{
  "day": "2026-09-08",
  "boundary": "UTC calendar day",
  "published_count": 1564,
  "by_severity": {
    "CRITICAL": 87,
    "HIGH": 867,
    "MEDIUM": 473,
    "LOW": 26
  },
  "kev_count": 2,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 111,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-81963",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": true,
      "kev_due_at": "2026-09-22",
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-59",
      "title": "Windows Update Stack Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81963"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-85880",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": true,
      "kev_due_at": "2026-09-22",
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85880"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-71376",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00985,
      "epss_percentile": 0.60089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi",
      "product": "Cosminexus Component Container",
      "cwe": "CWE-78",
      "title": "OS Command Injection Vulnerability in Cosminexus Component Container",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71376"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-67367",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00811,
      "epss_percentile": 0.54615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "SIMOVE Fleetmanager V3.1",
      "cwe": "CWE-23",
      "title": "A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1), SIPLANT V1.7 (All versions), SIPLANT V2.2 (All versions), SIPLANT V3.0 (All versions), SIPLANT V3.1 (All versions < V3.1.4). Affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the embedded HTTP server. This could allow an unauthenticated remote attacker to read arbitrary files from the underlying operating system without any credentials, potentially exposing sensitive data such as credential stores, private keys, and configuration secrets.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67367"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-76561",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00592,
      "epss_percentile": 0.46181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Certificate System 9",
      "cwe": "CWE-78",
      "title": "Pki-core: dogtag/pki: certprofile-import allows code execution via unsanitized profile content (externalprocessconstraint)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76561"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-86510",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00463,
      "epss_percentile": 0.38565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DIR-822A",
      "cwe": "CWE-119",
      "title": "D-Link DIR-822A L2TP Control Message tunnel_set_params out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86510"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-85400",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "TYPO3 CMS",
      "cwe": "CWE-266",
      "title": "TYPO3 CMS - Missing Authorization in lowlevel commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85400"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-86509",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00433,
      "epss_percentile": 0.36353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DIR-895L",
      "cwe": "CWE-119",
      "title": "D-Link DIR-895L udhcpcd serverpacket.c sendACK stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86509"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-77132",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00409,
      "epss_percentile": 0.34198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "TYPO3 CMS",
      "cwe": "CWE-200",
      "title": "TYPO3 CMS - Information Disclosure via Backend Localization Wizard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77132"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-86511",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.33849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "java-json-tools",
      "product": "jackson-coreutils",
      "cwe": "CWE-400",
      "title": "java-json-tools jackson-coreutils JacksonUtils.java BigDecimal.toPlainString resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86511"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-86513",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.33849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "java-json-tools",
      "product": "jackson-coreutils",
      "cwe": "CWE-400",
      "title": "java-json-tools jackson-coreutils JSON Pointer parser TreePointer.java TreePointer.tokensFromInput allocation of resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86513"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-82710",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00404,
      "epss_percentile": 0.33719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "usage_rules",
      "cwe": "CWE-150",
      "title": "Terminal escape sequence injection in mix usage_rules.search_docs via package documentation metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82710"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-86590",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0037,
      "epss_percentile": 0.30174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Che",
      "cwe": "CWE-918",
      "title": "In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP GET request with no host filtering. An authenticated user can exploit this server-side request forgery (SSRF) to read responses from internal network addresses, including the cloud instance metadata service (169.254.169.254), loopback interfaces, RFC-1918 private ranges, and in-cluster Kubernetes services. The operator-configured allowlist (spec.devEnvironments.allowedSources.urls) is not consulted. The vulnerability is fixed in version 7.122.0, which adds private-address blocking, IPv4-mapped IPv6 bypass prevention, operator allowlist enforcement, and disables HTTP redirects on the outbound request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86590"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-12962",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00361,
      "epss_percentile": 0.2923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Armoury Crate",
      "cwe": "CWE-942",
      "title": "A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application's local service endpoint.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12962"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-9331",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PixelYourSite",
      "product": "EDD Product Catalog Feed by PixelYourSite",
      "cwe": "CWE-862",
      "title": "EDD Product Catalog Feed by PixelYourSite <= 1.0.2 - Authenticated (Subscriber+) Arbitrary Options Deletion via Missing Authorization on 'delete' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9331"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-62645",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00348,
      "epss_percentile": 0.27777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Reyrolle 7SR5",
      "cwe": "CWE-306",
      "title": "A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass the authentication and gain unauthorized access to the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62645"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-58240",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00343,
      "epss_percentile": 0.27247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP NetWeaver (Message Server)",
      "cwe": "CWE-308",
      "title": "Missing Authentication check in SAP NetWeaver (Message Server)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58240"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-62647",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00337,
      "epss_percentile": 0.26526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Reyrolle 7SR5",
      "cwe": "CWE-20",
      "title": "A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevant values (such as session identifiers used for authentication purposes) that is not initialized with a True Random Number Generator (TRNG), resulting in a predictable sequence of generated values. This could allow an unauthenticated remote attacker to more easily predict the generated values and impersonate a legitimate authenticated user, potentially gaining unauthorized access to the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62647"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-86515",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00337,
      "epss_percentile": 0.26602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "vgmstream",
      "cwe": "CWE-400",
      "title": "vgmstream txtp txtp_parser.c add_entry resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86515"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-62648",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Reyrolle 7SR5",
      "cwe": "CWE-787",
      "title": "A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL component contained in pre-authenticated HTTP messages is not properly validated before appending additional data to it, resulting in an out-of-bounds write condition in memory. This could allow an unauthenticated remote attacker to crash the affected device, causing a reboot and resulting in a denial-of-service condition.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62648"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-62649",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Reyrolle 7SR5",
      "cwe": "CWE-770",
      "title": "A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The web server does not properly limit or manage system resources when processing a high volume of concurrent HTTP requests. This could allow an unauthenticated remote attacker to cause the entire device to crash and reboot, resulting in a denial-of-service condition.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62649"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-44756",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00321,
      "epss_percentile": 0.24744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Extended Passport (EPP) Processing",
      "cwe": "CWE-120",
      "title": "Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44756"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-62650",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Reyrolle 7SR5",
      "cwe": "CWE-288",
      "title": "A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforced, allowing role-based access control (RBAC) restrictions to be bypassed through manipulation of request data. This could allow an authenticated, low-privileged remote attacker to escalate privileges to an administrative level.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62650"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-66768",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00318,
      "epss_percentile": 0.24343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP NetWeaver (SAP GUI for Java)",
      "cwe": "CWE-807",
      "title": "Improper Access Control in SAP NetWeaver (SAP GUI for Java)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66768"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-86519",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.24346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Student Crud Operation",
      "cwe": "CWE-200",
      "title": "code-projects Student Crud Operation Backup File card_activation.sql information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86519"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-62646",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00315,
      "epss_percentile": 0.24003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Reyrolle 7SR5",
      "cwe": "CWE-331",
      "title": "A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier is generated using an algorithm with insufficient randomness, resulting in a token with low entropy that can be predicted or brute-forced within a feasible number of attempts. This could allow an unauthenticated remote attacker to derive valid session identifiers and bypass authentication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62646"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-71377",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00314,
      "epss_percentile": 0.23886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi",
      "product": "Cosminexus Component Container",
      "cwe": "CWE-88",
      "title": "Command Argument Injection Vulnerability in Cosminexus Component Container",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71377"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-71374",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.23853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi",
      "product": "Cosminexus Component Container",
      "cwe": "CWE-502",
      "title": "Deserialization of Untrusted Data Vulnerability in Cosminexus Component Container",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71374"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-76969",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00294,
      "epss_percentile": 0.21659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Cloud Application Programming Model (CAP)",
      "cwe": "CWE-522",
      "title": "Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76969"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-86514",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.19434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "vgmstream",
      "cwe": "CWE-119",
      "title": "vgmstream txth-txtp txth.c sscanf stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86514"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-86550",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00267,
      "epss_percentile": 0.18641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "NebulaOS",
      "cwe": "CWE-79",
      "title": "UXSS vulnerability in ZTE browser products",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86550"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-81790",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.18259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Viszt Péter",
      "product": "Csomagpontok és szállítási címkék WooCommerce-hez",
      "cwe": "CWE-862",
      "title": "WordPress Csomagpontok és szállítási címkék WooCommerce-hez plugin < 4.2.8 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81790"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-48888",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.17931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Automattic",
      "product": "WooCommerce",
      "cwe": "CWE-770",
      "title": "WordPress WooCommerce plugin < 11.1.0 - Denial of Service Attack vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48888"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-66767",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP NetWeaver Application Server for ABAP and ABAP Platform",
      "cwe": "CWE-191",
      "title": "Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66767"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-71375",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.15836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi",
      "product": "Cosminexus Component Container",
      "cwe": "CWE-611",
      "title": "XXE Vulnerability in Cosminexus Component Container",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71375"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-86516",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.13936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elenavanengelenmaslova",
      "product": "mocknest-serverless",
      "cwe": "CWE-266",
      "title": "elenavanengelenmaslova mocknest-serverless AWS GitHub OIDC Deployment Helper Script github-oidc-role.yaml privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86516"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-76968",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.13886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Web Dispatcher, Internet Communication Manager and SAP Content Server",
      "cwe": "CWE-497",
      "title": "Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76968"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-44766",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP S/4HANA (Intercompany Matching and Reconciliation)",
      "cwe": "CWE-89",
      "title": "SQL Injection vulnerability in SAP S/4HANA (Intercompany Matching and Reconciliation)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44766"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-76958",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00223,
      "epss_percentile": 0.12852,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Integration Suite",
      "cwe": "CWE-611",
      "title": "XML External Entity (XXE) Vulnerability in SAP Integration Suite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76958"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-76977",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.12842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAPUI5(Frame Options Allowlist)",
      "cwe": "CWE-1289",
      "title": "Clickjacking vulnerability in SAPUI5(Frame Options Allowlist)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76977"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-58113",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.12116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Teamcenter V2412",
      "cwe": "CWE-79",
      "title": "A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim's Teamcenter session.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58113"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-76967",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.12109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP NetWeaver Business Client",
      "cwe": "CWE-502",
      "title": "Insecure Deserialization in SAP NetWeaver Business Client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76967"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-58234",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00212,
      "epss_percentile": 0.11424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Process Integration (SOAP Adapter)",
      "cwe": "CWE-776",
      "title": "Denial of Service vulnerability in SAP Process Integration (SOAP Adapter)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58234"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-86512",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "java-json-tools",
      "product": "json-patch",
      "cwe": "CWE-266",
      "title": "java-json-tools json-patch Copy Move Operations CopyOperation.java MoveOperation.apply access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86512"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-62652",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.10723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Reyrolle 7SR5",
      "cwe": "CWE-215",
      "title": "A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from which debugging symbols have not been removed. This could allow an unauthenticated attacker with access to the publicly available firmware update files to more easily reverse engineer the device's firmware, facilitating the identification of further vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62652"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-19397",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Control Center Express Agent",
      "cwe": "CWE-306",
      "title": "Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session. Refer to the ' Security Update for ASUS Control Center Express Agent ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19397"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-86517",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.10426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System us_searchfrm.php mysqli_query sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86517"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-86518",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.10426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Student Crud Operation",
      "cwe": "CWE-74",
      "title": "code-projects Student Crud Operation edit.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86518"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-76962",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP S/4HANA (Manage Bank Chains app)",
      "cwe": "CWE-862",
      "title": "Missing Authorization check in SAP S/4HANA (Manage Bank Chains app)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76962"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-81792",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MultiVendorX",
      "product": "Product Catalog Enquiry for WooCommerce by MultiVendorX",
      "cwe": "CWE-266",
      "title": "WordPress Product Catalog Enquiry for WooCommerce by MultiVendorX plugin <= 6.1.4 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81792"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-81802",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Magepeople inc.",
      "product": "WpEvently",
      "cwe": "CWE-639",
      "title": "WordPress WpEvently plugin <= 5.6.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81802"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-50093",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.08809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Siveillance Control Pro V3.0",
      "cwe": "CWE-434",
      "title": "A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < V3.0.22.2177), Siveillance Control V4.0 (All versions < V4.0.11.2177). A vulnerability in the OIS web module allows an attacker to upload arbitrary files to the server. Successful exploitation of this vulnerability could allow an attacker to gain root access on the host system, potentially leading to a full compromise of the affected OIS environment.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50093"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-81781",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00183,
      "epss_percentile": 0.07965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unbounce",
      "product": "Unbounce Landing Pages",
      "cwe": "CWE-862",
      "title": "WordPress Unbounce Landing Pages plugin <= 1.1.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81781"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-62653",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00183,
      "epss_percentile": 0.07908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Reyrolle 7SR5",
      "cwe": "CWE-787",
      "title": "A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The input received over a proprietary communication protocol that is exposed when the device is placed into a special firmware-update mode is not properly validated, resulting in a memory corruption condition. This could allow an unauthenticated attacker with physical access to the device to cause a crash and potentially execute arbitrary code on the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62653"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-76963",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP NetWeaver and ABAP Platform",
      "cwe": "CWE-862",
      "title": "Missing Authorization Check in Application Server ABAP of SAP NetWeaver and ABAP Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76963"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-81806",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "John Darrel",
      "product": "Hide My WP Ghost",
      "cwe": "CWE-918",
      "title": "WordPress Hide My WP Ghost plugin <= 7.0.09 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81806"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-76971",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Manufacturing Integration and Intelligence",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery in SAP Manufacturing Integration and Intelligence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76971"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-81798",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Easy Appointments",
      "product": "Easy Appointments",
      "cwe": "CWE-79",
      "title": "WordPress Easy Appointments plugin <= 4.0.2.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81798"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-84817",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock",
      "product": "JetFormBuilder",
      "cwe": "CWE-79",
      "title": "WordPress JetFormBuilder plugin <= 3.6.5.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84817"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-84818",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.0417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "100plugins",
      "product": "Open User Map",
      "cwe": "CWE-79",
      "title": "WordPress Open User Map plugin <= 1.4.50 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84818"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-84820",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unlimited Elements",
      "product": "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)",
      "cwe": "CWE-79",
      "title": "WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.17 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84820"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-34223",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Desigo CC ClickOnce Client V6",
      "cwe": "CWE-94",
      "title": "A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All versions), Desigo CC Flex Client V7 (All versions), Desigo CC Installed Client V6 (All versions), Desigo CC Installed Client V7 (All versions). The affected application is vulnerable to Client Code Execution (CCE) due to insufficient input validation when handling scripts embedded within user-defined graphics documents. Specifically, when the script within a graphics document is designed or modified by an attacker to include malicious commands. When a user opens a compromised graphics document, the embedded script is executed on the client application instance, allowing an attacker to write arbitrary files to the client's operating system. Successful exploitation requires an attacker to craft a malicious graphics document and entice a user with sufficient privileges to display it. This could lead to compromise of the client operating system and potential lateral movement within the organization.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34223"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-74859",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 8",
      "cwe": "CWE-22",
      "title": "Gnome-tweaks: path traversal in theme installer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74859"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-62654",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Reyrolle 7SR5",
      "cwe": "CWE-494",
      "title": "A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated via a physical key sequence during device boot, in which the device downloads and executes program code from a network server without verifying its authenticity or integrity. This could allow an attacker with physical access to the device to upload and execute arbitrary, unsigned code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62654"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-75809",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Armoury Crate",
      "cwe": "CWE-782",
      "title": "Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver authentication and using IOCTLs to read from and write to PCIe configuration space.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75809"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-75808",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Armoury Crate",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by bypassing driver authentication and allocating an unrestricted amount of memory.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75808"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-75810",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Armoury Crate",
      "cwe": "CWE-749",
      "title": "Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigger system management interrupts (SMIs). Repeatedly triggering SMI may lead to a denial-of-service (DoS) condition.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75810"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-75811",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Armoury Crate",
      "cwe": "CWE-1256",
      "title": "Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause hardware damage by bypassing driver authentication and accessing critical model-specific registers.Refer to the ' Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75811"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-76960",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00094,
      "epss_percentile": 0.00664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP S/4HANA (Finance for Advanced Payment Management)",
      "cwe": "CWE-352",
      "title": "Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76960"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-76961",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00094,
      "epss_percentile": 0.00663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP S/4HANA (Finance for Advanced Payment Management)",
      "cwe": "CWE-352",
      "title": "Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76961"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-16004",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0009,
      "epss_percentile": 0.0048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Armoury Crate",
      "cwe": "CWE-782",
      "title": "Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL requests by bypassing the driver's verification. Refer to the ' Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16004"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-16005",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0009,
      "epss_percentile": 0.0048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Armoury Crate",
      "cwe": "CWE-763",
      "title": "Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt data structures and cause a system crash (BSOD).Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16005"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-16006",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0009,
      "epss_percentile": 0.00481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Armoury Crate",
      "cwe": "CWE-497",
      "title": "Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCTL request by bypassing the driver's verification, potentially providing further insight into the kernel memory layout.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16006"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-18023",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0009,
      "epss_percentile": 0.0048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Armoury Crate",
      "cwe": "CWE-226",
      "title": "Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via a crafted IOCTL request that bypasses the driver's security verification mechanism. Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18023"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-16003",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.0009,
      "epss_percentile": 0.00481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Armoury Crate",
      "cwe": "CWE-782",
      "title": "Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IOCTL request by bypassing the driver's verification.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16003"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-76959",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00088,
      "epss_percentile": 0.00422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP S/4HANA (Finance for Advanced Payment Management)",
      "cwe": "CWE-352",
      "title": "Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76959"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-86597",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00087,
      "epss_percentile": 0.00392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Snowflake",
      "product": "Snowflake Connector for Python",
      "cwe": "CWE-532",
      "title": "Sensitive information written to logs by Snowflake drivers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86597"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-28659",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android XR",
      "cwe": null,
      "title": "In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28659"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-49883",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android Wear",
      "cwe": null,
      "title": "In checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49883"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-82004",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-78",
      "title": "Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82004"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-12645",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ivanti",
      "product": "Ivanti Neurons for ITSM",
      "cwe": "CWE-862",
      "title": "A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12645"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-12646",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ivanti",
      "product": "Ivanti Neurons for ITSM",
      "cwe": "CWE-862",
      "title": "A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12646"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-12647",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ivanti",
      "product": "Ivanti Neurons for ITSM",
      "cwe": "CWE-862",
      "title": "A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12647"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-12650",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ivanti",
      "product": "Neurons for ITSM",
      "cwe": "CWE-502",
      "title": "A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12650"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-19232",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-863",
      "title": "Adobe Experience Manager | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19232"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-26084",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiSandbox PaaS",
      "cwe": "CWE-284",
      "title": "A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26084"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-48273",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-95",
      "title": "ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48273"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-78234",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apache Camel - HawtIO 4",
      "cwe": "CWE-295",
      "title": "Hawtio-operator: hawtio-operator: service-ca signing oracle allows arbitrary-cn certificate issuance to namespace edit users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78234"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-83941",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Entra",
      "cwe": "CWE-862",
      "title": "Entra ID Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83941"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-84869",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ConnectWise",
      "product": "ScreenConnect",
      "cwe": "CWE-269",
      "title": "ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84869"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-86464",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse aeriOS",
      "cwe": "CWE-200",
      "title": "In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. The Helm chart exposed the Keycloak service and its PostgreSQL backing database through Kubernetes NodePort services by default, while the Docker Compose deployment similarly exposed PostgreSQL on all network interfaces. The deployment included fixed default credentials for the Keycloak administrator and PostgreSQL database user, and the previous Helm chart configuration did not provide adequate secret management for these credentials. In addition, predefined application users with known credentials were provided for development and testing without sufficiently warning operators against their use in production environments. An attacker able to reach the exposed services could use the published default credentials to obtain administrative access to the Identity Manager or direct access to its database. This could allow unauthorized access to or modification of identity-management data, including users, roles, client credentials, sessions, and cryptographic material, and could enable the creation of privileged identities or tokens accepted by other aeriOS components. The issue has been addressed by generating a random Keycloak administrator password by default, managing Keycloak and PostgreSQL credentials through Kubernetes Secrets, and restricting PostgreSQL to an internal service in both the Helm chart and Docker Compose deployment. OpenLDAP is also restricted to an internal service. The predefined users intended for development and testing are retained, but the documentation now explicitly warns that their default credentials must not be used in production and that these users should be removed or their credentials changed after installation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86464"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-12744",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ivanti",
      "product": "Neurons for ITSM",
      "cwe": "CWE-502",
      "title": "A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12744"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-12745",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ivanti",
      "product": "Neurons for ITSM",
      "cwe": "CWE-502",
      "title": "A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12745"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-49921",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-122",
      "title": "In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49921"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-58822",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-704",
      "title": "In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58822"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-66302",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Skype for Business Server 2015 CU13",
      "cwe": "CWE-73",
      "title": "Skype for Business Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66302"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-68839",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-20",
      "title": "Windows USB Mass Storage Class Driver Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68839"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-69276",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69276"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-69408",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69408"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-69431",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Telnet Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69431"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-69463",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69463"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-69491",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft DirectMusic Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69491"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-69493",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Event Logging Service Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69493"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-69496",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Compressed Folder Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69496"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-69525",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Remote Desktop Services Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69525"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-69579",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Message Queuing Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69579"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-69586",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Windows PDF Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69586"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-69590",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69590"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-69595",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows Server 2012",
      "cwe": "CWE-416",
      "title": "Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69595"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-69715",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Direct Show Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69715"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-69730",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows DNS Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69730"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-69768",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows RNDIS Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69768"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-69769",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows HTTP Print Provider Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69769"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-69819",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-787",
      "title": "RPC Runtime Library Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69819"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-69824",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Standard XPS Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69824"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-69829",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Shell Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69829"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-69845",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-20",
      "title": "Windows DHCP Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69845"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-69910",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Windows Hyper-V Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69910"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-70296",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-787",
      "title": "Windows Imaging Component Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70296"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-72979",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows DHCP Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72979"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-72982",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Windows Netlogon Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72982"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-72983",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Internet Connection Sharing (ICS) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72983"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-73009",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73009"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-73010",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Microsoft Failover Cluster Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73010"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-73025",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-1390",
      "title": "Windows iSCSI Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73025"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-77493",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-415",
      "title": "Windows Graphics Component Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77493"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-78445",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows Server 2012",
      "cwe": "CWE-416",
      "title": "Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78445"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-78509",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Outlook Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78509"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-78510",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78510"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-79569",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79569"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-79576",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-287",
      "title": "An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79576"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-65669",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "SQL Server Management Studio 22",
      "cwe": "CWE-74",
      "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65669"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-81376",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-693",
      "title": "Visual Studio Code Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81376"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-82533",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DeepSeek",
      "product": "DeepSeek Harness",
      "cwe": "CWE-807",
      "title": "DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82533"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-61516",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netis Systems",
      "product": "NX10",
      "cwe": "CWE-522",
      "title": "Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61516"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-69356",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-79",
      "title": "Microsoft Exchange Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69356"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-76200",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Commerce",
      "cwe": "CWE-79",
      "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76200"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-76201",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Commerce",
      "cwe": "CWE-79",
      "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76201"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-77089",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Commvault",
      "product": "Commvault Cloud",
      "cwe": null,
      "title": "Command Center API Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77089"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-86738",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-79",
      "title": "Snipe-IT before 8.7.0 CSS Injection via Custom CSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86738"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-82067",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-178",
      "title": "Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82067"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-84197",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Ditto",
      "cwe": "CWE-295",
      "title": "In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, the WebSocket transport hard-codes rejectUnauthorized: false when creating the underlying ws WebSocket. Certificate chain and hostname validation are therefore disabled for every wss:// connection, and no builder option, constructor argument or environment variable lets an application turn validation back on. An attacker in a position to intercept the connection can present an arbitrary certificate, complete the TLS handshake, read the credentials that the configured authentication provider sends in the Authorization header of the WebSocket upgrade request, and read, alter or inject Ditto Protocol messages for the lifetime of the connection. The Java client, the browser/DOM JavaScript client and the HTTP transport of the Node.js client are not affected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84197"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-53939",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenIDC",
      "product": "cjose",
      "cwe": "CWE-321",
      "title": "OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encryption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53939"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-69641",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-862",
      "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69641"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-73309",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XenForo",
      "product": "XenForo",
      "cwe": "CWE-697",
      "title": "XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73309"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-73311",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XenForo",
      "product": "XenForo",
      "cwe": "CWE-294",
      "title": "XenForo < 2.3.13 OAuth2 Authorization Code Reuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73311"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-73312",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XenForo",
      "product": "XenForo",
      "cwe": "CWE-294",
      "title": "XenForo < 2.3.13 Refresh Token Replay via Expired Access Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73312"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-75156",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow FAB provider",
      "cwe": "CWE-346",
      "title": "Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated — cross-tenant authentication bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75156"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-75746",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-89",
      "title": "ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75746"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-86729",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-307",
      "title": "WWBN AVideo Unrestricted Authentication Attempts via get_api_preauthorize",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86729"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-53581",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opnsense",
      "product": "core",
      "cwe": "CWE-22",
      "title": "ntp: write path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53581"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-69854",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Spring Cloud Azure",
      "cwe": "CWE-287",
      "title": "Spring Cloud Azure Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69854"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-85982",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Auth0",
      "product": "Auth0 AD/LDAP Connector",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85982"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-12648",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ivanti",
      "product": "Neurons for ITSM",
      "cwe": "CWE-502",
      "title": "A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12648"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-12651",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ivanti",
      "product": "Neurons for ITSM",
      "cwe": "CWE-502",
      "title": "A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12651"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-16502",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "livecomposer",
      "product": "Live Composer – Free WordPress Website Builder",
      "cwe": "CWE-502",
      "title": "Live Composer <= 2.1.18 - Authenticated (Contributor+) PHP Object Injection via Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16502"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-18851",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ivanti",
      "product": "Endpoint Manager Mobile",
      "cwe": "CWE-862",
      "title": "Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18851"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-62706",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62706"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-62744",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-122",
      "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62744"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-62895",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Arc SQL Server Extension",
      "cwe": "CWE-89",
      "title": "Azure Arc SQL Server Extension Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62895"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-65772",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Dynamics 365 (on-premises) version 9.1",
      "cwe": "CWE-502",
      "title": "Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65772"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-66814",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-1220",
      "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66814"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-66818",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-269",
      "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66818"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-66819",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-89",
      "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66819"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-66820",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-89",
      "title": "SQL Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66820"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-67368",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-59",
      "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67368"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-67370",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-89",
      "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67370"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-67373",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2025 (CU8)",
      "cwe": "CWE-122",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67373"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-67380",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-122",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67380"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-67381",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-122",
      "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67381"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-67384",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-122",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67384"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-67385",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-416",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67385"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-67388",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-122",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67388"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-67631",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-122",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67631"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-67638",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2025 (CU8)",
      "cwe": "CWE-122",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67638"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-67639",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-122",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67639"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-67642",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2025 (CU8)",
      "cwe": "CWE-122",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67642"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-67643",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2022 (CU 26)",
      "cwe": "CWE-122",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67643"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-68775",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-122",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68775"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-68786",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-122",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68786"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-68828",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68828"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-69266",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "title": "Windows DHCP Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69266"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-69268",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "cwe": "CWE-284",
      "title": "Microsoft Office SharePoint Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69268"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-69273",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "cwe": "CWE-284",
      "title": "Microsoft Office SharePoint Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69273"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-69282",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "cwe": "CWE-284",
      "title": "Microsoft Office SharePoint Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69282"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-69285",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69285"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-69291",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Volume Manager Extension Driver Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69291"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-69334",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Volume Manager Extension Driver Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69334"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-69355",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-73",
      "title": "Microsoft Exchange Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69355"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-69360",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69360"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-69386",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-122",
      "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69386"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-69434",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows URL Moniker Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69434"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-69439",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": ".NET 10.0",
      "cwe": "CWE-122",
      "title": ".NET and Visual Studio Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69439"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-69442",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69442"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-69461",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69461"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-69464",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "cwe": "CWE-250",
      "title": "Microsoft Office SharePoint Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69464"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-69465",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "cwe": "CWE-862",
      "title": "Microsoft Office SharePoint Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69465"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-69485",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-908",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69485"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-69494",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Event Logging Service Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69494"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-69495",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Event Logging Service Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69495"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-69499",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "title": "Windows Imaging Component Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69499"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-69511",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69511"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-69518",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Remote Desktop Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69518"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-69522",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": ".NET 10.0",
      "cwe": "CWE-122",
      "title": ".NET and Visual Studio Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69522"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-69529",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Access Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69529"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-69547",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows DHCP Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69547"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-69551",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows DNS Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69551"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-69556",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69556"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-69598",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-131",
      "title": "Windows iSCSI Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69598"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-69601",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69601"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-69603",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Hyper-V Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69603"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-69614",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-20",
      "title": "Microsoft Office Access Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69614"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-69628",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows iSCSI Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69628"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-69629",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Outlook Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69629"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-69632",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-416",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69632"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-69649",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Raw Image Extension",
      "cwe": "CWE-122",
      "title": "Raw Image Extension Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69649"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-69669",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Kernel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69669"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-69671",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69671"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-69676",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-294",
      "title": "Windows Kerberos Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69676"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-69678",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-416",
      "title": "Microsoft Office PowerPoint Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69678"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-69686",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-121",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69686"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-69712",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows Server 2012",
      "cwe": "CWE-416",
      "title": "Windows Key Distribution Center Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69712"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-69716",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "cwe": "CWE-89",
      "title": "Microsoft Office SharePoint Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69716"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-69722",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-121",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69722"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-69724",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "cwe": "CWE-862",
      "title": "Microsoft Office SharePoint Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69724"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-69729",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-122",
      "title": "Windows Credential Providers Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69729"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-69740",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-416",
      "title": "Windows Hello Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69740"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-69742",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-190",
      "title": "Microsoft Office Publisher Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69742"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-69759",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-121",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69759"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-69764",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69764"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-69767",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-416",
      "title": "Microsoft Office PowerPoint Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69767"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-69772",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Network File System Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69772"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-69778",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Access Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69778"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-69784",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-416",
      "title": "Windows Hello Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69784"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-69797",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-416",
      "title": "Microsoft Office PowerPoint Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69797"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-69860",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Imaging Component Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69860"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-70203",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Media Player Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70203"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-70351",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "WebP Image Extension",
      "cwe": "CWE-122",
      "title": "Microsoft WebP Image Extension Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70351"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-70586",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Paint Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70586"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-71328",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": ".NET 10.0",
      "cwe": "CWE-122",
      "title": ".NET and Visual Studio Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71328"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-71336",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "title": "Windows Work Folder Service Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71336"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-71352",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-191",
      "title": "Windows Remote Access Connection Manager Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71352"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-72933",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft WDAC OLE DB provider for SQL Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72933"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-72940",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-122",
      "title": "Windows Schannel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72940"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-72950",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72950"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-72959",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72959"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-72960",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Media Player Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72960"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-72972",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72972"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-72973",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72973"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-72986",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Graphic Fonts Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72986"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-73006",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "DirectWrite Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73006"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-73012",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Management Services Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73012"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-73013",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Imaging Component Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73013"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-73016",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "DirectWrite Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73016"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-73018",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Graphic Fonts Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73018"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-73023",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Imaging Component Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73023"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-73028",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-284",
      "title": "SQL Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73028"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-77097",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Commvault",
      "product": "Commvault Cloud",
      "cwe": "CWE-306",
      "title": "Private Metrics Server Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77097"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-77098",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Commvault",
      "product": "Commvault Cloud",
      "cwe": "CWE-89",
      "title": "Private Metrics Server SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77098"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-77480",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-1220",
      "title": "SQL Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77480"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-77481",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-122",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77481"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-77482",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-122",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77482"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-77483",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-1390",
      "title": "SQL Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77483"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-77484",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2019 (CU 32)",
      "cwe": "CWE-502",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77484"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-77486",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-122",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77486"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-77487",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-284",
      "title": "SQL Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77487"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-77495",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Imaging Component Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77495"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-77504",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-415",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77504"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-77901",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-476",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77901"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-77906",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Visual Studio 2026 version 18.9",
      "cwe": "CWE-122",
      "title": "Visual Studio Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77906"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-77907",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Visual Studio 2026 version 18.9",
      "cwe": "CWE-122",
      "title": "Visual Studio Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77907"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-77908",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Dynamics 365 Customer Engagement V9.1",
      "cwe": "CWE-94",
      "title": "Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77908"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-78439",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Office 365 for Mac",
      "cwe": "CWE-121",
      "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78439"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-78442",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-122",
      "title": "Windows OLE DB Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78442"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-78456",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2022 (CU 26)",
      "cwe": "CWE-122",
      "title": "SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78456"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-78462",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-639",
      "title": "Visual Studio Code Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78462"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-78463",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Remote Desktop client for Windows Desktop",
      "cwe": "CWE-94",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78463"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-78504",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-121",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78504"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-78505",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78505"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-78507",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-416",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78507"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-78511",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78511"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-78512",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78512"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-78514",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-416",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78514"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-78517",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78517"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-78518",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-20",
      "title": "Microsoft Office Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78518"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-78519",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-908",
      "title": "Microsoft Office Outlook Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78519"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-78521",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78521"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-78524",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-787",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78524"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-78525",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-416",
      "title": "Microsoft Office Outlook Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78525"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-78526",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78526"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-79376",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-20",
      "title": "An issue in the l2cap_handle_data() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79376"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-80074",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Remote Desktop client for Windows Desktop",
      "cwe": "CWE-122",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80074"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-80077",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Remote Desktop client for Windows Desktop",
      "cwe": "CWE-122",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80077"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-80080",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-415",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80080"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-80081",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-416",
      "title": "Microsoft Office PowerPoint Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80081"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-80083",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-822",
      "title": "Windows Hyper-V Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80083"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-80085",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80085"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-80096",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80096"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-81352",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Web Media Extensions",
      "cwe": "CWE-122",
      "title": "Web Media Extensions Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81352"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-81385",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-502",
      "title": "Microsoft Office Publisher Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81385"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-81952",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81952"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-81955",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Windows Graphics Component Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81955"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-81996",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-863",
      "title": "Acrobat Reader | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81996"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-83992",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Imaging Component Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83992"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-83996",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Error Reporting Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83996"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-83998",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83998"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-85877",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-122",
      "title": "Windows Print Spooler Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85877"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-12611",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Jetty",
      "cwe": "CWE-400",
      "title": "A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive. This is caused by a race condition in the server when handling RST_STREAM frames and GOAWAY frames sent by the client. The race condition \"resets\" the HTTP2Flusher.terminated, previously set to a non-null value, to the null value, allowing entries to be enqueued in the flusher that however will never be processed. These unprocessed entries are the ones that would unblock the write-blocked threads.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12611"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-33197",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMI",
      "product": "AptioV",
      "cwe": "CWE-184",
      "title": "BDS Module Bypass Secure Boot Advisory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33197"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-55250",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "macropay-solutions",
      "product": "maravel-framework",
      "cwe": "CWE-294",
      "title": "Maravel-Framework Token Replay Vulnerability via Premature JWT Blacklist Eviction in Tagged Caches",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55250"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-73314",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XenForo",
      "product": "XenForo",
      "cwe": "CWE-754",
      "title": "XenForo < 2.3.13 Signature Verification Bypass via PayPal REST Webhook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73314"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-73316",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XenForo",
      "product": "XenForo",
      "cwe": "CWE-345",
      "title": "XenForo < 2.3.13 Payment Replay via PayPal REST Payment Provider",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73316"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-77101",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Commvault",
      "product": "Commvault Cloud",
      "cwe": "CWE-121",
      "title": "CommServe Stack-based Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77101"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-77102",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Commvault",
      "product": "Commvault Cloud",
      "cwe": "CWE-122",
      "title": "CommServe Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77102"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-77103",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Commvault",
      "product": "Commvault Cloud",
      "cwe": "CWE-288",
      "title": "CommServe Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77103"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-77105",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Commvault",
      "product": "Commvault Cloud",
      "cwe": "CWE-347",
      "title": "CommServe Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77105"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-77111",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Commerce",
      "cwe": "CWE-863",
      "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77111"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-80219",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apache Camel - HawtIO 4",
      "cwe": "CWE-1390",
      "title": "Hawtio-operator: hawtio-operator: oauthclient created with grantmethod auto and no secret enables oauth token theft",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80219"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-82064",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-617",
      "title": "Unauthenticated Denial of Service in MongoDB Server via Assertion Failure in Read Concern Processing on Replica Set Members",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82064"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-82075",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-770",
      "title": "Uncontrolled Resource Consumption in MongoDB Sharded Cluster Router Allows Unauthenticated Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82075"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-86075",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-770",
      "title": "n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86075"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-86076",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-94",
      "title": "n8n: Expression Sandbox Escape in Editor-UI Enables Stored Cross-User JavaScript Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86076"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-86721",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-287",
      "title": "AVideo through c3edcc274c Authorization Bypass via Session Cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86721"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-86727",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-306",
      "title": "AVideo through 29.0 Information Disclosure via stats.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86727"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-86728",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-306",
      "title": "AVideo through 29.0 Unauthenticated Disclosure via epg.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86728"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-86730",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-94",
      "title": "Craft CMS 5.0.0-RC1 before 5.10.12 Behavior Injection RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86730"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-86732",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-94",
      "title": "Craft CMS before 5.10.12 Remote Code Execution via element-index",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86732"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-61517",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netis Systems",
      "product": "NX10",
      "cwe": "CWE-78",
      "title": "Netis NX10 OS Command Injection via Ping Diagnostic Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61517"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-74239",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XenForo",
      "product": "XenForo",
      "cwe": "CWE-22",
      "title": "XenForo < 2.3.13 Path Traversal via Style Archive Importer on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74239"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-75990",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Illustrator Desktop 2026",
      "cwe": "CWE-863",
      "title": "Illustrator | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75990"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-75991",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Illustrator Desktop 2026",
      "cwe": "CWE-20",
      "title": "Illustrator | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75991"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-76190",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-95",
      "title": "ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76190"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-76199",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Photoshop 2026",
      "cwe": "CWE-427",
      "title": "Photoshop Desktop | Uncontrolled Search Path Element (CWE-427)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76199"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-77109",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Commerce",
      "cwe": "CWE-863",
      "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77109"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-77774",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Commerce",
      "cwe": "CWE-863",
      "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77774"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-79721",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mlflow",
      "product": "mlflow",
      "cwe": "CWE-829",
      "title": "Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79721"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-80097",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Authenticator for Android",
      "cwe": "CWE-287",
      "title": "Microsoft Authenticator Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80097"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-86712",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan before 3.8.2 Remote Code Execution via Clipboard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86712"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-86720",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-639",
      "title": "WWBN AVideo Missing Authorization via resendRestreamer.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86720"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-86722",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-287",
      "title": "AVideo Authentication Bypass via SQL Cache Invalidation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86722"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-86723",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-287",
      "title": "AVideo LoginControl PGP Authentication Bypass via verifyChallenge",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86723"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-86733",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-78",
      "title": "Snipe-IT before 8.7.0 Remote Code Execution via Backup Restore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86733"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-67378",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2019 (CU 32)",
      "cwe": "CWE-822",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67378"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-67379",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2019 (CU 32)",
      "cwe": "CWE-121",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67379"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-67636",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2019 (CU 32)",
      "cwe": "CWE-125",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67636"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-74860",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-763",
      "title": "Libxml2: double-free/uaf in libxml2 python bindings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74860"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-75993",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-79",
      "title": "ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75993"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-77091",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Commvault",
      "product": "Commvault Cloud",
      "cwe": "CWE-22",
      "title": "DataCube Security Feature Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77091"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-85384",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "RE210 AC750",
      "cwe": "CWE-121",
      "title": "Authenticated Stack-Based Buffer Overflow in RE210 AC750 Configuration Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85384"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-69479",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69479"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-69638",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69638"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-75999",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-20",
      "title": "ColdFusion | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75999"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-77503",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77503"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-77827",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Maono",
      "product": "Maono Link",
      "cwe": "CWE-428",
      "title": "Maono Link local privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77827"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-86819",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Waves Audio Ltd.",
      "product": "Waves Central",
      "cwe": "CWE-862",
      "title": "Waves Central local privilege escalation via Improper XPC Client Authentication in macOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86819"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-19203",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Jetty",
      "cwe": "CWE-444",
      "title": "A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused by Jetty accepting a lone LF character as a terminator in parts of chunked request parsing. Depending on the Jetty version and configured HTTP compliance mode, this may occur in chunk extensions, chunk data termination, or trailer termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19203"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-69646",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Skype for Business Server 2015 CU13",
      "cwe": "CWE-347",
      "title": "Skype for Business Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69646"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-77104",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Commvault",
      "product": "Commvault Cloud",
      "cwe": "CWE-22",
      "title": "CommServe Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77104"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-81821",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AVEVA",
      "product": "Pipeline Integrity Monitor",
      "cwe": "CWE-321",
      "title": "AVEVA Pipeline Integrity Monitor Use of hard-coded cryptographic key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81821"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-81822",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AVEVA",
      "product": "Pipeline Integrity Monitor",
      "cwe": "CWE-327",
      "title": "AVEVA Pipeline Integrity Monitor Use of a Broken or Risky Cryptographic Algorithm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81822"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-53938",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenIDC",
      "product": "cjose",
      "cwe": "CWE-122",
      "title": "OpenIDC/cjose has a heap buffer overflow in AES Key Wrap decryption (A128KW/A192KW/A256KW)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53938"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-69820",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-122",
      "title": "Windows Hello Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69820"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-69846",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "title": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69846"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-69874",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-822",
      "title": "Windows ALPC Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69874"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-69906",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69906"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-72958",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-415",
      "title": "Windows Credential Guard Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72958"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-72961",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72961"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-72962",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-122",
      "title": "Windows USB Video Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72962"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-73310",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XenForo",
      "product": "XenForo",
      "cwe": "CWE-863",
      "title": "XenForo < 2.3.13 OAuth2 Authorization Code Token Theft via redirect_uri Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73310"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-76191",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Animate 2023",
      "cwe": "CWE-94",
      "title": "Animate | Improper Control of Generation of Code ('Code Injection') (CWE-94)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76191"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-76202",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Commerce",
      "cwe": "CWE-863",
      "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76202"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-77968",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apache Camel - HawtIO 4",
      "cwe": "CWE-269",
      "title": "Hawtio-operator: hawtio-operator: cluster-wide secrets read/write granted to operator serviceaccount",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77968"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-81354",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-122",
      "title": "Windows Hello Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81354"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-81356",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-444",
      "title": "Visual Studio Code Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81356"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-81357",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-918",
      "title": "Visual Studio Code Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81357"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-81378",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-436",
      "title": "Visual Studio Code Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81378"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-81379",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-636",
      "title": "Visual Studio Code Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81379"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-81994",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-1321",
      "title": "Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81994"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-83939",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 26H1",
      "cwe": "CWE-822",
      "title": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83939"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-86600",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Snowflake",
      "product": "Snowflake Connector for Python",
      "cwe": "CWE-441",
      "title": "Workload identity attestation generated before login host validation in Snowflake drivers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86600"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-47297",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2019 (CU 32)",
      "cwe": "CWE-502",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47297"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-55007",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2019 Cumulative Update 14",
      "cwe": "CWE-415",
      "title": "Microsoft Exchange Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55007"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-69325",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft JScript Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69325"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-69380",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-862",
      "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69380"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-69438",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-681",
      "title": "Microsoft JScript Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69438"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-69510",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Windows DHCP Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69510"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-69524",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69524"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-69530",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69530"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-69546",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69546"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-69620",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Windows DHCP Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69620"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-69680",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-346",
      "title": "Windows DNS Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69680"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-69732",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69732"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-69782",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows DNS Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69782"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-69786",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Text Shaping Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69786"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-69813",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows DNS Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69813"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-69827",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows DNS Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69827"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-69858",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows Server 2022",
      "cwe": "CWE-416",
      "title": "Windows DNS Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69858"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-69989",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows DNS Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69989"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-70342",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70342"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-70563",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-59",
      "title": "Windows Shell Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70563"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-72936",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-416",
      "title": "Windows SMB Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72936"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-72981",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "IP Helper Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72981"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-72987",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows DNS Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72987"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-75021",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fastify-cli",
      "product": "fastify-cli",
      "cwe": "CWE-1327",
      "title": "fastify-cli vulnerable to remote code execution via ignored explicit Inspector bind address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75021"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-77505",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows DNS Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77505"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-78444",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-822",
      "title": "Microsoft Failover Cluster Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78444"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-78449",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78449"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-78450",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78450"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-78626",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Okta",
      "product": "Okta Access Gateway",
      "cwe": "CWE-863",
      "title": "Improper Input Sanitization in Okta Access Gateway Protected Rules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78626"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-83527",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ivanti",
      "product": "Sentry",
      "cwe": "CWE-288",
      "title": "An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83527"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-83997",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-416",
      "title": "Windows Message Queuing Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83997"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-84393",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiOS",
      "cwe": "CWE-297",
      "title": "A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here>",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84393"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-55277",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-120",
      "title": "In checkUiccListenConfigNeeded of RoutingManager.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55277"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-68827",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows GDI+ Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68827"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-68834",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68834"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-68838",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68838"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-68876",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68876"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-68878",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Windows Fast FAT Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68878"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-68880",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68880"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-68894",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Error Reporting Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68894"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-69271",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Standard XPS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69271"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-69301",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69301"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-69322",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-415",
      "title": "Microsoft Windows Search Component Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69322"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-69332",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69332"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-69346",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Print Spooler Components Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69346"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-69365",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-125",
      "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69365"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-69371",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69371"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-69412",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Windows DHCP Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69412"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-69418",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Volume Manager Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69418"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-69423",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows USB Video Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69423"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-69427",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69427"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-69458",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows BitLocker Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69458"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-69462",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Error Reporting Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69462"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-69481",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Enterprise App Management Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69481"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-69503",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-121",
      "title": "Windows USB Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69503"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-69505",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69505"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-69512",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69512"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-69619",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows exFAT File System Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69619"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-69623",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows HTTP Print Provider Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69623"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-69625",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-122",
      "title": "Connected User Experiences and Telemetry Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69625"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-69643",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69643"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-69681",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69681"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-69689",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-121",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69689"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-69714",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69714"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-69717",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Group Policy Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69717"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-69727",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69727"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-69762",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-121",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69762"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-69773",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69773"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-69777",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-122",
      "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69777"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-69807",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-22",
      "title": "PowerShell Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69807"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-69826",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69826"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-69847",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows DHCP Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69847"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-69875",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-122",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69875"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-69876",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-415",
      "title": "Windows DHCP Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69876"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-83948",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Azure CLI",
      "cwe": "CWE-77",
      "title": "Microsoft Azure CLI Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83948"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-28664",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-693",
      "title": "In WriteImageToDisk of runtime_image.cc, there is a possible file tampering due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28664"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-49927",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-190",
      "title": "In multiple locations, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49927"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-49932",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-122",
      "title": "In parseParts of PduParser.java, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49932"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-55273",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-20",
      "title": "In AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55273"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-55285",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-120",
      "title": "In openLogicalChannel of multiple files, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55285"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-55294",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-122",
      "title": "In ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55294"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-56172",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows VHD miniport driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56172"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-56177",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56177"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-56198",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-125",
      "title": "Microsoft Trace Data Helper Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56198"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-58599",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "HEVC Video Extensions",
      "cwe": "CWE-122",
      "title": "HEVC Video Extensions Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58599"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-58600",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "HEVC Video Extensions",
      "cwe": "CWE-122",
      "title": "HEVC Video Extensions Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58600"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-58611",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Xbox Gaming Services",
      "cwe": "CWE-285",
      "title": "Xbox Gaming Services Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58611"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-58823",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-120",
      "title": "In stpropnci_process_std of stpropnci_std.cc, there is a possible memory safety issue due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58823"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-58839",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-120",
      "title": "In forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58839"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-58846",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-269",
      "title": "In kvm_iommu_map_sg of iommu.c, there is a possible use after free due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58846"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-58874",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-269",
      "title": "In multiple functions of SmsController.java, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58874"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-58941",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-20",
      "title": "In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58941"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-62697",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-416",
      "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62697"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-62804",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-73",
      "title": "Microsoft Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62804"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-62810",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62810"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-68787",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-122",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68787"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-68832",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68832"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-68841",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68841"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-68844",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Storage Spaces Controller Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68844"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-68845",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68845"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-68848",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Print Spooler Components Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68848"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-68850",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-122",
      "title": "Microsoft Account Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68850"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-68875",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-126",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68875"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-68877",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Storage Spaces Controller Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68877"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-68885",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Standard XPS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68885"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-68888",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Standard XPS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68888"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-68890",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Standard XPS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68890"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-68892",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Standard XPS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68892"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-68896",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-36",
      "title": "Microsoft Windows Search Component Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68896"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-69265",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69265"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-69269",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-191",
      "title": "Microsoft Standard XPS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69269"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-69270",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-20",
      "title": "Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69270"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-69277",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69277"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-69283",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows CD-ROM Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69283"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-69284",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows DCOM Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69284"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-69289",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-59",
      "title": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69289"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-69290",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Windows Storage Spaces Controller Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69290"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-69293",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-20",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69293"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-69295",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-20",
      "title": "Windows USB Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69295"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-69298",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69298"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-69307",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69307"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-69312",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69312"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-69323",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69323"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-69324",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Performance Monitor Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69324"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-69328",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-426",
      "title": "Windows Storage Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69328"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-69348",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-122",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69348"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-69352",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-20",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69352"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-69359",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Active Directory Domain Services Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69359"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-69368",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69368"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-69377",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-862",
      "title": "Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69377"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-69389",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Storage Management Provider Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69389"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-69391",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "Windows Broker Infrastructure Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69391"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-69392",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-416",
      "title": "Windows Shell Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69392"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-69407",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "title": "Volume Manager Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69407"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-69420",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69420"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-69421",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69421"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-69424",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Distributed File System (DFS) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69424"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-69426",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows VOLSNAP.SYS Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69426"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-69432",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Volume Manager Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69432"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-69433",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Error Reporting Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69433"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-69436",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-122",
      "title": "Windows Error Reporting Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69436"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-69444",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Windows Speech Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69444"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-69445",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-22",
      "title": "Windows Compressed Folder Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69445"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-69447",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-122",
      "title": "Windows Audio Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69447"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-69450",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Error Reporting Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69450"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-69455",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69455"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-69456",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Windows Speech Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69456"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-69459",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-122",
      "title": "Windows Power Dependency Coordinator Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69459"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-69467",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-121",
      "title": "Microsoft Graphics Component Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69467"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-69475",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-822",
      "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69475"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-69476",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69476"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-69478",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69478"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-69480",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-122",
      "title": "Windows Partition Management Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69480"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-69489",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69489"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-69508",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-121",
      "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69508"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-69509",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Role: Windows Fax Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69509"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-69513",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-122",
      "title": "Windows Error Reporting Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69513"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-69528",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-306",
      "title": "Windows Shell Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69528"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-69532",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69532"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-69534",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-77",
      "title": "Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69534"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-69535",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-122",
      "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69535"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-69538",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Spaceport.sys Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69538"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-69541",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69541"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-69542",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-122",
      "title": "Windows Camera Frame Server Monitor Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69542"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-69544",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 26H1",
      "cwe": "CWE-122",
      "title": "Windows SMB Client Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69544"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-69561",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows CD-ROM Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69561"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-69571",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69571"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-69576",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Graphic Fonts Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69576"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-69580",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69580"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-69582",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-126",
      "title": "Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69582"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-69583",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69583"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-69584",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "title": "Windows USB Video Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69584"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-69585",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-704",
      "title": "Microsoft Windows Search Component Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69585"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-69589",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69589"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-69592",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69592"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-69593",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69593"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-69594",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-122",
      "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69594"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2026-69604",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Audio Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69604"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-69608",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "title": "Microsoft Windows Search Component Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69608"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2026-69612",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-36",
      "title": "Windows Error Reporting Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69612"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2026-69685",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Kerberos Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69685"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-69687",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-191",
      "title": "Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69687"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-69691",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69691"
    },
    {
      "rank": 564,
      "cve_id": "CVE-2026-69707",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "title": "Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69707"
    },
    {
      "rank": 565,
      "cve_id": "CVE-2026-69709",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69709"
    },
    {
      "rank": 566,
      "cve_id": "CVE-2026-69720",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-122",
      "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69720"
    },
    {
      "rank": 567,
      "cve_id": "CVE-2026-69725",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-415",
      "title": "Windows Hello Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69725"
    },
    {
      "rank": 568,
      "cve_id": "CVE-2026-69731",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "HID Class Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69731"
    },
    {
      "rank": 569,
      "cve_id": "CVE-2026-69738",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69738"
    },
    {
      "rank": 570,
      "cve_id": "CVE-2026-69758",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69758"
    },
    {
      "rank": 571,
      "cve_id": "CVE-2026-69785",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-426",
      "title": "Windows Smart Card Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69785"
    },
    {
      "rank": 572,
      "cve_id": "CVE-2026-69787",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69787"
    },
    {
      "rank": 573,
      "cve_id": "CVE-2026-69790",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-122",
      "title": "Windows Credential Providers Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69790"
    },
    {
      "rank": 574,
      "cve_id": "CVE-2026-69799",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-362",
      "title": "Windows Hello Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69799"
    },
    {
      "rank": 575,
      "cve_id": "CVE-2026-69801",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-122",
      "title": "Windows Audio Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69801"
    },
    {
      "rank": 576,
      "cve_id": "CVE-2026-69821",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-116",
      "title": "Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69821"
    },
    {
      "rank": 577,
      "cve_id": "CVE-2026-69822",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-122",
      "title": "Windows Kerberos Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69822"
    },
    {
      "rank": 578,
      "cve_id": "CVE-2026-69841",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69841"
    },
    {
      "rank": 579,
      "cve_id": "CVE-2026-69844",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69844"
    },
    {
      "rank": 580,
      "cve_id": "CVE-2026-69864",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-416",
      "title": "Windows Hello Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69864"
    },
    {
      "rank": 581,
      "cve_id": "CVE-2026-69900",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-822",
      "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69900"
    },
    {
      "rank": 582,
      "cve_id": "CVE-2026-69907",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-280",
      "title": "Windows Enterprise App Management Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69907"
    },
    {
      "rank": 583,
      "cve_id": "CVE-2026-69921",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-122",
      "title": "Windows Print Spooler Components Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69921"
    },
    {
      "rank": 584,
      "cve_id": "CVE-2026-70289",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70289"
    },
    {
      "rank": 585,
      "cve_id": "CVE-2026-70334",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-184",
      "title": "Visual Studio Code Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70334"
    },
    {
      "rank": 586,
      "cve_id": "CVE-2026-70564",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Print Spooler Components Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70564"
    },
    {
      "rank": 587,
      "cve_id": "CVE-2026-70569",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-125",
      "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70569"
    },
    {
      "rank": 588,
      "cve_id": "CVE-2026-70572",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70572"
    },
    {
      "rank": 589,
      "cve_id": "CVE-2026-70574",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70574"
    },
    {
      "rank": 590,
      "cve_id": "CVE-2026-70581",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-20",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70581"
    },
    {
      "rank": 591,
      "cve_id": "CVE-2026-70583",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Core Messaging Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70583"
    },
    {
      "rank": 592,
      "cve_id": "CVE-2026-70584",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-843",
      "title": "Windows Core Messaging Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70584"
    },
    {
      "rank": 593,
      "cve_id": "CVE-2026-71334",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows NFS Portmapper Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71334"
    },
    {
      "rank": 594,
      "cve_id": "CVE-2026-71337",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-121",
      "title": "Windows Storage Management Provider Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71337"
    },
    {
      "rank": 595,
      "cve_id": "CVE-2026-71343",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Remote Access Connection Manager Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71343"
    },
    {
      "rank": 596,
      "cve_id": "CVE-2026-71345",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-787",
      "title": "Windows Spaceport.sys Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71345"
    },
    {
      "rank": 597,
      "cve_id": "CVE-2026-72929",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-354",
      "title": "Windows Installer Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72929"
    },
    {
      "rank": 598,
      "cve_id": "CVE-2026-72941",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72941"
    },
    {
      "rank": 599,
      "cve_id": "CVE-2026-72944",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Role: Windows Fax Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72944"
    },
    {
      "rank": 600,
      "cve_id": "CVE-2026-72946",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-122",
      "title": "Microsoft Storage Port Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72946"
    },
    {
      "rank": 601,
      "cve_id": "CVE-2026-72953",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-122",
      "title": "Windows USB Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72953"
    },
    {
      "rank": 602,
      "cve_id": "CVE-2026-72957",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Deployment Services Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72957"
    },
    {
      "rank": 603,
      "cve_id": "CVE-2026-72965",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows WebClient Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72965"
    },
    {
      "rank": 604,
      "cve_id": "CVE-2026-72967",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Network Connection Broker Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72967"
    },
    {
      "rank": 605,
      "cve_id": "CVE-2026-72988",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72988"
    },
    {
      "rank": 606,
      "cve_id": "CVE-2026-72990",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72990"
    },
    {
      "rank": 607,
      "cve_id": "CVE-2026-72991",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72991"
    },
    {
      "rank": 608,
      "cve_id": "CVE-2026-72992",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72992"
    },
    {
      "rank": 609,
      "cve_id": "CVE-2026-72993",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72993"
    },
    {
      "rank": 610,
      "cve_id": "CVE-2026-72994",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-20",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72994"
    },
    {
      "rank": 611,
      "cve_id": "CVE-2026-72995",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72995"
    },
    {
      "rank": 612,
      "cve_id": "CVE-2026-72996",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-20",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72996"
    },
    {
      "rank": 613,
      "cve_id": "CVE-2026-72997",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72997"
    },
    {
      "rank": 614,
      "cve_id": "CVE-2026-73000",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73000"
    },
    {
      "rank": 615,
      "cve_id": "CVE-2026-73001",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73001"
    },
    {
      "rank": 616,
      "cve_id": "CVE-2026-73002",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73002"
    },
    {
      "rank": 617,
      "cve_id": "CVE-2026-73007",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73007"
    },
    {
      "rank": 618,
      "cve_id": "CVE-2026-73011",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73011"
    },
    {
      "rank": 619,
      "cve_id": "CVE-2026-73014",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-862",
      "title": "Data Sharing Service Client Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73014"
    },
    {
      "rank": 620,
      "cve_id": "CVE-2026-73015",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73015"
    },
    {
      "rank": 621,
      "cve_id": "CVE-2026-73020",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73020"
    },
    {
      "rank": 622,
      "cve_id": "CVE-2026-73021",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-20",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73021"
    },
    {
      "rank": 623,
      "cve_id": "CVE-2026-73024",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Services for NFS ONCRPC XDR Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73024"
    },
    {
      "rank": 624,
      "cve_id": "CVE-2026-73026",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73026"
    },
    {
      "rank": 625,
      "cve_id": "CVE-2026-75631",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Photoshop 2026",
      "cwe": "CWE-787",
      "title": "Photoshop Desktop | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75631"
    },
    {
      "rank": 626,
      "cve_id": "CVE-2026-75771",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Photoshop 2026",
      "cwe": "CWE-190",
      "title": "Photoshop Desktop | Integer Overflow or Wraparound (CWE-190)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75771"
    },
    {
      "rank": 627,
      "cve_id": "CVE-2026-75862",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Photoshop 2026",
      "cwe": "CWE-190",
      "title": "Photoshop Desktop | Integer Overflow or Wraparound (CWE-190)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75862"
    },
    {
      "rank": 628,
      "cve_id": "CVE-2026-75863",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Photoshop 2026",
      "cwe": "CWE-190",
      "title": "Photoshop Desktop | Integer Overflow or Wraparound (CWE-190)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75863"
    },
    {
      "rank": 629,
      "cve_id": "CVE-2026-75992",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Illustrator Desktop 2026",
      "cwe": "CWE-787",
      "title": "Illustrator | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75992"
    },
    {
      "rank": 630,
      "cve_id": "CVE-2026-77489",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-476",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77489"
    },
    {
      "rank": 631,
      "cve_id": "CVE-2026-77500",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-763",
      "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77500"
    },
    {
      "rank": 632,
      "cve_id": "CVE-2026-77904",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77904"
    },
    {
      "rank": 633,
      "cve_id": "CVE-2026-78447",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78447"
    },
    {
      "rank": 634,
      "cve_id": "CVE-2026-78448",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78448"
    },
    {
      "rank": 635,
      "cve_id": "CVE-2026-79907",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-415",
      "title": "Acrobat Reader | Double Free (CWE-415)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79907"
    },
    {
      "rank": 636,
      "cve_id": "CVE-2026-79908",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-787",
      "title": "Acrobat Reader | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79908"
    },
    {
      "rank": 637,
      "cve_id": "CVE-2026-79909",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79909"
    },
    {
      "rank": 638,
      "cve_id": "CVE-2026-80075",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-122",
      "title": "Windows Work Folders Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80075"
    },
    {
      "rank": 639,
      "cve_id": "CVE-2026-80161",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-843",
      "title": "Acrobat Reader | Access of Resource Using Incompatible Type ('Type Confusion') (CWE-843)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80161"
    },
    {
      "rank": 640,
      "cve_id": "CVE-2026-81353",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "HEIF Image Extension",
      "cwe": "CWE-122",
      "title": "HEIF Image Extensions Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81353"
    },
    {
      "rank": 641,
      "cve_id": "CVE-2026-81386",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81386"
    },
    {
      "rank": 642,
      "cve_id": "CVE-2026-81388",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-121",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81388"
    },
    {
      "rank": 643,
      "cve_id": "CVE-2026-81396",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-121",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81396"
    },
    {
      "rank": 644,
      "cve_id": "CVE-2026-81397",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81397"
    },
    {
      "rank": 645,
      "cve_id": "CVE-2026-81398",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81398"
    },
    {
      "rank": 646,
      "cve_id": "CVE-2026-81947",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81947"
    },
    {
      "rank": 647,
      "cve_id": "CVE-2026-81948",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81948"
    },
    {
      "rank": 648,
      "cve_id": "CVE-2026-81949",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-190",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81949"
    },
    {
      "rank": 649,
      "cve_id": "CVE-2026-81950",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-415",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81950"
    },
    {
      "rank": 650,
      "cve_id": "CVE-2026-81951",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81951"
    },
    {
      "rank": 651,
      "cve_id": "CVE-2026-81953",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-121",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81953"
    },
    {
      "rank": 652,
      "cve_id": "CVE-2026-81954",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-416",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81954"
    },
    {
      "rank": 653,
      "cve_id": "CVE-2026-81956",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81956"
    },
    {
      "rank": 654,
      "cve_id": "CVE-2026-81957",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81957"
    },
    {
      "rank": 655,
      "cve_id": "CVE-2026-81959",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81959"
    },
    {
      "rank": 656,
      "cve_id": "CVE-2026-81960",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81960"
    },
    {
      "rank": 657,
      "cve_id": "CVE-2026-81973",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81973"
    },
    {
      "rank": 658,
      "cve_id": "CVE-2026-81975",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81975"
    },
    {
      "rank": 659,
      "cve_id": "CVE-2026-81976",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81976"
    },
    {
      "rank": 660,
      "cve_id": "CVE-2026-81979",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-787",
      "title": "Acrobat Reader | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81979"
    },
    {
      "rank": 661,
      "cve_id": "CVE-2026-81980",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-787",
      "title": "Acrobat Reader | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81980"
    },
    {
      "rank": 662,
      "cve_id": "CVE-2026-81981",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-787",
      "title": "Acrobat Reader | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81981"
    },
    {
      "rank": 663,
      "cve_id": "CVE-2026-81983",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-787",
      "title": "Acrobat Reader | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81983"
    },
    {
      "rank": 664,
      "cve_id": "CVE-2026-81985",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81985"
    },
    {
      "rank": 665,
      "cve_id": "CVE-2026-81986",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81986"
    },
    {
      "rank": 666,
      "cve_id": "CVE-2026-81987",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-190",
      "title": "Acrobat Reader | Integer Overflow or Wraparound (CWE-190)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81987"
    },
    {
      "rank": 667,
      "cve_id": "CVE-2026-81988",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81988"
    },
    {
      "rank": 668,
      "cve_id": "CVE-2026-81989",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81989"
    },
    {
      "rank": 669,
      "cve_id": "CVE-2026-81990",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81990"
    },
    {
      "rank": 670,
      "cve_id": "CVE-2026-81992",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-122",
      "title": "Acrobat Reader | Heap-based Buffer Overflow (CWE-122)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81992"
    },
    {
      "rank": 671,
      "cve_id": "CVE-2026-82005",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Photoshop 2026",
      "cwe": "CWE-787",
      "title": "Photoshop Desktop | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82005"
    },
    {
      "rank": 672,
      "cve_id": "CVE-2026-82006",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Photoshop 2026",
      "cwe": "CWE-122",
      "title": "Photoshop Desktop | Heap-based Buffer Overflow (CWE-122)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82006"
    },
    {
      "rank": 673,
      "cve_id": "CVE-2026-82007",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Photoshop 2026",
      "cwe": "CWE-190",
      "title": "Photoshop Desktop | Integer Overflow or Wraparound (CWE-190)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82007"
    },
    {
      "rank": 674,
      "cve_id": "CVE-2026-83498",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-822",
      "title": "Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83498"
    },
    {
      "rank": 675,
      "cve_id": "CVE-2026-83942",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-862",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83942"
    },
    {
      "rank": 676,
      "cve_id": "CVE-2026-83952",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-122",
      "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83952"
    },
    {
      "rank": 677,
      "cve_id": "CVE-2026-83954",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83954"
    },
    {
      "rank": 678,
      "cve_id": "CVE-2026-83955",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83955"
    },
    {
      "rank": 679,
      "cve_id": "CVE-2026-83967",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83967"
    },
    {
      "rank": 680,
      "cve_id": "CVE-2026-83968",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-400",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83968"
    },
    {
      "rank": 681,
      "cve_id": "CVE-2026-83969",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83969"
    },
    {
      "rank": 682,
      "cve_id": "CVE-2026-83970",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83970"
    },
    {
      "rank": 683,
      "cve_id": "CVE-2026-83971",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83971"
    },
    {
      "rank": 684,
      "cve_id": "CVE-2026-83972",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83972"
    },
    {
      "rank": 685,
      "cve_id": "CVE-2026-83973",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83973"
    },
    {
      "rank": 686,
      "cve_id": "CVE-2026-83974",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83974"
    },
    {
      "rank": 687,
      "cve_id": "CVE-2026-83975",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83975"
    },
    {
      "rank": 688,
      "cve_id": "CVE-2026-83976",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83976"
    },
    {
      "rank": 689,
      "cve_id": "CVE-2026-83977",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83977"
    },
    {
      "rank": 690,
      "cve_id": "CVE-2026-83978",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83978"
    },
    {
      "rank": 691,
      "cve_id": "CVE-2026-83979",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83979"
    },
    {
      "rank": 692,
      "cve_id": "CVE-2026-83980",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83980"
    },
    {
      "rank": 693,
      "cve_id": "CVE-2026-83981",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83981"
    },
    {
      "rank": 694,
      "cve_id": "CVE-2026-83982",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83982"
    },
    {
      "rank": 695,
      "cve_id": "CVE-2026-83983",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83983"
    },
    {
      "rank": 696,
      "cve_id": "CVE-2026-83985",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83985"
    },
    {
      "rank": 697,
      "cve_id": "CVE-2026-83986",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83986"
    },
    {
      "rank": 698,
      "cve_id": "CVE-2026-83987",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83987"
    },
    {
      "rank": 699,
      "cve_id": "CVE-2026-83988",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83988"
    },
    {
      "rank": 700,
      "cve_id": "CVE-2026-83990",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-121",
      "title": "Microsoft Graphics Component Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83990"
    },
    {
      "rank": 701,
      "cve_id": "CVE-2026-83995",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83995"
    },
    {
      "rank": 702,
      "cve_id": "CVE-2026-84000",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Graphics Component Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84000"
    },
    {
      "rank": 703,
      "cve_id": "CVE-2026-85983",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Auth0",
      "product": "Auth0 AD/LDAP Connector",
      "cwe": "CWE-94",
      "title": "Local Privilege Escalation in Auth0 AD/LDAP Connector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85983"
    },
    {
      "rank": 704,
      "cve_id": "CVE-2026-73315",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XenForo",
      "product": "XenForo",
      "cwe": "CWE-918",
      "title": "XenForo < 2.3.13 SSRF via PayPal REST Webhook Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73315"
    },
    {
      "rank": 705,
      "cve_id": "CVE-2026-77106",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Commvault",
      "product": "Commvault Cloud",
      "cwe": "CWE-862",
      "title": "Cvlaunchd Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77106"
    },
    {
      "rank": 706,
      "cve_id": "CVE-2026-77909",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure CycleCloud 8.9.2",
      "cwe": "CWE-522",
      "title": "Azure CycleCloud Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77909"
    },
    {
      "rank": 707,
      "cve_id": "CVE-2026-78623",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Okta",
      "product": "Okta Access Gateway",
      "cwe": "CWE-89",
      "title": "Improper Handling of SAML Assertion Attributes in Okta Access Gateway Advanced Mode Datastores",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78623"
    },
    {
      "rank": 708,
      "cve_id": "CVE-2026-82536",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RooCodeInc",
      "product": "Roo-Code",
      "cwe": "CWE-184",
      "title": "Roo-Code 3.54.0 Auto-Approve Bypass via Shell Command Pipe Operator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82536"
    },
    {
      "rank": 709,
      "cve_id": "CVE-2026-82537",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RooCodeInc",
      "product": "Roo-Code",
      "cwe": "CWE-436",
      "title": "Roo-Code 3.54.0 Auto-Approve Bypass via Shell Parser Word-Boundary Mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82537"
    },
    {
      "rank": 710,
      "cve_id": "CVE-2026-86083",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-94",
      "title": "n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86083"
    },
    {
      "rank": 711,
      "cve_id": "CVE-2026-73313",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XenForo",
      "product": "XenForo",
      "cwe": "CWE-863",
      "title": "XenForo < 2.3.13 MFA Bypass via Passkey TFA Provider",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73313"
    },
    {
      "rank": 712,
      "cve_id": "CVE-2026-77110",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Commerce",
      "cwe": "CWE-22",
      "title": "Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77110"
    },
    {
      "rank": 713,
      "cve_id": "CVE-2026-82053",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-863",
      "title": "Improper Session Handling in MongoDB Server LDAP Authorization Integration Leads to Incorrect Role Assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82053"
    },
    {
      "rank": 714,
      "cve_id": "CVE-2026-3174",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stellarwp",
      "product": "Event Tickets and Registration",
      "cwe": "CWE-862",
      "title": "Event Tickets and Registration <= 5.27.4 - Missing Authorization to Unauthenticated Stripe Credentials Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3174"
    },
    {
      "rank": 715,
      "cve_id": "CVE-2026-16025",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PayTR Payment and Electronic Money Institution Inc.",
      "product": "PayTR Virtual Pos iFrame API (v9x) WHMCS Module",
      "cwe": "CWE-1284",
      "title": "Improper Payment Validation in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16025"
    },
    {
      "rank": 716,
      "cve_id": "CVE-2026-16037",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PayTR Payment and Electronic Money Institution Inc.",
      "product": "PayTR Virtual Pos iFrame API (v9x) WHMCS Module",
      "cwe": "CWE-208",
      "title": "Callback Authentication Bypass via Timing Attack in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16037"
    },
    {
      "rank": 717,
      "cve_id": "CVE-2026-16497",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Triton Inference Server",
      "cwe": "CWE-834",
      "title": "NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16497"
    },
    {
      "rank": 718,
      "cve_id": "CVE-2026-47625",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Triton Inference Server",
      "cwe": "CWE-862",
      "title": "NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47625"
    },
    {
      "rank": 719,
      "cve_id": "CVE-2026-57098",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Remote Desktop client for Windows Desktop",
      "cwe": "CWE-347",
      "title": "Microsoft Remote Desktop App for Windows Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57098"
    },
    {
      "rank": 720,
      "cve_id": "CVE-2026-57099",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "AspNetCore.OData",
      "cwe": "CWE-770",
      "title": "ASP.NET Core Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57099"
    },
    {
      "rank": 721,
      "cve_id": "CVE-2026-62759",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-290",
      "title": "Windows Netlogon Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62759"
    },
    {
      "rank": 722,
      "cve_id": "CVE-2026-62813",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62813"
    },
    {
      "rank": 723,
      "cve_id": "CVE-2026-66304",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Skype for Business Server 2015 CU13",
      "cwe": "CWE-918",
      "title": "Skype for Business Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66304"
    },
    {
      "rank": 724,
      "cve_id": "CVE-2026-66307",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Skype for Business Server 2015 CU13",
      "cwe": "CWE-191",
      "title": "Skype for Business and Lync Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66307"
    },
    {
      "rank": 725,
      "cve_id": "CVE-2026-67376",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-190",
      "title": "Microsoft SQL Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67376"
    },
    {
      "rank": 726,
      "cve_id": "CVE-2026-68887",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Message Queuing Queue Manager Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68887"
    },
    {
      "rank": 727,
      "cve_id": "CVE-2026-69329",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "BranchCache Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69329"
    },
    {
      "rank": 728,
      "cve_id": "CVE-2026-69342",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows DHCP Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69342"
    },
    {
      "rank": 729,
      "cve_id": "CVE-2026-69378",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-674",
      "title": "Microsoft Exchange Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69378"
    },
    {
      "rank": 730,
      "cve_id": "CVE-2026-69397",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Microsoft OpenSSH for Windows Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69397"
    },
    {
      "rank": 731,
      "cve_id": "CVE-2026-69428",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows LDAP - Lightweight Directory Access Protocol Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69428"
    },
    {
      "rank": 732,
      "cve_id": "CVE-2026-69429",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-122",
      "title": "Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69429"
    },
    {
      "rank": 733,
      "cve_id": "CVE-2026-69443",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-125",
      "title": "Windows Device Health Attestation (DHA) Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69443"
    },
    {
      "rank": 734,
      "cve_id": "CVE-2026-69514",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Remote Desktop Services Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69514"
    },
    {
      "rank": 735,
      "cve_id": "CVE-2026-69539",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Remote Desktop Services Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69539"
    },
    {
      "rank": 736,
      "cve_id": "CVE-2026-69587",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-476",
      "title": "Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69587"
    },
    {
      "rank": 737,
      "cve_id": "CVE-2026-69588",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-401",
      "title": "Windows TCP/IP Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69588"
    },
    {
      "rank": 738,
      "cve_id": "CVE-2026-69599",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-416",
      "title": "Remote Desktop Services Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69599"
    },
    {
      "rank": 739,
      "cve_id": "CVE-2026-69607",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Deployment Services Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69607"
    },
    {
      "rank": 740,
      "cve_id": "CVE-2026-69631",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "title": "Windows DNS Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69631"
    },
    {
      "rank": 741,
      "cve_id": "CVE-2026-69710",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-362",
      "title": "Windows Hello Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69710"
    },
    {
      "rank": 742,
      "cve_id": "CVE-2026-69744",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-476",
      "title": "Windows Kerberos Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69744"
    },
    {
      "rank": 743,
      "cve_id": "CVE-2026-69760",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Kerberos Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69760"
    },
    {
      "rank": 744,
      "cve_id": "CVE-2026-69793",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-1288",
      "title": "Windows TCP/IP Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69793"
    },
    {
      "rank": 745,
      "cve_id": "CVE-2026-69804",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "cwe": "CWE-367",
      "title": "Microsoft Office SharePoint Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69804"
    },
    {
      "rank": 746,
      "cve_id": "CVE-2026-69805",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Visual Studio 2022 version 17.14",
      "cwe": "CWE-73",
      "title": ".NET Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69805"
    },
    {
      "rank": 747,
      "cve_id": "CVE-2026-69809",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-401",
      "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69809"
    },
    {
      "rank": 748,
      "cve_id": "CVE-2026-69852",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69852"
    },
    {
      "rank": 749,
      "cve_id": "CVE-2026-69881",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-476",
      "title": "Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69881"
    },
    {
      "rank": 750,
      "cve_id": "CVE-2026-69890",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows Virtual Trusted Platform Module Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69890"
    },
    {
      "rank": 751,
      "cve_id": "CVE-2026-70065",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-401",
      "title": "Windows DHCP Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70065"
    },
    {
      "rank": 752,
      "cve_id": "CVE-2026-70570",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70570"
    },
    {
      "rank": 753,
      "cve_id": "CVE-2026-70579",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-125",
      "title": "Windows Mobile Broadband Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70579"
    },
    {
      "rank": 754,
      "cve_id": "CVE-2026-70587",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-170",
      "title": "Windows Remote Desktop Protocol Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70587"
    },
    {
      "rank": 755,
      "cve_id": "CVE-2026-71330",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-497",
      "title": "Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71330"
    },
    {
      "rank": 756,
      "cve_id": "CVE-2026-72923",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "OpenApi.YamlReader",
      "cwe": "CWE-400",
      "title": "Microsoft.OpenApi.YamlReader/Readers vulnerable to denial of service via YAML alias expansion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72923"
    },
    {
      "rank": 757,
      "cve_id": "CVE-2026-72928",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows Server 2025",
      "cwe": "CWE-416",
      "title": "Windows DNS Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72928"
    },
    {
      "rank": 758,
      "cve_id": "CVE-2026-72932",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-126",
      "title": "Windows Message Queuing Queue Manager Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72932"
    },
    {
      "rank": 759,
      "cve_id": "CVE-2026-72943",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Deployment Services Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72943"
    },
    {
      "rank": 760,
      "cve_id": "CVE-2026-72949",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-476",
      "title": "Windows SMB Server Network Transport Driver (srvnet.sys) Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72949"
    },
    {
      "rank": 761,
      "cve_id": "CVE-2026-72954",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Deployment Services Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72954"
    },
    {
      "rank": 762,
      "cve_id": "CVE-2026-72989",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-908",
      "title": "Windows Failover Cluster Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72989"
    },
    {
      "rank": 763,
      "cve_id": "CVE-2026-73017",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-122",
      "title": "Graphics Kernel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73017"
    },
    {
      "rank": 764,
      "cve_id": "CVE-2026-75998",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-284",
      "title": "ColdFusion | Improper Access Control (CWE-284)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75998"
    },
    {
      "rank": 765,
      "cve_id": "CVE-2026-77108",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Commerce",
      "cwe": "CWE-863",
      "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77108"
    },
    {
      "rank": 766,
      "cve_id": "CVE-2026-77494",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-843",
      "title": "Windows DHCP Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77494"
    },
    {
      "rank": 767,
      "cve_id": "CVE-2026-77498",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows DHCP Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77498"
    },
    {
      "rank": 768,
      "cve_id": "CVE-2026-77499",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-843",
      "title": "Windows DHCP Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77499"
    },
    {
      "rank": 769,
      "cve_id": "CVE-2026-77501",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows DHCP Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77501"
    },
    {
      "rank": 770,
      "cve_id": "CVE-2026-77502",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows DHCP Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77502"
    },
    {
      "rank": 771,
      "cve_id": "CVE-2026-77886",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows DHCP Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77886"
    },
    {
      "rank": 772,
      "cve_id": "CVE-2026-77888",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-843",
      "title": "Windows DHCP Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77888"
    },
    {
      "rank": 773,
      "cve_id": "CVE-2026-77889",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-843",
      "title": "Windows DHCP Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77889"
    },
    {
      "rank": 774,
      "cve_id": "CVE-2026-77890",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-843",
      "title": "Windows DHCP Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77890"
    },
    {
      "rank": 775,
      "cve_id": "CVE-2026-77893",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows DHCP Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77893"
    },
    {
      "rank": 776,
      "cve_id": "CVE-2026-77895",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows DHCP Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77895"
    },
    {
      "rank": 777,
      "cve_id": "CVE-2026-77898",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77898"
    },
    {
      "rank": 778,
      "cve_id": "CVE-2026-78574",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Okta",
      "product": "Okta Hyperdrive Integration Plugin",
      "cwe": "CWE-426",
      "title": "Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78574"
    },
    {
      "rank": 779,
      "cve_id": "CVE-2026-79377",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "A heap overflow in the a2dp_decoder_sbc.cpp component of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79377"
    },
    {
      "rank": 780,
      "cve_id": "CVE-2026-81355",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81355"
    },
    {
      "rank": 781,
      "cve_id": "CVE-2026-83989",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Services for NFS ONCRPC XDR Driver Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83989"
    },
    {
      "rank": 782,
      "cve_id": "CVE-2026-84001",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Key Distribution Center Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84001"
    },
    {
      "rank": 783,
      "cve_id": "CVE-2026-86711",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electerm",
      "product": "electerm",
      "cwe": "CWE-749",
      "title": "electerm before 5.3.15 Arbitrary Command Execution via Unvalidated runGlobalAsync IPC Bridge",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86711"
    },
    {
      "rank": 784,
      "cve_id": "CVE-2026-19651",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Enterprise Build of Quarkus",
      "cwe": "CWE-639",
      "title": "IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19651"
    },
    {
      "rank": 785,
      "cve_id": "CVE-2026-69347",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Fast FAT Driver Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69347"
    },
    {
      "rank": 786,
      "cve_id": "CVE-2026-76196",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Photoshop Android",
      "cwe": "CWE-384",
      "title": "Photoshop Mobile | Session Fixation (CWE-384)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76196"
    },
    {
      "rank": 787,
      "cve_id": "CVE-2026-78461",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-22",
      "title": "Visual Studio Code Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78461"
    },
    {
      "rank": 788,
      "cve_id": "CVE-2026-81383",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-706",
      "title": "Visual Studio Code Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81383"
    },
    {
      "rank": 789,
      "cve_id": "CVE-2026-84003",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Authentication Library",
      "cwe": "CWE-294",
      "title": "Microsoft Authentication Library (MSAL) for Node.js Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84003"
    },
    {
      "rank": 790,
      "cve_id": "CVE-2026-69402",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "cwe": "CWE-79",
      "title": "Microsoft Office SharePoint Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69402"
    },
    {
      "rank": 791,
      "cve_id": "CVE-2026-69417",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "cwe": "CWE-79",
      "title": "Microsoft Office SharePoint Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69417"
    },
    {
      "rank": 792,
      "cve_id": "CVE-2026-69477",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Access Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69477"
    },
    {
      "rank": 793,
      "cve_id": "CVE-2026-77092",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Commvault",
      "product": "Commvault Cloud",
      "cwe": "CWE-502",
      "title": "Content Extractor Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77092"
    },
    {
      "rank": 794,
      "cve_id": "CVE-2026-78627",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Okta",
      "product": "Okta Hyperdrive Integration Plugin",
      "cwe": "CWE-532",
      "title": "Improper Credential Protection in Okta Hyperdrive Integration Installer Logging",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78627"
    },
    {
      "rank": 795,
      "cve_id": "CVE-2026-81349",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure HDInsight",
      "cwe": "CWE-78",
      "title": "Azure HDInsight Ambari Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81349"
    },
    {
      "rank": 796,
      "cve_id": "CVE-2026-82061",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-416",
      "title": "Use-After-Free in MongoDB Server Query Execution Memory Tracking Subsystem Leads to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82061"
    },
    {
      "rank": 797,
      "cve_id": "CVE-2026-82071",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-787",
      "title": "Insufficient Validation of Storage Engine Configuration Options in MongoDB Server Leads to Out-of-Bounds Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82071"
    },
    {
      "rank": 798,
      "cve_id": "CVE-2026-84387",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiSandbox",
      "cwe": "CWE-77",
      "title": "A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via <insert attack vector here>",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84387"
    },
    {
      "rank": 799,
      "cve_id": "CVE-2026-11573",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qt",
      "product": "qt",
      "cwe": "CWE-674",
      "title": "QDomDocument::toByteArray() crashes when parsing svg file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11573"
    },
    {
      "rank": 800,
      "cve_id": "CVE-2026-16769",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "silabs.com",
      "product": "WiseCnnect",
      "cwe": "CWE-440",
      "title": "RS9116W/SiWx917 plaintext pause encryption request causes DOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16769"
    },
    {
      "rank": 801,
      "cve_id": "CVE-2026-20293",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Enterprise NFV Infrastructure Software",
      "cwe": "CWE-749",
      "title": "Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20293"
    },
    {
      "rank": 802,
      "cve_id": "CVE-2026-66305",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Skype for Business Server 2015 CU13",
      "cwe": "CWE-603",
      "title": "Skype for Business Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66305"
    },
    {
      "rank": 803,
      "cve_id": "CVE-2026-68835",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Print Spooler Components Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68835"
    },
    {
      "rank": 804,
      "cve_id": "CVE-2026-68846",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68846"
    },
    {
      "rank": 805,
      "cve_id": "CVE-2026-68889",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Standard XPS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68889"
    },
    {
      "rank": 806,
      "cve_id": "CVE-2026-68893",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Remote Desktop Licensing Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68893"
    },
    {
      "rank": 807,
      "cve_id": "CVE-2026-69272",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Standard XPS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69272"
    },
    {
      "rank": 808,
      "cve_id": "CVE-2026-69274",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69274"
    },
    {
      "rank": 809,
      "cve_id": "CVE-2026-69296",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69296"
    },
    {
      "rank": 810,
      "cve_id": "CVE-2026-69305",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Microsoft Windows Search Component Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69305"
    },
    {
      "rank": 811,
      "cve_id": "CVE-2026-69313",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Standard XPS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69313"
    },
    {
      "rank": 812,
      "cve_id": "CVE-2026-69314",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Device Association Broker Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69314"
    },
    {
      "rank": 813,
      "cve_id": "CVE-2026-69336",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Standard XPS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69336"
    },
    {
      "rank": 814,
      "cve_id": "CVE-2026-69337",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-415",
      "title": "Windows Registry Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69337"
    },
    {
      "rank": 815,
      "cve_id": "CVE-2026-69338",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Remote Desktop Gateway Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69338"
    },
    {
      "rank": 816,
      "cve_id": "CVE-2026-69340",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69340"
    },
    {
      "rank": 817,
      "cve_id": "CVE-2026-69357",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows NDIS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69357"
    },
    {
      "rank": 818,
      "cve_id": "CVE-2026-69358",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-908",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69358"
    },
    {
      "rank": 819,
      "cve_id": "CVE-2026-69364",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows Print Spooler Components Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69364"
    },
    {
      "rank": 820,
      "cve_id": "CVE-2026-69366",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69366"
    },
    {
      "rank": 821,
      "cve_id": "CVE-2026-69384",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-476",
      "title": "Virtual Hard Disk (VHD) Miniport Driver Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69384"
    },
    {
      "rank": 822,
      "cve_id": "CVE-2026-69396",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows NDIS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69396"
    },
    {
      "rank": 823,
      "cve_id": "CVE-2026-69451",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Management Instrumentation Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69451"
    },
    {
      "rank": 824,
      "cve_id": "CVE-2026-69460",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69460"
    },
    {
      "rank": 825,
      "cve_id": "CVE-2026-69482",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-379",
      "title": "Windows Error Reporting Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69482"
    },
    {
      "rank": 826,
      "cve_id": "CVE-2026-69536",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-416",
      "title": "Remote Desktop Services Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69536"
    },
    {
      "rank": 827,
      "cve_id": "CVE-2026-69553",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-862",
      "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69553"
    },
    {
      "rank": 828,
      "cve_id": "CVE-2026-69597",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-416",
      "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69597"
    },
    {
      "rank": 829,
      "cve_id": "CVE-2026-69602",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69602"
    },
    {
      "rank": 830,
      "cve_id": "CVE-2026-69688",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69688"
    },
    {
      "rank": 831,
      "cve_id": "CVE-2026-69706",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69706"
    },
    {
      "rank": 832,
      "cve_id": "CVE-2026-69757",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69757"
    },
    {
      "rank": 833,
      "cve_id": "CVE-2026-69761",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69761"
    },
    {
      "rank": 834,
      "cve_id": "CVE-2026-69775",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-416",
      "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69775"
    },
    {
      "rank": 835,
      "cve_id": "CVE-2026-73321",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XenForo",
      "product": "XenForo",
      "cwe": "CWE-674",
      "title": "XenForo < 2.3.13 Uncontrolled Recursion DoS via BBCode Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73321"
    },
    {
      "rank": 836,
      "cve_id": "CVE-2026-82052",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-617",
      "title": "$regexFindAll may crash mongod server when byte-matching multi-byte UTF-8 chars",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82052"
    },
    {
      "rank": 837,
      "cve_id": "CVE-2026-82054",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-770",
      "title": "Uncontrolled Resource Consumption in MongoDB Server JSON Pointer Parser Leads to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82054"
    },
    {
      "rank": 838,
      "cve_id": "CVE-2026-82055",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-476",
      "title": "Null Pointer Dereference in MongoDB Server 2dsphere Index Key Generation Leads to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82055"
    },
    {
      "rank": 839,
      "cve_id": "CVE-2026-82057",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-843",
      "title": "Type Confusion in MongoDB Server WiredTiger Storage Engine via Custom Collection Configuration Leads to Persistent Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82057"
    },
    {
      "rank": 840,
      "cve_id": "CVE-2026-82058",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-248",
      "title": "Unhandled Exception in MongoDB Server JSON Schema Validation Error Generation Leads to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82058"
    },
    {
      "rank": 841,
      "cve_id": "CVE-2026-82065",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-617",
      "title": "Insufficient Validation of Storage Configuration Options in MongoDB Server Leads to Persistent Denial of Service via Corrupted Metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82065"
    },
    {
      "rank": 842,
      "cve_id": "CVE-2026-82068",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-617",
      "title": "Persistent Fatal Assertion Crash in MongoDB Server via Crafted Retryable Write Commands Leads to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82068"
    },
    {
      "rank": 843,
      "cve_id": "CVE-2026-82070",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-522",
      "title": "Insufficiently Protected Credentials in MongoDB Server Diagnostic Reporting Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82070"
    },
    {
      "rank": 844,
      "cve_id": "CVE-2026-82073",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-863",
      "title": "Improper Validation in MongoDB Server Aggregation Framework Allows Authorization Bypass and Unauthorized Collection Access with Atlas Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82073"
    },
    {
      "rank": 845,
      "cve_id": "CVE-2026-82074",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in MongoDB Server Aggregation Framework Allows Unauthorized Read Access to Collection Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82074"
    },
    {
      "rank": 846,
      "cve_id": "CVE-2026-82076",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-190",
      "title": "Integer Overflow in Query Planner Leads to Unbounded Memory Allocation and Denial of Service in MongoDB Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82076"
    },
    {
      "rank": 847,
      "cve_id": "CVE-2026-86081",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-1333",
      "title": "n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86081"
    },
    {
      "rank": 848,
      "cve_id": "CVE-2026-86082",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-918",
      "title": "n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86082"
    },
    {
      "rank": 849,
      "cve_id": "CVE-2026-86713",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PX4",
      "product": "PX4-Autopilot",
      "cwe": "CWE-416",
      "title": "PX4 Autopilot through 1.17.0 Use-After-Free in load_mon",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86713"
    },
    {
      "rank": 850,
      "cve_id": "CVE-2026-86718",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-352",
      "title": "WWBN AVideo Cross-Site Request Forgery via deleteHistory.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86718"
    },
    {
      "rank": 851,
      "cve_id": "CVE-2026-86724",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-352",
      "title": "AVideo YPTWallet saveBalance.php Cross-Site Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86724"
    },
    {
      "rank": 852,
      "cve_id": "CVE-2026-86725",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-639",
      "title": "AVideo SocialMediaPublisher Missing Authorization via add.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86725"
    },
    {
      "rank": 853,
      "cve_id": "CVE-2026-86726",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-522",
      "title": "AVideo through 29.0 Information Disclosure via restreamsActive.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86726"
    },
    {
      "rank": 854,
      "cve_id": "CVE-2026-86731",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-862",
      "title": "Craft CMS 5.0.0-RC1 before 5.10.12 Permission Escalation via UsersController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86731"
    },
    {
      "rank": 855,
      "cve_id": "CVE-2026-86734",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-400",
      "title": "Snipe-IT before 8.7.1 Denial of Service via Unbounded Note Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86734"
    },
    {
      "rank": 856,
      "cve_id": "CVE-2026-50349",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50349"
    },
    {
      "rank": 857,
      "cve_id": "CVE-2026-58848",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-362",
      "title": "In multiple functions of alloc.c, there is a possible unauthorized read/write access due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58848"
    },
    {
      "rank": 858,
      "cve_id": "CVE-2026-62694",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Installer Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62694"
    },
    {
      "rank": 859,
      "cve_id": "CVE-2026-68824",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-362",
      "title": "Connected User Experiences and Telemetry Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68824"
    },
    {
      "rank": 860,
      "cve_id": "CVE-2026-68825",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-416",
      "title": "Windows Bind Filter Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68825"
    },
    {
      "rank": 861,
      "cve_id": "CVE-2026-68837",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows File History Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68837"
    },
    {
      "rank": 862,
      "cve_id": "CVE-2026-68840",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows USB Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68840"
    },
    {
      "rank": 863,
      "cve_id": "CVE-2026-68847",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-416",
      "title": "Connected User Experiences and Telemetry Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68847"
    },
    {
      "rank": 864,
      "cve_id": "CVE-2026-68884",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68884"
    },
    {
      "rank": 865,
      "cve_id": "CVE-2026-68897",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Microsoft Standard XPS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68897"
    },
    {
      "rank": 866,
      "cve_id": "CVE-2026-69275",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69275"
    },
    {
      "rank": 867,
      "cve_id": "CVE-2026-69279",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69279"
    },
    {
      "rank": 868,
      "cve_id": "CVE-2026-69280",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69280"
    },
    {
      "rank": 869,
      "cve_id": "CVE-2026-69281",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows License Manager Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69281"
    },
    {
      "rank": 870,
      "cve_id": "CVE-2026-69287",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69287"
    },
    {
      "rank": 871,
      "cve_id": "CVE-2026-69292",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-415",
      "title": "Remote Desktop Gateway Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69292"
    },
    {
      "rank": 872,
      "cve_id": "CVE-2026-69299",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-416",
      "title": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69299"
    },
    {
      "rank": 873,
      "cve_id": "CVE-2026-69300",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-416",
      "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69300"
    },
    {
      "rank": 874,
      "cve_id": "CVE-2026-69309",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-415",
      "title": "Windows Print Spooler Components Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69309"
    },
    {
      "rank": 875,
      "cve_id": "CVE-2026-69310",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows DNS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69310"
    },
    {
      "rank": 876,
      "cve_id": "CVE-2026-69311",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Audio Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69311"
    },
    {
      "rank": 877,
      "cve_id": "CVE-2026-69319",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows USB Video Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69319"
    },
    {
      "rank": 878,
      "cve_id": "CVE-2026-69331",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69331"
    },
    {
      "rank": 879,
      "cve_id": "CVE-2026-69333",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69333"
    },
    {
      "rank": 880,
      "cve_id": "CVE-2026-69335",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69335"
    },
    {
      "rank": 881,
      "cve_id": "CVE-2026-69341",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Image Acquisition Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69341"
    },
    {
      "rank": 882,
      "cve_id": "CVE-2026-69362",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Error Reporting Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69362"
    },
    {
      "rank": 883,
      "cve_id": "CVE-2026-69379",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-59",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69379"
    },
    {
      "rank": 884,
      "cve_id": "CVE-2026-69383",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-73",
      "title": "Windows Shell Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69383"
    },
    {
      "rank": 885,
      "cve_id": "CVE-2026-69385",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69385"
    },
    {
      "rank": 886,
      "cve_id": "CVE-2026-69388",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows Bluetooth Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69388"
    },
    {
      "rank": 887,
      "cve_id": "CVE-2026-69394",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Audio Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69394"
    },
    {
      "rank": 888,
      "cve_id": "CVE-2026-69398",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-362",
      "title": "Windows Bluetooth Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69398"
    },
    {
      "rank": 889,
      "cve_id": "CVE-2026-69401",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Audio Video Control Transport Protocol Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69401"
    },
    {
      "rank": 890,
      "cve_id": "CVE-2026-69404",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69404"
    },
    {
      "rank": 891,
      "cve_id": "CVE-2026-69410",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69410"
    },
    {
      "rank": 892,
      "cve_id": "CVE-2026-69413",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69413"
    },
    {
      "rank": 893,
      "cve_id": "CVE-2026-69422",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Windows USB Video Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69422"
    },
    {
      "rank": 894,
      "cve_id": "CVE-2026-69430",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Embedded Mode Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69430"
    },
    {
      "rank": 895,
      "cve_id": "CVE-2026-69440",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-367",
      "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69440"
    },
    {
      "rank": 896,
      "cve_id": "CVE-2026-69441",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows Installer Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69441"
    },
    {
      "rank": 897,
      "cve_id": "CVE-2026-69448",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-362",
      "title": "Windows Bluetooth Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69448"
    },
    {
      "rank": 898,
      "cve_id": "CVE-2026-69466",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-367",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69466"
    },
    {
      "rank": 899,
      "cve_id": "CVE-2026-69468",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69468"
    },
    {
      "rank": 900,
      "cve_id": "CVE-2026-69470",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Connected User Experiences and Telemetry Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69470"
    },
    {
      "rank": 901,
      "cve_id": "CVE-2026-69472",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Devices Human Interface Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69472"
    },
    {
      "rank": 902,
      "cve_id": "CVE-2026-69473",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69473"
    },
    {
      "rank": 903,
      "cve_id": "CVE-2026-69488",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69488"
    },
    {
      "rank": 904,
      "cve_id": "CVE-2026-69492",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Partition Management Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69492"
    },
    {
      "rank": 905,
      "cve_id": "CVE-2026-69498",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69498"
    },
    {
      "rank": 906,
      "cve_id": "CVE-2026-69500",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Image Acquisition Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69500"
    },
    {
      "rank": 907,
      "cve_id": "CVE-2026-69501",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-822",
      "title": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69501"
    },
    {
      "rank": 908,
      "cve_id": "CVE-2026-69516",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Connected Devices Platform Service (Cdpsvc) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69516"
    },
    {
      "rank": 909,
      "cve_id": "CVE-2026-69517",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows Wireless Networking Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69517"
    },
    {
      "rank": 910,
      "cve_id": "CVE-2026-69540",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows Audio Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69540"
    },
    {
      "rank": 911,
      "cve_id": "CVE-2026-69549",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-125",
      "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69549"
    },
    {
      "rank": 912,
      "cve_id": "CVE-2026-69560",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Work Folder Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69560"
    },
    {
      "rank": 913,
      "cve_id": "CVE-2026-69563",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69563"
    },
    {
      "rank": 914,
      "cve_id": "CVE-2026-69564",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Online Certificate Status Protocol (OCSP) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69564"
    },
    {
      "rank": 915,
      "cve_id": "CVE-2026-69567",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69567"
    },
    {
      "rank": 916,
      "cve_id": "CVE-2026-69573",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69573"
    },
    {
      "rank": 917,
      "cve_id": "CVE-2026-69574",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69574"
    },
    {
      "rank": 918,
      "cve_id": "CVE-2026-69575",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Storage Spaces Controller Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69575"
    },
    {
      "rank": 919,
      "cve_id": "CVE-2026-69578",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69578"
    },
    {
      "rank": 920,
      "cve_id": "CVE-2026-69581",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69581"
    },
    {
      "rank": 921,
      "cve_id": "CVE-2026-69600",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Microsoft Windows Search Component Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69600"
    },
    {
      "rank": 922,
      "cve_id": "CVE-2026-69605",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-416",
      "title": "Microsoft Install Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69605"
    },
    {
      "rank": 923,
      "cve_id": "CVE-2026-69606",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-416",
      "title": "Windows Shell Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69606"
    },
    {
      "rank": 924,
      "cve_id": "CVE-2026-69610",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-126",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69610"
    },
    {
      "rank": 925,
      "cve_id": "CVE-2026-69611",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69611"
    },
    {
      "rank": 926,
      "cve_id": "CVE-2026-69613",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Image Acquisition Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69613"
    },
    {
      "rank": 927,
      "cve_id": "CVE-2026-69617",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 26H1",
      "cwe": "CWE-125",
      "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69617"
    },
    {
      "rank": 928,
      "cve_id": "CVE-2026-69621",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Role: Windows Fax Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69621"
    },
    {
      "rank": 929,
      "cve_id": "CVE-2026-69630",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69630"
    },
    {
      "rank": 930,
      "cve_id": "CVE-2026-69645",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69645"
    },
    {
      "rank": 931,
      "cve_id": "CVE-2026-69648",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-416",
      "title": "Windows Notification Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69648"
    },
    {
      "rank": 932,
      "cve_id": "CVE-2026-69652",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69652"
    },
    {
      "rank": 933,
      "cve_id": "CVE-2026-69654",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Accounts Control Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69654"
    },
    {
      "rank": 934,
      "cve_id": "CVE-2026-69682",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-362",
      "title": "Windows Host Guardian Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69682"
    },
    {
      "rank": 935,
      "cve_id": "CVE-2026-69692",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Audio Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69692"
    },
    {
      "rank": 936,
      "cve_id": "CVE-2026-69693",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Device Association Broker Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69693"
    },
    {
      "rank": 937,
      "cve_id": "CVE-2026-69694",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-502",
      "title": "Windows IP Address Management (IPAM) Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69694"
    },
    {
      "rank": 938,
      "cve_id": "CVE-2026-69708",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows Web Platform Storage Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69708"
    },
    {
      "rank": 939,
      "cve_id": "CVE-2026-69711",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69711"
    },
    {
      "rank": 940,
      "cve_id": "CVE-2026-69735",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Broadcast DVR User Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69735"
    },
    {
      "rank": 941,
      "cve_id": "CVE-2026-69779",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-367",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69779"
    },
    {
      "rank": 942,
      "cve_id": "CVE-2026-69791",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69791"
    },
    {
      "rank": 943,
      "cve_id": "CVE-2026-69806",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": ".NET 10.0",
      "cwe": "CWE-94",
      "title": ".NET Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69806"
    },
    {
      "rank": 944,
      "cve_id": "CVE-2026-69814",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-416",
      "title": "Windows Credential Providers Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69814"
    },
    {
      "rank": 945,
      "cve_id": "CVE-2026-69816",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Accounts Control Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69816"
    },
    {
      "rank": 946,
      "cve_id": "CVE-2026-69817",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Bluetooth Port Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69817"
    },
    {
      "rank": 947,
      "cve_id": "CVE-2026-69818",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69818"
    },
    {
      "rank": 948,
      "cve_id": "CVE-2026-69834",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows ALPC Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69834"
    },
    {
      "rank": 949,
      "cve_id": "CVE-2026-69838",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Print Spooler Components Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69838"
    },
    {
      "rank": 950,
      "cve_id": "CVE-2026-69859",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-191",
      "title": "Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69859"
    },
    {
      "rank": 951,
      "cve_id": "CVE-2026-69866",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69866"
    },
    {
      "rank": 952,
      "cve_id": "CVE-2026-69889",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows Bluetooth Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69889"
    },
    {
      "rank": 953,
      "cve_id": "CVE-2026-69891",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Media Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69891"
    },
    {
      "rank": 954,
      "cve_id": "CVE-2026-69896",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Windows Error Reporting Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69896"
    },
    {
      "rank": 955,
      "cve_id": "CVE-2026-69911",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Microsoft Windows Search Component Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69911"
    },
    {
      "rank": 956,
      "cve_id": "CVE-2026-70283",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-863",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70283"
    },
    {
      "rank": 957,
      "cve_id": "CVE-2026-70562",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-415",
      "title": "Windows Audio Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70562"
    },
    {
      "rank": 958,
      "cve_id": "CVE-2026-70565",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows AF_UNIX Socket Provider Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70565"
    },
    {
      "rank": 959,
      "cve_id": "CVE-2026-70567",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-415",
      "title": "Windows Display Enhancement Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70567"
    },
    {
      "rank": 960,
      "cve_id": "CVE-2026-70568",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Defender Firewall Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70568"
    },
    {
      "rank": 961,
      "cve_id": "CVE-2026-70573",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-20",
      "title": "Windows Biometric Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70573"
    },
    {
      "rank": 962,
      "cve_id": "CVE-2026-70577",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70577"
    },
    {
      "rank": 963,
      "cve_id": "CVE-2026-70578",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-122",
      "title": "Windows Credential Guard Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70578"
    },
    {
      "rank": 964,
      "cve_id": "CVE-2026-70585",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows Server 2012",
      "cwe": "CWE-416",
      "title": "Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70585"
    },
    {
      "rank": 965,
      "cve_id": "CVE-2026-71332",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Secure Socket Tunneling Protocol (SSTP) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71332"
    },
    {
      "rank": 966,
      "cve_id": "CVE-2026-71333",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71333"
    },
    {
      "rank": 967,
      "cve_id": "CVE-2026-71340",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows File History Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71340"
    },
    {
      "rank": 968,
      "cve_id": "CVE-2026-71342",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71342"
    },
    {
      "rank": 969,
      "cve_id": "CVE-2026-71351",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-415",
      "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71351"
    },
    {
      "rank": 970,
      "cve_id": "CVE-2026-71353",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-415",
      "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71353"
    },
    {
      "rank": 971,
      "cve_id": "CVE-2026-72926",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Internet Connection Sharing (ICS) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72926"
    },
    {
      "rank": 972,
      "cve_id": "CVE-2026-72930",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72930"
    },
    {
      "rank": 973,
      "cve_id": "CVE-2026-72952",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-125",
      "title": "Windows Spaceport.sys Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72952"
    },
    {
      "rank": 974,
      "cve_id": "CVE-2026-72963",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Modern Execution Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72963"
    },
    {
      "rank": 975,
      "cve_id": "CVE-2026-73003",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73003"
    },
    {
      "rank": 976,
      "cve_id": "CVE-2026-73005",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows Authentication Methods Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73005"
    },
    {
      "rank": 977,
      "cve_id": "CVE-2026-73022",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73022"
    },
    {
      "rank": 978,
      "cve_id": "CVE-2026-77485",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-416",
      "title": "SQL Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77485"
    },
    {
      "rank": 979,
      "cve_id": "CVE-2026-77894",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows Installer Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77894"
    },
    {
      "rank": 980,
      "cve_id": "CVE-2026-77897",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Power Automate agent for virtual desktops",
      "cwe": "CWE-23",
      "title": "Microsoft Power Automate Desktop Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77897"
    },
    {
      "rank": 981,
      "cve_id": "CVE-2026-77899",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Windows Security Center Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77899"
    },
    {
      "rank": 982,
      "cve_id": "CVE-2026-77905",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Management Instrumentation Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77905"
    },
    {
      "rank": 983,
      "cve_id": "CVE-2026-78457",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Windows Security Health Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78457"
    },
    {
      "rank": 984,
      "cve_id": "CVE-2026-78464",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-367",
      "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78464"
    },
    {
      "rank": 985,
      "cve_id": "CVE-2026-80093",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80093"
    },
    {
      "rank": 986,
      "cve_id": "CVE-2026-81192",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-dotnet-contrib",
      "cwe": "CWE-426",
      "title": "OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81192"
    },
    {
      "rank": 987,
      "cve_id": "CVE-2026-81389",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81389"
    },
    {
      "rank": 988,
      "cve_id": "CVE-2026-82062",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-863",
      "title": "Improper Authorization in MongoDB Server applyOps Command Allows Writes to Arbitrary Internal Storage Tables via Feature Gate Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82062"
    },
    {
      "rank": 989,
      "cve_id": "CVE-2026-83940",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83940"
    },
    {
      "rank": 990,
      "cve_id": "CVE-2026-83999",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-59",
      "title": "Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83999"
    },
    {
      "rank": 991,
      "cve_id": "CVE-2026-85360",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85360"
    },
    {
      "rank": 992,
      "cve_id": "CVE-2026-86135",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Dimension",
      "cwe": "CWE-352",
      "title": "Dimension CSRF Vulnerability in Database Snapshot Creation Allows Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86135"
    },
    {
      "rank": 993,
      "cve_id": "CVE-2026-53933",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "macropay-solutions",
      "product": "maravel-framework",
      "cwe": "CWE-203",
      "title": "Maravel-Framework Vulnerable to Side-Channel Information Disclosure (Error Oracle) via Dynamic Route Fuzzing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53933"
    },
    {
      "rank": 994,
      "cve_id": "CVE-2026-81531",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link System Inc.",
      "product": "Omada Software Controller",
      "cwe": "CWE-200",
      "title": "Unauthenticated Account Information Disclosure in Multiple Omada Controllers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81531"
    },
    {
      "rank": 995,
      "cve_id": "CVE-2026-81823",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AVEVA",
      "product": "Pipeline Integrity Monitor",
      "cwe": "CWE-862",
      "title": "AVEVA Pipeline Integrity Monitor Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81823"
    },
    {
      "rank": 996,
      "cve_id": "CVE-2026-86804",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seakee",
      "product": "CPA-Manager-Plus",
      "cwe": "CWE-266",
      "title": "seakee CPA-Manager-Plus HTTP handler.go CPAResource improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86804"
    },
    {
      "rank": 997,
      "cve_id": "CVE-2026-86806",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opengeos",
      "product": "GeoLibre",
      "cwe": "CWE-918",
      "title": "opengeos GeoLibre _is_within_roots server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86806"
    },
    {
      "rank": 998,
      "cve_id": "CVE-2026-86810",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open-Web-Analytics",
      "cwe": "CWE-287",
      "title": "Open-Web-Analytics Controller Controller.php checkCapabilityAndAuthenticateUser improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86810"
    },
    {
      "rank": 999,
      "cve_id": "CVE-2026-65812",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Teams for Android",
      "cwe": "CWE-201",
      "title": "Microsoft Teams for Android Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65812"
    },
    {
      "rank": 1000,
      "cve_id": "CVE-2026-68833",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68833"
    },
    {
      "rank": 1001,
      "cve_id": "CVE-2026-69415",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-306",
      "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69415"
    },
    {
      "rank": 1002,
      "cve_id": "CVE-2026-69490",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows USB Mass Storage Class Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69490"
    },
    {
      "rank": 1003,
      "cve_id": "CVE-2026-69566",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69566"
    },
    {
      "rank": 1004,
      "cve_id": "CVE-2026-71329",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71329"
    },
    {
      "rank": 1005,
      "cve_id": "CVE-2026-71348",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Spaceport.sys Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71348"
    },
    {
      "rank": 1006,
      "cve_id": "CVE-2026-71349",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Spaceport.sys Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71349"
    },
    {
      "rank": 1007,
      "cve_id": "CVE-2026-71350",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Spaceport.sys Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71350"
    },
    {
      "rank": 1008,
      "cve_id": "CVE-2026-72985",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Volume Shadow Copy Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72985"
    },
    {
      "rank": 1009,
      "cve_id": "CVE-2026-72999",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows USB Hub Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72999"
    },
    {
      "rank": 1010,
      "cve_id": "CVE-2026-77892",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-693",
      "title": "Windows Boot Manager Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77892"
    },
    {
      "rank": 1011,
      "cve_id": "CVE-2026-78451",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-822",
      "title": "Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78451"
    },
    {
      "rank": 1012,
      "cve_id": "CVE-2026-78579",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Okta",
      "product": "Okta Access Gateway",
      "cwe": "CWE-90",
      "title": "Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78579"
    },
    {
      "rank": 1013,
      "cve_id": "CVE-2026-69350",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69350"
    },
    {
      "rank": 1014,
      "cve_id": "CVE-2026-69373",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69373"
    },
    {
      "rank": 1015,
      "cve_id": "CVE-2026-69449",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows BitLocker Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69449"
    },
    {
      "rank": 1016,
      "cve_id": "CVE-2026-71339",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Installer Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71339"
    },
    {
      "rank": 1017,
      "cve_id": "CVE-2026-72927",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Winsock Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72927"
    },
    {
      "rank": 1018,
      "cve_id": "CVE-2026-72935",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72935"
    },
    {
      "rank": 1019,
      "cve_id": "CVE-2026-72948",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-23",
      "title": "Windows DNS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72948"
    },
    {
      "rank": 1020,
      "cve_id": "CVE-2026-78625",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Okta",
      "product": "Okta Access Gateway",
      "cwe": "CWE-94",
      "title": "Insufficient Validation of Dashboard Application Labels in Okta Access Gateway Dashboard Site Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78625"
    },
    {
      "rank": 1021,
      "cve_id": "CVE-2026-78630",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Okta",
      "product": "Okta Access Gateway",
      "cwe": "CWE-78",
      "title": "Improper Input Neutralization in Okta Access Gateway SNMP Configuration Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78630"
    },
    {
      "rank": 1022,
      "cve_id": "CVE-2026-85981",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Auth0",
      "product": "Auth0 AD/LDAP Connector",
      "cwe": "CWE-306",
      "title": "Unauthenticated Localhost Admin Panel in Auth0 AD/LDAP Connector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85981"
    },
    {
      "rank": 1023,
      "cve_id": "CVE-2026-19201",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "go-attestation",
      "cwe": "CWE-674",
      "title": "Denial of Service via Unbounded Recursion in go-attestation Windows SIPA Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19201"
    },
    {
      "rank": 1024,
      "cve_id": "CVE-2026-69469",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-122",
      "title": "Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69469"
    },
    {
      "rank": 1025,
      "cve_id": "CVE-2026-78545",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Okta",
      "product": "Okta Access Gateway",
      "cwe": "CWE-94",
      "title": "Improper Input Sanitization in Okta Access Gateway Application Label Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78545"
    },
    {
      "rank": 1026,
      "cve_id": "CVE-2026-78550",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Okta",
      "product": "Okta Access Gateway",
      "cwe": "CWE-95",
      "title": "Improper Input Handling in Okta Access Gateway Management Console Exception Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78550"
    },
    {
      "rank": 1027,
      "cve_id": "CVE-2026-17509",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPML",
      "product": "WPML Multilingual CMS",
      "cwe": "CWE-89",
      "title": "WPML Multilingual CMS <= 4.9.5 - Incorrect Authorization to Authenticated (Subscriber+) SQL Injection via ‘elementIds’",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17509"
    },
    {
      "rank": 1028,
      "cve_id": "CVE-2026-18021",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "beaverbuilder",
      "product": "Beaver Builder Page Builder – Drag and Drop Website Builder",
      "cwe": "CWE-94",
      "title": "Beaver Builder Page Builder <= 2.10.3.1 - Unauthenticated Arbitrary Shortcode Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18021"
    },
    {
      "rank": 1029,
      "cve_id": "CVE-2026-53637",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sylius",
      "product": "Sylius",
      "cwe": "CWE-672",
      "title": "Sylius: Cart FormComponent allows modification or deletion of an already-completed order",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53637"
    },
    {
      "rank": 1030,
      "cve_id": "CVE-2026-58649",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": ".NET 10.0",
      "cwe": "CWE-346",
      "title": ".NET Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58649"
    },
    {
      "rank": 1031,
      "cve_id": "CVE-2026-62762",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-476",
      "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62762"
    },
    {
      "rank": 1032,
      "cve_id": "CVE-2026-62801",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-22",
      "title": "Microsoft PowerShell Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62801"
    },
    {
      "rank": 1033,
      "cve_id": "CVE-2026-63523",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Skype for Business Server 2015 CU13",
      "cwe": "CWE-79",
      "title": "Skype for Business Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63523"
    },
    {
      "rank": 1034,
      "cve_id": "CVE-2026-64918",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-522",
      "title": "Microsoft Office Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64918"
    },
    {
      "rank": 1035,
      "cve_id": "CVE-2026-66303",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Skype for Business Server 2015 CU13",
      "cwe": "CWE-476",
      "title": "Skype for Business and Lync Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66303"
    },
    {
      "rank": 1036,
      "cve_id": "CVE-2026-66306",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Skype for Business Server 2015 CU13",
      "cwe": "CWE-209",
      "title": "Skype for Business Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66306"
    },
    {
      "rank": 1037,
      "cve_id": "CVE-2026-66308",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Skype for Business Server 2015 CU13",
      "cwe": "CWE-125",
      "title": "Skype for Business and Lync Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66308"
    },
    {
      "rank": 1038,
      "cve_id": "CVE-2026-66816",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2022 (CU 26)",
      "cwe": "CWE-778",
      "title": "Microsoft SQL Server Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66816"
    },
    {
      "rank": 1039,
      "cve_id": "CVE-2026-67369",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2025 (CU8)",
      "cwe": "CWE-125",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67369"
    },
    {
      "rank": 1040,
      "cve_id": "CVE-2026-67383",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2025 (CU8)",
      "cwe": "CWE-209",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67383"
    },
    {
      "rank": 1041,
      "cve_id": "CVE-2026-67386",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-908",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67386"
    },
    {
      "rank": 1042,
      "cve_id": "CVE-2026-67389",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2022 (CU 26)",
      "cwe": "CWE-125",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67389"
    },
    {
      "rank": 1043,
      "cve_id": "CVE-2026-67390",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-126",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67390"
    },
    {
      "rank": 1044,
      "cve_id": "CVE-2026-67393",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-126",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67393"
    },
    {
      "rank": 1045,
      "cve_id": "CVE-2026-67624",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2019 (CU 32)",
      "cwe": "CWE-125",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67624"
    },
    {
      "rank": 1046,
      "cve_id": "CVE-2026-67629",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-125",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67629"
    },
    {
      "rank": 1047,
      "cve_id": "CVE-2026-67630",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-125",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67630"
    },
    {
      "rank": 1048,
      "cve_id": "CVE-2026-67633",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-125",
      "title": "Microsoft SQL Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67633"
    },
    {
      "rank": 1049,
      "cve_id": "CVE-2026-67641",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2022 (CU 26)",
      "cwe": "CWE-190",
      "title": "Microsoft SQL Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67641"
    },
    {
      "rank": 1050,
      "cve_id": "CVE-2026-67645",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-125",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67645"
    },
    {
      "rank": 1051,
      "cve_id": "CVE-2026-67648",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-908",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67648"
    },
    {
      "rank": 1052,
      "cve_id": "CVE-2026-68776",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-908",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68776"
    },
    {
      "rank": 1053,
      "cve_id": "CVE-2026-68777",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-125",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68777"
    },
    {
      "rank": 1054,
      "cve_id": "CVE-2026-68778",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-125",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68778"
    },
    {
      "rank": 1055,
      "cve_id": "CVE-2026-68779",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-125",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68779"
    },
    {
      "rank": 1056,
      "cve_id": "CVE-2026-68780",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-125",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68780"
    },
    {
      "rank": 1057,
      "cve_id": "CVE-2026-68781",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-125",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68781"
    },
    {
      "rank": 1058,
      "cve_id": "CVE-2026-68784",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-125",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68784"
    },
    {
      "rank": 1059,
      "cve_id": "CVE-2026-68898",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows iSCSI Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68898"
    },
    {
      "rank": 1060,
      "cve_id": "CVE-2026-69267",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-1220",
      "title": "Windows Connected User Experiences and Telemetry Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69267"
    },
    {
      "rank": 1061,
      "cve_id": "CVE-2026-69297",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-257",
      "title": "Windows DHCP Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69297"
    },
    {
      "rank": 1062,
      "cve_id": "CVE-2026-69361",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-918",
      "title": "Microsoft Exchange Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69361"
    },
    {
      "rank": 1063,
      "cve_id": "CVE-2026-69374",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-770",
      "title": "Windows SMB Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69374"
    },
    {
      "rank": 1064,
      "cve_id": "CVE-2026-69375",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-639",
      "title": "Microsoft Exchange Server Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69375"
    },
    {
      "rank": 1065,
      "cve_id": "CVE-2026-69395",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-134",
      "title": "Active Directory Certificate Services (AD CS) Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69395"
    },
    {
      "rank": 1066,
      "cve_id": "CVE-2026-69409",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "cwe": "CWE-250",
      "title": "Microsoft Office SharePoint Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69409"
    },
    {
      "rank": 1067,
      "cve_id": "CVE-2026-69497",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-401",
      "title": "Windows DHCP Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69497"
    },
    {
      "rank": 1068,
      "cve_id": "CVE-2026-69562",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-125",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69562"
    },
    {
      "rank": 1069,
      "cve_id": "CVE-2026-69624",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-184",
      "title": "Active Directory Certificate Services (AD CS) Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69624"
    },
    {
      "rank": 1070,
      "cve_id": "CVE-2026-69626",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-126",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69626"
    },
    {
      "rank": 1071,
      "cve_id": "CVE-2026-69636",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "cwe": "CWE-89",
      "title": "Microsoft Office SharePoint Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69636"
    },
    {
      "rank": 1072,
      "cve_id": "CVE-2026-69642",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Skype for Business Server 2015 CU13",
      "cwe": "CWE-79",
      "title": "Skype for Business Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69642"
    },
    {
      "rank": 1073,
      "cve_id": "CVE-2026-69683",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "cwe": "CWE-918",
      "title": "Microsoft Office SharePoint Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69683"
    },
    {
      "rank": 1074,
      "cve_id": "CVE-2026-69719",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-126",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69719"
    },
    {
      "rank": 1075,
      "cve_id": "CVE-2026-69734",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69734"
    },
    {
      "rank": 1076,
      "cve_id": "CVE-2026-69739",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69739"
    },
    {
      "rank": 1077,
      "cve_id": "CVE-2026-69781",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-401",
      "title": "Windows DHCP Client Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69781"
    },
    {
      "rank": 1078,
      "cve_id": "CVE-2026-69839",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-248",
      "title": "Windows iSCSI Target Service Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69839"
    },
    {
      "rank": 1079,
      "cve_id": "CVE-2026-70019",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-65",
      "title": "Windows Compressed Folder Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70019"
    },
    {
      "rank": 1080,
      "cve_id": "CVE-2026-72938",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-822",
      "title": "Microsoft Office PowerPoint Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72938"
    },
    {
      "rank": 1081,
      "cve_id": "CVE-2026-72939",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-476",
      "title": "Windows Routing and Remote Access Service (RRAS) Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72939"
    },
    {
      "rank": 1082,
      "cve_id": "CVE-2026-72942",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Spaceport.sys Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72942"
    },
    {
      "rank": 1083,
      "cve_id": "CVE-2026-72956",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-822",
      "title": "Microsoft Office PowerPoint Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72956"
    },
    {
      "rank": 1084,
      "cve_id": "CVE-2026-72974",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-126",
      "title": "Microsoft Office Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72974"
    },
    {
      "rank": 1085,
      "cve_id": "CVE-2026-72975",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office PowerPoint Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72975"
    },
    {
      "rank": 1086,
      "cve_id": "CVE-2026-72977",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-20",
      "title": "Microsoft Office PowerPoint Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72977"
    },
    {
      "rank": 1087,
      "cve_id": "CVE-2026-73029",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2019 (CU 32)",
      "cwe": "CWE-126",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73029"
    },
    {
      "rank": 1088,
      "cve_id": "CVE-2026-76000",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-400",
      "title": "ColdFusion | Uncontrolled Resource Consumption (CWE-400)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76000"
    },
    {
      "rank": 1089,
      "cve_id": "CVE-2026-77896",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "title": "Windows Remote Desktop Client Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77896"
    },
    {
      "rank": 1090,
      "cve_id": "CVE-2026-77911",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77911"
    },
    {
      "rank": 1091,
      "cve_id": "CVE-2026-78441",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-125",
      "title": "Windows OLE DB Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78441"
    },
    {
      "rank": 1092,
      "cve_id": "CVE-2026-78453",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-191",
      "title": "Microsoft Windows SCSI Class System File Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78453"
    },
    {
      "rank": 1093,
      "cve_id": "CVE-2026-78502",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78502"
    },
    {
      "rank": 1094,
      "cve_id": "CVE-2026-78503",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78503"
    },
    {
      "rank": 1095,
      "cve_id": "CVE-2026-78515",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78515"
    },
    {
      "rank": 1096,
      "cve_id": "CVE-2026-78520",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Outlook Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78520"
    },
    {
      "rank": 1097,
      "cve_id": "CVE-2026-78522",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78522"
    },
    {
      "rank": 1098,
      "cve_id": "CVE-2026-80073",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Outlook Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80073"
    },
    {
      "rank": 1099,
      "cve_id": "CVE-2026-80076",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80076"
    },
    {
      "rank": 1100,
      "cve_id": "CVE-2026-80078",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80078"
    },
    {
      "rank": 1101,
      "cve_id": "CVE-2026-80079",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80079"
    },
    {
      "rank": 1102,
      "cve_id": "CVE-2026-80082",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80082"
    },
    {
      "rank": 1103,
      "cve_id": "CVE-2026-80084",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Outlook Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80084"
    },
    {
      "rank": 1104,
      "cve_id": "CVE-2026-80086",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office PowerPoint Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80086"
    },
    {
      "rank": 1105,
      "cve_id": "CVE-2026-80087",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80087"
    },
    {
      "rank": 1106,
      "cve_id": "CVE-2026-80088",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80088"
    },
    {
      "rank": 1107,
      "cve_id": "CVE-2026-80089",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80089"
    },
    {
      "rank": 1108,
      "cve_id": "CVE-2026-80090",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80090"
    },
    {
      "rank": 1109,
      "cve_id": "CVE-2026-80091",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-908",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80091"
    },
    {
      "rank": 1110,
      "cve_id": "CVE-2026-81377",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-22",
      "title": "Visual Studio Code Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81377"
    },
    {
      "rank": 1111,
      "cve_id": "CVE-2026-81381",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-522",
      "title": "GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81381"
    },
    {
      "rank": 1112,
      "cve_id": "CVE-2026-84391",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiAnalyzer",
      "cwe": "CWE-457",
      "title": "A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here>",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84391"
    },
    {
      "rank": 1113,
      "cve_id": "CVE-2026-84685",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Auth0",
      "product": "react-native-auth0",
      "cwe": "CWE-488",
      "title": "Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84685"
    },
    {
      "rank": 1114,
      "cve_id": "CVE-2026-12230",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thimpress",
      "product": "LearnPress – WordPress LMS Plugin for Create and Sell Online Courses",
      "cwe": "CWE-79",
      "title": "LearnPress <= 4.3.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'layout_custom_css'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12230"
    },
    {
      "rank": 1115,
      "cve_id": "CVE-2026-33388",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nozomi Networks",
      "product": "Guardian",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33388"
    },
    {
      "rank": 1116,
      "cve_id": "CVE-2026-69878",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows DHCP Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69878"
    },
    {
      "rank": 1117,
      "cve_id": "CVE-2026-70582",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows Management Instrumentation Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70582"
    },
    {
      "rank": 1118,
      "cve_id": "CVE-2026-71338",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-415",
      "title": "Windows Failover Cluster Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71338"
    },
    {
      "rank": 1119,
      "cve_id": "CVE-2026-72947",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-191",
      "title": "Windows File History Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72947"
    },
    {
      "rank": 1120,
      "cve_id": "CVE-2026-76931",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dylanjkotze",
      "product": "Zephyr Project Manager",
      "cwe": "CWE-79",
      "title": "Zephyr Project Manager <= 3.3.205 - Authenticated (Custom+) Stored Cross-Site Scripting via 'message' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76931"
    },
    {
      "rank": 1121,
      "cve_id": "CVE-2026-77887",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows DHCP Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77887"
    },
    {
      "rank": 1122,
      "cve_id": "CVE-2026-77891",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows DHCP Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77891"
    },
    {
      "rank": 1123,
      "cve_id": "CVE-2026-53639",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sylius",
      "product": "Sylius",
      "cwe": "CWE-639",
      "title": "Sylius: IDOR on Shop Payment Request API endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53639"
    },
    {
      "rank": 1124,
      "cve_id": "CVE-2026-81824",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AVEVA",
      "product": "Pipeline Integrity Monitor",
      "cwe": "CWE-79",
      "title": "AVEVA Pipeline Integrity Monitor cross-site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81824"
    },
    {
      "rank": 1125,
      "cve_id": "CVE-2026-81904",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-862",
      "title": "Concrete CMS before 9.5.3 is vulnerable to Missing Authorization in Stack/Container Sub-Block Asset Registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81904"
    },
    {
      "rank": 1126,
      "cve_id": "CVE-2026-81997",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-863",
      "title": "Acrobat Reader | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81997"
    },
    {
      "rank": 1127,
      "cve_id": "CVE-2026-84942",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "Amazon OpenSearch Service",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84942"
    },
    {
      "rank": 1128,
      "cve_id": "CVE-2026-86077",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-862",
      "title": "n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86077"
    },
    {
      "rank": 1129,
      "cve_id": "CVE-2026-86079",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-22",
      "title": "n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86079"
    },
    {
      "rank": 1130,
      "cve_id": "CVE-2026-86080",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-347",
      "title": "n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86080"
    },
    {
      "rank": 1131,
      "cve_id": "CVE-2026-53937",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "modelcontextprotocol",
      "product": "io.modelcontextprotocol:kotlin-sdk",
      "cwe": "CWE-400",
      "title": "MCP Kotlin SDK's unbounded line buffer in StdioServerTransport/StdioClientTransport leads to memory exhaustion (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53937"
    },
    {
      "rank": 1132,
      "cve_id": "CVE-2026-18090",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Gdk-pixbuf: gdk-pixbuf: heap out-of-bounds read in uncompress() via crafted icns rle block",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18090"
    },
    {
      "rank": 1133,
      "cve_id": "CVE-2026-76002",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion 2025",
      "cwe": "CWE-79",
      "title": "ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76002"
    },
    {
      "rank": 1134,
      "cve_id": "CVE-2026-77654",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Algosec",
      "product": "Horizon Security Analyzer",
      "cwe": "CWE-266",
      "title": "Local Privilege Escalation via Misconfigured Sudoers Entry in Horizon Security Analyzer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77654"
    },
    {
      "rank": 1135,
      "cve_id": "CVE-2026-56101",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenBSD",
      "cwe": "CWE-697",
      "title": "OpenBSD ieee80211_crypto_tkip.c TKIP MIC Countermeasure Logic Inversion DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56101"
    },
    {
      "rank": 1136,
      "cve_id": "CVE-2026-78216",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_lua",
      "cwe": "CWE-1220",
      "title": "AshLua eval read operations can read field-policy-protected fields via aggregates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78216"
    },
    {
      "rank": 1137,
      "cve_id": "CVE-2026-78230",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash_ai",
      "cwe": "CWE-1220",
      "title": "AshAi aggregate tool can read field-policy-protected fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78230"
    },
    {
      "rank": 1138,
      "cve_id": "CVE-2026-78552",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Okta",
      "product": "Okta Access Gateway",
      "cwe": "CWE-693",
      "title": "Validation Bypass in Okta Access Gateway Custom Directives",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78552"
    },
    {
      "rank": 1139,
      "cve_id": "CVE-2026-78622",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Okta",
      "product": "Okta Verify for Windows",
      "cwe": "CWE-59",
      "title": "Improper Link Resolution in Okta Verify for Windows Uninstaller Data Removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78622"
    },
    {
      "rank": 1140,
      "cve_id": "CVE-2026-82056",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-416",
      "title": "Race Condition in MongoDB Server Text Index Query Parsing Leads to Heap Use-After-Free and Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82056"
    },
    {
      "rank": 1141,
      "cve_id": "CVE-2026-82059",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-617",
      "title": "Improper Access Restriction of Internal Aggregation Expression in MongoDB Server Leads to Assertion Failure and Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82059"
    },
    {
      "rank": 1142,
      "cve_id": "CVE-2026-82063",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-416",
      "title": "Use-After-Free in MongoDB Server Cursor Management Component Leads to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82063"
    },
    {
      "rank": 1143,
      "cve_id": "CVE-2026-86078",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-1321",
      "title": "n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86078"
    },
    {
      "rank": 1144,
      "cve_id": "CVE-2026-86084",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-288",
      "title": "n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86084"
    },
    {
      "rank": 1145,
      "cve_id": "CVE-2026-69304",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": ".NET 10.0",
      "cwe": "CWE-409",
      "title": "ASP.NET Core Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69304"
    },
    {
      "rank": 1146,
      "cve_id": "CVE-2026-69382",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-327",
      "title": "Microsoft Exchange Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69382"
    },
    {
      "rank": 1147,
      "cve_id": "CVE-2026-69803",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows DHCP Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69803"
    },
    {
      "rank": 1148,
      "cve_id": "CVE-2026-69929",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows DHCP Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69929"
    },
    {
      "rank": 1149,
      "cve_id": "CVE-2026-69930",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows DHCP Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69930"
    },
    {
      "rank": 1150,
      "cve_id": "CVE-2026-70091",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows DNS Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70091"
    },
    {
      "rank": 1151,
      "cve_id": "CVE-2026-70124",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows DHCP Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70124"
    },
    {
      "rank": 1152,
      "cve_id": "CVE-2026-72978",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-770",
      "title": "Active Directory Federation Services (AD FS) Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72978"
    },
    {
      "rank": 1153,
      "cve_id": "CVE-2026-78523",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows DNS Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78523"
    },
    {
      "rank": 1154,
      "cve_id": "CVE-2026-78620",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Okta",
      "product": "Okta Access Gateway",
      "cwe": "CWE-73",
      "title": "Improper Path Validation in Okta Access Gateway Kerberos Configuration Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78620"
    },
    {
      "rank": 1155,
      "cve_id": "CVE-2026-86073",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-863",
      "title": "n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86073"
    },
    {
      "rank": 1156,
      "cve_id": "CVE-2026-86074",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-918",
      "title": "n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86074"
    },
    {
      "rank": 1157,
      "cve_id": "CVE-2026-86735",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-918",
      "title": "snipe-it before 8.7.0 SSRF via IPv6 transition address bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86735"
    },
    {
      "rank": 1158,
      "cve_id": "CVE-2026-86993",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-862",
      "title": "n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86993"
    },
    {
      "rank": 1159,
      "cve_id": "CVE-2026-69559",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Teams for Android",
      "cwe": "CWE-346",
      "title": "Microsoft Teams for Android Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69559"
    },
    {
      "rank": 1160,
      "cve_id": "CVE-2026-68874",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Program Compatibility Assistant Service Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68874"
    },
    {
      "rank": 1161,
      "cve_id": "CVE-2026-69317",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69317"
    },
    {
      "rank": 1162,
      "cve_id": "CVE-2026-69349",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-908",
      "title": "Windows Management Instrumentation Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69349"
    },
    {
      "rank": 1163,
      "cve_id": "CVE-2026-69372",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Network File System Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69372"
    },
    {
      "rank": 1164,
      "cve_id": "CVE-2026-69393",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Spaceport.sys Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69393"
    },
    {
      "rank": 1165,
      "cve_id": "CVE-2026-69405",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-401",
      "title": "Windows DHCP Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69405"
    },
    {
      "rank": 1166,
      "cve_id": "CVE-2026-69416",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-126",
      "title": "Windows DHCP Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69416"
    },
    {
      "rank": 1167,
      "cve_id": "CVE-2026-69507",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-538",
      "title": "Microsoft Windows Search Component Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69507"
    },
    {
      "rank": 1168,
      "cve_id": "CVE-2026-69552",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-209",
      "title": "Windows Print Spooler Components Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69552"
    },
    {
      "rank": 1169,
      "cve_id": "CVE-2026-69569",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-822",
      "title": "Windows Print Spooler Components Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69569"
    },
    {
      "rank": 1170,
      "cve_id": "CVE-2026-69572",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows SMB Client Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69572"
    },
    {
      "rank": 1171,
      "cve_id": "CVE-2026-69591",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-125",
      "title": "Windows NTFS Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69591"
    },
    {
      "rank": 1172,
      "cve_id": "CVE-2026-69637",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows DHCP Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69637"
    },
    {
      "rank": 1173,
      "cve_id": "CVE-2026-69679",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows DHCP Server Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69679"
    },
    {
      "rank": 1174,
      "cve_id": "CVE-2026-69723",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-497",
      "title": "Windows Kernel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69723"
    },
    {
      "rank": 1175,
      "cve_id": "CVE-2026-69832",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-497",
      "title": "Win32k Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69832"
    },
    {
      "rank": 1176,
      "cve_id": "CVE-2026-78629",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Okta",
      "product": "Okta Hyperdrive Agent",
      "cwe": "CWE-303",
      "title": "Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78629"
    },
    {
      "rank": 1177,
      "cve_id": "CVE-2026-54611",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "instantsoft",
      "product": "icms2",
      "cwe": "CWE-94",
      "title": "InstantCMS has Remote Code Execution in package installer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54611"
    },
    {
      "rank": 1178,
      "cve_id": "CVE-2026-68830",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-59",
      "title": "Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68830"
    },
    {
      "rank": 1179,
      "cve_id": "CVE-2026-68831",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-552",
      "title": "Windows Defender Firewall Service Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68831"
    },
    {
      "rank": 1180,
      "cve_id": "CVE-2026-68842",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-497",
      "title": "Windows MIDI Service Module Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68842"
    },
    {
      "rank": 1181,
      "cve_id": "CVE-2026-68843",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68843"
    },
    {
      "rank": 1182,
      "cve_id": "CVE-2026-68851",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-126",
      "title": "Windows NTFS Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68851"
    },
    {
      "rank": 1183,
      "cve_id": "CVE-2026-68852",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-200",
      "title": "Microsoft Account Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68852"
    },
    {
      "rank": 1184,
      "cve_id": "CVE-2026-68873",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-532",
      "title": "Windows Program Compatibility Assistant Service Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68873"
    },
    {
      "rank": 1185,
      "cve_id": "CVE-2026-68881",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Microsoft Standard XPS Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68881"
    },
    {
      "rank": 1186,
      "cve_id": "CVE-2026-68886",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-209",
      "title": "Windows Network Connection Broker Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68886"
    },
    {
      "rank": 1187,
      "cve_id": "CVE-2026-68895",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-197",
      "title": "Internet Storage Name Service Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68895"
    },
    {
      "rank": 1188,
      "cve_id": "CVE-2026-69286",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-20",
      "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69286"
    },
    {
      "rank": 1189,
      "cve_id": "CVE-2026-69288",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-908",
      "title": "Windows GDI+ Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69288"
    },
    {
      "rank": 1190,
      "cve_id": "CVE-2026-69294",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-209",
      "title": "Microsoft COM for Windows Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69294"
    },
    {
      "rank": 1191,
      "cve_id": "CVE-2026-69303",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Push Message Routing Service Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69303"
    },
    {
      "rank": 1192,
      "cve_id": "CVE-2026-69308",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Microsoft Standard XPS Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69308"
    },
    {
      "rank": 1193,
      "cve_id": "CVE-2026-69315",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-497",
      "title": "Windows License Manager Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69315"
    },
    {
      "rank": 1194,
      "cve_id": "CVE-2026-69318",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Imaging Component Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69318"
    },
    {
      "rank": 1195,
      "cve_id": "CVE-2026-69321",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-306",
      "title": "Windows Power Dependency Coordinator Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69321"
    },
    {
      "rank": 1196,
      "cve_id": "CVE-2026-69339",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-497",
      "title": "Windows MIDI Service Module Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69339"
    },
    {
      "rank": 1197,
      "cve_id": "CVE-2026-69343",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Overlay Filter Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69343"
    },
    {
      "rank": 1198,
      "cve_id": "CVE-2026-69344",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-125",
      "title": "Windows Print Spooler Components Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69344"
    },
    {
      "rank": 1199,
      "cve_id": "CVE-2026-69345",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Microsoft Standard XPS Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69345"
    },
    {
      "rank": 1200,
      "cve_id": "CVE-2026-69351",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-359",
      "title": "Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69351"
    },
    {
      "rank": 1201,
      "cve_id": "CVE-2026-69353",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Text Shaping Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69353"
    },
    {
      "rank": 1202,
      "cve_id": "CVE-2026-69367",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Microsoft Standard XPS Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69367"
    },
    {
      "rank": 1203,
      "cve_id": "CVE-2026-69369",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows DNS Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69369"
    },
    {
      "rank": 1204,
      "cve_id": "CVE-2026-69376",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Microsoft Standard XPS Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69376"
    },
    {
      "rank": 1205,
      "cve_id": "CVE-2026-69390",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Spaceport.sys Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69390"
    },
    {
      "rank": 1206,
      "cve_id": "CVE-2026-69403",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-862",
      "title": "Windows SMB Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69403"
    },
    {
      "rank": 1207,
      "cve_id": "CVE-2026-69406",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-497",
      "title": "Windows Kernel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69406"
    },
    {
      "rank": 1208,
      "cve_id": "CVE-2026-69453",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-862",
      "title": "Microsoft Windows Search Component Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69453"
    },
    {
      "rank": 1209,
      "cve_id": "CVE-2026-69457",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows USB Driver Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69457"
    },
    {
      "rank": 1210,
      "cve_id": "CVE-2026-69504",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows NTFS Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69504"
    },
    {
      "rank": 1211,
      "cve_id": "CVE-2026-69527",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows USB Mass Storage Class Driver Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69527"
    },
    {
      "rank": 1212,
      "cve_id": "CVE-2026-69531",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-441",
      "title": "Microsoft Windows Speech Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69531"
    },
    {
      "rank": 1213,
      "cve_id": "CVE-2026-69554",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-306",
      "title": "Microsoft Windows Search Component Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69554"
    },
    {
      "rank": 1214,
      "cve_id": "CVE-2026-69568",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Storage Spaces Controller Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69568"
    },
    {
      "rank": 1215,
      "cve_id": "CVE-2026-69609",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Win32k Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69609"
    },
    {
      "rank": 1216,
      "cve_id": "CVE-2026-69616",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Remote Desktop Services Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69616"
    },
    {
      "rank": 1217,
      "cve_id": "CVE-2026-69618",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows SMB Client Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69618"
    },
    {
      "rank": 1218,
      "cve_id": "CVE-2026-69627",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Remote Desktop Licensing Service Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69627"
    },
    {
      "rank": 1219,
      "cve_id": "CVE-2026-69672",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-908",
      "title": "Windows DNS Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69672"
    },
    {
      "rank": 1220,
      "cve_id": "CVE-2026-69674",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-306",
      "title": "Windows Modern Device Management (MDM) Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69674"
    },
    {
      "rank": 1221,
      "cve_id": "CVE-2026-69684",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-209",
      "title": "Windows Error Reporting Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69684"
    },
    {
      "rank": 1222,
      "cve_id": "CVE-2026-69741",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-125",
      "title": "Windows Spaceport.sys Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69741"
    },
    {
      "rank": 1223,
      "cve_id": "CVE-2026-69770",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-908",
      "title": "Windows Spaceport.sys Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69770"
    },
    {
      "rank": 1224,
      "cve_id": "CVE-2026-69794",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-126",
      "title": "Windows Encrypting File System (EFS) Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69794"
    },
    {
      "rank": 1225,
      "cve_id": "CVE-2026-69808",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Win32k Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69808"
    },
    {
      "rank": 1226,
      "cve_id": "CVE-2026-69862",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Wireless Wide Area Network Service Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69862"
    },
    {
      "rank": 1227,
      "cve_id": "CVE-2026-70145",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Microsoft Windows Search Component Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70145"
    },
    {
      "rank": 1228,
      "cve_id": "CVE-2026-70290",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-908",
      "title": "Win32k Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70290"
    },
    {
      "rank": 1229,
      "cve_id": "CVE-2026-71341",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Partition Management Driver Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71341"
    },
    {
      "rank": 1230,
      "cve_id": "CVE-2026-72937",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Storage Port Driver Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72937"
    },
    {
      "rank": 1231,
      "cve_id": "CVE-2026-72945",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-908",
      "title": "Windows Task Scheduler Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72945"
    },
    {
      "rank": 1232,
      "cve_id": "CVE-2026-72964",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-306",
      "title": "Windows Internet Connection Sharing (ICS) Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72964"
    },
    {
      "rank": 1233,
      "cve_id": "CVE-2026-72966",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-862",
      "title": "Windows Remote Access Connection Manager Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72966"
    },
    {
      "rank": 1234,
      "cve_id": "CVE-2026-73004",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-306",
      "title": "Windows Autopilot Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73004"
    },
    {
      "rank": 1235,
      "cve_id": "CVE-2026-73008",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-359",
      "title": "Windows Biometric Service Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73008"
    },
    {
      "rank": 1236,
      "cve_id": "CVE-2026-77488",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-191",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77488"
    },
    {
      "rank": 1237,
      "cve_id": "CVE-2026-77491",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows GDI Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77491"
    },
    {
      "rank": 1238,
      "cve_id": "CVE-2026-77492",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Storage Port Driver Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77492"
    },
    {
      "rank": 1239,
      "cve_id": "CVE-2026-78454",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows CD-ROM Driver Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78454"
    },
    {
      "rank": 1240,
      "cve_id": "CVE-2026-78506",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-170",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78506"
    },
    {
      "rank": 1241,
      "cve_id": "CVE-2026-78513",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office PowerPoint Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78513"
    },
    {
      "rank": 1242,
      "cve_id": "CVE-2026-79910",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-125",
      "title": "Acrobat Reader | Out-of-bounds Read (CWE-125)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79910"
    },
    {
      "rank": 1243,
      "cve_id": "CVE-2026-80160",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-125",
      "title": "Acrobat Reader | Out-of-bounds Read (CWE-125)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80160"
    },
    {
      "rank": 1244,
      "cve_id": "CVE-2026-80162",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80162"
    },
    {
      "rank": 1245,
      "cve_id": "CVE-2026-81387",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-497",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81387"
    },
    {
      "rank": 1246,
      "cve_id": "CVE-2026-81390",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81390"
    },
    {
      "rank": 1247,
      "cve_id": "CVE-2026-81391",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-908",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81391"
    },
    {
      "rank": 1248,
      "cve_id": "CVE-2026-81392",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-20",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81392"
    },
    {
      "rank": 1249,
      "cve_id": "CVE-2026-81393",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81393"
    },
    {
      "rank": 1250,
      "cve_id": "CVE-2026-81394",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-497",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81394"
    },
    {
      "rank": 1251,
      "cve_id": "CVE-2026-81395",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81395"
    },
    {
      "rank": 1252,
      "cve_id": "CVE-2026-81399",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-126",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81399"
    },
    {
      "rank": 1253,
      "cve_id": "CVE-2026-81400",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81400"
    },
    {
      "rank": 1254,
      "cve_id": "CVE-2026-81401",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-843",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81401"
    },
    {
      "rank": 1255,
      "cve_id": "CVE-2026-81958",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-908",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81958"
    },
    {
      "rank": 1256,
      "cve_id": "CVE-2026-81977",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-191",
      "title": "Acrobat Reader | Integer Underflow (Wrap or Wraparound) (CWE-191)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81977"
    },
    {
      "rank": 1257,
      "cve_id": "CVE-2026-81978",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-125",
      "title": "Acrobat Reader | Out-of-bounds Read (CWE-125)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81978"
    },
    {
      "rank": 1258,
      "cve_id": "CVE-2026-81982",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-125",
      "title": "Acrobat Reader | Out-of-bounds Read (CWE-125)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81982"
    },
    {
      "rank": 1259,
      "cve_id": "CVE-2026-81984",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81984"
    },
    {
      "rank": 1260,
      "cve_id": "CVE-2026-81991",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-125",
      "title": "Acrobat Reader | Out-of-bounds Read (CWE-125)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81991"
    },
    {
      "rank": 1261,
      "cve_id": "CVE-2026-81993",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-122",
      "title": "Acrobat Reader | Heap-based Buffer Overflow (CWE-122)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81993"
    },
    {
      "rank": 1262,
      "cve_id": "CVE-2026-82001",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-400",
      "title": "Acrobat Reader | Uncontrolled Resource Consumption (CWE-400)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82001"
    },
    {
      "rank": 1263,
      "cve_id": "CVE-2026-83501",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-125",
      "title": "Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83501"
    },
    {
      "rank": 1264,
      "cve_id": "CVE-2026-83949",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-126",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83949"
    },
    {
      "rank": 1265,
      "cve_id": "CVE-2026-83951",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-126",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83951"
    },
    {
      "rank": 1266,
      "cve_id": "CVE-2026-83991",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-306",
      "title": "Windows Cloud Files Mini Filter Driver Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-83991"
    },
    {
      "rank": 1267,
      "cve_id": "CVE-2026-85875",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85875"
    },
    {
      "rank": 1268,
      "cve_id": "CVE-2026-86665",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aircheng-org",
      "product": "iWebShop-5",
      "cwe": "CWE-862",
      "title": "aircheng-org iWebShop-5 update.php index authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86665"
    },
    {
      "rank": 1269,
      "cve_id": "CVE-2026-86666",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aircheng-org",
      "product": "iWebShop-5",
      "cwe": "CWE-284",
      "title": "aircheng-org iWebShop-5 pic.php uploadFile unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86666"
    },
    {
      "rank": 1270,
      "cve_id": "CVE-2026-86669",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aircheng-org",
      "product": "iWebShop-5",
      "cwe": "CWE-287",
      "title": "aircheng-org iWebShop-5 systemseller.php login improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86669"
    },
    {
      "rank": 1271,
      "cve_id": "CVE-2026-86672",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ningzichun",
      "product": "Student Management System",
      "cwe": "CWE-200",
      "title": "ningzichun Student Management System Backup example.7z information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86672"
    },
    {
      "rank": 1272,
      "cve_id": "CVE-2026-86673",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ningzichun",
      "product": "Student Management System",
      "cwe": "CWE-259",
      "title": "ningzichun Student Management System Database Connection database.php mysqli_connect hard-coded credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86673"
    },
    {
      "rank": 1273,
      "cve_id": "CVE-2026-86716",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cesanta",
      "product": "mJS",
      "cwe": "CWE-119",
      "title": "Cesanta mJS mjs_tok.c skip_spaces_and_comments heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86716"
    },
    {
      "rank": 1274,
      "cve_id": "CVE-2026-86808",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moltis-org",
      "product": "moltis",
      "cwe": "CWE-287",
      "title": "moltis-org moltis vault.rs vault_recovery_handler missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86808"
    },
    {
      "rank": 1275,
      "cve_id": "CVE-2025-64542",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64542"
    },
    {
      "rank": 1276,
      "cve_id": "CVE-2025-64584",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64584"
    },
    {
      "rank": 1277,
      "cve_id": "CVE-2025-64588",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64588"
    },
    {
      "rank": 1278,
      "cve_id": "CVE-2025-64589",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64589"
    },
    {
      "rank": 1279,
      "cve_id": "CVE-2025-64610",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64610"
    },
    {
      "rank": 1280,
      "cve_id": "CVE-2025-64618",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64618"
    },
    {
      "rank": 1281,
      "cve_id": "CVE-2025-64830",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64830"
    },
    {
      "rank": 1282,
      "cve_id": "CVE-2025-64838",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64838"
    },
    {
      "rank": 1283,
      "cve_id": "CVE-2025-64854",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64854"
    },
    {
      "rank": 1284,
      "cve_id": "CVE-2025-64866",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64866"
    },
    {
      "rank": 1285,
      "cve_id": "CVE-2025-64868",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64868"
    },
    {
      "rank": 1286,
      "cve_id": "CVE-2026-2520",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ladela",
      "product": "Online Scheduling and Appointment Booking System – Bookly",
      "cwe": "CWE-862",
      "title": "Online Scheduling and Appointment Booking System – Bookly <= 27.2 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Plugin Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2520"
    },
    {
      "rank": 1287,
      "cve_id": "CVE-2026-19479",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19479"
    },
    {
      "rank": 1288,
      "cve_id": "CVE-2026-19612",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19612"
    },
    {
      "rank": 1289,
      "cve_id": "CVE-2026-19644",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19644"
    },
    {
      "rank": 1290,
      "cve_id": "CVE-2026-19713",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19713"
    },
    {
      "rank": 1291,
      "cve_id": "CVE-2026-27227",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27227"
    },
    {
      "rank": 1292,
      "cve_id": "CVE-2026-71356",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71356"
    },
    {
      "rank": 1293,
      "cve_id": "CVE-2026-71357",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71357"
    },
    {
      "rank": 1294,
      "cve_id": "CVE-2026-71388",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71388"
    },
    {
      "rank": 1295,
      "cve_id": "CVE-2026-71440",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71440"
    },
    {
      "rank": 1296,
      "cve_id": "CVE-2026-71565",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71565"
    },
    {
      "rank": 1297,
      "cve_id": "CVE-2026-72626",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72626"
    },
    {
      "rank": 1298,
      "cve_id": "CVE-2026-72627",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72627"
    },
    {
      "rank": 1299,
      "cve_id": "CVE-2026-75629",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75629"
    },
    {
      "rank": 1300,
      "cve_id": "CVE-2026-75635",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75635"
    },
    {
      "rank": 1301,
      "cve_id": "CVE-2026-75636",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75636"
    },
    {
      "rank": 1302,
      "cve_id": "CVE-2026-75637",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75637"
    },
    {
      "rank": 1303,
      "cve_id": "CVE-2026-75639",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75639"
    },
    {
      "rank": 1304,
      "cve_id": "CVE-2026-75640",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75640"
    },
    {
      "rank": 1305,
      "cve_id": "CVE-2026-75642",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75642"
    },
    {
      "rank": 1306,
      "cve_id": "CVE-2026-75643",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75643"
    },
    {
      "rank": 1307,
      "cve_id": "CVE-2026-75644",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75644"
    },
    {
      "rank": 1308,
      "cve_id": "CVE-2026-75646",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75646"
    },
    {
      "rank": 1309,
      "cve_id": "CVE-2026-75647",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75647"
    },
    {
      "rank": 1310,
      "cve_id": "CVE-2026-75651",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75651"
    },
    {
      "rank": 1311,
      "cve_id": "CVE-2026-75652",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75652"
    },
    {
      "rank": 1312,
      "cve_id": "CVE-2026-75657",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75657"
    },
    {
      "rank": 1313,
      "cve_id": "CVE-2026-75659",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75659"
    },
    {
      "rank": 1314,
      "cve_id": "CVE-2026-75660",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75660"
    },
    {
      "rank": 1315,
      "cve_id": "CVE-2026-75661",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75661"
    },
    {
      "rank": 1316,
      "cve_id": "CVE-2026-75666",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75666"
    },
    {
      "rank": 1317,
      "cve_id": "CVE-2026-75667",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75667"
    },
    {
      "rank": 1318,
      "cve_id": "CVE-2026-75668",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75668"
    },
    {
      "rank": 1319,
      "cve_id": "CVE-2026-75669",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75669"
    },
    {
      "rank": 1320,
      "cve_id": "CVE-2026-75670",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75670"
    },
    {
      "rank": 1321,
      "cve_id": "CVE-2026-75671",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75671"
    },
    {
      "rank": 1322,
      "cve_id": "CVE-2026-75672",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75672"
    },
    {
      "rank": 1323,
      "cve_id": "CVE-2026-75674",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75674"
    },
    {
      "rank": 1324,
      "cve_id": "CVE-2026-75675",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75675"
    },
    {
      "rank": 1325,
      "cve_id": "CVE-2026-75677",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75677"
    },
    {
      "rank": 1326,
      "cve_id": "CVE-2026-75678",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75678"
    },
    {
      "rank": 1327,
      "cve_id": "CVE-2026-75679",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75679"
    },
    {
      "rank": 1328,
      "cve_id": "CVE-2026-75680",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75680"
    },
    {
      "rank": 1329,
      "cve_id": "CVE-2026-75681",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75681"
    },
    {
      "rank": 1330,
      "cve_id": "CVE-2026-75683",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75683"
    },
    {
      "rank": 1331,
      "cve_id": "CVE-2026-75685",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75685"
    },
    {
      "rank": 1332,
      "cve_id": "CVE-2026-75687",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75687"
    },
    {
      "rank": 1333,
      "cve_id": "CVE-2026-75690",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75690"
    },
    {
      "rank": 1334,
      "cve_id": "CVE-2026-75691",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75691"
    },
    {
      "rank": 1335,
      "cve_id": "CVE-2026-75692",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75692"
    },
    {
      "rank": 1336,
      "cve_id": "CVE-2026-75693",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75693"
    },
    {
      "rank": 1337,
      "cve_id": "CVE-2026-75694",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75694"
    },
    {
      "rank": 1338,
      "cve_id": "CVE-2026-75695",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75695"
    },
    {
      "rank": 1339,
      "cve_id": "CVE-2026-75696",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75696"
    },
    {
      "rank": 1340,
      "cve_id": "CVE-2026-75700",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75700"
    },
    {
      "rank": 1341,
      "cve_id": "CVE-2026-75701",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75701"
    },
    {
      "rank": 1342,
      "cve_id": "CVE-2026-75702",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75702"
    },
    {
      "rank": 1343,
      "cve_id": "CVE-2026-75704",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75704"
    },
    {
      "rank": 1344,
      "cve_id": "CVE-2026-75705",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75705"
    },
    {
      "rank": 1345,
      "cve_id": "CVE-2026-75706",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75706"
    },
    {
      "rank": 1346,
      "cve_id": "CVE-2026-75707",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75707"
    },
    {
      "rank": 1347,
      "cve_id": "CVE-2026-75708",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75708"
    },
    {
      "rank": 1348,
      "cve_id": "CVE-2026-75709",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75709"
    },
    {
      "rank": 1349,
      "cve_id": "CVE-2026-75710",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75710"
    },
    {
      "rank": 1350,
      "cve_id": "CVE-2026-75711",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75711"
    },
    {
      "rank": 1351,
      "cve_id": "CVE-2026-75712",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75712"
    },
    {
      "rank": 1352,
      "cve_id": "CVE-2026-75713",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75713"
    },
    {
      "rank": 1353,
      "cve_id": "CVE-2026-75714",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75714"
    },
    {
      "rank": 1354,
      "cve_id": "CVE-2026-75715",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75715"
    },
    {
      "rank": 1355,
      "cve_id": "CVE-2026-75716",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75716"
    },
    {
      "rank": 1356,
      "cve_id": "CVE-2026-75717",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75717"
    },
    {
      "rank": 1357,
      "cve_id": "CVE-2026-75718",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75718"
    },
    {
      "rank": 1358,
      "cve_id": "CVE-2026-75719",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75719"
    },
    {
      "rank": 1359,
      "cve_id": "CVE-2026-75720",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75720"
    },
    {
      "rank": 1360,
      "cve_id": "CVE-2026-75722",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75722"
    },
    {
      "rank": 1361,
      "cve_id": "CVE-2026-75724",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75724"
    },
    {
      "rank": 1362,
      "cve_id": "CVE-2026-75725",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75725"
    },
    {
      "rank": 1363,
      "cve_id": "CVE-2026-75727",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75727"
    },
    {
      "rank": 1364,
      "cve_id": "CVE-2026-75729",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75729"
    },
    {
      "rank": 1365,
      "cve_id": "CVE-2026-75730",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75730"
    },
    {
      "rank": 1366,
      "cve_id": "CVE-2026-75731",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75731"
    },
    {
      "rank": 1367,
      "cve_id": "CVE-2026-75733",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75733"
    },
    {
      "rank": 1368,
      "cve_id": "CVE-2026-75734",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75734"
    },
    {
      "rank": 1369,
      "cve_id": "CVE-2026-75735",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75735"
    },
    {
      "rank": 1370,
      "cve_id": "CVE-2026-75736",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75736"
    },
    {
      "rank": 1371,
      "cve_id": "CVE-2026-75737",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75737"
    },
    {
      "rank": 1372,
      "cve_id": "CVE-2026-75738",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75738"
    },
    {
      "rank": 1373,
      "cve_id": "CVE-2026-75739",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75739"
    },
    {
      "rank": 1374,
      "cve_id": "CVE-2026-75740",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75740"
    },
    {
      "rank": 1375,
      "cve_id": "CVE-2026-75741",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75741"
    },
    {
      "rank": 1376,
      "cve_id": "CVE-2026-75742",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75742"
    },
    {
      "rank": 1377,
      "cve_id": "CVE-2026-79905",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79905"
    },
    {
      "rank": 1378,
      "cve_id": "CVE-2026-84385",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiSOAR on-premise",
      "cwe": "CWE-284",
      "title": "A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.6, FortiSOAR on-premise 7.5.0 through 7.5.3, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow attacker to escalation of privilege via <insert attack vector here>",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84385"
    },
    {
      "rank": 1379,
      "cve_id": "CVE-2026-19614",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CyberELF",
      "product": "NanoXML",
      "cwe": "CWE-611",
      "title": "XML External Entity (XXE) Injection in CyberELF NanoXML",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19614"
    },
    {
      "rank": 1380,
      "cve_id": "CVE-2026-19625",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Enterprise Build of Quarkus",
      "cwe": "CWE-284",
      "title": "IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19625"
    },
    {
      "rank": 1381,
      "cve_id": "CVE-2026-33389",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nozomi Networks",
      "product": "Guardian",
      "cwe": "CWE-671",
      "title": "Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian/CMC before 26.3.0 and Arc before v2.7.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33389"
    },
    {
      "rank": 1382,
      "cve_id": "CVE-2026-33391",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nozomi Networks",
      "product": "Guardian",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33391"
    },
    {
      "rank": 1383,
      "cve_id": "CVE-2026-47680",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fluxcd",
      "product": "source-controller",
      "cwe": "CWE-23",
      "title": "Source controller: Improper path handling allows traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47680"
    },
    {
      "rank": 1384,
      "cve_id": "CVE-2026-70575",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-476",
      "title": "Windows Schannel Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70575"
    },
    {
      "rank": 1385,
      "cve_id": "CVE-2026-78446",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Distributed File System (DFS) Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78446"
    },
    {
      "rank": 1386,
      "cve_id": "CVE-2026-78631",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Okta",
      "product": "Okta Hyperdrive Agent",
      "cwe": "CWE-532",
      "title": "Improper Restriction of Sensitive Information in Okta Hyperdrive Agent Logging",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78631"
    },
    {
      "rank": 1387,
      "cve_id": "CVE-2026-81380",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-77",
      "title": "GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81380"
    },
    {
      "rank": 1388,
      "cve_id": "CVE-2026-82066",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-125",
      "title": "Heap Out-of-Bounds Read in MongoDB Server Query Planning Component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82066"
    },
    {
      "rank": 1389,
      "cve_id": "CVE-2026-86714",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PX4",
      "product": "PX4-Autopilot",
      "cwe": "CWE-125",
      "title": "PX4 Autopilot through 1.17.0 Stack Buffer Over-read via netman",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86714"
    },
    {
      "rank": 1390,
      "cve_id": "CVE-2026-86719",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-352",
      "title": "WWBN AVideo CustomizeUser Cross-Site Request Forgery Session Hijacking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86719"
    },
    {
      "rank": 1391,
      "cve_id": "CVE-2026-86736",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-682",
      "title": "snipe-it before 8.7.0 Checkout Request Counter Integrity Failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86736"
    },
    {
      "rank": 1392,
      "cve_id": "CVE-2026-86737",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-862",
      "title": "snipe-it before 8.7.0 Missing Authorization via barcode endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86737"
    },
    {
      "rank": 1393,
      "cve_id": "CVE-2026-86994",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-862",
      "title": "n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86994"
    },
    {
      "rank": 1394,
      "cve_id": "CVE-2026-86995",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-22",
      "title": "n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86995"
    },
    {
      "rank": 1395,
      "cve_id": "CVE-2026-86996",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-862",
      "title": "n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86996"
    },
    {
      "rank": 1396,
      "cve_id": "CVE-2026-33387",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nozomi Networks",
      "product": "Guardian",
      "cwe": "CWE-1336",
      "title": "Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33387"
    },
    {
      "rank": 1397,
      "cve_id": "CVE-2026-33920",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nozomi Networks",
      "product": "Guardian",
      "cwe": "CWE-352",
      "title": "Cross-site request forgery in the Guardian/CMC login before 26.3.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33920"
    },
    {
      "rank": 1398,
      "cve_id": "CVE-2026-73317",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XenForo",
      "product": "XenForo",
      "cwe": "CWE-863",
      "title": "XenForo < 2.3.13 Missing Authorization via ACP Cache-Rebuild Dispatcher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73317"
    },
    {
      "rank": 1399,
      "cve_id": "CVE-2026-73318",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XenForo",
      "product": "XenForo",
      "cwe": "CWE-863",
      "title": "XenForo < 2.3.13 Missing Authorization via force-agreement Controller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73318"
    },
    {
      "rank": 1400,
      "cve_id": "CVE-2026-73319",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XenForo",
      "product": "XenForo",
      "cwe": "CWE-79",
      "title": "XenForo < 2.3.13 XSS via Dynamic Redirect Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73319"
    },
    {
      "rank": 1401,
      "cve_id": "CVE-2026-73320",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XenForo",
      "product": "XenForo",
      "cwe": "CWE-639",
      "title": "XenForo < 2.3.13 Unauthenticated Information Disclosure via Unfurl Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73320"
    },
    {
      "rank": 1402,
      "cve_id": "CVE-2026-82069",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-212",
      "title": "Improper Redaction of Query Literals in MongoDB Server Query Statistics Serialization on Sharded Cluster Router",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82069"
    },
    {
      "rank": 1403,
      "cve_id": "CVE-2026-84386",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiClientWindows",
      "cwe": "CWE-283",
      "title": "A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector here>",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84386"
    },
    {
      "rank": 1404,
      "cve_id": "CVE-2026-86085",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-862",
      "title": "n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86085"
    },
    {
      "rank": 1405,
      "cve_id": "CVE-2026-72976",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72976"
    },
    {
      "rank": 1406,
      "cve_id": "CVE-2026-78635",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Okta",
      "product": "Okta Privileged Access Client",
      "cwe": "CWE-88",
      "title": "Improper Input Validation in the Okta Privileged Access SSH Client URL Handler Argument",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78635"
    },
    {
      "rank": 1407,
      "cve_id": "CVE-2026-79904",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Photoshop Android",
      "cwe": "CWE-22",
      "title": "Photoshop Mobile | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79904"
    },
    {
      "rank": 1408,
      "cve_id": "CVE-2026-22575",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiManager",
      "cwe": "CWE-284",
      "title": "An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1 through 7.4.10, FortiManager Cloud 7.2 all versions may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22575"
    },
    {
      "rank": 1409,
      "cve_id": "CVE-2026-68785",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SQL Server 2017 (CU 31)",
      "cwe": "CWE-122",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68785"
    },
    {
      "rank": 1410,
      "cve_id": "CVE-2026-78624",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Okta",
      "product": "Okta Access Gateway",
      "cwe": "CWE-22",
      "title": "Improper Path Validation in Okta Access Gateway Backup and Restore Functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78624"
    },
    {
      "rank": 1411,
      "cve_id": "CVE-2026-69474",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-126",
      "title": "Windows Overlay Filter Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69474"
    },
    {
      "rank": 1412,
      "cve_id": "CVE-2026-78560",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Okta",
      "product": "Okta Access Gateway",
      "cwe": "CWE-287",
      "title": "Improper Authentication Validation in Okta Access Gateway Pass-Through Authentication Source",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78560"
    },
    {
      "rank": 1413,
      "cve_id": "CVE-2026-68849",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-125",
      "title": "Windows Bluetooth Port Driver Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68849"
    },
    {
      "rank": 1414,
      "cve_id": "CVE-2026-68891",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Microsoft Standard XPS Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68891"
    },
    {
      "rank": 1415,
      "cve_id": "CVE-2026-69316",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-126",
      "title": "Windows Overlay Filter Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69316"
    },
    {
      "rank": 1416,
      "cve_id": "CVE-2026-69425",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-59",
      "title": "Windows NTFS Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69425"
    },
    {
      "rank": 1417,
      "cve_id": "CVE-2026-69483",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Image Acquisition Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69483"
    },
    {
      "rank": 1418,
      "cve_id": "CVE-2026-69771",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-59",
      "title": "Windows Container Manager Service Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69771"
    },
    {
      "rank": 1419,
      "cve_id": "CVE-2026-69792",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows Win32K Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69792"
    },
    {
      "rank": 1420,
      "cve_id": "CVE-2026-69853",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-908",
      "title": "Win32k Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69853"
    },
    {
      "rank": 1421,
      "cve_id": "CVE-2026-69895",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Spaceport.sys Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69895"
    },
    {
      "rank": 1422,
      "cve_id": "CVE-2026-72931",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-772",
      "title": "Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72931"
    },
    {
      "rank": 1423,
      "cve_id": "CVE-2026-69381",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Storage Port Driver Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69381"
    },
    {
      "rank": 1424,
      "cve_id": "CVE-2026-69548",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows RNDIS Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69548"
    },
    {
      "rank": 1425,
      "cve_id": "CVE-2026-69690",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "cwe": "CWE-79",
      "title": "Microsoft Office SharePoint Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69690"
    },
    {
      "rank": 1426,
      "cve_id": "CVE-2026-78452",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-125",
      "title": "Microsoft Windows SCSI Class System File Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78452"
    },
    {
      "rank": 1427,
      "cve_id": "CVE-2026-78508",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows CD-ROM Driver Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78508"
    },
    {
      "rank": 1428,
      "cve_id": "CVE-2026-0001",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arm Ltd",
      "product": "Bifrost GPU Kernel Driver",
      "cwe": "CWE-416",
      "title": "Mali GPU Kernel Driver allows access to already freed memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0001"
    },
    {
      "rank": 1429,
      "cve_id": "CVE-2026-69713",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-1395",
      "title": "Windows Secure Boot Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69713"
    },
    {
      "rank": 1430,
      "cve_id": "CVE-2026-72980",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-427",
      "title": "Windows Hello Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72980"
    },
    {
      "rank": 1431,
      "cve_id": "CVE-2026-53638",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sylius",
      "product": "Sylius",
      "cwe": "CWE-863",
      "title": "Sylius: Channel-based payment method restriction bypass on shop account orders API endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53638"
    },
    {
      "rank": 1432,
      "cve_id": "CVE-2026-73019",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-41",
      "title": "Windows URL Moniker Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73019"
    },
    {
      "rank": 1433,
      "cve_id": "CVE-2026-78455",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Xbox Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78455"
    },
    {
      "rank": 1434,
      "cve_id": "CVE-2026-78516",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-126",
      "title": "Windows Storage Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78516"
    },
    {
      "rank": 1435,
      "cve_id": "CVE-2026-79603",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-664",
      "title": "Unconditionally do TLB flushing ahead of page scrubbing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79603"
    },
    {
      "rank": 1436,
      "cve_id": "CVE-2026-86853",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox for iOS",
      "cwe": "CWE-451",
      "title": "Repeated external URL scheme launches could potentially cause a denial of service in Firefox for iOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86853"
    },
    {
      "rank": 1437,
      "cve_id": "CVE-2026-80159",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat",
      "cwe": "CWE-426",
      "title": "Acrobat Reader | Untrusted Search Path (CWE-426)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80159"
    },
    {
      "rank": 1438,
      "cve_id": "CVE-2026-69615",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "cwe": "CWE-79",
      "title": "Microsoft Office SharePoint Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69615"
    },
    {
      "rank": 1439,
      "cve_id": "CVE-2026-69904",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "cwe": "CWE-918",
      "title": "Microsoft Office SharePoint Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69904"
    },
    {
      "rank": 1440,
      "cve_id": "CVE-2026-75726",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager as a Cloud Service",
      "cwe": "CWE-20",
      "title": "Adobe Experience Manager | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75726"
    },
    {
      "rank": 1441,
      "cve_id": "CVE-2026-86564",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Fast Datapath for RHEL 10",
      "cwe": "CWE-125",
      "title": "Dpdk: dpdk: missing length validation before reading command_data in virtio-net control queue handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86564"
    },
    {
      "rank": 1442,
      "cve_id": "CVE-2026-48707",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "instantsoft",
      "product": "icms2",
      "cwe": "CWE-918",
      "title": "InstantCMS vulnerable to SSRF via upload redirect bypass allows internal network service scanning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48707"
    },
    {
      "rank": 1443,
      "cve_id": "CVE-2026-84389",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiSIEM",
      "cwe": "CWE-601",
      "title": "A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or commands via <insert attack vector here>",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84389"
    },
    {
      "rank": 1444,
      "cve_id": "CVE-2026-86670",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aircheng-org",
      "product": "iWebShop-5",
      "cwe": "CWE-326",
      "title": "aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86670"
    },
    {
      "rank": 1445,
      "cve_id": "CVE-2026-84392",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiOS",
      "cwe": "CWE-476",
      "title": "A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.6, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84392"
    },
    {
      "rank": 1446,
      "cve_id": "CVE-2026-82060",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-943",
      "title": "Insufficient Validation of Shard Key Values in MongoDB Server Leads to Query Operator Injection in Change Stream Post-Image Lookups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82060"
    },
    {
      "rank": 1447,
      "cve_id": "CVE-2026-86668",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aircheng-org",
      "product": "iWebShop-5",
      "cwe": "CWE-79",
      "title": "aircheng-org iWebShop-5 pic.php uploadFile cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86668"
    },
    {
      "rank": 1448,
      "cve_id": "CVE-2026-86674",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ningzichun",
      "product": "Student Management System",
      "cwe": "CWE-384",
      "title": "ningzichun Student Management System login.php session_start session fixiation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86674"
    },
    {
      "rank": 1449,
      "cve_id": "CVE-2026-86675",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System us_edit.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86675"
    },
    {
      "rank": 1450,
      "cve_id": "CVE-2026-86644",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "star7th",
      "product": "showdoc",
      "cwe": "CWE-79",
      "title": "star7th showdoc API Page Save Endpoint editormd.js cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86644"
    },
    {
      "rank": 1451,
      "cve_id": "CVE-2026-86667",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aircheng-org",
      "product": "iWebShop-5",
      "cwe": "CWE-74",
      "title": "aircheng-org iWebShop-5 member.php member_list sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86667"
    },
    {
      "rank": 1452,
      "cve_id": "CVE-2026-9215",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "XR1000",
      "cwe": "CWE-352",
      "title": "A CSRF vulnerability exists in certain NETGEAR XR series devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9215"
    },
    {
      "rank": 1453,
      "cve_id": "CVE-2026-9216",
      "cvss_base": 1.2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "RAX30",
      "cwe": "CWE-121",
      "title": "Insufficient input validation vulnerability exists in certain NETGEAR RAX Models",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9216"
    },
    {
      "rank": 1454,
      "cve_id": "CVE-2026-0054",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In isCallerAllowed of WalletContextualLocationsService.kt, there is a possible way to get wallet information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0054"
    },
    {
      "rank": 1455,
      "cve_id": "CVE-2026-0065",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In areBackgroundActivityStartsAllowed of BackgroundLaunchProcessController.java, there is a possible unintended way to launch activities in the background due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0065"
    },
    {
      "rank": 1456,
      "cve_id": "CVE-2026-0084",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple functions of HostEmulationManager.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0084"
    },
    {
      "rank": 1457,
      "cve_id": "CVE-2026-0860",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arm Ltd",
      "product": "Valhall GPU Kernel Driver",
      "cwe": "CWE-200",
      "title": "Mali GPU Kernel Driver allows access to sensitive kernel information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0860"
    },
    {
      "rank": 1458,
      "cve_id": "CVE-2026-5729",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arm Ltd",
      "product": "Valhall GPU Kernel Driver",
      "cwe": "CWE-416",
      "title": "Mali GPU Kernel Driver allows access to already freed memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5729"
    },
    {
      "rank": 1459,
      "cve_id": "CVE-2026-7476",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arm Ltd",
      "product": "Bifrost GPU Kernel Driver",
      "cwe": "CWE-416",
      "title": "Mali GPU Kernel Driver allows access to already freed memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7476"
    },
    {
      "rank": 1460,
      "cve_id": "CVE-2026-7477",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arm Ltd",
      "product": "Bifrost GPU Kernel Driver",
      "cwe": "CWE-416",
      "title": "Mali GPU Kernel Driver allows access to already freed memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7477"
    },
    {
      "rank": 1461,
      "cve_id": "CVE-2026-9034",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arm Ltd",
      "product": "Bifrost GPU Userspace Driver",
      "cwe": "CWE-416",
      "title": "Mali GPU Userspace Driver allows access to already freed memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9034"
    },
    {
      "rank": 1462,
      "cve_id": "CVE-2026-9040",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arm Ltd",
      "product": "Bifrost GPU Kernel Driver",
      "cwe": "CWE-362",
      "title": "Mali GPU Kernel Driver allows denial of service or disclosure of sensitive information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9040"
    },
    {
      "rank": 1463,
      "cve_id": "CVE-2026-11891",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arm Ltd",
      "product": "Valhall GPU Userspace Driver",
      "cwe": "CWE-416",
      "title": "Mali GPU Userspace Driver allows access to already freed memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11891"
    },
    {
      "rank": 1464,
      "cve_id": "CVE-2026-12285",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arm Ltd",
      "product": "Bifrost GPU Kernel Driver",
      "cwe": "CWE-416",
      "title": "Mali GPU Kernel Driver allows access to already freed memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12285"
    },
    {
      "rank": 1465,
      "cve_id": "CVE-2026-12387",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arm Ltd",
      "product": "Bifrost GPU Kernel Driver",
      "cwe": "CWE-416",
      "title": "Mali GPU Kernel Driver allows access to already freed memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12387"
    },
    {
      "rank": 1466,
      "cve_id": "CVE-2026-19872",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "HTML-FormHandler",
      "cwe": "CWE-79",
      "title": "HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19872"
    },
    {
      "rank": 1467,
      "cve_id": "CVE-2026-28572",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In onCreate of InstallLaunch.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28572"
    },
    {
      "rank": 1468,
      "cve_id": "CVE-2026-28582",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In onCreate of ConfirmDeviceCredentialActivity.java, there is a possible unauthorized access to and modification of device credentials due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28582"
    },
    {
      "rank": 1469,
      "cve_id": "CVE-2026-28583",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In validate_camera_metadata_structure of camera_metadata.c, there is a possible out of bounds write due to a logical error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28583"
    },
    {
      "rank": 1470,
      "cve_id": "CVE-2026-28584",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In createSessionInternal of PackageInstallerService.java, there is a possible way to permanently DoS the device due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28584"
    },
    {
      "rank": 1471,
      "cve_id": "CVE-2026-28590",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple locations, there is a possible improper encryption key validation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28590"
    },
    {
      "rank": 1472,
      "cve_id": "CVE-2026-28593",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28593"
    },
    {
      "rank": 1473,
      "cve_id": "CVE-2026-28594",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple locations, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28594"
    },
    {
      "rank": 1474,
      "cve_id": "CVE-2026-28596",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28596"
    },
    {
      "rank": 1475,
      "cve_id": "CVE-2026-28599",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In addCreatorToken of ActivityManagerService.java, there is a possible Intent Redirection Bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28599"
    },
    {
      "rank": 1476,
      "cve_id": "CVE-2026-28600",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In onCreate of PaymentDefaultDialog.java, there is a possible way to change default payment app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28600"
    },
    {
      "rank": 1477,
      "cve_id": "CVE-2026-28602",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In setClipboardAccessNotificationsEnabledForUser of ClipboardService.java, there is a possible mult-iuser isolation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28602"
    },
    {
      "rank": 1478,
      "cve_id": "CVE-2026-28603",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible read/write access to private files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28603"
    },
    {
      "rank": 1479,
      "cve_id": "CVE-2026-28604",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple locations, there is a possible use after free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28604"
    },
    {
      "rank": 1480,
      "cve_id": "CVE-2026-28606",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead to remote escalation of privilege without user consent with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28606"
    },
    {
      "rank": 1481,
      "cve_id": "CVE-2026-28607",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple functions in multiple locations, there is a possible background activity launch bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28607"
    },
    {
      "rank": 1482,
      "cve_id": "CVE-2026-28609",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In read of MatroskaExtractor.cpp, there is a possible out-of-bounds write due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28609"
    },
    {
      "rank": 1483,
      "cve_id": "CVE-2026-28611",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple functions of NfcService.java, there is a possible silent payment session hijacking enablement due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28611"
    },
    {
      "rank": 1484,
      "cve_id": "CVE-2026-28612",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In resolveActivity of ActivityStarter.java, there is a possible way to perform Intent Redirection attacks due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28612"
    },
    {
      "rank": 1485,
      "cve_id": "CVE-2026-28613",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In initAppLinkTypeAndIntent of ChannelImpl.java, there is a possible launch an arbitrary intent due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28613"
    },
    {
      "rank": 1486,
      "cve_id": "CVE-2026-28614",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In onCreate of SlicePermissionActivity.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28614"
    },
    {
      "rank": 1487,
      "cve_id": "CVE-2026-28616",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In Setup Wizard, there is a possible way to force connection to a malicious network due to confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28616"
    },
    {
      "rank": 1488,
      "cve_id": "CVE-2026-28617",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In add of WifiNetworkSuggestionsManager.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28617"
    },
    {
      "rank": 1489,
      "cve_id": "CVE-2026-28618",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28618"
    },
    {
      "rank": 1490,
      "cve_id": "CVE-2026-28620",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple locations, there is a possible unauthorized URI access due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28620"
    },
    {
      "rank": 1491,
      "cve_id": "CVE-2026-28622",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In getQueryBuilderInternal of MediaProvider.java, there is a possible way to retrieve location metadata due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28622"
    },
    {
      "rank": 1492,
      "cve_id": "CVE-2026-28623",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In writeToParcel of BleRssiRangingCapabilities.java, there is a possible way to obtain the Bluetooth MAC address due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28623"
    },
    {
      "rank": 1493,
      "cve_id": "CVE-2026-28624",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple locations, there is a possible read/write access to files without the proper permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28624"
    },
    {
      "rank": 1494,
      "cve_id": "CVE-2026-28626",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In onCreate of SetupPassthroughActivity.java, there is a possible way to launch arbitrary activity due to Intent redirection . This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28626"
    },
    {
      "rank": 1495,
      "cve_id": "CVE-2026-28627",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In btm_sec_encrypt_change of btm_sec.cc, there is a possible downgrade attack due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28627"
    },
    {
      "rank": 1496,
      "cve_id": "CVE-2026-28630",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In onCreate of ContactsPickerActivity.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28630"
    },
    {
      "rank": 1497,
      "cve_id": "CVE-2026-28631",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In buildMiniResolver of IntentForwarderActivity.java, there is a possible consent bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28631"
    },
    {
      "rank": 1498,
      "cve_id": "CVE-2026-28633",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In initForUserNoTracing of VoiceInteractionManagerService.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28633"
    },
    {
      "rank": 1499,
      "cve_id": "CVE-2026-28634",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In handleUssdRequest of PhoneInterfaceManager.java, there is a possible way to send a USSD request without permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28634"
    },
    {
      "rank": 1500,
      "cve_id": "CVE-2026-28636",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In setupLayout of PickActivity.java, there is a possible bypass of the \"Install unknown apps\" security restriction due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28636"
    },
    {
      "rank": 1501,
      "cve_id": "CVE-2026-28638",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple functions of XmpDataParser.java, there is a possible improper data sanitization due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28638"
    },
    {
      "rank": 1502,
      "cve_id": "CVE-2026-28639",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28639"
    },
    {
      "rank": 1503,
      "cve_id": "CVE-2026-28642",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In executeRequest of ActivityStarter.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28642"
    },
    {
      "rank": 1504,
      "cve_id": "CVE-2026-28644",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28644"
    },
    {
      "rank": 1505,
      "cve_id": "CVE-2026-28650",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In setHiddenWhileSuspended of WindowState.java, there is a possible overlay bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28650"
    },
    {
      "rank": 1506,
      "cve_id": "CVE-2026-28652",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple functions of RangingServiceImpl.java, there is a possible MITM due to a missing permission check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28652"
    },
    {
      "rank": 1507,
      "cve_id": "CVE-2026-28653",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28653"
    },
    {
      "rank": 1508,
      "cve_id": "CVE-2026-28655",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple functions of RemoteViews.java, there is a possible background activity launch bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28655"
    },
    {
      "rank": 1509,
      "cve_id": "CVE-2026-28656",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28656"
    },
    {
      "rank": 1510,
      "cve_id": "CVE-2026-28657",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In onActivityResult of AppWidgetConfigActivityProxy.java, there is a possible unauthorized URI permission grant due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28657"
    },
    {
      "rank": 1511,
      "cve_id": "CVE-2026-28658",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In findMetaAuthUid of AccountsDb.java, there is a possible frp bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28658"
    },
    {
      "rank": 1512,
      "cve_id": "CVE-2026-28660",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In getAllSessions of multiple files, there is a possible confused deputy due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28660"
    },
    {
      "rank": 1513,
      "cve_id": "CVE-2026-28662",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28662"
    },
    {
      "rank": 1514,
      "cve_id": "CVE-2026-28663",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28663"
    },
    {
      "rank": 1515,
      "cve_id": "CVE-2026-28666",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple functions of LocalImageResolver.java, there is a possible Remote Persistent Denial of Service due to a DNG image rendering check bypass. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28666"
    },
    {
      "rank": 1516,
      "cve_id": "CVE-2026-28668",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In LimitRealloc of malloc_limit.cpp, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28668"
    },
    {
      "rank": 1517,
      "cve_id": "CVE-2026-28671",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In updateInternal of MediaProvider.java, there is a possible expose contents of files due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28671"
    },
    {
      "rank": 1518,
      "cve_id": "CVE-2026-30754",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP encoding process. In the nal_send function in libavformat/rtpenc_h264_hevc.c, a negative size parameter (size=-3) is passed to memcpy when transmitting H.264/HEVC streams via RTP using a crafted input file. This was detected using AddressSanitizer.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30754"
    },
    {
      "rank": 1519,
      "cve_id": "CVE-2026-45515",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45515"
    },
    {
      "rank": 1520,
      "cve_id": "CVE-2026-45519",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In screenArgsForPermissionCheckIfAny of multiple locations there is a possible risk of unauthorized access due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45519"
    },
    {
      "rank": 1521,
      "cve_id": "CVE-2026-45520",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In onAttach of BiometricsSettingsBase.java, there is a possible authentication bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45520"
    },
    {
      "rank": 1522,
      "cve_id": "CVE-2026-45521",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In openFile of AppFuseBridge.java, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45521"
    },
    {
      "rank": 1523,
      "cve_id": "CVE-2026-45525",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple locations, there is a possible improper data sanitization due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45525"
    },
    {
      "rank": 1524,
      "cve_id": "CVE-2026-45527",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In convertCleanApertureToRect of HeifCleanAperture.cpp, there is a possible way to cause a temporary denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45527"
    },
    {
      "rank": 1525,
      "cve_id": "CVE-2026-45528",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45528"
    },
    {
      "rank": 1526,
      "cve_id": "CVE-2026-45531",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In read_boot_region of fsck.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45531"
    },
    {
      "rank": 1527,
      "cve_id": "CVE-2026-49879",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49879"
    },
    {
      "rank": 1528,
      "cve_id": "CVE-2026-49881",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49881"
    },
    {
      "rank": 1529,
      "cve_id": "CVE-2026-49882",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49882"
    },
    {
      "rank": 1530,
      "cve_id": "CVE-2026-49884",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49884"
    },
    {
      "rank": 1531,
      "cve_id": "CVE-2026-49887",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In maybeRemoveInvalidInstallerPackageName of InstallRepository.kt, there is a possible unauthorized app update due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49887"
    },
    {
      "rank": 1532,
      "cve_id": "CVE-2026-49895",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In get_eht_operation_channel_width of ieee802_11_common.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49895"
    },
    {
      "rank": 1533,
      "cve_id": "CVE-2026-49918",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple functions, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49918"
    },
    {
      "rank": 1534,
      "cve_id": "CVE-2026-49919",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In tt_face_colr_blend_layer of ttcolr.c, there is a possible remote code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49919"
    },
    {
      "rank": 1535,
      "cve_id": "CVE-2026-52307",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management component of ClassCMS 1CMS v5.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the title field.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52307"
    },
    {
      "rank": 1536,
      "cve_id": "CVE-2026-52486",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52486"
    },
    {
      "rank": 1537,
      "cve_id": "CVE-2026-55256",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In parsePartHeaders of multiple files, there is a possible persistent denial of service due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55256"
    },
    {
      "rank": 1538,
      "cve_id": "CVE-2026-55290",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In setTo of ResourceTypes.cpp, there is a possible out-of-bounds heap read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55290"
    },
    {
      "rank": 1539,
      "cve_id": "CVE-2026-58820",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": null,
      "title": "In multiple locations, there is a possible memory safety issue due to integer overflow. This could lead to local escalation of privilege with no additional execution privileges required.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58820"
    },
    {
      "rank": 1540,
      "cve_id": "CVE-2026-62437",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": null,
      "title": "x86: DMs may cause mem leak by IRQ binding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62437"
    },
    {
      "rank": 1541,
      "cve_id": "CVE-2026-78738",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Document management file upload feature.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78738"
    },
    {
      "rank": 1542,
      "cve_id": "CVE-2026-78741",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78741"
    },
    {
      "rank": 1543,
      "cve_id": "CVE-2026-78742",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78742"
    },
    {
      "rank": 1544,
      "cve_id": "CVE-2026-78834",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugin. An authenticated low-privileged user who can modify page content and provide controlled imported content can trigger server-side execution by referencing crafted external or uploaded text content through the affected content import feature.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78834"
    },
    {
      "rank": 1545,
      "cve_id": "CVE-2026-78837",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 allows attackers to access sensitive database information via a crafted SQL statement.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78837"
    },
    {
      "rank": 1546,
      "cve_id": "CVE-2026-78838",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A reflected cross-site scripting (XSS) vulnerability in the grid_datasource.php component of AppNitro MachForm v30 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted payload into the filter[filters][0][field] parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78838"
    },
    {
      "rank": 1547,
      "cve_id": "CVE-2026-78971",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78971"
    },
    {
      "rank": 1548,
      "cve_id": "CVE-2026-78997",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain (via a reflected XSS) that leverages the browser's internal JavaScript bridge to register a deferred callback, navigate the tab to a victim site, and then execute attacker-controlled code on that site when a login dialog is dismissed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78997"
    },
    {
      "rank": 1549,
      "cve_id": "CVE-2026-79378",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in the btm_acl_handle() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79378"
    },
    {
      "rank": 1550,
      "cve_id": "CVE-2026-79379",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "A buffer overflow in the SBC_DecodeFrames() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier and fixed in v.5.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted frame.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79379"
    },
    {
      "rank": 1551,
      "cve_id": "CVE-2026-79570",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79570"
    },
    {
      "rank": 1552,
      "cve_id": "CVE-2026-79571",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cancel orders, and modify categories without authentication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79571"
    },
    {
      "rank": 1553,
      "cve_id": "CVE-2026-79572",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An XXE (XML External Entity) vulnerability in the level-rule module of Distribution Management v1.0.0 allows attackers to read sensitive files, scan internal networks, or launch server attacks via supplying a crafted XML payload.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79572"
    },
    {
      "rank": 1554,
      "cve_id": "CVE-2026-79573",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "L-ONE v1.0.0 was discovered to contain multiple SQL injection vulnerabilities in the /attachment/getBusinessUploadList component via the busid, id, and taskid parameters. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79573"
    },
    {
      "rank": 1555,
      "cve_id": "CVE-2026-79574",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79574"
    },
    {
      "rank": 1556,
      "cve_id": "CVE-2026-79575",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "The JWT signing secret in yfexam-exam v2.0 is derived from the username and the current month instead of a random server-side key, making the secret key easily obtainable via a bruteforce attack.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79575"
    },
    {
      "rank": 1557,
      "cve_id": "CVE-2026-79577",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79577"
    },
    {
      "rank": 1558,
      "cve_id": "CVE-2026-79588",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79588"
    },
    {
      "rank": 1559,
      "cve_id": "CVE-2026-79602",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": null,
      "title": "x86: improper handling of HVM emulation return codes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79602"
    },
    {
      "rank": 1560,
      "cve_id": "CVE-2026-84282",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ascensio System SIA / OnlyOffice",
      "product": "ONLYOFFICE ownCloud integration plugin",
      "cwe": null,
      "title": "A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin (version 9.12)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84282"
    },
    {
      "rank": 1561,
      "cve_id": "CVE-2026-85484",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "HTML-FormHandler",
      "cwe": "CWE-79",
      "title": "HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85484"
    },
    {
      "rank": 1562,
      "cve_id": "CVE-2026-85485",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "HTML-FormHandler",
      "cwe": "CWE-79",
      "title": "HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85485"
    },
    {
      "rank": 1563,
      "cve_id": "CVE-2026-85630",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "HTML-FormHandler",
      "cwe": "CWE-79",
      "title": "HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85630"
    },
    {
      "rank": 1564,
      "cve_id": "CVE-2026-86840",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bitfrost.io",
      "product": "Bifrost",
      "cwe": null,
      "title": "Bifrost Unauthorized Channel Commission Attribution Allows Commission Diversion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86840"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-75650",
      "detail": "ADDED TO KEV — CVE-2026-75650 (Adobe Commerce). Remediation due September 11, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-81963",
      "detail": "ADDED TO KEV — CVE-2026-81963 (Microsoft Windows 11 version 23H2). Remediation due September 22, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-85880",
      "detail": "ADDED TO KEV — CVE-2026-85880 (Microsoft Windows 10 Version 1607). Remediation due September 22, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-86218",
      "detail": "ADDED TO KEV — CVE-2026-86218 (N-able N-central). Remediation due September 11, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-52251",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-52251. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-70141",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-70141. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-70146",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-70146. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-70147",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-70147. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-70148",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-70148. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-70149",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-70149. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-70150",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-70150. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-70151",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-70151. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-70152",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-70152. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-32146",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-32146 (Gleam). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4740",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4740 (Red Hat multicluster engine for Kubernetes 2.1). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4878",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67276",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67276 (Mikrotik RouterOS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67277",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67277 (Mikrotik RouterOS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67278",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67278 (Mikrotik RouterOS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67279",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67279 (Mikrotik RouterOS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67281",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67281 (Mikrotik RouterOS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67299",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67299 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67301",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67301 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67302",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67302 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67304",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67304 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67305",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67305 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67306",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67306 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69414",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69414 (Microsoft Malware Protection Engine). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71624",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71624. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71626",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71626. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-79697",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-79697 (Advantech WISE-6610-NB). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-80116",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-80116 (PassMark Software PerformanceTest). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82547",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82547 (Linux Foundation Magma). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85046",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85046 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85381",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85381 (light0011 cms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85399",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85399 (code-projects Hospital Information System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85406",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85406 (Eleveo Quality Management). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85513",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85513 (StackStorm st2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85636",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85636 (jofpin trape). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85643",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85643 (code-projects Online Shopping System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85701",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85701 (ramon-victor freegpt-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-85702",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-85702 (ramon-victor freegpt-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86060",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86060 (Mikrotik RouterOS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86159",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86159 (SourceCodester Online Voting System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86160",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86160 (SourceCodester Online Voting System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86162",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86162 (SourceCodester Online Voting System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86163",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86163 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86164",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86164 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86165",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86165 (Tenda HG10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86167",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86167 (Tenda HG10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86168",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86168 (code-projects Content Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86171",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86171 (DefaultFuction CRM). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86175",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86175 (netbox-community netbox). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86177",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86177 (pterodactyl panel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86178",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86178 (pixelfed). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86179",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86179 (code-projects Daily Expense Manager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86180",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86180 (code-projects Task Management System In PHP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86182",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86182 (diem-project diem). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86209",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86209 (SourceCodester Class and Exam Timetabling System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86211",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86211 (rabindralamsal inventory-management-system). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86214",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86214 (Mstfakts College-Management-System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86216",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86216 (code-projects Hotel and Tourism Reservation in PHP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86220",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86220 (SourceCodester Class and Exam Timetabling System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86221",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86221 (SourceCodester Class and Exam Timetabling System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86223",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86223 (SourceCodester Class and Exam Timetabling System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86225",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86225 (SourceCodester Class and Exam Timetabling System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86226",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86226 (Projectwolds Online Attendance System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86228",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86228 (JeecgBoot). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86232",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86232 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86233",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86233 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86235",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86235 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86237",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86237 (openagents-org openagents). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86238",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86238 (projectworlds Online Examination System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86240",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86240 (liufee FeehiCMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86244",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86244 (FastAdmin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86245",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86245 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86261",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86261 (sfturing hosp_order). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86263",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86263 (sfturing hosp_order). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86264",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86264 (sfturing ssm_pro). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86267",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86267 (itsourcecode Information System Society Membership System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86269",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86269 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86270",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86270 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86272",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86272 (Beijing Meite Software Technology U+Smart Enjoyment WebSite). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86274",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86274 (projeto-siga siga). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86275",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86275 (SourceCodester Syllabus-Aligned Learning Management & Examination System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86277",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86277 (SourceCodester Syllabus-Aligned Learning Management & Examination System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86278",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86278 (SourceCodester Syllabus-Aligned Learning Management & Examination System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86280",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86280 (SourceCodester Syllabus-Aligned Learning Management & Examination System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86282",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86282 (jaychouchannel Tourism-Management-System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86284",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86284 (jaychouchannel Tourism-Management-System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86288",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86288 (ModelCloud GPTQModel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86290",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86290 (SourceCodester Online Voting System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86291",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86291 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86293",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86293 (SourceCodester Simple Traffic Offense System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86295",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86295 (D-Link DIR-895L). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86296",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86296 (D-Link DIR-822A). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86298",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86298 (SourceCodester Class and Exam Timetabling System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86300",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86300 (Tenda AC9). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86301",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86301 (code-projects Hospital Information System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86306",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86306 (light0011 cms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86307",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86307 (light0011 cms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86309",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86309 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86318",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86318 (java-json-tools json-patch). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86321",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86321 (java-json-tools jackson-coreutils). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-42385",
      "detail": "RESCORED — CVE-2024-42385 (Cesanta Mongoose Web Server). CVSS 4 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-42386",
      "detail": "RESCORED — CVE-2024-42386 (Cesanta Mongoose Web Server). CVSS 8.2 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-42391",
      "detail": "RESCORED — CVE-2024-42391 (Cesanta Mongoose Web Server). CVSS 4.3 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-42392",
      "detail": "RESCORED — CVE-2024-42392 (Cesanta Mongoose Web Server). CVSS 4 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-48651",
      "detail": "RESCORED — CVE-2025-48651 (Google Android). CVSS 4 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16689",
      "detail": "RESCORED — CVE-2026-16689 (IBM App Connect Enterprise). CVSS 6.2 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16693",
      "detail": "RESCORED — CVE-2026-16693 (IBM i). CVSS 4.4 → 4.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16826",
      "detail": "RESCORED — CVE-2026-16826 (IBM i). CVSS 5.3 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17057",
      "detail": "RESCORED — CVE-2026-17057 (IBM i). CVSS 6.5 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17207",
      "detail": "RESCORED — CVE-2026-17207 (IBM i). CVSS 6.5 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17255",
      "detail": "RESCORED — CVE-2026-17255 (IBM i). CVSS 4.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17259",
      "detail": "RESCORED — CVE-2026-17259 (IBM i). CVSS 4.3 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-17270",
      "detail": "RESCORED — CVE-2026-17270 (IBM i). CVSS 4.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18076",
      "detail": "RESCORED — CVE-2026-18076 (IBM i). CVSS 4.3 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18078",
      "detail": "RESCORED — CVE-2026-18078 (IBM i). CVSS 4.3 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18175",
      "detail": "RESCORED — CVE-2026-18175 (IBM i). CVSS 8.1 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18221",
      "detail": "RESCORED — CVE-2026-18221 (IBM i). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18341",
      "detail": "RESCORED — CVE-2026-18341 (IBM i). CVSS 6.3 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18567",
      "detail": "RESCORED — CVE-2026-18567 (IBM Db2 Mirror for i). CVSS 4.4 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-18858",
      "detail": "RESCORED — CVE-2026-18858 (IBM i). CVSS 3.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19301",
      "detail": "RESCORED — CVE-2026-19301 (IBM Langflow OSS). CVSS 5 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19305",
      "detail": "RESCORED — CVE-2026-19305 (IBM Langflow OSS). CVSS 8.6 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-27222",
      "detail": "RESCORED — CVE-2026-27222 (Adobe Experience Manager as a Cloud Service). CVSS 5.5 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-27238",
      "detail": "RESCORED — CVE-2026-27238 (Adobe Experience Manager as a Cloud Service). CVSS 7.8 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-27258",
      "detail": "RESCORED — CVE-2026-27258 (Adobe Experience Manager as a Cloud Service). CVSS 5.5 → 5.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-62916",
      "detail": "RESCORED — CVE-2026-62916 (Microsoft Entra). CVSS 9.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-65818",
      "detail": "RESCORED — CVE-2026-65818 (Microsoft Power Platform). CVSS 8.5 → 9.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69855",
      "detail": "RESCORED — CVE-2026-69855 (Microsoft Copilot in Azure). CVSS 7.7 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70178",
      "detail": "RESCORED — CVE-2026-70178 (Microsoft Fabric). CVSS 8.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70429",
      "detail": "RESCORED — CVE-2026-70429 (Jenkins Project Jenkins). CVSS 8.1 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-71407",
      "detail": "RESCORED — CVE-2026-71407 (Fortinet FortiOS). CVSS 5.6 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-75007",
      "detail": "RESCORED — CVE-2026-75007 (Roundcube Webmail). CVSS 5.4 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-75010",
      "detail": "RESCORED — CVE-2026-75010 (Roundcube Webmail). CVSS 6.4 → 4.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-76956",
      "detail": "RESCORED — CVE-2026-76956 (libexpat project libexpat). CVSS 5.9 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-76957",
      "detail": "RESCORED — CVE-2026-76957 (libexpat project libexpat). CVSS 4.9 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-77640",
      "detail": "RESCORED — CVE-2026-77640 (torproject Tor). CVSS 3.7 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-77641",
      "detail": "RESCORED — CVE-2026-77641 (torproject Tor). CVSS 6.5 → 8.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-77642",
      "detail": "RESCORED — CVE-2026-77642 (torproject Tor). CVSS 7.5 → 9.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-80098",
      "detail": "RESCORED — CVE-2026-80098 (Microsoft Copilot Studio). CVSS 9.3 → 10 (NVD)."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2021-47996",
      "detail": "REJECTED — CVE-2021-47996 (sparklemotion nokogiri). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2022-50998",
      "detail": "REJECTED — CVE-2022-50998 (sparklemotion nokogiri). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2022-50999",
      "detail": "REJECTED — CVE-2022-50999 (sparklemotion nokogiri). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2022-51000",
      "detail": "REJECTED — CVE-2022-51000 (sparklemotion nokogiri). Record withdrawn by the CNA."
    },
    {
      "type": "REJECTED",
      "cve_id": "CVE-2023-54354",
      "detail": "REJECTED — CVE-2023-54354 (sparklemotion nokogiri). Record withdrawn by the CNA."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2022-51016",
      "detail": "PATCH SHIPPED — CVE-2022-51016 (pmmp PocketMine-MP). Fixed in PocketMine-MP 3.27.0."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2022-51017",
      "detail": "PATCH SHIPPED — CVE-2022-51017 (pmmp PocketMine-MP). Fixed in PocketMine-MP 3.26.5."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2022-51018",
      "detail": "PATCH SHIPPED — CVE-2022-51018 (pmmp PocketMine-MP). Fixed in PocketMine-MP 3.26.5."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-18743",
      "detail": "PATCH SHIPPED — CVE-2026-18743 (rpm-software-management popt). Fixed in Red Hat Hardened Images 1.19-11.1.hum1."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-23255",
      "detail": "ENRICHED — CVE-2026-23255 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-23399",
      "detail": "ENRICHED — CVE-2026-23399 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-31681",
      "detail": "ENRICHED — CVE-2026-31681 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-43085",
      "detail": "ENRICHED — CVE-2026-43085 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-43089",
      "detail": "ENRICHED — CVE-2026-43089 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-43492",
      "detail": "ENRICHED — CVE-2026-43492 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64369",
      "detail": "ENRICHED — CVE-2026-64369 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64370",
      "detail": "ENRICHED — CVE-2026-64370 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64371",
      "detail": "ENRICHED — CVE-2026-64371 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64373",
      "detail": "ENRICHED — CVE-2026-64373 (Linux). Received CVSS 4.7 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64376",
      "detail": "ENRICHED — CVE-2026-64376 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64377",
      "detail": "ENRICHED — CVE-2026-64377 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-64381",
      "detail": "ENRICHED — CVE-2026-64381 (Linux). Received CVSS 7.8 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
