8. 9. 2026
60
Microsoft heeft 4 kwetsbaarheden verholpen in diverse Azure componenten. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de categorieën schade, zoals genoemd in onderstaande tabel. De kwetsbaarheid met kenmerk CVE-2026-69854 heeft een CVSS-score van 9,0. Een kwaadwillende die al over een geldige sessie beschikt, kan de kwetsbaarheid onder specifieke voorwaarden, zoals bepaalde protocolinstellingen of configuraties, misbruiken om zijn rechten…
EPSS 0.01
CVE-2026-62895
CVE-2026-69854
CVE-2026-77909
CVE-2026-81961
Microsoft
NL
tg: zranitelnost
tp: identita
8. 9. 20:39 · NCSC-NL · NCSC-2026-0347 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Azure
Whelp, here we are. Deep into the new normal. With nearly 1,000 CVEs coming out from Microsoft and a healthy release from Adobe as well, there’s a phrase from my military days that comes to mind: embrace the suck. Take an extend break from your regularly scheduled activities as we take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check out the Patch Report webcast on our YouTube channel. It should…
KEV ✓
EPSS 0.02
CVSS 10.0
CVE-2026-55007
CVE-2026-65669
CVE-2026-69465
CVE-2026-69525
CVE-2026-75650
CVE-2026-80097
CVE-2026-81963
CVE-2026-85880
Adobe
Microsoft
US
tg: zneužíváno
tg: zranitelnost
tg: přehled
8. 9. 20:32 · ZDI Blog · The September 2026 Security Update Review
Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. [...]
Microsoft
US
tg: zneužíváno
tg: zranitelnost
8. 9. 20:18 · BleepingComputer · Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
104Critical860Important0Moderate0LowMicrosoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important.This month’s update includes patches for:.NET.NET and Visual StudioASP.NET CoreActive Directory Certificate Services (AD CS)Active Directory Domain…
KEV ✓
EPSS 0.42
CVSS 7.8
CVE-2023-21674
CVE-2026-81963
CVE-2026-85880
Microsoft
US
tg: zneužíváno
tg: zranitelnost
8. 9. 20:07 · Tenable Research · Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.
EPSS 0.00
CVE-2026-62804
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-62804 Microsoft Word Remote Code Execution Vulnerability
Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.00
CVE-2026-84003
Microsoft
US
tg: zranitelnost
tp: identita
8. 9. 16:00 · Microsoft Security · CVE-2026-84003 Microsoft Authentication Library (MSAL) for Node.js Spoofing Vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00
CVE-2026-85875
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-85875 Microsoft Office Excel Information Disclosure Vulnerability
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.
EPSS 0.00
CVE-2026-84000
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-84000 Microsoft Graphics Component Remote Code Execution Vulnerability
Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
EPSS 0.00
CVE-2026-83990
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-83990 Microsoft Graphics Component Elevation of Privilege Vulnerability
Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
EPSS 0.00
CVE-2026-70145
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-70145 Microsoft Windows Search Component Information Disclosure Vulnerability
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
EPSS 0.00
CVE-2026-83949
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-83949 Microsoft Office Word Information Disclosure Vulnerability
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
EPSS 0.00
CVE-2026-83951
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-83951 Microsoft Office Word Information Disclosure Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Microsoft Azure CLI allows an authorized attacker to execute code over a network.
EPSS 0.00
CVE-2026-83948
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-83948 Microsoft Azure CLI Remote Code Execution Vulnerability
Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.
EPSS 0.00
CVE-2026-77897
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-77897 Microsoft Power Automate Desktop Elevation of Privilege Vulnerability
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00
CVE-2026-81948
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81948 Microsoft Excel Remote Code Execution Vulnerability
Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00
CVE-2026-81950
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81950 Microsoft Excel Remote Code Execution Vulnerability
Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00
CVE-2026-81949
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81949 Microsoft Excel Remote Code Execution Vulnerability
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00
CVE-2026-81953
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81953 Microsoft Excel Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00
CVE-2026-81959
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81959 Microsoft Excel Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01
CVE-2026-81952
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81952 Microsoft Word Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00
CVE-2026-81951
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81951 Microsoft Excel Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
EPSS 0.01
CVE-2026-81955
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81955 Windows Graphics Component Remote Code Execution Vulnerability
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00
CVE-2026-81388
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81388 Microsoft Excel Remote Code Execution Vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00
CVE-2026-81957
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81957 Microsoft Excel Remote Code Execution Vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00
CVE-2026-81395
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81395 Microsoft Excel Information Disclosure Vulnerability
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00
CVE-2026-81960
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81960 Microsoft Excel Remote Code Execution Vulnerability
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00
CVE-2026-81394
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81394 Microsoft Excel Information Disclosure Vulnerability
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00
CVE-2026-81389
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81389 Microsoft Excel Remote Code Execution Vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00
CVE-2026-81400
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81400 Microsoft Excel Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00
CVE-2026-81393
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81393 Microsoft Excel Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00
CVE-2026-81956
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81956 Microsoft Excel Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00
CVE-2026-81397
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81397 Microsoft Excel Remote Code Execution Vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00
CVE-2026-81392
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81392 Microsoft Excel Information Disclosure Vulnerability
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00
CVE-2026-81396
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81396 Microsoft Excel Remote Code Execution Vulnerability
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00
CVE-2026-81958
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81958 Microsoft Excel Information Disclosure Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00
CVE-2026-81401
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81401 Microsoft Excel Information Disclosure Vulnerability
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00
CVE-2026-81391
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81391 Microsoft Excel Information Disclosure Vulnerability
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00
CVE-2026-81399
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81399 Microsoft Excel Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00
CVE-2026-81390
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81390 Microsoft Excel Information Disclosure Vulnerability
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00
CVE-2026-81954
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81954 Microsoft Excel Remote Code Execution Vulnerability
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
EPSS 0.00
CVE-2026-81387
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81387 Microsoft Excel Information Disclosure Vulnerability
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00
CVE-2026-81947
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81947 Microsoft Excel Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00
CVE-2026-81386
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81386 Microsoft Excel Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00
CVE-2026-81398
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81398 Microsoft Excel Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
EPSS 0.01
CVE-2026-81385
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81385 Microsoft Office Publisher Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
EPSS 0.00
CVE-2026-81353
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81353 HEIF Image Extensions Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network.
EPSS 0.00
CVE-2026-81352
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-81352 Web Media Extensions Remote Code Execution Vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
EPSS 0.01
CVE-2026-80082
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-80082 Microsoft Office Information Disclosure Vulnerability
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
EPSS 0.00
CVE-2026-80081
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-80081 Microsoft Office PowerPoint Remote Code Execution Vulnerability
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
EPSS 0.01
CVE-2026-80090
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-80090 Microsoft Office Word Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
EPSS 0.01
CVE-2026-80089
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-80089 Microsoft Office Information Disclosure Vulnerability
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network.
EPSS 0.01
CVE-2026-80091
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-80091 Microsoft Office Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
EPSS 0.01
CVE-2026-80088
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-80088 Microsoft Office Word Information Disclosure Vulnerability
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.00
CVE-2026-80085
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-80085 Microsoft Office Word Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to disclose information over a network.
EPSS 0.01
CVE-2026-80087
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-80087 Microsoft Office Information Disclosure Vulnerability
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01
CVE-2026-80080
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-80080 Microsoft Office Word Remote Code Execution Vulnerability
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
EPSS 0.01
CVE-2026-80086
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-80086 Microsoft Office PowerPoint Information Disclosure Vulnerability
Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
EPSS 0.01
CVE-2026-78525
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-78525 Microsoft Office Outlook Remote Code Execution Vulnerability
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.
EPSS 0.01
CVE-2026-80084
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-80084 Microsoft Office Outlook Information Disclosure Vulnerability
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01
CVE-2026-78526
Microsoft
US
tg: zranitelnost
8. 9. 16:00 · Microsoft Security · CVE-2026-78526 Microsoft Office Word Remote Code Execution Vulnerability