These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-72975 is an out-of-bounds read vulnerability in Microsoft Office PowerPoint that allows an unauthorized attacker to disclose information over a network. The CVE record was published on 2026-09-08T18:20:23.750Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Microsoft Office PowerPoint deployments, which defenders should assess for exposure and [truncated]
Microsoft Office Excel is vulnerable to a buffer over-read, allowing unauthorized attackers to disclose information over a network. This CVE has a CVSS score of 6.5 and a severity of MEDIUM. The CVE was published on 2026-09-08T18:20:23.620Z and last modified on 2026-09-17T20:18:08.903Z. The vulnerability affects Microsoft 365 Apps, Office 2016, Office 2019, Office 2021, and Office 2024. Defenders should p [truncated]
A heap-based buffer overflow vulnerability exists in Microsoft Office Word, potentially allowing an unauthorized attacker to execute code over a network. This high-severity vulnerability, classified under CWE-122, has a CVSS score of 8.8. Defenders should assess exposure, especially in network-accessible environments, and prioritize patching. The vulnerability's details are sourced from the CVE Program re [truncated]
Microsoft Office Word is vulnerable to a heap-based buffer overflow, which could allow an unauthorized attacker to execute code over a network. This vulnerability affects Microsoft Office Word deployments and has a high severity impact. Defenders should assess exposure and prioritize patching, especially in environments where users open documents from untrusted sources. The CVE record and NVD entry provid [truncated]
CVE-2026-72967 is a high-severity vulnerability in the Windows Network Connection Broker that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. Microsoft has released a patch for this vulnerability. System administrators and security teams should assess exposure and apply patches immediately to prevent local privilege escalati [truncated]
A missing authorization vulnerability in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally. This medium-severity issue, tracked as CVE-2026-72966, was publicly disclosed on 2026-09-08 and last modified on 2026-09-17. Microsoft has provided a vendor advisory and patch for this vulnerability. System administrators and security teams should assess exposure an [truncated]
A use-after-free vulnerability in the Windows WebClient Service allows an authorized attacker to elevate privileges locally. This CVE was published on 2026-09-08T18:20:22.577Z and was last modified on 2026-09-21T15:34:53.907Z. The vulnerability exists in the Windows WebClient Service and allows an authorized attacker to elevate privileges locally through a use-after-free weakness. Defenders and administra [truncated]
A missing authentication vulnerability in Windows Internet Connection Sharing (ICS) could allow an authorized local attacker to perform tampering. Microsoft has released a patch for this vulnerability. The vulnerability, tracked as CVE-2026-72964, is caused by a missing authentication mechanism in Windows Internet Connection Sharing (ICS). This allows an authorized local attacker to perform tampering. ICS [truncated]
CVE-2026-72963 is a high-severity vulnerability in Windows Modern Execution Server, classified as CWE-416, that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7. Microsoft has released a patch for this vulnerability. Affected Windows system administrators and security teams should assess exposure and apply patches to prevent local privilege escalation. T [truncated]
A heap-based buffer overflow vulnerability exists in the Windows USB Video Driver, allowing an authorized attacker to elevate privileges locally. This CVE was published on 2026-09-08T18:20:22.070Z and was last modified on 2026-09-21T20:04:21.483Z. The NVD entry is currently Analyzed. The vulnerability has a CVSS score of 8.2 and a severity rating of HIGH. System administrators and security teams responsib [truncated]
CVE-2026-72961 is a high-severity vulnerability in Windows Hyper-V that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 8.2 and is classified as CWE-122. Microsoft has released a patch for this vulnerability. System administrators and security teams should review vulnerability management processes to ensure timely patching and monitor system logs for pote [truncated]
A heap-based buffer overflow vulnerability exists in Windows Media Player, which could allow an unauthorized attacker to execute code over a network. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. Microsoft has released a patch for this vulnerability. System administrators and users of Windows Media Player should be aware of this vulnerability and take steps to mitigate it by a [truncated]
A remote code execution vulnerability exists in the Windows Routing and Remote Access Service (RRAS). This vulnerability allows an attacker to gain unauthorized access to a victim's machine, potentially leading to disruption of critical services and unauthorized access to sensitive data. System administrators and security teams should assess exposure and prioritize remediation, especially for systems with [truncated]
A double free vulnerability in Windows Credential Guard allows an authorized attacker to elevate privileges locally. This CVE was published on 2026-09-08T18:20:21.440Z and was last modified on 2026-09-21T15:53:05.120Z. The vulnerability exists in Windows 11 and Windows Server 2025 systems, particularly those with Credential Guard enabled. Defenders should assess exposure and prioritize patching for these [truncated]
CVE-2026-72957 is a high-severity vulnerability in Windows Deployment Services that allows an authorized attacker to execute code locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. Microsoft has released a patch for this vulnerability. A heap-based buffer overflow exists in Windows Deployment Services, enabling local code execution by authorized attackers. Defenders should asses [truncated]
A use-after-free vulnerability in Windows Deployment Services allows an authorized attacker to execute code over a network. This issue affects various Windows versions, including Windows 10, Windows Server 2012, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025, and has a CVSS score of 7.5. Microsoft has released an advisory and patch for this vulnerability. Defenders [truncated]
A heap-based buffer overflow vulnerability exists in the Windows USB Driver, allowing an authorized attacker to elevate privileges locally. The CVE record was published on 2026-09-08T18:20:20.857Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Windows 10, Windows 11, and Windows Server, posing a significant risk to systems with elevated access. Defend [truncated]
An out-of-bounds read vulnerability in Windows Spaceport.sys allows an authorized attacker to execute code locally. This issue affects multiple Windows versions, including Windows 10, Windows 11, and Windows Server, and has been addressed by Microsoft. The vulnerability has a CVSS score of 7, indicating high severity. Defenders should assess their exposure and apply patches from Microsoft. The CVE record [truncated]
A remote code execution vulnerability exists in the Windows Routing and Remote Access Service (RRAS). This vulnerability allows an attacker to gain unauthorized access to a victim's machine, potentially leading to disruption of critical services and unauthorized access to sensitive data. Windows RRAS administrators and defenders should assess exposure and prioritize remediation efforts. The vulnerability [truncated]
A null pointer dereference vulnerability in the Windows SMB Server Network Transport Driver (srvnet.sys) can allow an unauthorized attacker to deny service over a network. This issue affects various versions of Windows 11 and Windows Server. Microsoft has released a patch for this vulnerability. The vulnerability is a result of improper handling of certain network requests, leading to a denial of service. [truncated]
A relative path traversal vulnerability in Windows DNS allows an authorized attacker to elevate privileges locally. This CVE has a CVSS score of 6.7 and is considered medium severity. The vulnerability was published on 2026-09-08T18:20:20.190Z and last modified on 2026-09-21T20:02:59.760Z. The vulnerability affects Windows 10, Windows Server 2012, Windows Server 2016, Windows Server 2019, Windows Server 2 [truncated]
CVE-2026-72947 is an integer underflow vulnerability in the Windows File History Service that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 6.4 and a severity of MEDIUM. Microsoft has released a patch for this vulnerability. System administrators and security teams should assess exposure and apply patches or mitigations to vulnerable systems. The vulner [truncated]
CVE-2026-72946 is a high-severity vulnerability in the Storage Port Driver, a heap-based buffer overflow allows an authorized attacker to elevate privileges locally. The CVE record was published on 2026-09-08T18:20:19.893Z and has not been modified since then. Defenders should assess exposure and prioritize patching or mitigating this vulnerability. The vulnerability has a CVSS score of 7.8 and is classif [truncated]
An authorized attacker can disclose information locally due to the use of an uninitialized resource in Windows Task Scheduler. This vulnerability, CVE-2026-72945, is a medium-severity issue that allows local information disclosure. Defenders responsible for Windows systems, particularly those using Windows Task Scheduler, should assess exposure and apply patches from Microsoft. The vulnerability exists du [truncated]
CVE-2026-72944 is a high-severity vulnerability in the Windows Fax Service that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as a heap-based buffer overflow. Microsoft has released a patch for this vulnerability, and defenders should prioritize patching to prevent potential attacks.
CVE-2026-72943 is a high-severity use-after-free vulnerability in Windows Deployment Services, allowing authorized attackers to execute code remotely. Defenders should assess exposure, prioritize patching, and monitor network activity for suspicious behavior related to Windows Deployment Services. The vulnerability's impact is significant because it can be exploited over a network, potentially leading to [truncated]
CVE-2026-72942 is a MEDIUM severity vulnerability in Windows Spaceport.sys that allows unauthorized attackers to disclose information over a network. The CVE record was published on 2026-09-08T18:20:19.253Z and has not been modified since then. The NVD entry is currently Analyzed. Defenders responsible for Windows 10 Version 1607, Windows Server 2016, and other affected systems should verify exposure and [truncated]
A heap-based buffer overflow vulnerability exists in the Windows Biometric Service, allowing an authorized attacker to elevate privileges locally. This CVE was published on 2026-09-08T18:20:19.093Z and was last modified on 2026-09-11T14:17:32.900Z. The vulnerability has a CVSS score of 7.8 and is considered HIGH severity. Defenders responsible for Windows systems, especially those with exposed biometric s [truncated]
A heap-based buffer overflow vulnerability exists in Windows Schannel, allowing an unauthorized attacker to execute code over a network. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. Microsoft has released a patch for this vulnerability. Defenders responsible for Windows systems, particularly those exposed to the internet, should assess their exposure and prioritize patchin [truncated]
A null pointer dereference vulnerability in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network. This CVE was published on 2026-09-08T18:20:18.780Z and was last modified on 2026-09-22T12:29:22.893Z. The vulnerability exists in the Windows Routing and Remote Access Service (RRAS) and allows an authorized attacker to cause a denial of service conditi [truncated]