strong></span><span style='font-size: undefined;'> Rapid7 provides a detailed technical analysis and exploit script to N-able, along with a proposed timeline for a coordinated disclosure.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>September 5, 2026:</strong></span><span style='font-size: undefined;'> N-able release </span><a href="https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF3_Release_Notes.htm"><span style='font-size: undefined;'>N-central 2026.3 HF3</span></a><span style='font-size: undefined;'> which fixes two of the vulnerabilities (CVE-2026-86206, CVE-2026-86207) reported by Rapid7.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>September 7, 2026:</strong></span><span style='font-size: undefined;'> Rapid7 contacts N-able requesting clarity on several issues. N-able responds the same day with requested information.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>September 8, 2026:</strong></span><span style='font-size: undefined;'> This disclosure for CVE-2026-86206 and CVE-2026-86207.</span></p></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed</link>
      <guid isPermaLink="false">blt70b071a4b09e549f</guid>
      <category><![CDATA[Vulnerability Disclosure]]></category>
      <category><![CDATA[Rapid7 Disclosure]]></category>
      <category><![CDATA[Labs]]></category>
      <category><![CDATA[Vulnerability Management]]></category><dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
      <pubDate>Tue, 08 Sep 2026 11:01:27 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltcbf09ec3af35e28e/6a15c63f08221ed5144dbf77/webinar-rapid7-logo.jpg" medium="image" />
    </item>
    <item>
      <title><![CDATA[DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors]]></title>
      <description><![CDATA[<h2><span style='font-size: undefined;'>Overview</span></h2><p style="direction: ltr;"><span style='font-size: undefined;'>A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and engage in long-term surveillance.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected.</span></p><p><span style='font-size: undefined;'>Operating alongside this are an SSH keylogger, a curl-based RAT, and a stager. The RAT maintains a watchdog thread dedicated to tracking HAProxy’s health, and reporting it back to the operator’s infrastructure. The earliest uploads on VirusTotal date back to mid-2025 and the involved HAProxy 2.8.12-0fdb194</span><span style='font-size: undefined;'><strong> </strong></span><span style='font-size: undefined;'>was released on 22 November 2024, establishing this as the earliest possible compilation date for this build.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The toolkit is attributed with medium confidence to DPRK APTs, given that the attacks Rapid7 observed were targeting South Korean media and automotive sectors, likely aiming at long-term espionage, the usage of simple xor-based encryption, custom substitution cipher, and the list of C2s hardcoded is associated to APT37 by </span><a href="https://threatfox.abuse.ch/browse/tag/RicochetChollima/" target="_blank"><span style='font-size: undefined;'>ThreatFox</span></a><span style='font-size: undefined;'> and </span><a href="https://github.com/stamparm/trails/blob/main/malware/apt_37.txt" target="_blank"><span style='font-size: undefined;'>maltrail</span></a><span style='font-size: undefined;'>. Analysis shows that the ted backdoor could be part of a broader framework covering nginx backdoor as well. The ted plugin registers a custom HAProxy filter that hooks the HTTP parser to inspect and log high-value traffic, steal session cookies, and perform a client IP selection to decide whether to inject custom scripts in the webpage being rendered.</span></p><h2><span style='font-size: undefined;'>Technical analysis</span></h2><p style="direction: ltr;"><span style='font-size: undefined;'>Rapid7 researchers revealed that the toolkit was used in campaigns targeting South Korean automotive and media sectors likely dating back to early 2025. The number of trojanized binaries and functionalities found suggest the scope could be long-term cyber espionage and surveillance. However, gathered evidence does not suffice to establish a timeline nor how the initial access was performed.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>At the time of analysis, both victims were running an edge webserver with ports 80, 443, and 25 exposed. Port 443 hosted the Groupware login portal and port 25 exposed a mail server. Either surface represents a plausible initial access vector consistent with documented Kimsuky tradecraft. Since the beginning of 2026 </span><a href="https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant" target="_blank"><span style='font-size: undefined;'>Kimsuky</span></a><span style='font-size: undefined;'> has been observed exploiting RCE vulnerabilities in externally accessible mail servers to compromise South Korean groupware vendors, while Groupware web portals represent the kind of exposed authenticated application that DPRK-nexus actors have repeatedly targeted for credential harvesting and exploitation. The specific entry point and any associated CVE remain unconfirmed pending further forensic evidence.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The scenario shown in Figure 1 assumes the initial access is obtained by exploitation of CVEs related to the Groupware portal. </span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta751583dd18a172b/6a99bbfe49d4290742a52396/ted-backdoor-attack-chain.png" alt="ted-backdoor-attack-chain.png" caption="Figure 1: Attack chain partially reconstructed" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="ted-backdoor-attack-chain.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta751583dd18a172b/6a99bbfe49d4290742a52396/ted-backdoor-attack-chain.png" data-sys-asset-uid="blta751583dd18a172b" data-sys-asset-filename="ted-backdoor-attack-chain.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 1: Attack chain partially reconstructed" data-sys-asset-alt="ted-backdoor-attack-chain.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 1: Attack chain partially reconstructed</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>The threat actor begins by exploiting a vulnerability in the Groupware login portal running on the edge webserver, gaining an initial foothold in the DMZ. From there, they establish persistence and harvest credentials from the compromised edge host (e.g. SSH keylogger), which also doubles as a staging server hosting the trojanized system ELFs.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>With a foothold on the edge, the attacker pivots inward and drops the stager onto internal servers. The stager checks for the presence of either crond or HAProxy, and only then deploys CurlRAT retrieving it either from its data section or the edge webserver. </span></p><p style="direction: ltr;"><span style='font-size: undefined;'>In parallel, ted backdoor is dropped onto the HAProxy load balancer. Once active,it establishes its own C2 channel to the external operator infrastructure, enabling data exfiltration, command execution, and script injection. On the victim side, the compromised load balancer silently redirects or serves malicious content to selected clients browsing through it, completing the watering-hole loop.</span></p><h3><span style='font-size: undefined;'>SSH keylogger</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'><span data-type='inlineCode'>4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5</span></span><span style='font-size: undefined;'> intercepts legitimate users' plaintext passwords and saves them to an encrypted log file under </span><span style='font-size: undefined;'><span data-type='inlineCode'>/var/lib/sshd/c8c68e629bba773a10ac80012d10bf19</span></span><span style='font-size: undefined;'>.</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta8df97a69c9aa427/6a99bcd460f795e0add78403/figure2.png" alt="figure2.png" caption="Figure 2: hardcoded master passwords in userauth_passwd()" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="figure2.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta8df97a69c9aa427/6a99bcd460f795e0add78403/figure2.png" data-sys-asset-uid="blta8df97a69c9aa427" data-sys-asset-filename="figure2.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 2: hardcoded master passwords in userauth_passwd()" data-sys-asset-alt="figure2.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 2: hardcoded master passwords in userauth_passwd()</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>After checking that entered credentials are not equal to TA’s master passwords, </span><span style='font-size: undefined;'><span data-type='inlineCode'>userauth_passwd()</span></span><span style='font-size: undefined;'> proceeds to encrypt them using a custom substitution cipher recurring throughout the toolkit and base64 encoding.</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltd20e9581e90f00eb/6a99bd06d62e117e1ae3993a/fig3.png" alt="fig3.png" caption="Figure 3: Substitution cipher used to encrypt credentials" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="fig3.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltd20e9581e90f00eb/6a99bd06d62e117e1ae3993a/fig3.png" data-sys-asset-uid="bltd20e9581e90f00eb" data-sys-asset-filename="fig3.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 3: Substitution cipher used to encrypt credentials" data-sys-asset-alt="fig3.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 3: Substitution cipher used to encrypt credentials</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>Pivoting from the above cipher, instances of polkitd, crond, agetty and atd binaries were identified using a similar encryption algorithm. Crond binaries were found to be delivered by a stager.</span></p><h3><span style='font-size: undefined;'>CurlRAT Stager</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>The stager </span><span style='font-size: undefined;'><span data-type='inlineCode'>5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91</span></span><span style='font-size: undefined;'> starts by decrypting its configuration strings using a 1-byte XOR, then verifies root privileges and profiles the OS checking system hostname, OS distribution and version IDs, kernel release and version numbers and CPU architecture to select the correct payload to drop. It decrypts the trojanized crond binary in memory, overwrites the system's legitimate daemon, and restarts the service. As shown below, only if HAProxy or cron are running on the system will it proceed to drop the backdoored crond.</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc45f8a3a17760dfb/6a99bd649ab7fd3b0723e93f/fig4.png" alt="fig4.png" caption="Figure 4: Stager configuration" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="fig4.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc45f8a3a17760dfb/6a99bd649ab7fd3b0723e93f/fig4.png" data-sys-asset-uid="bltc45f8a3a17760dfb" data-sys-asset-filename="fig4.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 4: Stager configuration" data-sys-asset-alt="fig4.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 4: Stager configuration</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>Checking for HAProxy presence is done as the binary, named by TA as ted backdoor. It also has RAT capabilities and plays a major role in the campaigns described. The embedded crond versions supported are CentOS 7.7, 7.8, 7.9 and Ubuntu 22.04 and after installing the backdoor, timestomping ensures the crond binary gets the same creation timestamp of </span><span style='font-size: undefined;'><span data-type='inlineCode'>/usr/bin/ssh</span></span><span style='font-size: undefined;'>. The stager ends by filtering out keywords such as tmp, wget cron and crond from Linux system logs using a staging file named </span><span style='font-size: undefined;'><span data-type='inlineCode'>/tmp/jasper-log</span></span><span style='font-size: undefined;'>, likely to blend in as the JSP (JavaServer Pages) engine in old Apache Tomcat versions, erasing any traces of the installation. The logs affected by the selective erasure are </span><span style='font-size: undefined;'><span data-type='inlineCode'>/root/.bash_history</span></span><span style='font-size: undefined;'> and the following under </span><span style='font-size: undefined;'><span data-type='inlineCode'>/var/log</span></span><span style='font-size: undefined;'>: </span><span style='font-size: undefined;'><span data-type='inlineCode'>messages</span></span><span style='font-size: undefined;'>, </span><span style='font-size: undefined;'><span data-type='inlineCode'>audit</span></span><span style='font-size: undefined;'>/</span><span style='font-size: undefined;'><span data-type='inlineCode'>audit.log</span></span><span style='font-size: undefined;'>, </span><span style='font-size: undefined;'><span data-type='inlineCode'>cmd.log</span></span><span style='font-size: undefined;'>, </span><span style='font-size: undefined;'><span data-type='inlineCode'>secure</span></span><span style='font-size: undefined;'>, </span><span style='font-size: undefined;'><span data-type='inlineCode'>syslog</span></span><span style='font-size: undefined;'>, </span><span style='font-size: undefined;'><span data-type='inlineCode'>auth.log</span></span><span style='font-size: undefined;'>.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><span data-type='inlineCode'>09739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe and fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61</span></span><span style='font-size: undefined;'> are a different variant of the stager that fetches backdoored binaries from a compromised victim’s server without embedding any payloads.</span></p><h3><span style='font-size: undefined;'>CurlRAT</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>The Ubuntu version is analyzed below, though CentOS samples follow the same logic except for the filepath used to hide config/staging files.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>As for the stager, </span><span style='font-size: undefined;'><span data-type='inlineCode'>feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3</span></span><span style='font-size: undefined;'> starts by decrypting configuration strings using a 1-byte XOR key (0x58).</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt47720b23053efeda/6a99bdeda163362e0d372f40/fig5.png" alt="fig5.png" caption="Figure 5: curlRAT configuration" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="fig5.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt47720b23053efeda/6a99bdeda163362e0d372f40/fig5.png" data-sys-asset-uid="blt47720b23053efeda" data-sys-asset-filename="fig5.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 5: curlRAT configuration" data-sys-asset-alt="fig5.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 5: curlRAT configuration</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>The main logic added to crond is executed via two threads. The first thread runs the start_routine function that creates the staging directory </span><span style='font-size: undefined;'><span data-type='inlineCode'>snapd</span></span><span style='font-size: undefined;'> under</span><span style='font-size: undefined;'><span data-type='inlineCode'> /var/lib</span></span><span style='font-size: undefined;'>, where it attempts to load the victim ID from </span><span style='font-size: undefined;'><span data-type='inlineCode'>/var/lib/snapd/g580</span></span><span style='font-size: undefined;'>. If network failures were previously recorded, it reaches out to a secondary domain – </span><span style='font-size: undefined;'><span data-type='inlineCode'>img.darklights.store</span></span><span style='font-size: undefined;'> – authenticating with </span><span style='font-size: undefined;'><span data-type='inlineCode'>api_token/ecd427ea8330a4ff73618483e00b9b41</span></span><span style='font-size: undefined;'> and setting the User-token header to the victim ID to fetch updated configuration under </span><span style='font-size: undefined;'><span data-type='inlineCode'>/tmp/nimon.unix-docbase.8564479396043450766-db6fb4443bc</span></span><span style='font-size: undefined;'>, where it’s then copied into </span><span style='font-size: undefined;'><span data-type='inlineCode'>/var/lib/snapd/g105</span></span><span style='font-size: undefined;'>.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>To decrypt the configuration, the first byte of the file initializes the seed of a feedback xor based cipher. Each poll cycle, a config file is fetched from the C2 server over HTTPS (falling back to HTTP on failure) using libcurl, with the victim token embedded in the User-token header. The fetched config is parsed for three single-character delimiters — </span><span style='font-size: undefined;'><strong>!</strong></span><span style='font-size: undefined;'> terminates the credential field,</span><span style='font-size: undefined;'><strong> #</strong></span><span style='font-size: undefined;'> marks the payload section, and </span><span style='font-size: undefined;'><strong>*</strong></span><span style='font-size: undefined;'> separates arguments — after which the credential field is compared against the local victim token.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>If authentication succeeds, a single-character mode byte (ASCII </span><span style='font-size: undefined;'><strong>'0'</strong></span><span style='font-size: undefined;'> through </span><span style='font-size: undefined;'><strong>'5'</strong></span><span style='font-size: undefined;'>) preceding the delimiter “#” selects one of six handler routines via a jump table. Payloads embedded in the config are decoded through a two-stage pipeline: standard Base64 decoding followed by a rolling cumulative XOR cipher keyed from the decoded header. The C2 task handler sleeps for 43,200 seconds (12 hours) between polls by default, but the operator can activate a fast-poll mode by setting a flag, reducing the interval to 30 seconds. A retry loop calls the handler up to six times per cycle with five-second intervals, failing fast if the first attempt does not succeed. The table below shows the C2 commands accepted.</span></p><p></p><table><colgroup data-width='1510'><col style="width:4.172185430463577%"/><col style="width:14.105960264900663%"/><col style="width:81.72185430463577%"/></colgroup><thead><tr><th><p style="direction: ltr;"><span style='font-size: undefined;'>Mode</span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'>Function</span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'>Description</span></p></th></tr></thead><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>0</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>cmd execution</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Base64 + XOR-decodes a command list from the config, executes each line via popen with stderr redirected to stdout, saves output into a 1 MB buffer, and sends the result back.</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>1</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>config write</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Decodes and writes a new config payload to disk, validates it, and sets the polling interval and fast-poll flag. If the validation fails, the C2 resets to img.monderhouse.space</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>2</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>staged payload drop</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Issues an authenticated HTTP POST to the C2 host with a task path as the body, streams the response to a temporary file, decompresses and moves it to the final drop path, unlinking the temp.</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>3</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>reverse shell</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Closes all file descriptors above 2, calls setuid(0) and setreuid(0, 0), forcing both its real and effective user IDs to root, and connects out before handing off to the shell dispatcher.</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>4</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>beacon</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Populates a 10 KB system-info structure and transmits it as a check-in beacon.</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>5</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>PTY shell</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>A full interactive PTY shell, the payload consists of an ip:port.</span></p></td></tr></tbody></table><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Modes 0–2 and 4 use libcurl-based HTTP/HTTPS, hence the name curlRAT. All modes use Base64+XOR encoding/decoding applied to the payload. The victim ID is obtained by concatenating "</span><span style='font-size: undefined;'><span data-type='inlineCode'>cron_3.0pl1-137ubuntu3</span></span><span style='font-size: undefined;'>", system hostname, ipv4 address, and the hardware/OS UUID (read from </span><span style='font-size: undefined;'><span data-type='inlineCode'>/sys/class/dmi/id/product_uuid</span></span><span style='font-size: undefined;'>), then applying MD5 hash and converting it to uppercase.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The layer of encryption used for all C2 interactions consists of a feedback xor cipher using an initial random seed (modulo 240 + 10, 0&lt;=seed&lt;=249) and then applying Base64 encoding. The malware encapsulates the encrypted and encoded payload, the service name, and the telemetry type into a formatted </span><span style='font-size: undefined;'><span data-type='inlineCode'>application/x-www-form-urlencoded HTTP POST body (name=%s&value=%s&type=%d)</span></span><span style='font-size: undefined;'> which is sent to the C2 and authenticated using an hardcoded API token, including the victim ID in the User-token header.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The second thread acts as the HAProxy watchdog. Before entering the monitoring loop, it checks for the presence of the file </span><span style='font-size: undefined;'><span data-type='inlineCode'>/usr/lib/libvirtlog.so.0</span></span><span style='font-size: undefined;'> to ensure the target is running in a virtualized environment, otherwise it sleeps 6 minutes and aborts. Then it accesses the MD5 victim ID under </span><span style='font-size: undefined;'><span data-type='inlineCode'>/var/lib/snapd/g580</span></span><span style='font-size: undefined;'> to check if the node is active and compromised. Every hour the watchdog reads the pid at </span><span style='font-size: undefined;'><span data-type='inlineCode'>/var/run/haproxy.pid</span></span><span style='font-size: undefined;'> and monitors the status of HAProxy by polling </span><span style='font-size: undefined;'><span data-type='inlineCode'>/proc/pid</span></span><span style='font-size: undefined;'>. The status can be one of the following codes:</span></p><ul><li style="direction: ltr;"><span style='font-size: undefined;'>0 (Started): Process transitioned from stopped to running</span></li><li style="direction: ltr;"><span style='font-size: undefined;'>1 (Stopped): Process is no longer active in the kernel process table</span></li><li style="direction: ltr;"><span style='font-size: undefined;'>2 (Restarted): PID file timestamp modified, and a new PID is detected</span></li><li style="direction: ltr;"><span style='font-size: undefined;'>3 (Reloaded): PID file timestamp modified, but the PID remained identical</span></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>The status is then sent to the C2 endpoint “</span><span style='font-size: undefined;'><span data-type='inlineCode'>writeservice_info</span></span><span style='font-size: undefined;'>” using the custom crypto layer and the telemetry type set to 0 (Figure 6).</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1b35acacad200f0d/6a99bed832b530f7916d215b/fig6.png" alt="fig6.png" caption="Figure 6: writeinfo_service monitoring HAProxy status" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="fig6.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1b35acacad200f0d/6a99bed832b530f7916d215b/fig6.png" data-sys-asset-uid="blt1b35acacad200f0d" data-sys-asset-filename="fig6.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 6: writeinfo_service monitoring HAProxy status" data-sys-asset-alt="fig6.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 6: writeinfo_service monitoring HAProxy status</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>The CentOS versions of curlRAT contain the same functionalities, except that functions are masqueraded as </span><span style='font-size: undefined;'><span data-type='inlineCode'>atd_</span></span><span style='font-size: undefined;'> routines to blend in during static analysis.</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta908db9e3d87a4e2/6a99bf0e32b530b1bb6d2162/fig7.png" alt="fig7.png" caption="Figure 7: The two threads running curlRAT logic" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="fig7.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta908db9e3d87a4e2/6a99bf0e32b530b1bb6d2162/fig7.png" data-sys-asset-uid="blta908db9e3d87a4e2" data-sys-asset-filename="fig7.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 7: The two threads running curlRAT logic" data-sys-asset-alt="fig7.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 7: The two threads running curlRAT logic</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>Below is the table summarizing the main RAT components.</span></p><p></p><table><colgroup data-width='1757'><col style="width:14.62720546385885%"/><col style="width:85.37279453614116%"/></colgroup><thead><tr><th><p style="direction: ltr;"><span style='font-size: undefined;'>Capability</span><span style='color:rgb(60, 64, 67);font-size: undefined;'><strong> </strong></span><span style='font-size: undefined;'>Group</span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'>Functions</span><span style='color:rgb(60, 64, 67);font-size: undefined;'><strong> </strong></span><span style='font-size: undefined;'>Identified</span></p></th></tr></thead><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Reverse Shell / PTY</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>atd_reverse_try_root, atd_reverse_create_conn, atd_reverse_is_alive, atd_reverse_open_pty, atd_reverse_cleanup_tty, atd_reverse_open_term, atd_reverse_handle_sigs, atd_reverse_close_inherited_sockets</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>C2 & Network Comms</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>atd_http_request, atd_response, atd_request, atd_download_to_file, atd_download_config, atd_encrypt_url, atd_decrypt_url, atd_check_haproxy, atd_write_callback</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Host Profiling & Recon</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>atd_get_hostname_info, atd_check_info, atd_get_ip_info, atd_get_system_info, atd_get_version_info, atd_get_machine_info, atd_get_service_info, atd_create_id, atd_get_id</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Command Execution & Crypto</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>atd_run_shell, atd_run_cmd, atd_run_module, atd_base64_encode, atd_base64_decode, atd_md5</span></p></td></tr></tbody></table><p style="direction: ltr;"><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>Earlier version of the RAT hardcode C2 without using XOR encryption (Figure 8).</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt89ccbe190af4d735/6a99bf445c31261e894400f6/fig8.png" alt="fig8.png" caption="Figure 8: Default configuration curlRAT 8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="fig8.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt89ccbe190af4d735/6a99bf445c31261e894400f6/fig8.png" data-sys-asset-uid="blt89ccbe190af4d735" data-sys-asset-filename="fig8.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 8: Default configuration curlRAT 8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c" data-sys-asset-alt="fig8.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 8: Default configuration curlRAT 8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>The </span><span style='font-size: undefined;'><span data-type='inlineCode'>atd_get_info()</span></span><span style='font-size: undefined;'> is a recon routine likely used to decide which binary trojanized next to ensure persistence on the node. It collects the service name of the compromised machine and sends it to the C2 via the </span><span style='font-size: undefined;'><span data-type='inlineCode'>atd_response</span></span><span style='font-size: undefined;'> routine together with Ipv4 address, OS version, and the list of services and listening port (Figure 9).</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt910c34bad4281748/6a99bf7248c29967bac6a1f9/image18.png" alt="image18.png" caption="  Figure 9: Recon module output sent to the C2" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="image18.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt910c34bad4281748/6a99bf7248c29967bac6a1f9/image18.png" data-sys-asset-uid="blt910c34bad4281748" data-sys-asset-filename="image18.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 9: Recon module output sent to the C2" data-sys-asset-alt="image18.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 9: Recon module output sent to the C2</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'><span data-type='inlineCode'>MODE</span></span><span style='font-size: undefined;'>, </span><span style='font-size: undefined;'><span data-type='inlineCode'>DELAY</span></span><span style='font-size: undefined;'> and </span><span style='font-size: undefined;'><span data-type='inlineCode'>SERVER_URL</span></span><span style='font-size: undefined;'> are parsed from the config file discussed previously. During the campaign observed by Rapid7, the RAT acts as a framework and constitutes the codebase to edit legitimate system daemons. Other trojanized instances found are agetty and polkitd, where we identified a similar pattern lacking the HAProxy monitor: the creation of a thread to run curlRAT, reaching to </span><span style='font-size: undefined;'><span data-type='inlineCode'>img.worksongo.store</span></span><span style='font-size: undefined;'> and </span><span style='font-size: undefined;'><span data-type='inlineCode'>img.socialteams.store</span></span><span style='font-size: undefined;'> respectively.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><span data-type='inlineCode'>atd_encrypt_url</span></span><span style='font-size: undefined;'> and </span><span style='font-size: undefined;'><span data-type='inlineCode'>atd_decrypt_url</span></span><span style='font-size: undefined;'> leverages the substitution cipher “E1x0X3f2R5w4g7u6D968kAeCdBPEpDhGJF4IiHHKzJvMtLlOnNcQmPNSjR2UFTUWOVTYIXZZ5aWcQbbeqd7gYf3i8hykGjCmsl9oonrqSp0sVrauKtLwAvBy1xMz=.#,+/--__" shared with the ssh keylogger.</span></p><h3><span style='font-size: undefined;'>Ted backdoor</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>The TA recompiled the HAProxy build 2.8.12 </span><span style='font-size: undefined;'><span data-type='inlineCode'>72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558</span></span><span style='font-size: undefined;'> (18MB) to include a custom plugin (named </span><span style='font-size: undefined;'><span data-type='inlineCode'>ted_plugin</span></span><span style='font-size: undefined;'>) leaving debug strings naming the backdoor.</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltb521a2240d97dd85/6a99bfd5923082231ec4bf1b/fig10.png" alt="fig10.png" caption="Figure 10: ted_plugin compiled as part of the source code" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="fig10.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltb521a2240d97dd85/6a99bfd5923082231ec4bf1b/fig10.png" data-sys-asset-uid="bltb521a2240d97dd85" data-sys-asset-filename="fig10.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 10: ted_plugin compiled as part of the source code" data-sys-asset-alt="fig10.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 10: ted_plugin compiled as part of the source code</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>Figure 10 shows that the plugin was directly compiled with the rest of HAProxy source code and hooks directly the built-in HTTP parser relying on internal HAProxy structure for searching HTTP request headers.</span><span style='color:rgb(60, 64, 67);font-size: undefined;'> </span><span style='font-size: undefined;'>The custom filter defined to capture traffic is loaded via the </span><span style='font-size: undefined;'><span data-type='inlineCode'>ted_load_filter_config</span></span><span style='font-size: undefined;'> routine. </span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltd4e372705f58b8ee/6a99bff43eabd01ddf441c16/fig11.png" alt="fig11.png" caption="Figure 11: my_filter_config struct" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="fig11.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltd4e372705f58b8ee/6a99bff43eabd01ddf441c16/fig11.png" data-sys-asset-uid="bltd4e372705f58b8ee" data-sys-asset-filename="fig11.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 11: my_filter_config struct" data-sys-asset-alt="fig11.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 11: my_filter_config struct</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>The routine reads the implant's operational configuration from </span><span style='font-size: undefined;'><span data-type='inlineCode'>~/cache/haproxy-1000.cache</span></span><span style='font-size: undefined;'>. Each field is decrypted in two layers: first </span><span style='font-size: undefined;'><span data-type='inlineCode'>ngx_decode</span></span><span style='font-size: undefined;'> applies a chained XOR seeded by the file's first byte; then </span><span style='font-size: undefined;'><span data-type='inlineCode'>ngx_decrypt_script</span></span><span style='font-size: undefined;'> applies a monoalphabetic substitution whose 67-entry mapping table is built at startup in </span><span style='font-size: undefined;'><span data-type='inlineCode'>ted_init_util</span></span><span style='font-size: undefined;'> from “E1x0X3f2R5w4g7u6D968kAeCdBPEpDhGJF4IiHHKzJvMtLlOnNcQmPNSjR2UFTUWOVTYIXZZ5aWcQbbeqd7gYf3i8hykGjCmsl9oonrqSp0sVrauKtLwAvBy1xMz=.#,+/--__" , and held in the </span><span style='font-size: undefined;'><span data-type='inlineCode'>ted_dec_dict</span></span><span style='font-size: undefined;'> uthash table keyed by Jenkins hash for O(1) lookup. The config carries the operating mode, all targeting regexes, every script rule with its payload paths and filenames, and the allowed operator keys. IP-based access control lists are loaded from </span><span style='font-size: undefined;'><span data-type='inlineCode'>haproxy-1001.cache</span></span><span style='font-size: undefined;'> and </span><span style='font-size: undefined;'><span data-type='inlineCode'>haproxy-1002.cache</span></span><span style='font-size: undefined;'> via the same decryption scheme. In other ted backdoor samples, the my_filter_config struct includes regexes to capture cookies as well.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>After loading its configuration, it sets up signal handling via </span><span style='font-size: undefined;'><span data-type='inlineCode'>ted_register_reload_signal_handler()</span></span><span style='font-size: undefined;'> and saves its C2 pipe under </span><span style='font-size: undefined;'><span data-type='inlineCode'>HAPROXY_MWORKER_PP_READ</span></span><span style='font-size: undefined;'> and </span><span style='font-size: undefined;'><span data-type='inlineCode'>HAPROXY_MWORKER_PP_WRITE</span></span><span style='font-size: undefined;'> environmental variables to survive reloads and restarts, saving child process activity via </span><span style='font-size: undefined;'><span data-type='inlineCode'>ted_extra_log()</span></span><span style='font-size: undefined;'>.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Below is the list of functions defined by the ted_plugin:</span></p><p><span style='font-size: undefined;'></span></p><table><colgroup data-width='1767'><col style="width:18.053197509903793%"/><col style="width:81.9468024900962%"/></colgroup><thead><tr><th><p style="direction: ltr;"><span style='font-size: undefined;'>C</span><span style='font-size: undefined;'>apability</span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'>ted_* routines</span></p></th></tr></thead><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>HTTP interception and traffic hooking</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>ted_flt_register_ops2, ted_http_headers_for_htx, ted_chn_analyze_for_htx_constprop_0, ted_chn_analyze_for_htx_constprop_0_cold, ted_http_payload, ted_find_value_from_header_ist</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>C2 and task execution</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>ted_pipe_master_thread, ted_pipe_worker_thread, ted_task_for_response, ted_alloc_task_context</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>IPC and pipes</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>ted_init_main_pipe, ted_create_pipe_file, ted_create_multi_pipe_file, ted_make_pipe_name</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Configuration and rules engine</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>ted_load_filter_config, ted_reload_filter_config, ted_free_filter_config, ted_load_ip_set</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>In-memory data structures</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>ted_set_add, ted_set_contains, ted_set_clean, ted_set_add_string, ted_set_contains_string, ted_set_clean_string</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Logging, file I/O</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>ted_extra_log, ted_save_capture_log2, ted_write_fd, ted_build_correct_path</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Initialization and persistence</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>ted_init_util, ted_register_reload_signal_handler, ted_regex_free</span></p></td></tr></tbody></table><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The HAProxy trace_ops struct is copied into my_filter_ops, and contains a hooked tracing method.</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt86751a3ddcb73b66/6a99c07560f795b250d7841d/fig12.png" alt="fig12.png" caption="Figure 12: my_filter_ops containing hooked methods" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="fig12.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt86751a3ddcb73b66/6a99c07560f795b250d7841d/fig12.png" data-sys-asset-uid="blt86751a3ddcb73b66" data-sys-asset-filename="fig12.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 12: my_filter_ops containing hooked methods" data-sys-asset-alt="fig12.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 12: my_filter_ops containing hooked methods</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'><span data-type='inlineCode'>trace_chn_start_analyze()</span></span><span style='font-size: undefined;'> is hooked via </span><span style='font-size: undefined;'><span data-type='inlineCode'>ted_chn_analyze_for_htx_constprop_0()</span></span><span style='font-size: undefined;'> that parses the HTX buffer — the memory region where HAProxy stores parsed, SSL-decrypted HTTP request. If an incoming request matches the endpoint "/favorite_list_2x_m500_ico.jpg" (Figure 13), the malware drops into a Command & Control mode, setting the field flag to 1 in the </span><span style='font-size: undefined;'><span data-type='inlineCode'>ted_rep_state</span></span><span style='font-size: undefined;'> structure that tracks the response state. </span></p><p></p><figure style="margin: 0"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltb4d77cd521a6f6ad/6a99c0bf27a5317512dc9ff9/fig13.png" height="519" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="fig13.png" asset-alt="fig13.png" width="1195" max-width="1195" max-height="519" style="max-width: 1195px; width: 1195px; max-height: 519px; height: 519px" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltb4d77cd521a6f6ad/6a99c0bf27a5317512dc9ff9/fig13.png" data-sys-asset-uid="bltb4d77cd521a6f6ad" data-sys-asset-filename="fig13.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="fig13.png" sys-style-type="display"/></figure><p>⠀</p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltdf5e7e85f5bbbdeb/6a99c0bfa163361493372f56/fig135.png" alt="fig135.png" caption="Figure 13: Dropping into C2 mode" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="fig135.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltdf5e7e85f5bbbdeb/6a99c0bfa163361493372f56/fig135.png" data-sys-asset-uid="bltdf5e7e85f5bbbdeb" data-sys-asset-filename="fig135.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 13: Dropping into C2 mode" data-sys-asset-alt="fig135.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 13: Dropping into C2 mode</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>First, it reaches into HAProxy's internal counters to decrement active connection stats, referencing fields from the proxy struct via hardcoded 2.8.12 offsets to clear any trace left: the per-backend </span><span style='font-size: undefined;'><span data-type='inlineCode'>beconn</span></span><span style='font-size: undefined;'>/</span><span style='font-size: undefined;'><span data-type='inlineCode'>feconn</span></span><span style='font-size: undefined;'> and the global </span><span style='font-size: undefined;'><span data-type='inlineCode'>actconn</span></span><span style='font-size: undefined;'>, then 64-bit fields within </span><span style='font-size: undefined;'><span data-type='inlineCode'>be_counters</span></span><span style='font-size: undefined;'> (</span><span style='font-size: undefined;'><span data-type='inlineCode'>cum_conn</span></span><span style='font-size: undefined;'>, </span><span style='font-size: undefined;'><span data-type='inlineCode'>cum_req</span></span><span style='font-size: undefined;'>, </span><span style='font-size: undefined;'><span data-type='inlineCode'>bytes_in</span></span><span style='font-size: undefined;'>, </span><span style='font-size: undefined;'><span data-type='inlineCode'>bytes_out</span></span><span style='font-size: undefined;'>) guarded against underflow, and 32-bit peak metrics (</span><span style='font-size: undefined;'><span data-type='inlineCode'>sps_max</span></span><span style='font-size: undefined;'>, </span><span style='font-size: undefined;'><span data-type='inlineCode'>conn_max</span></span><span style='font-size: undefined;'>, </span><span style='font-size: undefined;'><span data-type='inlineCode'>cps_max</span></span><span style='font-size: undefined;'>) decremented only when exactly 1. Secondly, it parses a custom hardcoded 14-byte header to obtain the payload length, then creates FIFO pipes via </span><span style='font-size: undefined;'><span data-type='inlineCode'>ted_make_pipe_name</span></span><span style='font-size: undefined;'> and </span><span style='font-size: undefined;'><span data-type='inlineCode'>ted_create_multi_pipe_file</span></span><span style='font-size: undefined;'> keyed on HAProxy's connection ID under </span><span style='font-size: undefined;'><span data-type='inlineCode'>/tmp</span></span><span style='font-size: undefined;'> (e.g. </span><span style='font-size: undefined;'><span data-type='inlineCode'>/tmp/t[ID]_w.pipe</span></span><span style='font-size: undefined;'>). If HAProxy is running in master-worker mode (</span><span style='font-size: undefined;'><span data-type='inlineCode'>MODE_MWORKER</span></span><span style='font-size: undefined;'>, bit 0x80), the connection ID is written to the </span><span style='font-size: undefined;'><span data-type='inlineCode'>pp_w2m</span></span><span style='font-size: undefined;'> pipe so the master process runs the dispatcher; otherwise a detached thread runs </span><span style='font-size: undefined;'><span data-type='inlineCode'>ted_pipe_worker_thread</span></span><span style='font-size: undefined;'> locally (Figure 13).</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The HTX walk filters on block type 4, which is </span><span style='font-size: undefined;'><span data-type='inlineCode'>HTX_BLK_DATA</span></span><span style='font-size: undefined;'>, and writes each block straight into </span><span style='font-size: undefined;'><span data-type='inlineCode'>fdPipe</span></span><span style='font-size: undefined;'> with </span><span style='font-size: undefined;'><span data-type='inlineCode'>write()</span></span><span style='font-size: undefined;'>. Any short write aborts and closes the pipe. Afterwards </span><span style='font-size: undefined;'><span data-type='inlineCode'>to_forward</span></span><span style='font-size: undefined;'>, </span><span style='font-size: undefined;'><span data-type='inlineCode'>output</span></span><span style='font-size: undefined;'>, </span><span style='font-size: undefined;'><span data-type='inlineCode'>buf.head</span></span><span style='font-size: undefined;'> and </span><span style='font-size: undefined;'><span data-type='inlineCode'>buf.data</span></span><span style='font-size: undefined;'> on the request channel are all zeroed. That tells HAProxy there is nothing left to forward, so the attacker's command body never reaches a backend server. The C2 request terminates at the load balancer, and no backend ever logs it.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The C2 dispatcher logic is resumed in the table below.</span></p><p><span style='font-size: undefined;'></span></p><table><colgroup data-width='1525'><col style="width:13.049180327868854%"/><col style="width:86.95081967213115%"/></colgroup><thead><tr><th><p style="direction: ltr;"><span style='font-size: undefined;'>Command</span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'>Description</span></p></th></tr></thead><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Opcode '0' (0x30)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Beacon: returns a version banner including build ID (24112201), HAProxy version (2.8.12-0fdb194), master-worker mode status, and chroot path.</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Opcode '1' (0x31)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>File upload: resolves path via ted_build_correct_path, writes file content via fopen(path, "wb"), and replies 1. Used to upload payload files for the injection path.</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Opcode '2' (0x32)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>File download: reads a path, stats it, writes the 8-byte size, and streams the contents back with EAGAIN handling.</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Opcode '3' (0x33)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Command execution: executes commands via popen; merges stdout/stderr, appends " 2&gt;&1", and streams output back XOR-encrypted.</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Opcode '9' (0x39)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Config update: writes new config to ~/cache/haproxy-1000.cache.bak, re-encrypts using chained XOR, validates via ted_load_filter_config, and renames over the active config file if successful.</span></p></td></tr></tbody></table><p style="direction: ltr;"><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>All five handlers write the same “HTTP/1.0 200 OK” header with Content-Type: text/html into the read pipe before the body. That's what the response task then relays out via </span><span style='font-size: undefined;'><span data-type='inlineCode'>send()</span></span><span style='font-size: undefined;'> on the raw socket, which is why the traffic looks like an ordinary HTTP response on the wire despite never passing through HAProxy's response path. Output back to the operator uses a rolling XOR cipher where each plaintext block is the key used to encrypt the next block with a random 1-byte seed.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>If the initial endpoint check does not match "/favorite_list_2x_m500_ico.jpg" and the filter is in capture mode, then traffic is selectively logged and victims are identified based on the </span><span style='font-size: undefined;'><span data-type='inlineCode'>capturelist_set</span></span><span style='font-size: undefined;'> field within the </span><span style='font-size: undefined;'><span data-type='inlineCode'>my_filter_config</span></span><span style='font-size: undefined;'> struct (Figure 11), containing the list of targeted IPs and subnets. It uses regular expressions to filter the incoming HTTP traffic, waiting for high-value requests (like a user hitting a /login endpoint or an admin panel).</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>When a victim's request matches the attacker's filters, the backdoor goes to work.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>It extracts the victim's source IP, the requested Host, the Referer, and the User-Agent formatting the data in a single-line record using exclamation marks as separators</span><span style='font-size: undefined;'><strong>.</strong></span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt354d73897f68b46f/6a99c169e1500a3cba017f6f/fig14.png" alt="fig14.png" caption="Figure 14: Real-time capturing of selected HTTP headers matching specific regexes" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="fig14.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt354d73897f68b46f/6a99c169e1500a3cba017f6f/fig14.png" data-sys-asset-uid="blt354d73897f68b46f" data-sys-asset-filename="fig14.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 14: Real-time capturing of selected HTTP headers matching specific regexes" data-sys-asset-alt="fig14.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 14: Real-time capturing of selected HTTP headers matching specific regexes</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>The execution flow continues based on conf-&gt;action; zero means passive logging only, non-zero starts the injection path. A request then has to clear four conditions. It needs a </span><span style='font-size: undefined;'><span data-type='inlineCode'>User-Agent</span></span><span style='font-size: undefined;'>, and if </span><span style='font-size: undefined;'><span data-type='inlineCode'>agent_pattern</span></span><span style='font-size: undefined;'> is configured that regex has to match. Second, the code scans the User-Agent for the bytes x,6,4, it selects between the two payload paths the matched rule retrieving them </span><span style='font-size: undefined;'><span data-type='inlineCode'>ted_script_config</span></span><span style='font-size: undefined;'> struct (path_32 at offset 0x18 and path_64 at 0x20). Third, the script rule list is walked until one </span><span style='font-size: undefined;'><span data-type='inlineCode'>ted_script_config</span></span><span style='font-size: undefined;'> entry's URL and referer regexes both match, with a null referer counting as an automatic pass. Thus the operator catches a victim arriving at a specific page from a specific referrer, rather than spraying at everyone hitting a URL.</span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt794c649ceafa88ea/6a99c1b6144a15a655de5222/fig15.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="fig15.png" asset-alt="fig15.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt794c649ceafa88ea/6a99c1b6144a15a655de5222/fig15.png" data-sys-asset-uid="blt794c649ceafa88ea" data-sys-asset-filename="fig15.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="fig15.png" sys-style-type="display"/></figure><p>⠀</p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt8d800efe34c0376b/6a99c1b6ecdaa72e7b053550/fig155.png" height="643" alt="fig155.png" caption="Figure 15: Custom ted structure defined to inject malicious code in the page, and store regex rules and the connection context" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="fig155.png" width="599" style="width: 599px; height: 643px" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt8d800efe34c0376b/6a99c1b6ecdaa72e7b053550/fig155.png" data-sys-asset-uid="blt8d800efe34c0376b" data-sys-asset-filename="fig155.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 15: Custom ted structure defined to inject malicious code in the page, and store regex rules and the connection context" data-sys-asset-alt="fig155.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 15: Custom ted structure defined to inject malicious code in the page, and store regex rules and the connection context</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>Fourth, the implant parses Accept</span><span style='font-size: undefined;'><strong>-</strong></span><span style='font-size: undefined;'>Language splitting on ; and =, pulling four operator-controlled fields: mrt for the 64-byte uid credential, msc for an 8-byte status, mst for an 8-byte score, and a fourth keyword read from off_355407 for a 1024-byte info</span><span style='font-size: undefined;'><strong> </strong></span><span style='font-size: undefined;'>blob. Parsing is order-independent and any subset can appear. If mrt yields a key, it must exist in allow_id_set, and that credential overrides IP filtering entirely, letting the operator reach the requested page from anywhere. It also upgrades the log record to the *-prefixed format carrying uid</span><span style='font-size: undefined;'><strong>, </strong></span><span style='font-size: undefined;'>status,</span><span style='font-size: undefined;'><strong> </strong></span><span style='font-size: undefined;'>score, and info. With no key, the fallback is IP-based:</span><span style='color:rgb(60, 64, 67);font-size: undefined;'><strong> </strong></span><span style='font-size: undefined;'>action == 1</span><span style='color:rgb(60, 64, 67);font-size: undefined;'><strong> </strong></span><span style='font-size: undefined;'>requires whitelist membership, action == 2 requires blacklist absence, both checked twice, once with the final octet zeroed for /24 subnet matching and once for the exact host.</span><span style='color:rgb(60, 64, 67);font-size: undefined;'><strong> </strong></span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Once all checks are cleared the chosen file is opened, stored in the per-connection </span><span style='font-size: undefined;'><span data-type='inlineCode'>ted_rep_state</span></span><span style='font-size: undefined;'> as </span><span style='font-size: undefined;'><span data-type='inlineCode'>fpAppend</span></span><span style='font-size: undefined;'> and </span><span style='font-size: undefined;'><span data-type='inlineCode'>nTotal</span></span><span style='font-size: undefined;'>, alongside a </span><span style='font-size: undefined;'><span data-type='inlineCode'>script_conf</span></span><span style='font-size: undefined;'> back-reference to the matched rule. The replace byte at offset 0x00 of that rule sets flag to 4 when zero and 2 when non-zero, distinguishing appending content from substituting it. Finally the code sets its filter flag and increments </span><span style='font-size: undefined;'><span data-type='inlineCode'>nb_rsp_data_filters</span></span><span style='font-size: undefined;'> or </span><span style='font-size: undefined;'><span data-type='inlineCode'>nb_req_data_filters</span></span><span style='font-size: undefined;'> on the stream, which is HAProxy's documented opt-in for body access– this time reusing the internal structure of the load balancer to inject code into the page at delivery time.</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt16fc773dd9007e22/6a99c2103eabd0222b441c22/image6.png" alt="image6.png" caption="Figure 16: Hooking the HTTP response" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="image6.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt16fc773dd9007e22/6a99c2103eabd0222b441c22/image6.png" data-sys-asset-uid="blt16fc773dd9007e22" data-sys-asset-filename="image6.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 16: Hooking the HTTP response" data-sys-asset-alt="image6.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 16: Hooking the HTTP response</figcaption></div></figure><p style="text-align: center;direction: ltr;">⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>Once a victim is marked for injection, two callbacks finish the job on the way out. </span><span style='font-size: undefined;'><span data-type='inlineCode'>ted_http_headers_for_htx</span></span><span style='font-size: undefined;'> runs first, and only when the data is on the response side, a state block is initialized during the request, and the transaction flag is set. It rechecks the response against the rule that matched earlier, testing Content-Type and the status line, so a payload is delivered only when the reply is a document worth modifying. It then reshapes the response to fit the incoming file: sets Content-Type, adds a Content-Disposition filename if the rule has one, writes the new body length into the custom length header, deletes Accept-Ranges so the client cannot request byte ranges and spot the size mismatch, and forces the status to 200</span><span style='color:rgb(24, 128, 56);font-size: undefined;'> </span><span style='font-size: undefined;'>OK if it was anything else.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><span data-type='inlineCode'>ted_http_payload</span></span><span style='font-size: undefined;'> performs the swap. For each body chunk, it takes only as much as the payload file has left, reads that slice from disk, decrypts it with </span><span style='font-size: undefined;'><span data-type='inlineCode'>ngx_decrypt_script</span></span><span style='font-size: undefined;'>, and substitutes it through HAProxy's own body-editing calls. When the replacement changes the body length, the code shifts every remaining filter's offset by the difference, so nothing downstream sees an inconsistency. With the rewritten length header and range support stripped, the size change leaves no trace.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>trace_http_end handles the leftover bytes. The previous callback can only overwrite bytes that already exist in the response, so when the payload is larger than the original body there is a remainder with nowhere to go. This function runs at the end of the response and appends it. It checks that the state block is in an injection mode, that the headers were already rewritten, and that fewer bytes have been delivered than the payload holds. If so, it measures the free space left in the response buffer, reads exactly that much from the payload file, decrypts it with </span><span style='font-size: undefined;'><span data-type='inlineCode'>ngx_decrypt_script</span></span><span style='font-size: undefined;'>, and appends it as a new data block, bumping the channel's output count to match. </span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The result is that a payload of any size can be delivered across as many passes as it takes, using HAProxy's own scheduler to drive the process.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>To ensure persistence, curlRAT is integrated and hidden as libc routines.</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltad22dc349282d1b4/6a99c23e5f9db770d2562114/image9.png" alt="image9.png" caption="Figure 17: ted backdoor including curlRAT configuration a8bfab4de81a1acb04aacdf757346946b0f5e30f0c9f402004016d0e425119c7" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="image9.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltad22dc349282d1b4/6a99c23e5f9db770d2562114/image9.png" data-sys-asset-uid="bltad22dc349282d1b4" data-sys-asset-filename="image9.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 17: ted backdoor including curlRAT configuration a8bfab4de81a1acb04aacdf757346946b0f5e30f0c9f402004016d0e425119c7" data-sys-asset-alt="image9.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 17: ted backdoor including curlRAT configuration a8bfab4de81a1acb04aacdf757346946b0f5e30f0c9f402004016d0e425119c7</figcaption></div></figure><p>⠀</p><h2><span style='font-size: undefined;'>Attacker infrastructure</span></h2><p style="direction: ltr;"><span style='font-size: undefined;'>The observed infrastructure follows a consistent pattern: Domains are registered under low-cost commodity TLDs —</span><span style='font-size: undefined;'><strong> </strong></span><span style='font-size: undefined;'>.store, .space, .site, .autos — and use subdomain schemes mimicking image-serving CDN endpoints (img.) They then blend payload delivery traffic into normal web browsing. The naming convention across suggests a shared registration workflow rather than ad-hoc infrastructure. The</span><span style='font-size: undefined;'><strong> </strong></span><span style='font-size: undefined;'><span data-type='inlineCode'>img.responsive.pstatic.autos</span></span><span style='font-size: undefined;'> mimics Naver's</span><span style='font-size: undefined;'><strong> </strong></span><span style='font-size: undefined;'>pstatic.net static content domain, a South Korean web platform, which combined with the watering-hole delivery model adopted by the ted backdoor is consistent with targeting of Korean-speaking users.</span></p><h2><span style='font-size: undefined;'>Attribution</span></h2><p style="direction: ltr;"><span style='font-size: undefined;'>At the time of the analysis, compromised servers had exposed the Groupware login portal on port 443, which is heavily present in Korean enterprise environments. The targeting of regional software (Groupware), mimicking Naver's static content domain, usage of simple xor and substitution ciphers and the watering-hole model already documented in the</span><a href="https://image.ahnlab.com/atip/content/file/20241126/(ENG%20ver)Operation%20Code%20on%20Toast(full).pdf" target="_blank"><span style='font-size: undefined;'> Operation Code on Toast</span></a><span style='font-size: undefined;'> (APT37)</span><span style='font-size: undefined;'><strong> </strong></span><span style='font-size: undefined;'>and </span><a href="https://securelist.com/operation-synchole-watering-hole-attacks-by-lazarus/116326/" target="_blank"><span style='font-size: undefined;'>Operation Synchole</span></a><span style='font-size: undefined;'> (Lazarus),</span><span style='font-size: undefined;'><strong> </strong></span><span style='font-size: undefined;'>allows medium confidence attribution to DPRK APT. The list of C2s hardcoded is associated with APT37 by </span><a href="https://threatfox.abuse.ch/browse/tag/RicochetChollima/" target="_blank"><span style='font-size: undefined;'>ThreatFox</span></a><span style='font-size: undefined;'> and </span><a href="https://github.com/stamparm/trails/blob/main/malware/apt_37.txt" target="_blank"><span style='font-size: undefined;'>maltrail</span></a><span style='font-size: undefined;'>.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The campaign's timeline and delivery mechanism overlap with Operation SyncHole, a concurrent Lazarus campaign documented by Kaspersky running from November 2024 through February 2025, in which Lazarus compromised South Korean media sites to redirect visitors to pages serving malicious JavaScript payloads. APT37 and Lazarus Group are distinct North Korean state-sponsored threat clusters assessed by </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/north-korea-cyber-structure-alignment-2023" target="_blank"><span style='font-size: undefined;'>Mandiant</span></a><span style='font-size: undefined;'> to operate under different DPRK agencies — APT37 under the Ministry of State Security, Lazarus under the Reconnaissance General Bureau — though both conduct cyber espionage targeting South Korean entities. Lazarus has been observed to deploy backdoored </span><a href="https://ics-cert.kaspersky.com/publications/reports/2023/09/25/apt-and-financial-attacks-on-industrial-organizations-in-h1-2023/#korean-speaking-activity" target="_blank"><span style='font-size: undefined;'>open-source</span></a><span style='font-size: undefined;'> programs to deliver malware and use feedback XOR + base64 to interact with the C2 by </span><a href="https://securelist.com/lazarus-andariel-mistakes-and-easyrat/110119/" target="_blank"><span style='font-size: undefined;'>Kaspersky</span></a><span style='font-size: undefined;'>. As of July 2026, similar suspected initial access has been reported by </span><a href="https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant" target="_blank"><span style='font-size: undefined;'>ENKI WhiteHat</span></a><span style='font-size: undefined;'>, suggesting that if a vulnerability in South Korean mail appliances exists, the exploitation could still be ongoing and leveraged by DPRK APTs.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Further evidence is necessary to make a more definitive assessment. Moreover, the presence of</span><span style='font-size: undefined;'><strong> </strong></span><span style='font-size: undefined;'>ngx_* prefixed routines within the ted backdoor</span><span style='font-size: undefined;'><strong> </strong></span><span style='font-size: undefined;'>suggest code reused from an nginx backdoor. The ngx_* prefixed routines were observed during the latest </span><a href="https://blog.xlab.qianxin.com/funnull-resurfaces-exposing-ringh23-arsenal-and-maccms-supply-chain-attacks/" target="_blank"><span style='font-size: undefined;'>Funnull</span></a><span style='font-size: undefined;'> campaign, where (similar to our case) a custom nginx filter was registered to hook HTTP traffic, and simple XOR encryption was applied to the configuration file. However, other than a similar naming convention, no significant code-level overlaps exist to support a stronger linkage.</span></p><h2><span style='font-size: undefined;'>Conclusion</span></h2><p style="direction: ltr;"><span style='font-size: undefined;'>ted backdoor and curlRAT were designed to persist during long-term espionage operations with the ability to steal cookie sessions, credentials, redirect selected users, conduct drive-by download attacks, and hide evidence of the tampered page to a specific range of IPs to evade detection. Defenders should treat any edge component managing user traffic, SSL, or runtime modules with the same strict security standards as their main application servers. Relying on the component's own logs is not enough; securing these systems requires independent network correlation, memory behavioral analysis, and binary integrity checks.</span></p><h2><span style='font-size: undefined;'>MITRE ATT&CK techniques</span></h2><table><colgroup data-width='1794.919191919192'><col style="width:10.692358340320883%"/><col style="width:22.11798736050693%"/><col style="width:34.931934697828325%"/><col style="width:32.25771960134386%"/></colgroup><thead><tr><th><p style="text-align: center;direction: ltr;"><span style='font-size: undefined;'><strong>Tactic</strong></span></p></th><th><p style="text-align: center;direction: ltr;"><span style='font-size: undefined;'><strong>Technique</strong></span></p></th><th><p style="text-align: center;direction: ltr;"><span style='font-size: undefined;'><strong>Detail</strong></span></p></th><th><p style="text-align: center;direction: ltr;"><span style='font-size: undefined;'><strong>Component</strong></span></p></th></tr></thead><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Initial access</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1190] Exploit public-facing application</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>HAProxy filter API abused as injection point; watering-hole payload delivery via compromised load balancer</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>ted backdoor</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Execution</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1059.004] Unix shell</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>popen() used for one-shot command execution per opcode '3'; PTY shell spawned per opcode '5'; reverse shell per opcode '3' in CurlRAT</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>ted backdoor, CurlRAT</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Execution</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1106] Native API</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>pthread_create / pthread_detach for detached shell threads; HAProxy pool_alloc / task_wakeup for async response scheduling</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>ted backdoor</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Persistence</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1574.006] Hijack execution flow: dynamic linker</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Implant loaded as HAProxy shared library filter at process start; persistent across HAProxy restarts</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>ted backdoor</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Persistence</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1543] Create or modify system process</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Legitimate crond binary overwritten in-place; service restarted; timestomping to match /usr/bin/ssh creation time</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Stager, CurlRAT</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Privilege escalation</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1548] Abuse elevation control mechanism</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>setuid(0) / setreuid(0,0) called before reverse shell daemonisation; stager verifies root before payload drop</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Stager, CurlRAT</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Defence evasion</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1036.005] Masquerade: match legitimate name</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>crond, polkitd, agetty, atd binary names used; CentOS variant masquerades functions as atd_ routines in static analysis</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Stager, CurlRAT</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Defence evasion</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1070.002] Clear Linux logs</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Selective keyword erasure (tmp, wget, cron, crond) from bash_history, messages, audit.log, secure, syslog, auth.log via /tmp/jasper-log staging file</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Stager</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Defence evasion</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1070.006] Timestomp</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Backdoored crond given same creation timestamp as /usr/bin/ssh post-install</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Stager</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Defence evasion</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1562.006] Disable or modify OS logging</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>HAProxy connection counters (beconn, feconn, actconn, cum_conn, cum_req, bytes_in, bytes_out, sps_max, conn_max, cps_max) atomically scrubbed via hardcoded struct offsets</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>ted backdoor</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Defence evasion</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1027] Obfuscated files or information</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Config files encrypted with chained XOR + monoalphabetic substitution; payload scripts encrypted with substitution cipher; C2 comms protected with feedback XOR + Base64</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Stager, CurlRAT, ted backdoor</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Defence evasion</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1497.001] Virtualisation/sandbox evasion</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>CurlRAT watchdog checks /usr/lib/libvirtlog.so.0 before activating; aborts if not in virtualized environment</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>CurlRAT</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Defence evasion</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1480] Execution guardrails</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Stager deploys only if HAProxy or cron are detected; CurlRAT validates victim token before handler dispatch; ted blacklists known scanner IPs</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Stager, CurlRAT, ted backdoor</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Credential access</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1556.003] Modify authentication process: pluggable authentication modules</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>SSH keylogger intercepts plaintext passwords; credentials saved to encrypted log at /var/lib/sshd/c8c68e629bba773a10ac80012d10bf19</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>CurlRAT</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Credential access</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1539] Steal web session cookie</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Passive capture engine intercepts HTTP sessions; harvests Source IP, Host, URL, Referer, User-Agent, Accept-Language key via regex-gated filters</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>ted backdoor</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Discovery</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1082] System information discovery</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Stager profiles hostname, OS distro, version, kernel release, CPU arch to select payload; CurlRAT beacon transmits 10KB system-info structure</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Stager, CurlRAT</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Discovery</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1057] Process discovery</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>CurlRAT watchdog polls /proc/haproxy.pid hourly; tracks started/stopped/restarted/reloaded states; reports via writeservice_info endpoint</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>CurlRAT</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Collection</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1185] Browser session hijacking</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Response body replaced or appended with decrypted payload script via HAProxy data filter callbacks; Content-Type, Content-Length, Content-Disposition rewritten; 200 OK forced; Accept-Ranges stripped</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>ted backdoor</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Collection</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1119] Automated collection</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Passive capture logs timestamped records per matched request; expanded * records written when Accept-Language mrt key present</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>ted backdoor</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>C2</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1071.001] Application layer protocol: web protocols</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>ted C2 tunnelled as HTTP through load balancer; CurlRAT polls C2 over HTTPS with libcurl fallback to HTTP; all payloads as application/x-www-form-urlencoded POST</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>CurlRAT, ted backdoor</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>C2</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1132.001] Data encoding: standard encoding</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>All CurlRAT C2 payloads Base64-encoded after feedback XOR; ted pipe protocol uses raw bytes with rolling XOR session key</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>CurlRAT, ted backdoor</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>C2</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1102] Web service</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>CurlRAT falls back to secondary C2 img.monderhouse.space on config validation failure; img.darklights.store used as backup config host</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>CurlRAT</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>C2</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1572] Protocol tunnelling</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Interactive shell tunnelled through HAProxy HTTP pipeline via named FIFOs; response exfiltrated via raw send() on TCP socket bypassing HAProxy logging</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>ted backdoor</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>C2</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1568] Dynamic resolution</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>CurlRAT victim ID derived from hostname + IP + hardware UUID + cron version string, MD5'd and uppercased; used as User-token header in all C2 requests</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>CurlRAT</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Exfiltration</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1041] Exfiltration over C2 channel</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>SSH credentials exfiltrated via CurlRAT C2; session capture logs written by ted; CurlRAT mode 0 streams command output back over same channel</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Stager, CurlRAT, ted backdoor, SSH keylogger</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Exfiltration</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>[T1560] Archive collected data</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>SSH keylogger output encrypted with substitution cipher before writing; CurlRAT applies feedback XOR + Base64 to all outbound data</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>CurlRAT, SSH keylogger</span></p></td></tr></tbody></table><h2><span style='font-size: undefined;'>Indicators of compromise (IOCs)</span></h2><h3><span style='font-size: undefined;'>CurlRAT Stager</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>09739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61</span></p><h3><span style='font-size: undefined;'>CurlRAT</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>83f7d565b0465546027052b597af46eae3a199e7a91fcc2ab936341147349130</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>7007a78d50a993cb174c685eba96eb442c9507e38fd9d8e5dffc712f613ec110</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>6cf1b5e92a9c0756f597a5ddefb38eba32961c52efac7ab2a0aa52c639a8fc53</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>ed72f4cd8d467b5c5d95ae6aeca4aaeea14d79565d379c1ca5871a714727be16</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>6cf1b5e92a9c0756f597a5ddefb38eba32961c52efac7ab2a0aa52c639a8fc53</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>d53c760c23b4405eb04ad0f20ead375440344b3bdf1fb7854ed12e40d155eabe - cronie</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>2f02b09d61d432134e994ad671258f523bbf289ae6091fd4eae192c60bd51b6f - agetty</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c - atd</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>a1d8af3a6acb731f07f72040eccb3450c1c83d40e29f736c2a63d35388660be4 - polkitd</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>12810854c8b2c391b23e2e18b013e873d0369b0637aa3cf993136c07188ba3b8</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>009a1e2d7a582a24e50cf2ffc2a005482c8e38f22bf5ed416053855f8d054e1e</span></p><h3><span style='font-size: undefined;'>SSH keylogger</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5</span></p><h3><span style='font-size: undefined;'>Ted backdoor</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>94630b96f628c96a6bff7904b40ffc9ad67c86f8a4ff6080c3b524831c93f402</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>a8bfab4de81a1acb04aacdf757346946b0f5e30f0c9f402004016d0e425119c7</span></p><h3><span style='font-size: undefined;'>C2</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>img.monderhouse.space</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>img.smartnords.site</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>img.darklights.store</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>img.responsive.pstatic.autos</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>img.socialteams.store</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>img.worksongo.store</span></p><h2><span style='font-size: undefined;'>Rapid7 customers</span></h2><p style="direction: ltr;"><span style='font-size: undefined;'></span></p>]]></description>
      <link>https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors</link>
      <guid isPermaLink="false">blte470e9524b9af32f</guid>
      <category><![CDATA[Hacking]]></category>
      <category><![CDATA[Labs]]></category>
      <category><![CDATA[Malware]]></category><dc:creator><![CDATA[Rapid7 Labs]]></dc:creator>
      <pubDate>Fri, 04 Sep 2026 12:00:00 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt83e3180716d766f0/69b180eb669f1ce1a02fe1aa/Purple-teaming-in-2026-hero.jpg" medium="image" />
    </item>
    <item>
      <title><![CDATA[Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On September 1, 2026, SonicWall </span><a href="https://www.sonicwall.com/es-mx/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities-snwlid-2026-0016/kA1VN000002AXmQ0AW"><span style='font-size: undefined;'>disclosed</span></a><span style='font-size: undefined;'> two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, </span><a href="https://nvd.nist.gov/vuln/detail/cve-2026-83548"><span style='font-size: undefined;'>CVE-2026-83548</span></a><span style='font-size: undefined;'> and </span><a href="https://nvd.nist.gov/vuln/detail/cve-2026-83549"><span style='font-size: undefined;'>CVE-2026-83549</span></a><span style='font-size: undefined;'>, can be chained to achieve unauthenticated remote code execution (RCE) on affected appliances.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-83548 is a critical pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. The flaw has a CVSS v3.1 base score of </span><a href="https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"><span style='font-size: undefined;'>10.0</span></a><span style='font-size: undefined;'> and can allow a remote, unauthenticated attacker to access sensitive functionality and perform unauthorized operations through an unintended alternate access path.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-83549 is a high-severity OS command injection vulnerability in the Appliance Management Console (AMC). On its own, exploitation requires an authenticated administrator and specific system conditions. Although, by leveraging the SSRF vulnerability CVE-2026-83548 an attacker could potentially exploit CVE-2026-83549 to execute arbitrary OS commands without prior authentication.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>SonicWall SMA1000 appliances are enterprise secure remote access gateways used to provide employees and other authorized users with access to internal applications and resources. Their role as network-edge systems makes successful exploitation particularly concerning, since affected Work Place interfaces may be exposed directly to the internet as part of normal deployment.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>SonicWall has confirmed active exploitation of both vulnerabilities in the wild, </span><span style='font-size: undefined;'>and both </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-83548"><span style='font-size: undefined;'>CVE-2026-83548</span></a><span style='font-size: undefined;'> and </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-83549"><span style='font-size: undefined;'>CVE-2026-83549</span></a><span style='font-size: undefined;'> have been added to CISA's Known Exploited Vulnerabilities (</span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"><span style='font-size: undefined;'>KEV</span></a><span style='font-size: undefined;'>) catalog. </span><span style='font-size: undefined;'>No public proof-of-concept exploit, indicators of compromise (IOCs), or attribution for the current activity were identified in the research available at the time of publication.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The vulnerabilities affect SMA1000 Models - 6210, 7210, 8200v running the following versions:</span></p><table><colgroup data-width='500'><col style="width:47.460317460317455%"/><col style="width:52.539682539682545%"/></colgroup><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Vulnerable Versions</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Fixed Versions</strong></span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'><span data-type='inlineCode'>12.4.3-03453 platform-hotfix</span></span><span style='font-size: undefined;'> and earlier</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><span data-type='inlineCode'>12.4.3-03526 (platform-hotfix)</span></span><span style='font-size: undefined;'> and higher versions</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'><span data-type='inlineCode'>12.5.0-02835 platform-hotfix </span></span><span style='font-size: undefined;'>and earlier</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><span data-type='inlineCode'>12.5.0-02952 (platform-hotfix)</span></span><span style='font-size: undefined;'> and higher versions.</span></p><p></p></td></tr></tbody></table><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations operating affected SonicWall SMA1000 appliances should prioritize applying SonicWall’s updated platform hotfixes immediately. Because exploitation was occurring before public disclosure, organizations should not rely solely on patching to determine whether an appliance has already been compromised.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>SonicWall recommends upgrading affected appliances to:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><span data-type='inlineCode'>12.4.3-03526 platform-hotfix</span></span><span style='font-size: undefined;'>, for systems on the </span><span style='font-size: undefined;'><span data-type='inlineCode'>12.4.3</span></span><span style='font-size: undefined;'> branch</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><span data-type='inlineCode'>12.5.0-02952 platform-hotfix</span></span><span style='font-size: undefined;'>, for systems on the </span><span style='font-size: undefined;'><span data-type='inlineCode'>12.5.0</span></span><span style='font-size: undefined;'> branch</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Affected Product/Component:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>SonicWall SMA1000 Appliance Work Place and Appliance Management Console</span></p></li></ul><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Version </span><span style='font-size: undefined;'><span data-type='inlineCode'>12.4.3-03453 platform-hotfix</span></span><span style='font-size: undefined;'> and earlier are affected.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Version </span><span style='font-size: undefined;'><span data-type='inlineCode'>12.5.0-02835 platform-hotfix</span></span><span style='font-size: undefined;'> and earlier are affected.</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>SonicWall additionally recommends that customers contact SonicWall Technical Support for assistance reviewing appliances for indicators of compromise.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>If evidence of compromise is identified, SonicWall recommends:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Re-imaging affected hardware appliances or re-deploying affected virtual appliances.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Changing all user and administrator passwords.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Resetting Time-based One-Time Password (TOTP) tokens.</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Given the confirmed exploitation of these vulnerabilities, organizations should treat potentially exposed appliances running vulnerable software as a priority for investigation as well as remediation.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Please read the SonicWall </span><a href="https://www.sonicwall.com/es-mx/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities-snwlid-2026-0016/kA1VN000002AXmQ0AW"><span style='font-size: undefined;'>security advisory</span></a><span style='font-size: undefined;'> for the latest vendor guidance.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3>Exposure Command, InsightVM, and Nexpose</h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-83548 and CVE-2026-83549 in the SMA1000 Appliance series with vulnerability checks expected to be available in the September 3rd content release.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>September 2, 2026:</strong></span><span style='font-size: undefined;'> Initial publication.</span></p></li><li><span style='font-size: undefined;'><strong>September 3, 2026:</strong></span><span style='font-size: undefined;'> CVE added to CISA KEV.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild</link>
      <guid isPermaLink="false">bltbb8920bb4038a592</guid>
      <category><![CDATA[Emergent Threat Response]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Wed, 02 Sep 2026 16:58:45 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!]]></title>
      <description><![CDATA[]]></description>
      <link>https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-payloads-exploits-scanners</link>
      <guid isPermaLink="false">blt526bc61553e28979</guid>
      <category><![CDATA[Metasploit]]></category>
      <category><![CDATA[Metasploit Weekly Wrapup]]></category><dc:creator><![CDATA[The Metasploit Team]]></dc:creator>
      <pubDate>Fri, 28 Aug 2026 14:57:18 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt0475760a2990dfd7/6849ab41a770d7563190a3ea/metasploit-fence.png" medium="image" />
    </item>
    <item>
      <title><![CDATA[PaperCut NG/MF Critical Zero-Day Exploited in the Wild]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview	</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On August 27, 2026, PaperCut Software published an </span><a href="https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/"><span style='font-size: undefined;'>urgent security advisory</span></a><span style='font-size: undefined;'> stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security emergency. At the initial time of disclosure, the vulnerability had not been assigned a CVE identifier, and PaperCut had not publicly disclosed a CVSS score, vulnerability class, authentication requirements, or the technical details of the exploit path. However on August 28, the vendor assigned CVE-2026-81578 and CVE-2026-82078 for the two vulnerabilities that make up the exploit chain.</span></p><table><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE ID</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Description</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CWE</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVSSv4</strong></span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-81578</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Authentication Bypass</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>CWE-306 Missing authentication for critical function.</span></p></td><td><p style="direction: ltr;"><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N"><span style='font-size: undefined;'>8.8 (High)</span></a></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-82078</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Unsafe Dynamic Class Loading in Database Connector</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>CWE-470 Use of Externally-Controlled input to select classes or code ('unsafe reflection').</span></p></td><td><p style="direction: ltr;"><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"><span style='font-size: undefined;'>9.4 (Critical)</span></a></p></td></tr></tbody></table><p style="direction: ltr;"><span style='font-size: undefined;'>PaperCut NG and PaperCut MF are print management platforms commonly deployed within enterprise, education, and other organizational environments. Because the PaperCut Application Server provides web-accessible administrative and application functionality, organizations with servers exposed to the public internet should prioritize remediation and access restriction.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>PaperCut stated in its </span><a href="https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/#current-status"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> that information supplied by a university customer’s security team and digital forensics and incident response team enabled its security response team to reproduce the vulnerability in PaperCut NG and PaperCut MF. On August 28, 2026 at 02:10 AEST, PaperCut released emergency patches for PaperCut NG and PaperCut MF versions 25 and 26, followed later the same day with patches for version 24.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>PaperCut has been targeted in the past; in 2023, </span><a href="https://www.rapid7.com/blog/post/2023/05/17/etr-cve-2023-27350-ongoing-exploitation-of-papercut-remote-code-execution-vulnerability/"><span style='font-size: undefined;'>CVE-2023-27350</span></a><span style='font-size: undefined;'> was broadly exploited in the wild by multiple threat-actor groups, including ransomware operators. This prior history increases the urgency organizations should address this new zero-day with.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>PaperCut currently considers all versions of PaperCut NG and PaperCut MF potentially impacted. Customers operating internet-accessible PaperCut Application Servers should take immediate action even if no suspicious activity has been observed.</span></p><p><span style='font-size: undefined;'>On August 31, 2026, both CVE-2026-81578 and CVE-2026-82078 were added to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) list of </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"><span style='font-size: undefined;'>known exploited vulnerabilities</span></a><span style='font-size: undefined;'> (KEV), based on evidence of active exploitation. A Metasploit module is now </span><a href="https://github.com/rapid7/metasploit-framework/pull/21842"><span style='font-size: undefined;'>available</span></a><span style='font-size: undefined;'> to validate exposure to the exploit chain.</span></p><h2 style="direction: ltr;">Technical overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>The vulnerability is an authentication bypass that lets attackers invoke privileged PaperCut components. This can be leveraged to reconfigure an external database lookup. When this lookup is triggered, malicious SQL can be executed, resulting in remote code execution.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>PaperCut uses the Apache </span><a href="https://tapestry.apache.org/"><span style='font-size: undefined;'>Tapestry</span></a><span style='font-size: undefined;'> framework, whose "complex direct" request format can identify one page to display and a different page containing the component to execute. PaperCut validates access only to the displayed page. By selecting either the public </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Error</span></span><span style='font-size: undefined;'> page or </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Exception</span></span><span style='font-size: undefined;'> page for display, an attacker can bypass authentication while invoking administrative components belonging to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>ConfigEditor</span></span><span style='font-size: undefined;'> or </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>UserList</span></span><span style='font-size: undefined;'>. Additionally, the first emergency patch could be bypassed by using the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Home</span></span><span style='font-size: undefined;'> page for display, however the newest version of the vendor patch correctly remediates this bypass.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The attack uses HTTP POST requests to the following URIs (Note that the path segment with the value 1 shown below can be any value for this path segment, and the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Error</span></span><span style='font-size: undefined;'> path segment may also be the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Exception</span></span><span style='font-size: undefined;'> or </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Home</span></span><span style='font-size: undefined;'> path segment):</span></p><pre language="html">/app?service=direct/1/Error/ConfigEditor/quickFindForm
/app?service=direct/1/Error/ConfigEditor/$Form
/app?service=direct/1/Error/UserList/$QuickFind.$Form</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The first two URIs provide unauthenticated access to PaperCut's configuration editor. The third can invoke a user or card search that triggers the configured external database lookup.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>An attacker first uses the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>ConfigEditor</span></span><span style='font-size: undefined;'> requests to modify four external user-lookup settings:</span></p><pre language="html">user-lookup.db-driver
user-lookup.db-url
user-lookup.id-to-username-sql
user-lookup.enabled</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>These settings normally allow administrators to connect PaperCut to an external card database. After bypassing authentication, however, the attacker can configure them with a malicious JDBC connection and a malicious SQL statement.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>By leveraging PaperCut's bundled Apache Derby database driver and supplying a Derby </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>CALL</span></span><span style='font-size: undefined;'> statement that activates its </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>foreignViews</span></span><span style='font-size: undefined;'> feature, Derby opens an attacker-controlled H2 JDBC URL. H2 processes an inline </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>INIT</span></span><span style='font-size: undefined;'> statement that creates a JavaScript-backed database trigger. PaperCut includes the Nashorn JavaScript engine, allowing that trigger to start an operating-system process. However it is expected that other mechanisms to execute an arbitrary command can also be used instead of Nashorn. Finally, the attacker submits a search through the forged </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>UserList</span></span><span style='font-size: undefined;'> request. This activates the external lookup and executes the malicious SQL.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations running PaperCut NG or PaperCut MF should prioritize patching on an emergency basis, particularly where the PaperCut Application Server is accessible from the public internet.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>PaperCut has released emergency </span><a href="https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/#emergency-patch-release"><span style='font-size: undefined;'>patches</span></a><span style='font-size: undefined;'> for PaperCut NG and PaperCut MF versions 24, 25 and 26. </span></p><p><span style='font-size: undefined;'><strong>Updated on September 1, 2026: Note that the vendor has released a </strong></span><a href="https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/#emergency-patch-release-3"><span style='font-size: undefined;'><strong>third version</strong></span></a><span style='font-size: undefined;'><strong> of the emergency patch. Any organization that has applied either the original first version or the second version of the emergency patch is not fully protected, and must apply the third emergency patch immediately.</strong></span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The vendor notes that these builds have not undergone their normal release process and are intended as emergency fixes for customers with public-facing servers that cannot otherwise sufficiently mitigate exposure.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>PaperCut recommends that administrators immediately restrict web access to trusted IP addresses only, such as internal corporate network ranges. Firewall rules, network access controls, reverse-proxy restrictions, or equivalent measures should be used to prevent untrusted internet hosts from reaching PaperCut web interfaces.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Please read the PaperCut security </span><a href="https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> for the latest remediation guidance, updated indicators of compromise, and additional release information.</span></p><h2 style="direction: ltr;">Artifacts/Evidence Sources and IOCs</h2><p style="direction: ltr;"><span style='font-size: undefined;'>For detection and forensic analysis, PaperCut has identified several preliminary artifacts and evidence sources that may indicate compromise.</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Application activity:</strong></span><span style='font-size: undefined;'> Alerts from intrusion-detection, endpoint-security, or network-monitoring products involving the PaperCut Application Server, particularly suspicious post-exploitation activity associated with </span><span style='font-size: undefined;'>pc-app.exe</span><span style='font-size: undefined;'>.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Log integrity:</strong></span><span style='font-size: undefined;'> Missing, unexpectedly truncated, or deleted PaperCut </span><span style='font-size: undefined;'>server.log</span><span style='font-size: undefined;'> files.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>PaperCut </strong></span><span style='font-size: undefined;'><strong>server.log</strong></span><span style='font-size: undefined;'><strong> entries:</strong></span></p></li><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>ERROR No suitable driver found for jdbc:no:x</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST</span></span></p></li></ul></ul><p style="direction: ltr;"><span style='font-size: undefined;'>PaperCut has not yet published validated network-based indicators such as malicious IP addresses, domains, or URLs.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The vendor specifically warns that the absence of these indicators should not be interpreted as evidence that a system has not been affected.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;">Exposure Command, InsightVM, and Nexpose</h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to this new PaperCut zero-day, with an authenticated vulnerability check expected to be available in the August 28 (today’s) content release.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>August 28, 2026:</strong></span><span style='font-size: undefined;'> Initial publication.</span></p></li><li><span style='font-size: undefined;'><strong>August 28, 2026:</strong></span><span style='font-size: undefined;'> Updated to reflect new emergency patches and CVE ID assignment. Updated remediation to include the new v24 patches. Updated Technical Overview to indicate first patch bypass.</span></li><li><span style='font-size: undefined;'><strong>August 31, 2026:</strong></span><span style='font-size: undefined;'> Updated the Overview to note that both CVEs were added to the CISA KEV list, and the availability of a Metasploit module.</span></li><li><span style='font-size: undefined;'><strong>September 1, 2026:</strong></span><span style='font-size: undefined;'> Updated the Remediation section to reflect the vendor's new emergency patch (release 3).</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild</link>
      <guid isPermaLink="false">blt64fadfaa2bae3901</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Vulnerability Management]]></category>
      <category><![CDATA[Zero-Day]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Fri, 28 Aug 2026 10:09:12 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs]]></title>
      <description><![CDATA[<h2>Introduction</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Despite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and imposter scams accounting for billions in financial losses each year. While stolen credit cards enable rapid, short-term monetization, Social Security numbers (SSNs) represent a far more permanent and dangerous tier within the cybercrime ecosystem, because unlike payment cards, they cannot simply be deactivated. Once exposed, an SSN can support enabling unauthorized lines of credit, synthetic identity fraud, and sophisticated tax scams.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>When exposed identity data belongs to corporate executives, board members, and other high-profile employees, the risk can extend beyond the individual. Threat actors target these high-profile individuals not just for their premium credit profiles, but to leverage their compromised identities for executive impersonation, corporate espionage, and downstream extortion. Rapid7’s recent alert telemetry underscores the severity of this targeted exposure: since early 2026 alone, we identified 476 instances of compromised SSN records across 395 unique corporate personnel. Over 73% of these exposures directly targeted top-level leadership, with C-suite executives comprising 44.6% of affected profiles and Presidents making up another 28.6%. Unsurprisingly, given the geographical nature of SSNs, 95.6% of these leaks stemmed from U.S.-headquartered organizations, concentrated heavily in high-value sectors like Financials (over 25%) and Industrials (17%).</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>In this blog, we explore the operational mechanics of the underground identity economy, focusing on three dominant SSN marketplaces tracked by Rapid7: Xilo, Bankom, and PeopleFinder, which together account for 81.5% of all executive SSN leaks in our dataset (led by Xilo at 40.8%, Bankom at 21.8%, and PeopleFinder at 18.9%). Using Rapid7 alert telemetry from the past year, we look at the profiles of affected corporate executives, how these marketplaces operate, and highlight how proactive dark web monitoring can mitigate upstream identity exposure before it is weaponized.</span></p><h2>Why stolen SSNs retain their value</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Not all stolen data retains its value for the same length of time. Leaked credentials can be reset, payment cards can be cancelled, and session tokens eventually expire. While these data types remain highly sought after by cybercriminals, their usefulness often depends on acting quickly before the victim or service provider invalidates them.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>SSNs differ as they are effectively permanent, serving as a core identity attribute. Once exposed, they can remain valuable for years, enabling a wide range of fraud schemes long after the original breach. When combined with other personally identifiable information (PII), such as a victim's name, date of birth, address, phone number, and employment history, an SSN becomes the foundation of a comprehensive identity profile that can be bought, sold, and repeatedly abused across the criminal ecosystem.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>These identity profiles enable far more than traditional identity theft. Threat actors use them to open fraudulent financial accounts, create synthetic identities, bypass identity verification processes, file fraudulent tax or government benefit claims, and support highly targeted social engineering campaigns. Rather than serving a single purpose, a complete identity record becomes a reusable asset that can be monetized multiple times by different threat actors.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>For corporate executives and other high-profile employees, exposed identity data can also create risk for the organization they represent. Publicly available information, from regulatory filings to corporate biographies and social media, can be combined with stolen identity data to build highly detailed profiles. These enriched records increase the credibility of phishing, business email compromise (BEC), and executive impersonation attacks, allowing threat actors to target not only the individual but also the organization they represent.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>This durability has fueled a thriving underground economy where identity records are treated as searchable, reusable inventory rather than one-time commodities. The marketplaces examined in this research demonstrate just how mature and accessible this ecosystem has become.</span></p><h2>Anatomy of an SSN marketplace</h2><p style="direction: ltr;"><span style='font-size: undefined;'>While platforms like Xilo, Bankomat, and PeopleFinder present a highly organized, user-friendly storefront, they operate strictly as downstream clearinghouses rather than original creators of their inventory. The vast supply of SSNs flooding these networks relies on a distinct, multi-tiered underground supply chain. The massive volume driving these platforms is primarily fueled by large-scale institutional network breaches, where wholesale hackers compromise data aggregators, healthcare systems, and financial providers. These massive SQL databases are sold in bulk on deep-web forums, where marketplace administrators purchase, parse, and upload them into their searchable storefronts. According to annual telemetry from the Identity Theft Resource Center, billions of individual data records are exposed annually through these mega-breaches, accounting for the vast majority of the inventory available online.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Another source of identity data comes from infostealer malware and targeted phishing campaigns. While mass breaches provide wholesale numbers, infostealers scrape highly contextual local data, such as saved browser forms and PDF documents like tax returns or corporate onboarding paperwork stored on unmanaged personal devices. When these localized logs are parsed by marketplace administrators, they yield the fresh, high-value identity profiles that allow buyers to target specific corporate leaders.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Although these platforms tap into a similar upstream supply chain, how they package and monetize this data varies significantly. To stand out in a maturing, highly competitive cybercrime market, each marketplace focuses on its own operational niche, ranging from ultra-low pricing and identity enrichment features to multi-asset carding integration and legacy data consistency. The following sections provide a deep dive into each marketplace, highlighting their specific functionalities, user interfaces, and distinct market advantages.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Xilo </span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Xilo has been active since at least March 2025. The marketplace is hosted as a Tor hidden service, while also maintaining mirror sites on the clear web to improve accessibility and resilience.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Users can search for specific individuals by name, state, country (US or Canada), or year of birth (Figure 1). They can also request records that include phone numbers and email addresses in addition to the victim's SSN. This can increase the value of the records by reducing the need for threat actors to source additional PII elsewhere. During our analysis, however, we did not identify any records that included email addresses, while records containing phone numbers were available at the same price as standard SSN records. Search results can also be sorted by price, although the cost appears to be fixed at $0.25 per SSN record.</span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blteda19dbdc405f202/6a90417460f7951d49d75eb7/Xilo-search-interface.png" alt="Xilo-search-interface.png" caption="Figure 1 – Xilo search interface" height="383" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Xilo-search-interface.png" width="1559" max-width="1559" max-height="383" style="max-width: 1559px; width: 1559px; max-height: 383px; height: 383px" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blteda19dbdc405f202/6a90417460f7951d49d75eb7/Xilo-search-interface.png" data-sys-asset-uid="blteda19dbdc405f202" data-sys-asset-filename="Xilo-search-interface.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 1 – Xilo search interface" data-sys-asset-alt="Xilo-search-interface.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 1 – Xilo search interface</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>Search results typically display the victim's full name, physical address, and date of birth before purchase. This information alone can help threat actors identify specific individuals for targeted campaigns, while the SSN is revealed only after the purchase is completed (Figure 2).</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5b7d664480dc4a31/6a9041c00a3bbeb38059e261/xilo-search-results.png" alt="xilo-search-results.png" caption="Figure 2 – Xilo search results" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="xilo-search-results.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5b7d664480dc4a31/6a9041c00a3bbeb38059e261/xilo-search-results.png" data-sys-asset-uid="blt5b7d664480dc4a31" data-sys-asset-filename="xilo-search-results.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 2 – Xilo search results" data-sys-asset-alt="xilo-search-results.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 2 – Xilo search results</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>In addition to standard searches, Xilo offers a reverse lookup service that accepts an SSN or phone number and returns additional PII, including the victim's full name and phone number (Figure 3). This service costs $0.50 per lookup, suggesting that enriching an existing identity profile is considered more valuable than purchasing an SSN alone. Threat actors can use this functionality to expand records obtained through the standard search, increasing the amount of PII associated with a single individual and, consequently, the potential for identity fraud.</span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltffe316bdd83f65d5/6a9041f5d05d4c308e580ae5/xilo-reverse-search.png" alt="xilo-reverse-search.png" caption="Figure 3 – Xilo reverse search" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="xilo-reverse-search.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltffe316bdd83f65d5/6a9041f5d05d4c308e580ae5/xilo-reverse-search.png" data-sys-asset-uid="bltffe316bdd83f65d5" data-sys-asset-filename="xilo-reverse-search.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 3 – Xilo reverse search" data-sys-asset-alt="xilo-reverse-search.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 3 – Xilo reverse search</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>The marketplace is supported by a Telegram channel used to announce technical updates and new domains. Although activity on the channel has been relatively limited, it has attracted more than 500 subscribers, providing an indication of interest in the service. Like many established cybercriminal services, Xilo appears prepared for domain disruptions by maintaining alternative access points and communicating them through Telegram, adopting the kind of resilience and service-continuity practices more commonly associated with legitimate online services.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Xilo accepts several cryptocurrencies, including Bitcoin, Litecoin, Monero, Ether, and Tether (USDT). Support for USDT is relatively uncommon among underground marketplaces and may reflect the marketplace's focus on US-based identity data. The minimum deposit is just $1, lowering the barrier to entry for new users, while bonuses are offered for deposits exceeding $100 to encourage larger account balances.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Beyond its own infrastructure, Xilo actively advertises on well-known cybercrime forums, including XSS, as well as carding communities such as WWH-Club and Altenens (Figure 4). This marketing strategy is common among underground marketplaces seeking to expand their customer base. More notably, Xilo's presence on carding-focused forums highlights the close relationship between stolen payment data and identity information, illustrating how different segments of the cybercrime ecosystem increasingly overlap and complement one another.</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7b8f2bd1df6fa1de/6a9042b20a3bbe812a59e279/Xilo-advertisement_-Altenens.png" alt="Xilo-advertisement_-Altenens.png" caption="Figure 4 – Xilo advertisement on Altenens" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Xilo-advertisement_-Altenens.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7b8f2bd1df6fa1de/6a9042b20a3bbe812a59e279/Xilo-advertisement_-Altenens.png" data-sys-asset-uid="blt7b8f2bd1df6fa1de" data-sys-asset-filename="Xilo-advertisement_-Altenens.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 4 – Xilo advertisement on Altenens" data-sys-asset-alt="Xilo-advertisement_-Altenens.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 4 – Xilo advertisement on Altenens</figcaption></div></figure><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Bankomat</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Active since at least March 2022, Bankomat is one of the more established marketplaces operating in the underground identity theft ecosystem. The platform is accessible as a Tor hidden service while maintaining multiple clear web domains to improve availability. Its emergence coincided with the shutdown of several prominent carding and PII marketplaces, including Joker's Stash and SSNDOB Marketplace, suggesting that Bankomat sought to capitalize on the resulting gap by combining identity data sales with traditional carding services.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The marketplace prominently lists its active domains and encourages users to save its onion address, describing it as the most reliable way to access the service. This reflects an awareness of the operational challenges faced by long-running underground marketplaces, particularly the risk of domain seizures and takedowns. By maintaining multiple access points and actively directing users toward its Tor service, Bankomat demonstrates the operational maturity needed to retain its customer base despite infrastructure disruptions.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Users can search for individuals by first and last name, combined with an additional identifier such as state, city, ZIP code, or date of birth (Figure 5). The search functionality is free, allowing users to identify potential victims before deciding whether to purchase a record. Search results display the victim's full name, date of birth, and physical addresses, while the SSN is revealed only after purchase at a fixed cost of $4 per record. Unlike Xilo, however, Bankomat does not offer additional identity enrichment services or the ability to purchase supplementary PII directly through the platform.</span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt906858a51dc885cc/6a9043058433ee1e2e840353/Bankomat-search-bar.png" alt="Bankomat-search-bar.png" caption="Figure 5 – Bankomat search bar" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Bankomat-search-bar.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt906858a51dc885cc/6a9043058433ee1e2e840353/Bankomat-search-bar.png" data-sys-asset-uid="blt906858a51dc885cc" data-sys-asset-filename="Bankomat-search-bar.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 5 – Bankomat search bar" data-sys-asset-alt="Bankomat-search-bar.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 5 – Bankomat search bar</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>Beyond SSN records, Bankomat also functions as a traditional carding marketplace by offering stolen payment card details for sale, obtained through third-party sellers. The platform supports card validation services, including Viper and 4chk, allowing buyers to verify whether stolen payment cards remain active before using or reselling them. Similar functionality is offered by established carding marketplaces, such as Findsome and UltimateShop.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>This combination of identity records, payment card data, and validation tools positions Bankomat as a one-stop marketplace for financially motivated threat actors. Rather than sourcing stolen identities and payment data from separate platforms, buyers can acquire multiple data types associated with the same victim through a single service. While SSN records cost $4, stolen payment card details are typically advertised for approximately $10, suggesting that Bankomat places greater commercial emphasis on its carding business, likely reflecting both higher profit margins and sustained demand within the underground economy (Figure 6).</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltb5ce8efb1b13a40a/6a904338d62e1184b0e364ce/bankomat-credit-card-listings.png" alt="bankomat-credit-card-listings.png" caption="Figure 7 – PeopleFinder SSN listings" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="bankomat-credit-card-listings.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltb5ce8efb1b13a40a/6a904338d62e1184b0e364ce/bankomat-credit-card-listings.png" data-sys-asset-uid="bltb5ce8efb1b13a40a" data-sys-asset-filename="bankomat-credit-card-listings.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 7 – PeopleFinder SSN listings" data-sys-asset-alt="bankomat-credit-card-listings.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 7 – PeopleFinder SSN listings</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>Bankomat currently accepts payments exclusively in Bitcoin, in contrast to newer marketplaces that increasingly support a wider range of cryptocurrencies to appeal to a broader customer base.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>PeopleFinder</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Active since at least February 2023, PeopleFinder is a successor to the SSNDOB Marketplace, whose primary domains were seized by law enforcement in June 2022. Following that takedown, the service re-emerged through a network of lookup mirrors using clear-web-sounding domain names such as “PeopleFinder.” The connection is also visible in the source code, where the front-end login page retains the original “ssndob” title text and logo. Through this infrastructure, the platform provides access to the same legacy database of more than 24 million compromised U.S. PII records.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>To maintain a steady customer stream, PeopleFinder actively advertises its database on high-profile cybercrime and carding forums like WWH-Club and Exploit. This deliberate marketing keeps the service highly visible to financially motivated threat actors seeking verification tools for downstream fraud.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The layout itself is highly streamlined, featuring a basic search bar that closely mirrors Bankomat's interface. Users can search the platform's database by name, date of birth, or physical address completely free of charge. The initial search output displays the victim's full name, date of birth, and associated physical addresses, allowing a threat actor to confirm they have targeted the correct corporate executive before paying for the record (Figure 7).</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc6ad5198e8f326a6/6a9043f060f7958996d75ece/peoplefinder-ssn-listings.png" alt="peoplefinder-ssn-listings.png" caption="Figure 7 – PeopleFinder SSN listings" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="peoplefinder-ssn-listings.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc6ad5198e8f326a6/6a9043f060f7958996d75ece/peoplefinder-ssn-listings.png" data-sys-asset-uid="bltc6ad5198e8f326a6" data-sys-asset-filename="peoplefinder-ssn-listings.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 7 – PeopleFinder SSN listings" data-sys-asset-alt="peoplefinder-ssn-listings.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 7 – PeopleFinder SSN listings</figcaption></div></figure><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>To reveal the hidden SSN, users must pay a fixed cost of $1.50 per lookup, putting its pricing structure right between Xilo and Bankomat. This strict, hyper-commoditized focus solely on core SSN details directly mirrors the operational blueprint of the original SSNDOB model. Rather than expanding into supplementary data types like phone numbers or credit cards, the operators chose to preserve their highly efficient, legacy pay-per-lookup infrastructure. The platform relies exclusively on Bitcoin transactions.</span></p><h2>What Rapid7 telemetry reveals about the executive threat landscape</h2><p style="direction: ltr;"><span style='font-size: undefined;'>By monitoring dark web SSN marketplaces, Rapid7 actively alerts clients when leaked records of their executives or designated employees are discovered.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Since the beginning of 2026, our telemetry has identified 476 instances of compromised SSN records, representing 395 unique individuals, as several monitored personnel were affected by multiple exposures. Within this sample, most of the leaked SSNs were recorded in Xilo (40.8%), followed by Bankom (21.8%) and PeopleFinder (18.9%) (Figure 8).</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt9c8deb9f4e41851d/6a904441d4aaa70e0b7f0e80/leaked-ssns-by-marketplace.png" alt="leaked-ssns-by-marketplace.png" caption="Figure 8 – The sample distribution of leaked SSNs by marketplace" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="leaked-ssns-by-marketplace.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt9c8deb9f4e41851d/6a904441d4aaa70e0b7f0e80/leaked-ssns-by-marketplace.png" data-sys-asset-uid="blt9c8deb9f4e41851d" data-sys-asset-filename="leaked-ssns-by-marketplace.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 8 – The sample distribution of leaked SSNs by marketplace" data-sys-asset-alt="leaked-ssns-by-marketplace.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 8 – The sample distribution of leaked SSNs by marketplace</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>Given that SSNs are issued within the United States, the overwhelming majority of compromised records in our dataset, 95.6%, were linked to organizations headquartered in the U.S., with others located in Spain, Canada, and Japan, trailing significantly behind (Figure 9).</span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7c4c10ea9f65329d/6a9044770a3bbeb4e859e287/leaked-ssns-by-country.png" alt="leaked-ssns-by-country.png" caption="Figure 9 – The sample distribution of leaked SSNs by country" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="leaked-ssns-by-country.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7c4c10ea9f65329d/6a9044770a3bbeb4e859e287/leaked-ssns-by-country.png" data-sys-asset-uid="blt7c4c10ea9f65329d" data-sys-asset-filename="leaked-ssns-by-country.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 9 – The sample distribution of leaked SSNs by country" data-sys-asset-alt="leaked-ssns-by-country.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 9 – The sample distribution of leaked SSNs by country</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>Financials represented the largest sector in our sample, accounting for more than a quarter of organizations whose monitored executives appeared in leaked SSN records, followed by Industrials at 17% (Figure 10). One possible reason for the concentration in Financials is the volume and sensitivity of customer and employee data these organizations hold, including PII and tax-related information, which can make exposed identities particularly valuable to threat actors. Industrials may also present attractive targets because of their interconnected supply chains, where compromised identities can potentially support broader fraud, impersonation, or access attempts across partner ecosystems.</span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt3858d7be6ddf8240/6a9044cac8ced9499c056239/leaked-ssns-by-sector.png" alt="leaked-ssns-by-sector.png" caption="Figure 10 – The sample distribution of leaked SSNs by sector " class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="leaked-ssns-by-sector.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt3858d7be6ddf8240/6a9044cac8ced9499c056239/leaked-ssns-by-sector.png" data-sys-asset-uid="blt3858d7be6ddf8240" data-sys-asset-filename="leaked-ssns-by-sector.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 10 – The sample distribution of leaked SSNs by sector" data-sys-asset-alt="leaked-ssns-by-sector.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 10 – The sample distribution of leaked SSNs by sector</figcaption></div></figure><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>A closer analysis of the roles of targeted personnel reveals that C-suite executives (such as Chief Executive Officers and Chief Financial Officers) make up the largest portion at 44.6%. Presidential positions represent the second-largest segment at 28.6%, while functional management and administrative roles account for 13.9% of the compromised profiles.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>These findings may reflect a natural monitoring bias, since organizations are more likely to prioritize senior personnel whose compromise poses a greater security risk. Even with that caveat, the concentration among senior leadership reinforces why executive identity exposure deserves specific attention.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Compromised executive PII can support targeted phishing, impersonation, and other social engineering campaigns against both the individual and the organization they represent.</span></p><p><span style='font-size: undefined;'></span></p><table><colgroup data-width='1425'><col style="width:25.6140350877193%"/><col style="width:45.05263157894737%"/><col style="width:15.859649122807017%"/><col style="width:13.473684210526315%"/></colgroup><tbody><tr><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'><strong>Role Category</strong></span></p></td><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'><strong>Key Roles Included</strong></span></p></td><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'><strong>Unique Target Count</strong></span></p></td><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'><strong>% of Unique Targets</strong></span></p></td></tr><tr><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Executive Leadership (C-Suite)</span></p></td><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>CEO, CFO, COO, CTO, CIO, Chief Revenue/Human Resources Officers</span></p></td><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>176</span></p></td><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>44.6%</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Presidents & Vice Presidents</span></p></td><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>President, SVP, EVP, Regional Vice Presidents</span></p></td><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>113</span></p></td><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>28.6%</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Functional Management & Admin</span></p></td><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Directors, Heads of Departments, Managers, Executive Assistants</span></p></td><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>55</span></p></td><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>13.9%</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Legal, Partner & Advisory</span></p></td><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Managing Members, Partners, Corporate/Securities Attorneys</span></p></td><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>33</span></p></td><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>8.4%</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Board, Governance & Officials</span></p></td><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Board Trustees, Directors of the Board, State Senators, Vice Chairs</span></p></td><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>18</span></p></td><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>4.6%</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>Total Unique Individuals</span></p></td><td><p><br/></p></td><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>395</span></p></td><td><p style="direction: ltr;"><span style='color:rgb(31, 31, 31);font-size: undefined;'>100.0%</span></p></td></tr></tbody></table><h2>From detection to action: Responding to exposed executive PII</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Because SSNs cannot simply be reset after exposure, organizations need a way to identify compromised executive PII early and determine what action can reduce the resulting risk.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>These alerts are triggered using customer-defined assets, specifically the names of designated VIPs. When a potential match is flagged, Rapid7 analysts conduct preliminary OSINT verification, checking biographical details such as the VIP's date of birth and primary locations, to confirm the listing's accuracy before issuing an alert to the customer.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Once alerted, customers can choose to purchase the exposed SSN record directly through the "Ask-an-Analyst" service using their allocated dark web purchase credits (Figure 11). This capability allows security teams to inspect the full record, verify whether the exposed SSN is genuine, and determine whether additional protective measures are necessary for the affected executive. Furthermore, on platforms like Xilo, purchasing the listing removes the record from the marketplace entirely, actively taking it off the shelf before other threat actors can acquire it.</span></p><p></p><figure style="margin: 0"><div style="display: inline-block"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1fa48534d153c2ed/6a90458f0897905f31efa75d/Rapid7-Platform-alert-leaked-executive-details.png" alt="Rapid7-Platform-alert-leaked-executive-details.png" caption="Figure 11 – Rapid7 Platform alert about the leaked details of a company executive" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Rapid7-Platform-alert-leaked-executive-details.png" style="width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1fa48534d153c2ed/6a90458f0897905f31efa75d/Rapid7-Platform-alert-leaked-executive-details.png" data-sys-asset-uid="blt1fa48534d153c2ed" data-sys-asset-filename="Rapid7-Platform-alert-leaked-executive-details.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 11 – Rapid7 Platform alert about the leaked details of a company executive" data-sys-asset-alt="Rapid7-Platform-alert-leaked-executive-details.png" data-sys-asset-position="none" sys-style-type="display"/><figcaption style="text-align:center">Figure 11 – Rapid7 Platform alert about the leaked details of a company executive</figcaption></div></figure><h2>Conclusion and strategic defense actions</h2><p style="direction: ltr;"><span style='font-size: undefined;'>The illicit marketplaces examined by Rapid7 show how cheaply and efficiently stolen identity data can now be searched, purchased, and enriched. For executives and other high-profile employees, an exposed SSN can remain useful to threat actors long after the original compromise and may support identity fraud, social engineering, executive impersonation, or business email compromise. Because that information cannot simply be reset, organizations should treat executive identity exposure as an ongoing security risk.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>To reduce that risk, executive protection and security teams should consider the following actions:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Monitor executive exposure on the dark web: Use digital risk protection capabilities configured with executive names, known locations, titles, and other relevant identifiers to detect compromised PII across illicit marketplaces and underground channels.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Use removal or takedown options where available: Where supported, work with security providers to acquire or remove exposed identity records before they are purchased and reused by other threat actors.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Reduce executives’ public digital footprint: Review public records, data-broker listings, corporate biographies, and social media profiles to limit unnecessary exposure of information such as dates of birth, home addresses, and phone numbers that can be used to enrich stolen records.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Require out-of-band verification for sensitive requests: Introduce mandatory secondary confirmation for financial transactions, access requests, or administrative changes involving executive accounts to reduce the risk of successful impersonation.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Provide targeted phishing and impersonation training: Give C-suite members, board members, and executive assistants focused guidance on how attackers can combine leaked PII with social engineering to make phishing and impersonation attempts more convincing.</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>The persistence of SSNs means the risk does not end when the original breach is discovered. Ongoing monitoring, rapid validation, and stronger verification controls can help organizations identify exposure earlier, reduce the value of stolen identity data, and make it harder for threat actors to turn compromised executive information into a wider attack against the business.</span></p>]]></description>
      <link>https://www.rapid7.com/blog/post/tr-identity-as-a-service-dark-web-marketplaces-executive-ssn</link>
      <guid isPermaLink="false">bltf2ecc50b5b8de859</guid>
      <category><![CDATA[Dark Web]]></category>
      <category><![CDATA[Phishing]]></category><dc:creator><![CDATA[Alexandra Blia]]></dc:creator>
      <pubDate>Thu, 27 Aug 2026 13:51:55 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt62de3c632e7d1ef7/6984a555a6b5ef052cb93196/Chrysalis-backdoor-blog.jpg" medium="image" />
    </item>
    <item>
      <title><![CDATA[Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)]]></title>
      <description><![CDATA[]]></description>
      <link>https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520</link>
      <guid isPermaLink="false">blt5f90657fff716e5d</guid>
      <category><![CDATA[Rapid7 Analysis]]></category>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Labs]]></category><dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
      <pubDate>Mon, 24 Aug 2026 16:18:05 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltcbf09ec3af35e28e/6a15c63f08221ed5144dbf77/webinar-rapid7-logo.jpg" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On August 19, 2026, a </span><a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939"><span style='font-size: undefined;'>security advisory</span></a><span style='font-size: undefined;'> was published for </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-19490"><span style='font-size: undefined;'>CVE-2026-19490</span></a><span style='font-size: undefined;'>, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>NetScaler ADC and NetScaler Gateway are widely deployed enterprise networking products commonly positioned at or near the network perimeter. NetScaler ADC provides application delivery, traffic management, load balancing, SSL/TLS offloading, and application security capabilities, while NetScaler Gateway provides secure remote access and VPN functionality. Because these systems are frequently deployed in enterprise DMZs and exposed to the public internet, authentication bypass vulnerabilities affecting Citrix products are nearly always exploited by threat actors.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-19490 </span><a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939"><span style='font-size: undefined;'>affects</span></a><span style='font-size: undefined;'> the following systems:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>NetScaler ADC and NetScaler Gateway 14.1:</strong></span><span style='font-size: undefined;'> Versions prior to </span><span style='font-size: undefined;'><span data-type='inlineCode'>14.1-73.32</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>NetScaler ADC and NetScaler Gateway 13.1:</strong></span><span style='font-size: undefined;'> Versions prior to </span><span style='font-size: undefined;'><span data-type='inlineCode'>13.1-63.21</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>NetScaler ADC FIPS:</strong></span><span style='font-size: undefined;'> Versions prior to </span><span style='font-size: undefined;'><span data-type='inlineCode'>14.1-73.32 FIPS</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>NetScaler ADC FIPS and NDcPP:</strong></span><span style='font-size: undefined;'> Versions prior to </span><span style='font-size: undefined;'><span data-type='inlineCode'>13.1-37.277</span></span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>As of August 19, 2026, Rapid7 has not observed evidence that CVE-2026-19490 is being exploited in the wild. However, organizations should prioritize patching affected systems on an emergency basis, since Citrix products are high-value targets that tend to quickly see exploitation in the wild.</span></p><p><span style='font-size: undefined;'>On September 9, 2026, CVE-2026-19490 was </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search=CVE-2026-19490&amp;field_date_added_wrapper=all&amp;field_cve=&amp;sort_by=field_date_added&amp;items_per_page=20&amp;url="><span style='font-size: undefined;'>added</span></a><span style='font-size: undefined;'> to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) list of known exploited vulnerabilities (</span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"><span style='font-size: undefined;'>KEV</span></a><span style='font-size: undefined;'>), based on evidence of active exploitation. With active exploitation now occurring, organizations running affected versions of Citrix NetScaler ADC and NetScaler Gateway should remediate these issues on an urgent basis, outside of normal patching cycles.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations running affected NetScaler ADC or NetScaler Gateway appliances should review the official NetScaler </span><a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> and apply the required updates to affected systems on an emergency basis.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Fixed versions for affected products are listed below:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>NetScaler ADC and NetScaler Gateway</strong></span><span style='font-size: undefined;'> </span><span style='font-size: undefined;'><span data-type='inlineCode'>14.1-73.32</span></span><span style='font-size: undefined;'> and later releases</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>NetScaler ADC and NetScaler Gateway</strong></span><span style='font-size: undefined;'> </span><span style='font-size: undefined;'><span data-type='inlineCode'>13.1-63.21</span></span><span style='font-size: undefined;'> and later releases of </span><span style='font-size: undefined;'><span data-type='inlineCode'>13.1</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>NetScaler ADC 14.1-FIPS</strong></span><span style='font-size: undefined;'> </span><span style='font-size: undefined;'><span data-type='inlineCode'>14.1-73.32 FIPS</span></span><span style='font-size: undefined;'> and later releases of </span><span style='font-size: undefined;'><span data-type='inlineCode'>14.1-FIPS</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>NetScaler ADC 13.1-FIPS and 13.1-NDcPP</strong></span><span style='font-size: undefined;'> </span><span style='font-size: undefined;'><span data-type='inlineCode'>13.1-37.277</span></span><span style='font-size: undefined;'> and later releases of </span><span style='font-size: undefined;'><span data-type='inlineCode'>13.1-FIPS</span></span><span style='font-size: undefined;'> and </span><span style='font-size: undefined;'><span data-type='inlineCode'>13.1-NDcPP</span></span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>According to Citrix, customers can determine whether affected systems are vulnerable to CVE-2026-19490 by inspecting their NetScaler configuration for the following configuration entries. If one or more of the following items are present, and if the systems are running affected versions, the system is likely to be exploitable:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>SAML action configuration is in place:</strong></span></p></li><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>"add authentication samlAction.*"</span></p></li></ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Auth or VPN vserver is configured:</strong></span></p></li><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'> "add authentication vserver .*"</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'> "add vpn vserver .*"</span></p></li></ul></ul><p style="direction: ltr;"><span style='font-size: undefined;'>For the latest guidance, please refer to the official </span><a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939"><span style='font-size: undefined;'>Citrix advisory</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;"><span style='color:rgb(24, 26, 27);'>Rapid7 customers</span></h2><h3 style="direction: ltr;">Exposure Command, InsightVM, and Nexpose</h3><p style="direction: ltr;"><span style='font-size: undefined;'>Customers can assess exposure to CVE-2026-19490 on Citrix NetScaler ADC and Gateway using a vulnerability check available in the August 20 content release.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>August 19, 2026:</strong></span><span style='font-size: undefined;'> Initial publication.</span></p></li><li><span style='font-size: undefined;'><strong>August 20, 2026:</strong></span><span style='font-size: undefined;'> Updated Rapid7 customers section to reflect availability of vulnerability check.</span></li><li><span style='font-size: undefined;'><strong>September 11, 2026:</strong></span><span style='font-size: undefined;'> Updated Overview to add new CISA KEV reference.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-19490-critical-vulnerability-affecting-citrix-netscaler-adc-and-netscaler-gateway</link>
      <guid isPermaLink="false">blt0010f65da682ee36</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Labs]]></category>
      <category><![CDATA[Vulnerability Management]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Wed, 19 Aug 2026 16:46:06 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Rapid7 and Licencias OnLine Partner to Accelerate Cybersecurity Maturity across Latin America]]></title>
      <description><![CDATA[<p style="direction: ltr;"><span style='font-size: undefined;'><em>Cássio De Alcântara is Director, LATAM Sales at Rapid7.</em></span></p><p><span style='font-size: undefined;'>Across Latin America, organizations are embracing cloud, AI, and digital transformation to drive innovation and business growth. These technologies create new opportunities, but also introduce greater complexity and expanding attack surfaces.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>In this environment, security leaders are being asked to understand where risk exists across increasingly distributed environments and quickly eliminate blind spots like Shadow IT and Shadow AI – all without adding operational complexity.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>To help security leaders and practitioners address this complexity, Rapid7 is excited to announce a new strategic distribution partnership with Licencias OnLine (LOL) across Latin America.</span></p><h2 style="direction: ltr;">Helping organizations stay ahead of evolving threats</h2><p style="direction: ltr;"><span style='font-size: undefined;'>In order to keep day-to-day business operations moving, organizations need security solutions that not only protect critical assets but also support innovation, regulatory compliance, and long-term digital transformation.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Rapid7's AI-powered cybersecurity operations platform helps organizations strengthen cyber resilience by unifying continuous exposure management, AI-driven threat detection and response, and security automation. By connecting security data across endpoint, cloud, identity, and infrastructure environments, organizations leverage one platform to gain the visibility to reduce risk and act with confidence.</span></p><h2 style="direction: ltr;">A shared commitment to partner success</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Success in today’s fragmented cybersecurity environments depends on a strong ecosystem of </span><a href="/partners/" target="_self"><span style='font-size: undefined;'>partners</span></a><span style='font-size: undefined;'> who can help organizations implement, optimize, and maximize the value of unified security operations.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>This is where Licencias OnLine comes in. With a strong, well-established presence across Latin America, deep cybersecurity expertise, and a highly specialized channel ecosystem, Licencias OnLine brings the local knowledge, technical enablement, and operational agility needed to help partners grow their cybersecurity practices and deliver greater value to customers.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Together, Rapid7 and Licencias OnLine will invest in technical training, partner enablement, joint marketing initiatives, and go-to-market programs that help partners expand </span><a href="/services/managed-detection-and-response-mdr/" target="_self"><span style='font-size: undefined;'>managed security services</span></a><span style='font-size: undefined;'>, strengthen customer relationships, and accelerate business growth across the region.</span></p><h2 style="direction: ltr;">Building cyber resilience together</h2><p style="direction: ltr;"><span style='font-size: undefined;'>As organizations across Latin America continue to modernize their IT environments, they should have access to security operations that are integrated, intelligent, and designed for today's AI-powered threat landscape.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Rapid7's open platform supports this approach through hundreds of technology integrations that help organizations eliminate security silos, improve visibility across their attack surfaces, and automate response workflows. This enables security teams to reduce operational complexity while improving cybersecurity program maturity.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>By combining Rapid7's global cybersecurity innovation with Licencias OnLine's regional expertise and trusted partner network, this new alliance will make it easier for organizations across Latin America to strengthen cyber resilience while enabling partners to see greater success through measurable business outcomes.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>We're excited to begin this next chapter together and look forward to supporting our partners as they help customers build stronger, more resilient security operations across the region.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Ready to grow with Rapid7? Discover how Rapid7 and Licencias OnLine are </span><a href="/partners/sales-partners/" target="_self"><span style='font-size: undefined;'>helping partners accelerate cybersecurity maturity</span></a><span style='font-size: undefined;'> across Latin America.</span></p>]]></description>
      <link>https://www.rapid7.com/blog/post/c-licencias-online-partnership-accelerates-latam-cybersecurity-maturity-latin-america</link>
      <guid isPermaLink="false">blt2d73acce368c3eab</guid>
      <category><![CDATA[Cybersecurity]]></category><dc:creator><![CDATA[Cássio De Alcântara]]></dc:creator>
      <pubDate>Wed, 19 Aug 2026 12:00:00 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt09a532eac4a02570/6852c5968e72c44b89691ca4/PSN-gov-showcase-hero-image-2.png" medium="image" />
    </item>
  </channel>
</rss>