CYBERSECURITYTRACKER
TRACKING7,631 stories in this site build1,635 vulnerability news stories in this site build
Vulnerabilities

September 2026 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 2 vulnerabilities with exploitation detected in the wild this month. This defender-focused view covers 3,860 vulnerabilities across 9,413 returned patch records from 4 vendors. Filter the month to date, or browse the static page trail without JavaScript.

9,413all patch recordsClear filters401criticalShow these records2Microsoft exploitation detectedShow these records4Microsoft in the Known Exploited Vulnerabilities catalogShow these records3,056tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 48 of 48 · records 9,401 to 9,413 of 9,413

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-80812 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0N/AOut-of-bandNot availableMicrosoft rating unavailableALSA: dummy: Check card index validity at probe
CVE-2026-80907 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0N/AOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: Fix UVD dpb min size calculation for H264
CVE-2026-80906 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0N/AOut-of-bandNot availableMicrosoft rating unavailablenet: packet: fix wrong transport_header when sending VLAN-tagged frame
CVE-2026-77860 ↗azl3 unbound 1.26.0-1 on Azure Linux 3.0N/AOut-of-bandNot availableMicrosoft rating unavailable'serve-expired' can bypass Unbound 'wait-limit'
CVE-2026-80822 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0N/AOut-of-bandNot availableMicrosoft rating unavailablemailbox: mchp-ipc-sbi: Add null check for devm_kasprintf()
CVE-2026-80901 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0N/AOut-of-bandNot availableMicrosoft rating unavailableipvs: fix the checksum validations
CVE-2026-80887 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0N/AOut-of-bandNot availableMicrosoft rating unavailabledrm/vmwgfx: use check_add_overflow for shader size+offset bound
CVE-2026-80795 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0N/AOut-of-bandNot availableMicrosoft rating unavailablenfc: nci: fix out-of-bounds write in nci_target_auto_activated()
CVE-2026-80911 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0N/AOut-of-bandNot availableMicrosoft rating unavailableASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked()
CVE-2026-80814 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0N/AOut-of-bandNot availableMicrosoft rating unavailablerndis_host: add overflow check in rndis_rx_fixup()
CVE-2026-80908 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0N/AOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: Reject UVD message with dimensions above 4096
CVE-2026-80883 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0N/AOut-of-bandNot availableMicrosoft rating unavailabledrm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered
CVE-2026-80781 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0N/AOut-of-bandNot availableMicrosoft rating unavailableHID: core: fix OOB read of field->usage in hid_set_field()

Glossary